Insights & Trends
RSSThe Out-of-Band Paradox
Break-glass access must never depend on the infrastructure it is meant to rescue. What audits of console-server estates keep revealing, and the design rules for management paths that survive the bad day.
RPKI: The Policy Was Perfect. The Validators Were Missing.
A fleet-wide RPKI deployment that validated nothing on several transit edges, and the general lesson about verifying effect instead of configuration presence.
Most of Your Firewall Rules Have Never Matched a Packet
In audit after audit, the large majority of firewall rules turn out to have matched zero traffic. Here is how rule bases decay, why it matters, and a guardrail pattern for cleaning up without breaking production.
Your MPLS Core Is Fine. Your VRF Import Policy Is the Problem.
How VRF route leaking silently defeats a north-south firewall model, and why east-west traffic that resolves in the fabric never sees your security policy at all.
Turning NetBox and Device Configs into a RAG Knowledge Base
Why raw CSV exports fail in retrieval-augmented generation, how narrative chunking fixes them, and when to skip RAG entirely and give the model an API instead.
Replacing the Corporate VPN with Cloudflare Zero Trust
A company-wide ZTNA rollout with the Cloudflare One agent: identity-driven access profiles, device posture enforcement, and the end of the flat VPN subnet.
Monitoring 200+ Network Devices with Zabbix, Graylog, and PagerDuty
How I built a monitoring stack for a 200+ device fleet: SNMPv3 polling, centralized logging, meaningful triggers, and alerts that arrive with context instead of noise.
Migrating a Multi-Campus Network to Cisco Catalyst Center
Moving a multi-campus network of Catalyst 9300 and 9500 switches under Catalyst Center: template-driven configuration, streaming telemetry, and the assurance data that changed how the team troubleshoots.