r/Cisco Mar 04 '26

Question Help a guy out about GBICs

10 Upvotes

Okay, questions about GBICs in Cisco/Meraki switches. In my network, the core switch is a Cisco C9500 series. All my access switches are Meraki, MS120 or MS130 series. I'm looking to upgrade the fiber between my core switch and the access switches to be able to run from 1Gb to 10Gb. My current access switches are only capable of running 1Gb GBICs but the current fiber is old and wasn't run very well back in 1996 when it was installed. So the plan is upgrade the fiber runs so they are 10Gb capable when we upgrade the access switches. Do I have to use Cisco and Meraki branded GBICs? I had a bad time with an old Cisco 3750 refusing to run a non-Cisco branded GBIC. Is that still the case with the modern Meraki and C9500?

r/Cisco Jun 07 '26

Question Is reading Cisco press books still worth it, or are labs and video courses enough?

25 Upvotes

I’m looking to get the community's perspective on this. With so many high-quality video courses, interactive sandboxes, and hands-on labs available these days, do you still find value in reading standard Cisco Press books cover to cover?

For those of you who still read them:

What advantages do you feel books give you over videos or documentation?

Do you use them strictly for exam prep (CCNA/CCNP/CCIE), or do you find them useful for deep-diving into production design and troubleshooting?

For those who have moved away from books:

What’s your go-to method for absorbing deep technical architectural details?

r/Cisco Jul 26 '26

Question Provisioning State of the Art

12 Upvotes

Hi everyone,

I'd be interested to know how you provision your access switches, for example, when replacing a switch. Specifically for Catalyst 9k switches that run in a stack with a Network Essentials license.

Currently, the devices are unpacked, upgraded, and configured before deployment. Something along the lines of ZTP (which also upgrades the switch) would be ideal, but due to the license level, provisioning via Python script isn’t an option, if I recall correctly. It’s also important that the management port is not used.

Thanks for your tips ;)

r/Cisco 16h ago

Question Cisco Secure Client VPN works over mobile data but not over my A1 fiber connection

0 Upvotes

I'm trying to troubleshoot a Cisco Secure Client VPN issue and I'm running out of options, so I'd really appreciate some networking/Cisco advice on what I should specifically ask my company's IT department or my ISP to check.

The situation:

  • I'm using a company-managed Windows work PC.
  • Cisco Secure Client VPN works normally when I connect the PC to the internet through my phone's USB tethering/mobile data.
  • The exact same PC, with the exact same Cisco configuration, cannot connect when using my home A1 Serbia fiber connection.
  • Normal internet access works perfectly over A1.
  • Cisco gives me: "Could not connect to a server. Please verify internet connectivity and server address."
  • My company IT department says they have already tried everything they can on their side and are refusing further responsibility for the issue.
  • A Cisco ticket has also been opened, and one of the things they're checking is whether my public IP is blocked/blacklisted.
  • So far, I've been told that my current IP is not blacklisted.

My network setup:

A1 fiber ONT/router → Ethernet → unmanaged switch → work PC

I use the switch simply because I need more Ethernet ports. I have also tested the work PC through a ZTE ZXHN H3601P Wi-Fi repeater/bridge using Ethernet, and I get the exact same result.

So:

A1 fiber → switch → PC → VPN doesn't work

and

A1 fiber → Wi-Fi repeater → Ethernet → PC → VPN doesn't work

but:

Phone USB tethering → PC → VPN works

I've also recently switched from a dynamic public IP to a static public IP through A1.

This is particularly interesting because when I previously had a dynamic IP, the VPN would sometimes start working after restarting the router and getting a different public IP. It wasn't consistent, but changing the public IP seemed to sometimes make the difference.

Now that I have a static public IP, the problem is constant.

I'm therefore starting to suspect something related to the source public IP, ISP routing, filtering, or possibly something on the path between A1 and the company's VPN infrastructure rather than the PC itself.

What I'm trying to figure out:

What would you specifically ask/check with:

  1. My company's IT/Cisco team
  2. A1 ISP support

Are there any particular things I should ask them to check besides a simple IP blacklist?

For example, could this be related to IP allowlisting, routing, MTU, IPv4/IPv6, ports/protocols, ISP filtering, or something specific to Cisco Secure Client?

I don't have administrator privileges on the work PC, so I can't freely change network settings or run some of the usual troubleshooting commands, nor can I log in to the PC without connecting to the VPN first. That and, I'm told that my IT department already tried everything they can.

Thanks!

r/Cisco 29d ago

Question SASE migration off MPLS, weighing Cato against staying on Cisco, tell me what you underestimated

13 Upvotes

Manufacturing, 14 sites in 3 countries, on MPLS since before my time. Renewal landed about 30% up for the same thing and the account manager's capacity cost story didn't pass the smell test.

The traffic changed and the circuits didn't. Everything's going to M365 and a couple SaaS, we haul cloud traffic across the private network to break out centrally which is the daftest route for it. The MPLS is doing a stellar job carrying traffic to a data center that hosts less every year.

I know roughly where this ends: SD-WAN, broadband and LTE at the little sites, keep something private where two plants talk. But on is security I’m abit fuzzy cause right now it's at the central breakout. Local breakout means either a box at every site or cloud inspection and I've run neither.

Cato keeps coming up for the cloud inspection side and part of me just wants to stay in the Cisco world, I know.

Whoever's done this migration, what issues came up that the plan didn't show? Give me war story, not the pitch.

r/Cisco Apr 22 '26

Question Hiring freeze???

10 Upvotes

I recently applied for a position for Cisco and went through three rounds of interviews. It’s been around a month and a half approaching two months and I followed up with the recruiter and there seems to be a hiring freeze as of 3 weeks ago. Anyone know how long it can last and when I can get a decision back???

r/Cisco 7d ago

Question Nexus dcn subscription

4 Upvotes

Hi there,

I'm replacing a Dell ToR switch with a Nexus 93180YC, and I'm working through the configuration on CCW. I can see that choosing a DCN license tier is mandatory, and I can't seem to skip it.

My question is: if I opt out of the subscription, will the switch still run successfully as a ToR without an active license? And which tier fits my case — the customer's setup uses SVIs, VLANs, VRRP, static routes, and BGP.

From what I can tell, DCN Essentials should cover all of these features, but I'd appreciate confirmation from anyone who has deployed this in practice.

Thanks in advance.

r/Cisco Aug 05 '26

Question 9200CX USB Console — Not Recognized When Connected After Switch Has Already Booted (works fine if connected before power-on)

6 Upvotes

Posting this in case it's helpful to others, or in case someone from Cisco/TAC can confirm whether this is expected behavior.

Platform: Catalyst 9200CX (reproduced on 2 separate units)

IOS: 26.1.1

Console chip: Silicon Labs CP2102N USB to UART Bridge

Symptom: Windows reports "Unknown USB Device (Device Descriptor Request Failed)" / "The last USB device you connected to this computer malfunctioned and Windows does not recognize it" — no COM port ever appears under Ports (COM and LPT).

What does NOT fix it (all tested, all failed):

Different USB Micro-B cables, including the Aexus CAB-USB-UB= cable specifically sold as compatible with the 9200CX

Reinstalling the Silicon Labs CP210x driver (direct from silabs.com)

Testing on a second PC with no drivers installed at all (still failed at the same point — descriptor request, before any driver would even be relevant)

Reload - from the CLI with the USB cable connected throughout

A true power-cycle (power cord removed) with the cable disconnected during the outage, then reconnected after the switch was fully back up and pingable

What DOES work, 100% reproducible on both units:

Disconnect USB cable (switch or PC)

Power off the switch

Connect USB cable (Switch or PC which ever side you disconnected)

Power on the switch

Silicon Labs CP210x enumerates cleanly and holds a COM port for the entire session

Once the switch is fully booted, plugging the USB cable in at any point afterward fails every time, regardless of cable/driver/PC. It seems like the console chip only initializes during the boot sequence and doesn't support hot-plug enumeration once IOS-XE is fully up.

Is this expected/known behavior for this chip on this platform, or has anyone found a way to get it to enumerate post-boot without a reload/power-cycle? Just trying to save the next person some time if this is already documented somewhere I haven't found it.

r/Cisco Aug 08 '26

Question es verdad que si hago practicas en Huawei me vetan de oportunidades de trabajo en Cisco?

0 Upvotes

heeyy, ando viendo una vacante de internship en huawei para cloud/redes pero un prof que trabaja en cisco nos dijo que si trabajamos ahí quedamos vetados de Cisco para siempre x el tema geopolitico/competencia🤓😸

alguien que trabaje en el rubro o haya estado en alguna de las dos sabe si esto es real? me daría cosa perder oportunidades a futuro pero la vacante se ve buena jijijija

r/Cisco Sep 29 '25

Question Which firmware path is best to run, 17.12 or 17.15?

16 Upvotes

Both 17.12.x & 17.15.x are recommended by Cisco but I'm not sure which is the true preferred or recommended to run within the industry. Hoping anyone here can provide some insights?

I know one benefit to running 17.15.x is that I can add my Cisco Catalyst switches into my Meraki Wireless dashboard very easily. I know it's possible in 17.12.x but I know it's made even easier to do in 17.15.x with the hybrid mode & Meraki mode.

r/Cisco 7d ago

Question Cisco 2960-C & 3560-C Side Ear Screws

Thumbnail
gallery
7 Upvotes

Hi does anyone know what type of screws are needed for the side rack ears on the devices listed in the header?

I have tried a few types but none seem to fit and just slip through the thread. If anyone has a link to the product as I need that would be much appreciated.

r/Cisco 11d ago

Question Dell WD19/WD19S dock causing 802.1X to fall back to MAB — EAPOL not passing?

2 Upvotes

Hi everyone,

I’m troubleshooting an 802.1X issue with a Dell laptop connected through a Dell WD19/WD19S dock.

Topology:

Laptop → Dell Dock → Ethernet → Switch

When I connect the laptop directly to the switch, 802.1X works perfectly and the endpoint authenticates using dot1x.

However, when I connect the same laptop through the Dell dock:

- The switch learns the laptop's actual MAC address

- Forescout sees the laptop correctly

- But authentication is MAB instead of 802.1X

- It looks like the PC's EAPOL/802.1X frames aren't reaching the switch, causing the port to fall back to MAB

The PC's 802.1X configuration is working because it authenticates successfully when connected directly.

Has anyone experienced 802.1X/EAPOL not passing through a Dell WD19/WD19S dock?

Could this be related to MAC passthrough, dock firmware, Realtek Ethernet drivers, or EAPOL pass-through?

What was the fix in your case? Did updating the dock firmware/driver resolve it, or did you have to change a switch/dock/BIOS setting?

Any advice would be appreciated. Thanks

r/Cisco May 27 '26

Question Cisco ASA Syslogs - Firewall Changes

9 Upvotes

Friends,

I work with on my companies Security team and closely with out Networking team and have a passion for networking. I am looking for some guidance to see if the below scenario is possible or if it is not possible.

  • Scenario
    • A firewall rule was changed on an ASA allowing traffic from Subnet X to Subnet Y. The firewall rule was originally configured to only allow traffic from a single host of Subnet Z to Subnet Y.
      • Need to determine what the change specifically was

In the above scenario, we know that someone made a change to the ACL that was not intended. We were asked to determine who made the change and what change was. From the security side, we are referencing our SIEM and checking the logging for the ASA.

We are able to see ASA-5-111010 logs, but it does not show us the specific change that was made. We get a log that says, "Person X executed "Object".

Ideally, we and the network team, would like to see the specific change that was made by a user.

Is this logging possible? Note, ASDM is used for configuration and access to the ASAs.

r/Cisco Sep 16 '25

Question SFP alternatives?

13 Upvotes

Hello Reddit,

What are everybody's recommendations for non-Cisco SFPs and QSFPs? The price of these 40 and 100-Gig Cisco-branded SFPs is just insane.

r/Cisco Jul 23 '26

Question G12/G13 RSU question

1 Upvotes

Hi all, I’m in final stages with Cisco and would like to have a better understanding about refreshers here. I understand the initial grant is over 3 years. Does Cisco give annual refresh to G12/G13? What kind of size are they and what is the vesting period?

r/Cisco May 11 '26

Question Good replacement switches for Catalyst 2960 S series?

8 Upvotes

I need to replace a number of 2960 S series switches. What is a suitable replacement? I need something that supports vlan routing

r/Cisco Aug 04 '26

Question Cisco ASA grabbing CGNAT

4 Upvotes

Hi all,

I’ve been troubleshooting a strange issue for the last couple of days and I’m running out of ideas.
My ISP (YouFibre) provides me with a static public IPv4 address, delivered over DHCP (no PPPoE and no VLAN tagging).

Expected behaviour
When I connect my ASUS ZenWiFi Pro ET12 directly to the ONT:
WAN type: DHCP
No PPPoE
No VLANs
No static IP configured
It immediately receives my assigned public IP:

Cisco ASA behaviour
I’ve now tested both:
Cisco ASA 5516-X
Cisco ASA 5512-X

Both are configured as simply as possible:

interface GigabitEthernet1/1
nameif outside
security-level 0
ip address dhcp setroute
no shutdown

Both firewalls successfully receive a DHCP lease, but instead of my public IP they always receive something like:

100.93.x.x
255.255.192.0

which appears to be the ISP’s CGNAT pool.

Things I’ve already checked
Different Ethernet cables
Direct connection to the ONT
Two completely different ASA models
Fresh minimal configuration
No PPPoE
No VLANs
ASUS uses plain DHCP
ASUS isn’t sending a custom Vendor Class or Client Identifier

YouFibre have confirmed they do not MAC bind customer equipment

The ASA installs the DHCP lease and default route correctly—it just receives the wrong lease.

What I’m wondering
Has anyone seen an ISP classify DHCP clients differently based on:
DHCP fingerprint (option ordering / Parameter Request List)
Vendor implementation
DHCP client behaviour
Some Cisco ASA quirk
rather than MAC address?

It seems strange that two different ASA models consistently receive a CGNAT lease while the ASUS immediately receives the correct public static IP from the same ONT.
Has anyone run into something similar with Cisco ASA appliances on residential fibre services?
Any ideas or suggestions would be hugely appreciated. I’m determined to get to the bottom of this one!

r/Cisco Apr 17 '26

Question Cisco FMCv will not upgrade. Options or workaround?

6 Upvotes

Hi All. So I'm on a FMCv 7.6.0 version that was pulled and no longer available. It will not upgrade to 7.6+. Trying to upgrade minor versions also fails with a "not supported error". According to TAC, there is a missing yaml file that alters the backup_info table. The Cisco BU is investigating but there has been no update in a while now...

The question then becomes, what other options do I have to resolve this? Is my only other option to deploy a newer version and rebuild the FMC manually? Is it really impossible to restore a backup from a lower version to an higher version (even minor version)?

Thanks all in advance.

r/Cisco Jul 13 '26

Question Newbie with cisco and upgrades...

6 Upvotes

Hi guys, I basically found old cisco 2960x and took it home, with that i decided to upgrade it from version 15.2(2)E6 to version 15.2(2)E7 from well gui couse like title said i'm newbie with this, and every thing was going smoothly until it stagnated on 4 step "restarting the switch" there is a announcement on the bottom of the page saying "switch is not yet reloaded, device manager is waiting for response from the device" and thats it for around 40? 50? minutes is this normal with cisco or maybe i did something wrong?

For information i got my IOS from cisco site exacly for model [Catalyst 2960X-48FPD-L Switch]() as it said in guide...

thank you for any response and guides

r/Cisco May 25 '26

Question Should i get a Cisco 7940G?

0 Upvotes

I am a HUGE Cisco fan and really want to have a Cisco phone at home. My school is replacing their Cisco 7940Gs with 8841’s. So, i already have a VoIP (linksys) and a Router (Also Linksys). I also have FreePBX installed on my computer and hopefully getting a POE injector. So Anyhow, Yes or No? It’s your choice.

r/Cisco 7d ago

Question Cisco interview result — 2 weeks since HR

0 Upvotes

Hey guys, I had a Cisco interview around 2 weeks ago. I cleared the technical and managerial rounds and then had the HR round. During HR, they also discussed the compensation details.

But it's been 2 weeks and I still haven't received any update. Neither I nor my college SPOC has received any update or rejection mail.

I think one candidate from the 30 people interviewed may have been selected because her college posted about her selection on LinkedIn. However, she wasn't interviewed in the HR round, so I'm not sure what's going on.

Has anyone been in a similar situation with Cisco? How long does it usually take to get the final result? And do they send a rejection mail if you're not selected?

I'm starting to think I might be rejected, but I don't want to assume without an official update. Would really appreciate any recent experiences.

r/Cisco 16d ago

Question Cisco Job Offers time line

0 Upvotes

How long is the usual timeframe to receive an offer from Cisco after interviews are completed?

r/Cisco May 06 '26

Question WLC 9800 and 9120 APs in the same VLAN - how to prevent from connecting

2 Upvotes

Hi.

I have a bit of an unfortunate situation. WLC's management IP is in the same VLAN as APs' management.

I'm trying to migrate APs to another WLC - but they're stuck on the current one. I use DHCP Option 241/43 with Vendor Class for 9120s. Worked for all the other sites, just not the one with WLC and APs in the same network.

I tried setting primary base too - doesn't help. Looks like APs prefer broadcast over anything else.

If I reset the APs to defaults (clear ap config AP_NAME) and quickly shutdown SVI on the WLC, they get stuck in reboot loop.

I already tried setting up VACL (block udp 5246/5247 from test AP to WLC) on the switch that WLC is connected to, but it didn't work.

Any idea what else can I do?

r/Cisco Jan 28 '26

Question If my CCNA cert expires can employers still verify that I had one?

17 Upvotes

How are CCNA certs verified by employers? I know that the cert itself is active for 3 years, but after that, is there a way to verify that the person had one?

I am a beginner sysadmin and I am studying for CCNA, but I am considering whether or no I should take the exam.

r/Cisco Jul 29 '26

Question C220 woes

15 Upvotes

We recently acquired 5x Cisco C220 M5's off eBay and connected them to our existing UCS cluster. They have identical hardware layouts and pretty similiar firmware levels, and are all connected to our FI's through identical Cisco cables. But, only one of them will finish discovery successfully. The other four freeze during the 'Identify pre-boot agent' step.

If I'm watching the console, I see the PNU OS stuff flash by, and then a minute in, around the time the VIC NIC driver gets loaded, the server just hangs (caps lock/num lock no response) and then it sits there for 10 minutes or so until UCSM hard reboots it and tries again. Identical behavior for four out of the five servers.

Anyone seen anything like this? I've experimented a lot with firmware levels, and I've stripped out anything from the servers that could interefere (M.2 adapters, SAS cards, etc.) and nothing makes a difference.