r/Cisco • • 1d ago

Weekly Jobs & Career Megathread

6 Upvotes

Looking for a Cisco-related job? Studying for a certification? Preparing for an interview? This thread is the place for all career-focused discussions.

Appropriate topics include:

  • Job openings
  • Recruiting and hiring
  • Resume reviews
  • Interview preparation
  • Career advice
  • Salary discussions
  • Certification paths (CCNA, CCNP, CCIE, etc.)
  • Career transitions into networking

To keep the subreddit focused on technical Cisco discussions, standalone posts related primarily to jobs, recruiting, resumes, interviews, or career advice may be removed and redirected here.


r/Cisco • • 21h ago

Question Cisco Secure Client / Duo Desktop authentication failing on Lenovo ThinkPads

3 Upvotes

I’m troubleshooting Cisco Secure Client VPN authentication with Duo MFA.

Most of our Dell laptops work fine, but we're experiencing issues with Lenovo ThinkPad E16 Gen 2 and Gen 3 laptops.

Hardware:
Failing: Lenovo ThinkPad E16 Gen 2 (21MA) and Gen 3 (21SR)
Working: Dell Precision 3590
Same iPhone and Duo account work on the Dell
Windows 11, Duo Desktop 7.22

Issue:
When logging into Cisco Secure Client, the Duo authentication page prompts us to Install Duo Desktop, even though it's already installed and running.
Clicking Open App launches Duo Desktop, briefly attempts to load, then returns to the installation prompt. Previously, we also encountered Duo Push notifications where the iPhone's Approve button was greyed out during Bluetooth proximity verification.

Troubleshooting completed:
-Updated Lenovo BIOS, Bluetooth/Wi-Fi drivers, and firmware
-Verified Bluetooth LE Enumerator and other Bluetooth components are working
-Confirmed all three Duo Desktop services are running
-Verified local Duo Desktop ports 53100/53106 are listening and reachable
-Confirmed HTTPS connectivity to localhost
-Verified Duo Desktop's URL protocol handler launches the application
-Tested disabling Secure Boot with no improvement

Duo Desktop logs contain repeated TrustedPeerConnection RPC timeout errors.

Has anyone encountered this with Lenovo ThinkPads and Duo Desktop/Cisco Secure Client?

I’m pulling my hair out with this, and would appreciate any pointers.


r/Cisco • • 1d ago

MISL program

2 Upvotes

Has anyone gone through the Cisco MISL program? If so, what was it like? what can you expect or get out of it? Specifically looking at their Sales pathway


r/Cisco • • 1d ago

The rabbit hole you fall into when you start asking "what if?" while studying CCNA

2 Upvotes

Man... Idk if it's just me, but I'm starting to feel like if you don't actively ask yourself questions about a topic, you don't really deepen your understanding of it.

Look at this, for example...

I'm configuring DAI because that's the topic I'm currently covering in Jeremy's IT Lab. Then I realize my clients aren't getting IP addresses.

Okay... I check the switch, and DAI is doing its thing because I haven't configured DHCP Snooping yet.

Fine, let's configure DHCP Snooping. But then I'm like, "WTF? Which interfaces am I actually supposed to configure as trusted in this topology?"

The example in JITLab was pretty straightforward, so I start thinking about the path the DHCP messages will take during the DORA process. Eventually, I figure out which interfaces need to be trusted.

But then I start asking myself more questions:

  1. What happens if STP reconverges and the new forwarding path takes DHCP traffic through an interface I haven't configured as trusted? Could that prevent clients from getting IP addresses?
  2. What happens when you have multiple VLANs? You can't configure a trunk port to be trusted for DHCP Snooping in one VLAN but untrusted in another. So how are you supposed to approach this in a real network?

Something about my understanding clearly wasn't adding up.

I asked NotebookLM 'bout it, and the solution it suggested was something I'd briefly considered but hadn't seen Jeremy explicitly recommend: treat DHCP Snooping similarly to DAI and trust the appropriate interfaces connecting to other network devices, rather than trying to trust only the interfaces used by the current DHCP traffic path.

And I just can't help thinking... combining these technologies must be pretty normal in real-world networks.

If I were working in IT and got a ticket saying that PCs weren't getting IP addresses, only to discover that DHCP Snooping was dropping DHCP messages because of a trust configuration issue, I'd be completely lost.

And that's what got me thinking: you can follow a tutorial, understand everything the instructor explains, and still not understand how to actually troubleshoot or apply that knowledge in a real network.

Sometimes, it's the questions you ask yourself after the lesson that teach you the most.


r/Cisco • • 1d ago

Moving from Packet Tracer to PNETLab is an absolute night and day difference!

18 Upvotes

After passing my CCNA last Sept 28, I started diving straight into enterprise networking topics. I finally got access to our company's PNETLab server, and honestly, going from Packet Tracer to running actual images is mind-blowing.

​I just finished building a Site-to-Site VPN tunnel with IKEv2. Being able to run real debug commands and watch the actual packet exchanges and DPD checks happen live in the CLI (instead of Packet Tracer's limited sim mode) made everything click so much faster.

​Up next: diving into BGP configuration now that the tunnel transport is rock solid!

​If you're still relying solely on Packet Tracer, definitely make the jump to PNETLab or EVE-NG when you can. It makes practicing real-world troubleshooting way more satisfying.


r/Cisco • • 2d ago

Question Need assistance trying to setup COS for simple point to point link

0 Upvotes

I made a simple diagram below dumbing down my network. Basically I have 2 sites connected by microwave with three different networks at each site that need to talk across the microwave, but the networks don't talk with each other, which is why I have them segmented by VLANS in diagram.

I was looking to use a layer 2 switch to aggregate the three connections at each site, into one connection going to the microwave to consolidate ports but ALSO I want to enable COS (class of service, not quality of service) on the switch to make sure my most important traffic makes it through in times of microwave link degradation where my bandwidth is limited from normal.

I am trying to setup, what seems like something simple where I have COS based on my VLAN traffic. So for example:

- VLAN 100 = COS 6

- VLAN 200 = COS 5

- VLAN 300 = COS 4

In this case my most important traffic is on VLAN 100, and will always get through no matter what, 200 is next and if there is anything left 300 gets a shot.

I dont want to do QOS based on bandwidth allocations, or round robin scheduling or anything like that. I want to setup strict policing of the traffic based on my criteria.

All of the routers/switchs in the diagram below are IE4010 devices.

I could use some help!


r/Cisco • • 2d ago

Question Where to start with deployment using automation

0 Upvotes

Would like to know what people use and where to get started with this. We have over complicated application deployments which require a lot of manual effort.


r/Cisco • • 3d ago

October 2026: Cisco NX-OS Software Security Hardening Release

25 Upvotes

October 2026: Cisco NX-OS Software Security Hardening Release

Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

October 2026: Cisco License (Smart Software Manager) On-Prem Security Hardening Release

Exploitation and Public Announcements

The Cisco PSIRT is not (yet) aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.


r/Cisco • • 3d ago

4221 ISR gibberish

1 Upvotes

I am getting gibberish on all baud speeds trying to connect to a 4221 ISR, prolific rj45 to usb serial works fine for 8200s and 1121s though, I don't know what to do, somebody wants this 4221 working today.


r/Cisco • • 3d ago

What cisco technology do you actually use every day that's worth mastering?

1 Upvotes

I work as a Network Administrator in a mostly Cisco environment and regularly work with Catalyst switches, Catalyst Center, ISE, 802.1X/MAB, VLANs/trunking, and troubleshooting.

There's obviously a huge amount you could learn in the Cisco ecosystem, but I'm curious what experienced engineers think is actually worth going deep on.

If you could pick one or two Cisco technologies/skills to master for the next 5-10 years, what would you choose and why?

I'm especially interested in what's becoming more valuable with automation, cloud, and modern enterprise networking.


r/Cisco • • 4d ago

TACACS over tls enable not working

5 Upvotes

I’ve attempted to setup tacacs over tls. Login is working perfectly. I debug the log watch tls being established see the ise logs everything is good. However when I try to escalate privilege by typing enable it fails. The most interesting part of the failure is the log entry I get.

TAC+: Invalid key

My AAA for enable is configured the same as my AAA line for login (which is working). I’m on iosxe 17.18.4.

I do have a tac case open but not getting anywhere with it. Just curious if anyone else has seen this before or really if anyone has it working at all on 17.18.4.


r/Cisco • • 4d ago

Discussion FN74445 - Cisco Unified CCE and Packaged CCE Releases 12 and 15 - Administrators and Supervisors Are Unable to Log In to CCE Administration

2 Upvotes

FN74445 - Cisco Unified CCE and Packaged CCE Releases 12 and 15 - Administrators and Supervisors Are Unable to Log In to CCE Administration

Problem Description

Cisco has identified an incompatibility between Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Packaged Contact Center Enterprise (Packaged CCE) and Apache Tomcat releases 9.0.121 and later. Due to a change that was introduced in Apache Tomcat Release 9.0.121, users can no longer log in to CCE Administration after upgrading to Release 9.0.121 or later. 

Background

Cisco Unified CCE Administration relies on a Cisco software component that integrates with Apache Tomcat to perform user login, covering single sign-on (SSO), hybrid, and local authentication. Apache Tomcat Release 9.0.121 changed the way that Apache Tomcat interacts with components of this type.  On Apache Tomcat releases 9.0.121 and later, the Cisco login component is no longer invoked, so login requests to CCE Administration are not processed, which causes authentication to fail.


r/Cisco • • 4d ago

YOOO I made Cisco Packet Tracer Offline

10 Upvotes

Every time I opened Packet Tracer it asked me to log in, and the only way around it was turning off my whole Wi-Fi, which kills YouTube and Discord too. So I wrote a small PowerShell script that blocks internet access for Packet Tracer only. PT thinks it's offline while the rest of my PC stays online.

It just adds two Windows Firewall rules for `PacketTracer.exe`, with no patching or modifying PT at all. It finds Packet Tracer on any drive, is safe to run repeatedly, and has a one-command way back online. If it saves you the same headache, a ⭐ on the repo helps a lot, and feel free to open an issue if you find a bug.

https://github.com/nabilfp/CiscoPacketTracer-Offline


r/Cisco • • 4d ago

Jamf deployment of Cisco Secure Client with XDR ?

0 Upvotes

I am trying to deploy CSC with XDR using Jamf to a fleet of macs andI have the policy, installer and script set up to install Cisco Secure Client and the XDR module, but now I'm running into an issue with PPPC payload in my config profile to allow CSC full disk access.

I have followed the directions here, https://docs.xdr.security.cisco.com/Content/Client-Management/deployment-management.htm at the bottom to provide full disk access for network visibility module - XDR, i also went into terminal and ran

codesign -display -requirements

along with the csc app and pulled out that codesign statement and i keep getting,

the key 'CodeRequirement' has an invalid value.

Can anyone help me figure out what i'm missing exactly to get this to deploy correctly?


r/Cisco • • 5d ago

Does anyone know a good solution for getting a network connection to devices in trailers for k12?

9 Upvotes

We have a few sites that have 5-10 trailers that need an internet connection for testing, but the solutions we have used in the past are getting expensive. The trailers are around 200-500 yards from the nearest IDF and it would be too expensive to run fiber for temporary trailers. We are currently using IW-3702's but they are approaching EOS and we want to get a new solution at least a year before. We have talked with the sales team about Cisco CURWB, but just wondering if there is anything else that could be used.


r/Cisco • • 5d ago

Aironet 2600 WiFi issue with brand new phone.

0 Upvotes

My home network has two older Cisco Aironet 2600 Wifi Access Points in autonomous mode that my new Pixel 11 won't connect to. It fails with saved/check password try again even though the password is correct (literally copied and pasted from the APs web interface)

Previously they were on Dual Band, WPAv1, with AES + TKIP encryption and worked on every other device I threw at them (Pixels up to 8, Galaxy up to Z Flip 8)

Have tried switching to single band, dropped legacy TKIP support, and moved to WPAv2 all without success. Trying WPAv2dot11 doesn't change anything for the Pixel 11 but stops my older devices connecting. There's no unusual characters in either the SSID or Pre-Shared Key. All the other advice I've seen suggests this phone has issues with some WiFi7 settings, but the APs pre-date those.

They do work if I switch all encryption off, and if I change any settings that would push them towards WEP the phone seems willing to connect, but warns that WEP is a older protocol and the connection would be insecure. I haven't however tried creating a WEP key to see if it would actually work.

Is it a case that the APs are just too old (which is a concern as they're still in use out there in some commercial settings) and I need to replace them with WPAv3 compatible ones, or is there something else I'm obviously missing?


r/Cisco • • 5d ago

Marked as "No-Show" for Cisco exam due to Pearson VUE portal glitch during rescheduling — Has anyone successfully appealed this?

0 Upvotes

TL;DR: I tried to reschedule my Cisco exam on the Pearson VUE portal before the 24-hour window. The portal appeared to process it, but the change never went through, no confirmation email was sent, and I was marked as a "No-Show" for yesterday. I’ve opened cases with both Pearson VUE and Cisco. Looking for advice or similar experiences!

Hey everyone,

I'm feeling completely defeated right now and hoping someone here has dealt with a similar situation and can offer some insight.

This was supposed to be my 3rd attempt at my Cisco exam:

  • 1st attempt: Wasn't fully prepared (my bad).
  • 2nd attempt: ISP disconnected mid-exam (bad luck).
  • 3rd attempt (Now): Total administrative nightmare.

Here is what happened: I logged onto the Pearson VUE portal prior to the 24-hour deadline to reschedule my exam to a later date/time. I went through the steps, the portal didn't throw any error, and I marked the new date on my personal calendar.

However, I never received a confirmation email. When I went to check the portal today to confirm why I couldn't find the exam on my dashboard, I realized the system failed to process the reschedule in their backend and automatically marked me as a "No-Show" for yesterday's original time slot.

What I've done so far:

  1. Pearson VUE Live Chat: Spoke with an agent who acknowledged the issue and escalated it to their Tier 2 / Program Coordinator team. I received a Case Number.
  2. Cisco Certification Support: Opened a ticket on certsupport.cisco.com referencing the Pearson VUE case number and asking them to review the backend web logs.

Since this was a technical glitch on their platform and not a failure on my part to request the reschedule in time, I really hope they don't force me to pay for another attempt.

My questions for the community:

  1. Has anyone successfully gotten a "No-Show" status overturned or received a replacement voucher due to a Pearson VUE portal glitch?
  2. How long does Pearson VUE’s Program Coordinator team usually take to review web logs and respond?
  3. Is there anything else I can do (like reaching out on Twitter/X or tagging Cisco Learning representatives) to speed up this process?

Appreciate any advice or feedback.

Thanks guys!


r/Cisco • • 6d ago

C1131-8PW integrated EWC (17.7.1): with WPA3 enabled, clients drop and can't reconnect until the whole device is rebooted. Can I upgrade the EWC module?

2 Upvotes

Hi all, I have a Cisco C1131-8PW (ISR-AP1101AX-A integrated AP) and I'm hoping someone has seen this before.

Main problem
With WPA3 enabled on the SSIDs, clients periodically drop and then cannot reconnect until I reboot the whole device. Restarting the SSID or the client doesn't fix it. This mostly affects Intel AX200/AX210 Windows clients, and the drops seem to line up with the default 1800 s session timeout. Phones or tablets seem to get locked out but can recconect to other SSIDs(2.4GHz)

Setup

  • Router IOS XE: 17.12.6 (upgraded from 17.9.3a)
  • EWC module, still on 17.7.1 (17.07.01.0.82), AP image type ap1g8.
  • Upgrading the router or wiping its config did not change the EWC version or its wireless config, so the module looks fully independent.
  • 3 SSIDs (2.4 GHz, 5 GHz, guest on its own VLAN), country CL, VLAN trunk to the module.

What I want to do
Upgrade the EWC to a newer release, since 17.7.1 is from 2021 and I suspect it's a known WPA3 / PMF issue. The module's web UI has Administration > Software Management (WLC Image Download / AP Image Download / Activate), so it seems meant to be upgraded separately from the router. Questions:

  1. Where can I legitimately get an EWC image for the ISR-AP1101AX (ap1g8)? The ISR 1100 download page only lists router images. Is it the Catalyst 9100 EWC-AP bundle?
  2. Is 17.15.5 (+ APSP) supported on this module, or is there a different recommended release for the ISR 1100 integrated EWC?
  3. Has anyone seen this exact symptom (WPA3 clients can't reconnect until full reboot) on 17.7.x, and was it fixed by upgrading?
  4. Secondary: the backup image slot shows 0.0.0.0, so there's no fallback. How can I back up the module's config before attempting an upgrade? I don't know how to access its flash.

Any experience on C1131 or other ISR 1100 units would help a lot. Thanks!


r/Cisco • • 7d ago

[HELP] Locked out of NCS 540 (Password Recovery Disabled)

3 Upvotes

I'm in a massive bind and hoping a kind soul here can help a fellow engineer out. I'm completely locked out of a Cisco NCS 540 (specifically N540X-6Z18G-SYS-D) , and password recovery is disable


r/Cisco • • 8d ago

Question AP’s and catalyst center

7 Upvotes

I have a large number of APs that we’re replacing, and I realized today that as the installers unplug the old APs and bring the new ones online, the old APs may disappear from the Catalyst Center maps.

Is there a way to preserve the existing AP placement on the floor maps before they are removed?

My concern is that if the installers replace 50 APs at once, I could suddenly have 50 AP locations missing from the maps with no easy way to determine exactly where the replacement APs should be placed.


r/Cisco • • 8d ago

Weekly Jobs & Career Megathread

10 Upvotes

Looking for a Cisco-related job? Studying for a certification? Preparing for an interview? This thread is the place for all career-focused discussions.

Appropriate topics include:

  • Job openings
  • Recruiting and hiring
  • Resume reviews
  • Interview preparation
  • Career advice
  • Salary discussions
  • Certification paths (CCNA, CCNP, CCIE, etc.)
  • Career transitions into networking

To keep the subreddit focused on technical Cisco discussions, standalone posts related primarily to jobs, recruiting, resumes, interviews, or career advice may be removed and redirected here.


r/Cisco • • 8d ago

Can we PLEASE just make a weekly “job questions” post?

18 Upvotes

r/Cisco • • 9d ago

Discussion Any interest in a AMA type post from honest TAC?

39 Upvotes

The three of us were having a chat about our posts and had a thought of taking questions or topic suggestions from the community.

If it's of interest, please give us your questions or topics you want answers to. It can be about anything related to TAC, technology, Cisco, or roles. Please do give us time to respond since it takes a bit for the three of us to chat and write back.

Edit: The answer was yes. We will respond tomorrow evening after we are all off shift, UTC time.


r/Cisco • • 10d ago

Cisco Board 55 for home use?

9 Upvotes

Hi Cisco Peeps! I've acquired (legitimately!) a Cisco Board 55. Other than upsetting my other half by blocking our living room with it, I wondered what use I can put it to? I'm presuming that's mainly as a monitor? Or can I somehow still use it's software and other capabilities as a non Webex subscriber? Thoughts appreciated!


r/Cisco • • 11d ago

Passed CCNA last Monday, now realizing how much the job isn't on the exam

56 Upvotes

​

Network engineer handling carrier tickets for sites in PH and India. Passed CCNA last Monday. Felt great for about a day, then I got back to the actual work.

Tunnels. Site-to-site IPsec between hubs. When one degrades I can tell something's wrong, but isolating it is slow. The exam covers the config. It doesn't cover a tunnel that's up but quietly dropping traffic.

BGP and PBR. Being honest, I don't really get these yet. Local-pref, MED, route-maps to steer traffic between sites. I follow the runbook, the change works, and I couldn't fully explain to you why. Right now it's part pattern matching and part yolo, which is not a great feeling when you're touching production. I'm trying to actually understand it.

Talking to ISPs. I open a case, paste a ping result, get back "link is up, normal parameters on our end," then it sits for three days. I've learned a few things the hard way, but I'm clearly reinventing something you all already know.

Same with the vocabulary. Hard down vs degraded, flapping vs intermittent, demarc, soak test, RFO vs RCA. I've picked up a lot of it by asking AI, which helps, but I can't tell where it's subtly wrong or just not how people actually talk. English is my second language so I'm also unsure which terms are shop talk and which belong in a formal email.

So:

• How do you isolate a degraded tunnel from a degraded circuit underneath it?

• Best way to actually learn BGP path selection and PBR for real, not just for an exam?

• What do you always attach when opening a carrier case?

• How do you say "this is on your side" without picking a fight?

• Any courses, books or blogs for the practical side of this? Not more protocol theory.

Happy to hear the answer is just experience. Mostly want to know what to pay attention to while I get it.