<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sohaïb Rihane | Field Notes</title><description>Notes on network architecture, automation, and security from Sohaïb Rihane, Senior Technical Consulting Engineer at Cisco.</description><link>https://sohaibrihane.com/</link><language>en</language><item><title>The Out-of-Band Paradox</title><link>https://sohaibrihane.com/blog/oob-management-paradox/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/oob-management-paradox/</guid><description>Break-glass access must never depend on the infrastructure it is meant to rescue. What audits of console-server estates keep revealing, and the design rules for management paths that survive the bad day.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>out-of-band</category><category>resilience</category><category>operations</category><category>design</category></item><item><title>RPKI: The Policy Was Perfect. The Validators Were Missing.</title><link>https://sohaibrihane.com/blog/rpki-policy-without-validators/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/rpki-policy-without-validators/</guid><description>A fleet-wide RPKI deployment that validated nothing on several transit edges, and the general lesson about verifying effect instead of configuration presence.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>bgp</category><category>rpki</category><category>routing security</category><category>audit</category></item><item><title>Most of Your Firewall Rules Have Never Matched a Packet</title><link>https://sohaibrihane.com/blog/firewall-rules-zero-hit/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/firewall-rules-zero-hit/</guid><description>In audit after audit, the large majority of firewall rules turn out to have matched zero traffic. Here is how rule bases decay, why it matters, and a guardrail pattern for cleaning up without breaking production.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>firewall</category><category>security</category><category>operations</category><category>cleanup</category></item><item><title>Your MPLS Core Is Fine. Your VRF Import Policy Is the Problem.</title><link>https://sohaibrihane.com/blog/vrf-route-leaking-east-west-blind-spot/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/vrf-route-leaking-east-west-blind-spot/</guid><description>How VRF route leaking silently defeats a north-south firewall model, and why east-west traffic that resolves in the fabric never sees your security policy at all.</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate><category>mpls</category><category>vrf</category><category>security</category><category>segmentation</category></item><item><title>Turning NetBox and Device Configs into a RAG Knowledge Base</title><link>https://sohaibrihane.com/blog/netbox-rag-knowledge-base/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/netbox-rag-knowledge-base/</guid><description>Why raw CSV exports fail in retrieval-augmented generation, how narrative chunking fixes them, and when to skip RAG entirely and give the model an API instead.</description><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate><category>ai</category><category>rag</category><category>netbox</category><category>documentation</category></item><item><title>Replacing the Corporate VPN with Cloudflare Zero Trust</title><link>https://sohaibrihane.com/blog/cloudflare-warp-ztna-rollout/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/cloudflare-warp-ztna-rollout/</guid><description>A company-wide ZTNA rollout with the Cloudflare One agent: identity-driven access profiles, device posture enforcement, and the end of the flat VPN subnet.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><category>zero trust</category><category>ztna</category><category>cloudflare</category><category>security</category></item><item><title>Monitoring 200+ Network Devices with Zabbix, Graylog, and PagerDuty</title><link>https://sohaibrihane.com/blog/monitoring-stack-zabbix-graylog/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/monitoring-stack-zabbix-graylog/</guid><description>How I built a monitoring stack for a 200+ device fleet: SNMPv3 polling, centralized logging, meaningful triggers, and alerts that arrive with context instead of noise.</description><pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate><category>monitoring</category><category>zabbix</category><category>graylog</category><category>observability</category></item><item><title>Migrating a Multi-Campus Network to Cisco Catalyst Center</title><link>https://sohaibrihane.com/blog/sda-catalyst-center-migration/</link><guid isPermaLink="true">https://sohaibrihane.com/blog/sda-catalyst-center-migration/</guid><description>Moving a multi-campus network of Catalyst 9300 and 9500 switches under Catalyst Center: template-driven configuration, streaming telemetry, and the assurance data that changed how the team troubleshoots.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>cisco</category><category>catalyst center</category><category>assurance</category><category>campus</category></item></channel></rss>