r/Cisco 10h ago

Sherlock has gotten better in the past few months

28 Upvotes

The title pretty much says it all. We had a weird issue involving asymetrical routing. I've learned at this point that "AI" is only as good as the information you feed it. In this case I fed it everything it needed. Sherlock offered me a fix although it wasn't quite reasonable. It involved more cabling, more SFP's and more configuration. I pushed back and offered an idea for an alternative fix for the current design. Sherlock confirmed my fix with a limitation we could live with. The issue was fixed within 16 hours of me opening the case. 8 of those hours I was sleeping. The interesting part of all this is that these weird routing issues had cropped up in the past. I had worked with actual TAC engineers submitting endless amounts of information and spent time on Webex meetings. None of them caught on to the design flaw. We were given a work around and told what we were trying may not even work based on conflicting Cisco documentation.


r/Cisco 44m ago

Question Nexus dcn subscription

Upvotes

Hi there,

I'm replacing a Dell ToR switch with a Nexus 93180YC, and I'm working through the configuration on CCW. I can see that choosing a DCN license tier is mandatory, and I can't seem to skip it.

My question is: if I opt out of the subscription, will the switch still run successfully as a ToR without an active license? And which tier fits my case — the customer's setup uses SVIs, VLANs, VRRP, static routes, and BGP.

From what I can tell, DCN Essentials should cover all of these features, but I'd appreciate confirmation from anyone who has deployed this in practice.

Thanks in advance.


r/Cisco 1d ago

Discussion [Meta] Can we stop with these incessant hiring posts?

93 Upvotes

Title. This seems like it's devolved from a Cisco subreddit talking about the technology stack to a "have I been hired yet?!" forum. I feel like everything from this subreddit now is just hiring questions. I opened up the sub and had to scroll past several posts about applications, letters of intent and internships/apprenticeships with the company itself before getting to an actual technical question / discussion.

I get that this is a Cisco subreddit but I don't think this really fits the intent of this subreddit, and I would request at the very least that we could at least require them to be tagged so that they can be filtered out.


r/Cisco 19m ago

Discussion Need Help

Upvotes

Hey folks,

I have a lot of confusion regarding the Cisco Software Engineer Apprenticeship and would really appreciate some insights from people who have gone through it.

For someone joining as a fresher, how was the one-year experience at Cisco?

  • What kind of work/projects do apprentices usually get?
  • Does the apprenticeship actually help with technical growth and future SDE opportunities?
  • How does the FTE conversion work after the one year? What are the realistic chances of getting a full-time offer?
  • Is the conversion mostly based on performance, team requirements, or available headcount?
  • does cisco provide some days of hotel or pg stay?
  • How valuable is the Cisco apprenticeship experience if you don't get converted?

If there are any current or former Cisco employees/apprentices here, I'd really appreciate it if you could share your honest experience - both the good and bad.

There’s a lot of confusion around this, so any advice would really help. Thanks!


r/Cisco 12h ago

CCNA automation

2 Upvotes

Is the INE course for ccna automation better or is the CBT nuggets better? Any other advice is appreciated thank you!


r/Cisco 22h ago

Every SASE and firewall deck now says dynamic threat prevention, for those running it does it catch anything signatures do not?

7 Upvotes

Sitting through SASE and firewall demos for a refresh and every single one has the same slide now. Dynamic threat prevention, AI this and behavioral that, stops threats as they evolve. Every vendor. Same slide. When I ask what is under it, it comes back to IPS and anti-malware and a DNS filter which is what we already run on the firewall.

Which leaves me stuck on whether I am getting a capability we do not have or just paying more for the same three engines with a new sticker. Our signature IPS catches the commodity junk fine. Anything a bit off shape walks straight through it and that is exactly what the dynamic engines are supposed to fix.

I have been burned by this pitch before so I am not taking the deck at face value. If you run one of these in prod, I want to know whether the behavioral side ever caught something real that your signatures missed and how bad the false positives got living with it day to day. Trying to work out what is worth paying for before I sign anything.


r/Cisco 9h ago

Can plz any of the apprentice from Cisco tell about the Software Engineer conversion ?

0 Upvotes

Asking bcs I have applied for the off campus Software Engineer role …n received that a application update that a recruiter might contact me regarding the next step but no update yet.
Plz help me outtt


r/Cisco 14h ago

Cisco Job

0 Upvotes

Hello, I e been trying to get on as a AE at Cisco and they always have positions available. I’ve been in sales and account management for 13 years and just trying to break in. Any tips? Or referral


r/Cisco 1d ago

Cisco Meet and Greet

0 Upvotes

I have received an offer from Cisco India , and I’ll be starting there from October. I had recently got a call from HR for meet and greet this September which is before my joining. What should i expect?Do I get to meet my team? Do they provide any goodies welcome kit for new hire?


r/Cisco 1d ago

Can plz any of the apprentice from Cisco tell about the Software Engineer conversion ?

0 Upvotes

Asking bcs I have applied for the off campus Software Engineer role …n received that a application update that a recruiter might contact me regarding the next step but no update yet.
Plz help me outtt


r/Cisco 2d ago

Question Sticky MAC on port without it being configured

5 Upvotes

Hello, I ran into an interesting issue today where a client could not connect to the network at all.

Upon investigation, it turned out that their MAC address is still showing on the port that they were connected to earlier, and not on the port that they were actually connected to now.

The port they were connected to earlier was through some device with an integrated switch, so the port did not go down after they unplugged their cable from it.

Interestingly enough, even though we do not have sticky MACs configured anywhere, the MAC remained on the port until I manually shut the port down for a second. Once I had done that, the client could connect without issues.

The switch was a stack of Catalyst 9300 switches running IOS-XE 17.15.1 (upgrade is scheduled for next maintenance).

Has anyone run into this before? Would you expect this to be the problem of using the dumb switch passthrough of another device?


r/Cisco 1d ago

CISCO OA UPDATE (29 august 2026)

0 Upvotes

Anyone recieved any mail from cisco regarding rejection or acceptance??


r/Cisco 1d ago

Cisco Account Team LFG Training

0 Upvotes

Cisco is making their account managers basically take a CCNA training. Does anyone have example tests for this?


r/Cisco 1d ago

Question HWE fresher campus drive

0 Upvotes

Hey, I need advice on what topics to prepare for a campus placement drive by CISCO for HWE, i can share the JD. Please comment down if you have past experience with this. Ill dm you


r/Cisco 1d ago

Question DISA STIG for Cisco FTD (and FMC)? All I see is a generic Firewall STIG and ASA.

1 Upvotes

I'm trying to make sure all my ducks are in a row with STIGs. At my last job there were ASAs and they had their own STIG and the generic Firewall STIG. Does anyone have any intel on what we're supposed to do with FTDs and subsequently FMCs?

Yes, I know the generic Firewall one will get the ball rolling. But Firewalls aren't as intuitive as a catalyst layer 2 switch. Some specific FIX TEXT would be nice.

Is anyone else having this same sorta road block? Are there plans to create an FTD STIG? If it's already out there I can't find it for the life of me and I've redownloaded the newest STIG library like 3 times. Any help would be appreciated, thanks!


r/Cisco 2d ago

Question CSAP ASE

0 Upvotes

Anyone from India/Singapore who got mail for Associate Solutions Engineer role?

It's mentioned that interviews will start early September.

Also any recent CSAP alumni? post 2023 from this region? - pl reach out, had a few doubts, tried to find on LinkedIn etc, but couldn't.


r/Cisco 1d ago

Discussion Cisco Compensation

0 Upvotes

does cisco give stay compensation to software trainee engineers like any hotel or pg stay?


r/Cisco 2d ago

9300x stack wise woes

6 Upvotes

Hey guys, long time since I had to build a stack wise pair. Have one access pair of 2 x 9300x stacks and one 4x pair.

The 4x pair has now twice lost its stack member provisioning with members losing sight of the active and standby and the active and standby losing sight of each other, though stack cables are correctly connected in the ring.

It leads to the active with highest priority keeping it's config but no others showing as joined in show switch stack...some members coming up the same and all but the active sometimes rebooting into the rommon after 5 reboots (or forced by mode button) and having to get the unset STACK_1_1 and wr erase and set the member I'd as unprovisioned to provisioned on the active/master. Or by setting switch clear stack-mode on the members... Or some combination of all of these.

They aren't live yet but I have had to move a power up a couple of times now and it's happened both times.

In rommon on all switches looping in rommon I can see the correct priorities and stack members using the set command... So I'm not sure why they go out of whack. Buggy IOS firmware?

Painful waiting for the reboots to get it sorted. What's the correct process here when this happens, I must be doing something wrong in sequence but my config looks good to me?

The other 2 x access pair is fine and have had no issue.


r/Cisco 1d ago

Anyone joining Cisco Apprenticeship on 23rd September 2026?

0 Upvotes

Hey guys, is anyone else joining the Cisco Apprenticeship Program on 23rd September 2026 as a Software Test Engineer?


r/Cisco 2d ago

Cisco ASA ASDM Management (Loopback)

2 Upvotes

We have firepower 1010 running ASA image 9.18(4)68. We have a need for management access using ASDM to a unique IP that can't have on a physical or SVI interface (dont ask its a long story). We came up with using a loopback with a nameif interface.

Below is a snapshot of the configuration

interface Loopback1

nameif asdmmgmt

ip address 172.30.255.1 255.255.255.255

interface Vlan10

description LAN

nameif inside

security-level 100

ip address 10.10.10.1 255.255.255.240

management-access inside

http 0.0.0.0 0.0.0.0 inside

http server enable 4443

Couple of items to point out, we can ping the 172.30.255.1 IP no issue. However when launching ASDM to IP 172.30.255.1:4443 it times out and we see error messages below.

Sep 01 2026 15:28:13: %ASA-2-106001: Inbound TCP connection denied from 192.168.10.10/61373 to 172.30.255.1/4443 flags SYN on interface inside

Sep 01 2026 15:28:16: %ASA-2-106001: Inbound TCP connection denied from 192.168.10.10/61373 to 172.30.255.1/4443 flags SYN on interface inside

We also do not have the option of specifying HTTP access to the nameif interface asdmmgmt for some reason.

fpr-76257072(config)# http 0 0 ?

configure mode commands/options:

Current available interface(s):

inside Name of interface Vlan10

outside Name of interface Ethernet1/1

Anyone ever try this ?


r/Cisco 3d ago

Discussion Information about a Job offer at Cisco.

10 Upvotes

I got offer from Cisco. It is in common hardware group. I am an fpga developer. During the interview, I didn’t get a clear idea about the group actually does.
Does Cisco actually ship products which has fpgas in them or does it just use them for prototyping?

If you know about this group, could you share info about how working in the group is. Are layoffs an ongoing thing?

Thank you


r/Cisco 3d ago

Cisco Licensing Sanity Check

1 Upvotes

Hi - we are looking at a pair of Cisco 8711-48Z-M routers to replace some older gear. I am a little confused about what licensing I need here. We are looking at the advanced feature suite. I understand that I need either the full chassis license or I can license it per 100G of capacity (pay as you consume). Then I also see a chassis based SIA license. Is this also needed? It looks like this is a minimum of 3 years and includes the SW updates?


r/Cisco 3d ago

Question Dell WD19/WD19S dock causing 802.1X to fall back to MAB — EAPOL not passing?

2 Upvotes

Hi everyone,

I’m troubleshooting an 802.1X issue with a Dell laptop connected through a Dell WD19/WD19S dock.

Topology:

Laptop → Dell Dock → Ethernet → Switch

When I connect the laptop directly to the switch, 802.1X works perfectly and the endpoint authenticates using dot1x.

However, when I connect the same laptop through the Dell dock:

- The switch learns the laptop's actual MAC address

- Forescout sees the laptop correctly

- But authentication is MAB instead of 802.1X

- It looks like the PC's EAPOL/802.1X frames aren't reaching the switch, causing the port to fall back to MAB

The PC's 802.1X configuration is working because it authenticates successfully when connected directly.

Has anyone experienced 802.1X/EAPOL not passing through a Dell WD19/WD19S dock?

Could this be related to MAC passthrough, dock firmware, Realtek Ethernet drivers, or EAPOL pass-through?

What was the fix in your case? Did updating the dock firmware/driver resolve it, or did you have to change a switch/dock/BIOS setting?

Any advice would be appreciated. Thanks


r/Cisco 3d ago

Best SASE providers with global PoP coverage for scaling AI traffic

1 Upvotes

Looking at this from the transport side rather than the security side.

AI traffic has a different profile than the web traffic our current design was built around: long-lived connections, streamed responses, bursty token throughput, and a small number of destination endpoints concentrated in a handful of US and EU regions. Add inline inspection on top and you are doing decrypt, inspect, and re-encrypt on sessions that stay open for minutes.

What that surfaces: PoP density matters less than PoP placement relative to model endpoints; inspection adds compute at the edge, which not every PoP footprint is provisioned for; our sites in South America and Southeast Asia are already the outliers on RTT, so adding an inspection hop there is the thing I am worried about; and peering to the major cloud and AI providers varies a lot by vendor and nobody publishes it clearly.

Questions for anyone who has measured rather than trusted the marketing map: what is your real added latency for an inspected AI session from a secondary-market site; does the vendor do inspection at every PoP or only at a subset of "full-stack" locations, since several are quietly the latter; and has anyone hit throughput ceilings on inspection during peak?


r/Cisco 3d ago

Is cisco networking accademy good , Imma absolute begineer

0 Upvotes

I am in a tier 3 clg pursuing bca at my 5 sem and I am fed up by all ts coding n shit and wanna get into cybersecurity plz tell me cisco Junior Cybersecurity Analyst good or not and how much of my time it may consume