- DMVPN (4)
- IPv6 (1)
- MPLS (1)
- Network Automation (19)
- Network Security (4)
- Network Services (8)
- Quality of Service (2)
- SDN (10)
recent posts
- BGP Security best Practices for ISPs and Enterprise Networks
- Protecting BGP with Filtering and RPKI
- BGP Security
- Security Architecture: More Than Just Firewalls
- DMVPN Dual Hub Dual Cloud – Full Redundancy Design
- DMVPN Dual Hub Single Cloud: Hub Redundancy Without Losing Path Control
- DMVPN Single Hub Dual Cloud: Why Redundancy Does Not Always Mean Optimal Failover
- DMVPN Single Hub Single Cloud: Design Behavior Across Phase 1, 2 and 3
- L3VPN is not just about labels, MP-BGP, or VRFs
- IPv6 Prefix Delegation and SLAAC
- WFQ, CBWFQ and LLQ Explained in a Practical Way
- How Traffic is Classified, Marked, and Queued
- NAT
- Proxy ARP
- DNS and HTTP GET with IP SLA
- Cisco IRB (Integrated Routing and Bridging)
- GLBP Weighting
- DNS Server on Cisco IOS
- DHCP Proxy over PPP
- ARP authorized
- QoS in Cisco SD-WAN
- Application-based traffic steering And AAR
- Creating Extranets and Access to Shared Services
- Enforcing Security Perimeters with Service Insertion
- Cisco SD-WAN TLOC Extension
- Cisco SD-WAN Security Features
- Traffic Engineering at Sites with Multiple Routers
- Isolating Guest Users from the Corporate VPN
- Cisco SD-WAN Hub-and-Spoke Topology
- Cisco SD-WAN Onboarding

-
One of the biggest takeaways from the RIPE NCC course is that there is no single feature that makes BGP secure. Even though technologies like RPKI have significantly improved routing security, they don’t solve every problem. RPKI only validates the origin of a route. It doesn’t verify whether the advertised AS Path is correct, nor…
-
One thing I really liked about the RIPE NCC course is that it doesn’t present a single “magic solution.” Instead, it explains that BGP security is built from multiple layers. Every mechanism addresses a different type of problem, and together they significantly reduce the chances of routing incidents. Prefix Filtering The first and probably most…
-
BGP is one of those protocols that quietly keeps the Internet running. As network engineers, we usually spend most of our time configuring neighbors, advertising prefixes, or troubleshooting routing issues. Security, however, is often something we don’t think much about until something goes wrong. I recently completed the BGP Security course from the RIPE NCC…
-
When most people hear the term cybersecurity, they immediately think about firewalls, antivirus software, or intrusion prevention systems. While these technologies are important, security architecture is much broader than individual security products. As part of Cisco U’s “Designing Cisco Security Infrastructure (SDSI)” learning path, I recently completed the Security Architecture Design Fundamentals module. The course…
-
When enterprises start scaling DMVPN deployments, a single hub or a single transport quickly becomes a limitation. The Dual Hub + Dual cloud design provides: while still keeping the overlay scalable with DMVPN Phase 3. Topology Overview We have two independent DMVPN clouds: MPLS Cloud Internet Cloud Each spoke connects to both hubs: This creates:…