<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Blogs on Mai Tan Duc</title>
    <link>https://ducmt.netlify.app/posts/blogs/</link>
    <description>Recent content in Blogs on Mai Tan Duc</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 03 Aug 2026 23:44:03 +0700</lastBuildDate>
    <atom:link href="https://ducmt.netlify.app/posts/blogs/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Optus 2025 Outage: Firewall Misconfiguration, Failed Redundancy, and Emergency Services Impact</title>
      <link>https://ducmt.netlify.app/posts/blogs/optus-2025-emergency-services-outage/</link>
      <pubDate>Fri, 19 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/optus-2025-emergency-services-outage/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-went-wrong-in-2025&#34; &gt;What Went Wrong in 2025&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-2023-outage-a-missed-warning&#34; &gt;The 2023 Outage: A Missed Warning&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#systemic-issues-and-regulatory-gaps&#34; &gt;Systemic Issues and Regulatory Gaps&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-needs-to-change&#34; &gt;What Needs to Change&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#pattern-of-failure-why-the-2025-outage-was-not-unforeseeable&#34; &gt;Pattern of Failure: Why the 2025 Outage Was Not Unforeseeable&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#key-lessons-learned&#34; &gt;Key Lessons Learned&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#emergency-systems-must-be-isolated-and-redundant&#34; &gt;Emergency Systems Must Be Isolated and Redundant&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-time-outage-reporting-is-critical&#34; &gt;Real-Time Outage Reporting Is Critical&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#infrastructure-upgrades-require-rigorous-testing&#34; &gt;Infrastructure Upgrades Require Rigorous Testing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#regulatory-oversight-needs-strengthening&#34; &gt;Regulatory Oversight Needs Strengthening&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#public-trust-depends-on-transparency-and-accountability&#34; &gt;Public Trust Depends on Transparency and Accountability&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#emergency-communications-should-be-a-national-priority&#34; &gt;Emergency Communications Should Be a National Priority&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;On September 18, 2025, Optus suffered a major network outage that disrupted Triple Zero (000) emergency services across several Australian states. The outage lasted over 13 hours and resulted in four confirmed deaths and hundreds of failed emergency calls — making it not just an infrastructure failure, but a public safety crisis with real human consequences.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Camera That Moved at Midnight: Why Default Passwords Are Not a Minor Risk</title>
      <link>https://ducmt.netlify.app/posts/blogs/camera-default-password-incident/</link>
      <pubDate>Sun, 03 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/camera-default-password-incident/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-the-night-guard-saw&#34; &gt;What the Night Guard Saw&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-first-two-theories-were-wrong&#34; &gt;The First Two Theories Were Wrong&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-the-access-log-actually-said&#34; &gt;What the Access Log Actually Said&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-real-attack-no-sophistication-required&#34; &gt;The Real Attack: No Sophistication Required&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-attackers-find-your-camera-without-knowing-your-address&#34; &gt;How Attackers Find Your Camera Without Knowing Your Address&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-remote-access-feature-is-the-exposure-vector&#34; &gt;The Remote Access Feature Is the Exposure Vector&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#why-behind-the-firewall-is-not-a-defence&#34; &gt;Why &amp;ldquo;Behind the Firewall&amp;rdquo; Is Not a Defence&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-attack-surface-what-an-unsecured-camera-system-exposes&#34; &gt;The Attack Surface: What an Unsecured Camera System Exposes&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#technical-remediation-what-a-proper-camera-security-hardening-looks-like&#34; &gt;Technical Remediation: What a Proper Camera Security Hardening Looks Like&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-1--credential-audit-and-reset&#34; &gt;Step 1 — Credential Audit and Reset&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-2--network-isolation-vlan-segmentation&#34; &gt;Step 2 — Network Isolation: VLAN Segmentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-3--remote-access-hardening&#34; &gt;Step 3 — Remote Access Hardening&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-4--firmware-and-patch-management&#34; &gt;Step 4 — Firmware and Patch Management&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-5--access-logging-and-alerting&#34; &gt;Step 5 — Access Logging and Alerting&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#network-topology-exposed-vs-hardened&#34; &gt;Network Topology: Exposed vs Hardened&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#exposed-configuration-what-most-businesses-run&#34; &gt;Exposed Configuration (What Most Businesses Run)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#hardened-configuration-what-it-should-look-like&#34; &gt;Hardened Configuration (What It Should Look Like)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-commissioning-checklist-that-should-be-non-negotiable&#34; &gt;The Commissioning Checklist That Should Be Non-Negotiable&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-to-check-your-own-system-right-now&#34; &gt;How to Check Your Own System Right Now&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;what-the-night-guard-saw&#34;&gt;&#xA;  What the Night Guard Saw&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#what-the-night-guard-saw&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;At some point past midnight, the security guard on night duty noticed one of the office PTZ cameras rotating on its own — panning slowly across the room as if someone were operating it remotely. No one was at the control workstation. No one was supposed to be accessing the system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Routing Protocol Triangle: EIGRP, OSPF, and BGP Explained Through Real-World Analogies</title>
      <link>https://ducmt.netlify.app/posts/blogs/routing-protocol-triangle/</link>
      <pubDate>Sat, 02 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/routing-protocol-triangle/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-problem-that-sends-engineers-to-the-wrong-place&#34; &gt;The Problem That Sends Engineers to the Wrong Place&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#eigrp-speed-and-built-in-redundancy&#34; &gt;EIGRP: Speed and Built-In Redundancy&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-dual-algorithm-always-knowing-the-backup-route&#34; &gt;The DUAL Algorithm: Always Knowing the Backup Route&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-operational-catch-query-propagation-and-eigrp-stub&#34; &gt;The Operational Catch: Query Propagation and EIGRP Stub&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuration-reference&#34; &gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ospf-discipline-maps-and-hierarchical-design&#34; &gt;OSPF: Discipline, Maps, and Hierarchical Design&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-ospf-thinks-a-map-not-a-rumour&#34; &gt;How OSPF Thinks: A Map, Not a Rumour&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#route-summarisation-at-the-abr-the-branch-manager-analogy&#34; &gt;Route Summarisation at the ABR: The Branch Manager Analogy&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuration-reference-1&#34; &gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#bgp-policy-over-speed&#34; &gt;BGP: Policy Over Speed&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#routing-by-policy-not-metric&#34; &gt;Routing by Policy, Not Metric&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#why-bgp-convergence-is-deliberately-slow&#34; &gt;Why BGP Convergence Is Deliberately Slow&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#dual-isp-traffic-engineering-with-bgp&#34; &gt;Dual-ISP Traffic Engineering with BGP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuration-reference-2&#34; &gt;Configuration Reference&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#protocol-comparison-choosing-the-right-tool&#34; &gt;Protocol Comparison: Choosing the Right Tool&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#traffic-flow-how-a-packet-moves-across-all-three-protocols&#34; &gt;Traffic Flow: How a Packet Moves Across All Three Protocols&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#topology-where-each-protocol-lives-in-an-enterprise-network&#34; &gt;Topology: Where Each Protocol Lives in an Enterprise Network&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-checklist-by-protocol&#34; &gt;Troubleshooting Checklist by Protocol&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;the-problem-that-sends-engineers-to-the-wrong-place&#34;&gt;&#xA;  The Problem That Sends Engineers to the Wrong Place&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-problem-that-sends-engineers-to-the-wrong-place&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;Every network engineer has sat in front of a black CLI screen asking the same question: &lt;em&gt;&amp;ldquo;The cable is in. The IP is correct. So why won&amp;rsquo;t these two routers talk to each other?&amp;rdquo;&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cameras Dropping Every Day at 2 PM: When the Root Cause Is Not the Camera</title>
      <link>https://ducmt.netlify.app/posts/blogs/poe-camera-disconnect-incident/</link>
      <pubDate>Wed, 30 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/poe-camera-disconnect-incident/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-initial-picture-symptoms-that-do-not-point-to-root-cause&#34; &gt;The Initial Picture: Symptoms That Do Not Point to Root Cause&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-poe-is-and-why-it-matters-more-than-most-people-think&#34; &gt;What PoE Is and Why It Matters More Than Most People Think&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#root-cause-poe-budget-overload-combined-with-thermal-throttling&#34; &gt;Root Cause: PoE Budget Overload Combined with Thermal Throttling&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-failure-mechanism&#34; &gt;The Failure Mechanism&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#traffic-flow-diagram&#34; &gt;Traffic Flow Diagram&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#current-topology-vs-correct-topology&#34; &gt;Current Topology vs Correct Topology&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#old-topology-single-point-of-failure&#34; &gt;Old Topology: Single Point of Failure&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#new-topology-proper-load-distribution&#34; &gt;New Topology: Proper Load Distribution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#technical-solution-three-layers-of-intervention&#34; &gt;Technical Solution: Three Layers of Intervention&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#layer-1--immediate-fix-poe-priority-configuration&#34; &gt;Layer 1 — Immediate Fix: PoE Priority Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#layer-2--permanent-fix-switch-load-distribution&#34; &gt;Layer 2 — Permanent Fix: Switch Load Distribution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#layer-3--prevention-thermal-management-and-monitoring&#34; &gt;Layer 3 — Prevention: Thermal Management and Monitoring&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#poe-standards-reference-choosing-the-right-switch-from-the-start&#34; &gt;PoE Standards Reference: Choosing the Right Switch from the Start&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#calculating-poe-budget-for-a-camera-system&#34; &gt;Calculating PoE Budget for a Camera System&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#questions-to-ask-before-signing-off-on-any-poe-system&#34; &gt;Questions to Ask Before Signing Off on Any PoE System&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;the-initial-picture-symptoms-that-do-not-point-to-root-cause&#34;&gt;&#xA;  The Initial Picture: Symptoms That Do Not Point to Root Cause&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#the-initial-picture-symptoms-that-do-not-point-to-root-cause&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;The security team described the symptoms accurately: cameras lose signal for a few minutes, consistently around 2 PM, then recover on their own. Not every day — only on hot, sunny ones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Static LAG with VMware ESXi – Why LACP Is Not Always the Right Answer</title>
      <link>https://ducmt.netlify.app/posts/blogs/etherchannel-esxi-static-lag-vs-lacp/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/etherchannel-esxi-static-lag-vs-lacp/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#static-lag-or-lacp--the-wrong-question-from-the-start&#34; &gt;Static LAG or LACP – The Wrong Question from the Start&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#nic-teaming-architecture-in-vmware-esxi&#34; &gt;NIC Teaming Architecture in VMware ESXi&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#vsphere-standard-switch-and-its-protocol-limitations&#34; &gt;vSphere Standard Switch and Its Protocol Limitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#vsphere-distributed-switch--when-lacp-is-actually-valid&#34; &gt;vSphere Distributed Switch – When LACP Is Actually Valid&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#mapping-esxi-teaming-policy-to-switch-configuration&#34; &gt;Mapping ESXi Teaming Policy to Switch Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-etherchannel-distributes-traffic&#34; &gt;How EtherChannel Distributes Traffic&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#flow-based-forwarding--not-round-robin&#34; &gt;Flow-Based Forwarding – Not Round-Robin&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#hash-algorithms-and-why-both-ends-must-agree&#34; &gt;Hash Algorithms and Why Both Ends Must Agree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-world-bandwidth-and-setting-the-right-expectations&#34; &gt;Real-World Bandwidth and Setting the Right Expectations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-silent-failure-scenario--ports-up-system-unstable&#34; &gt;The Silent Failure Scenario – Ports Up, System Unstable&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verification-on-cisco-ios-switches&#34; &gt;Verification on Cisco IOS Switches&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#confirm-all-member-ports-are-bundled&#34; &gt;Confirm All Member Ports Are Bundled&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-the-active-load-balance-algorithm&#34; &gt;Verify the Active Load-Balance Algorithm&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#detect-uneven-traffic-distribution&#34; &gt;Detect Uneven Traffic Distribution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#summary&#34; &gt;Summary&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;static-lag-or-lacp--the-wrong-question-from-the-start&#34;&gt;&#xA;  Static LAG or LACP – The Wrong Question from the Start&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#static-lag-or-lacp--the-wrong-question-from-the-start&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;In working with virtualisation network infrastructure, I&amp;rsquo;ve noticed a consistent pattern: when a network engineer looks at the uplink configuration between a switch and an ESXi host, the first question is almost always &lt;em&gt;&amp;ldquo;why aren&amp;rsquo;t you using LACP?&amp;rdquo;&lt;/em&gt; — and that&amp;rsquo;s the wrong question to start with.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Meta and Yandex Exploited Android&#39;s Localhost Channel to Bypass Privacy Controls</title>
      <link>https://ducmt.netlify.app/posts/blogs/android-localhost-tracking-bypass/</link>
      <pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/android-localhost-tracking-bypass/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#background-a-support-case-that-exposed-a-tracking-vector&#34; &gt;Background: A Support Case That Exposed a Tracking Vector&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-localhost-tracking-mechanism&#34; &gt;The Localhost Tracking Mechanism&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-tracking-scripts-collect-and-relay-identifiers&#34; &gt;How Tracking Scripts Collect and Relay Identifiers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-loopback-bridge-bypassing-sandbox-boundaries&#34; &gt;The Loopback Bridge: Bypassing Sandbox Boundaries&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#technical-breakdown-identifier-collection-loopback-routing-and-privacy-bypass&#34; &gt;Technical Breakdown: Identifier Collection, Loopback Routing, and Privacy Bypass&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#root-cause-android-design-decisions-that-created-the-vulnerability&#34; &gt;Root Cause: Android Design Decisions That Created the Vulnerability&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#mitigations-os-browser-and-regulatory-layers&#34; &gt;Mitigations: OS, Browser, and Regulatory Layers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-this-tells-us-about-privacy-at-the-platform-layer&#34; &gt;What This Tells Us About Privacy at the Platform Layer&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;background-a-support-case-that-exposed-a-tracking-vector&#34;&gt;&#xA;  Background: A Support Case That Exposed a Tracking Vector&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#background-a-support-case-that-exposed-a-tracking-vector&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;It started with a support ticket in June 2025. A user noticed that content he&amp;rsquo;d browsed in a standard Chrome session was surfacing as targeted recommendations inside a completely separate native app — one he hadn&amp;rsquo;t opened during that browsing session. The correlation was too precise to be coincidence, and too consistent to be a caching artefact.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AWX for Scheduled and Event-Driven Network Automation</title>
      <link>https://ducmt.netlify.app/posts/blogs/awx-scheduled-event-driven-automation/</link>
      <pubDate>Sat, 15 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/awx-scheduled-event-driven-automation/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#scheduled-playbook-execution-with-awx&#34; &gt;Scheduled Playbook Execution with AWX&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-network-backups-via-awx-scheduler&#34; &gt;Automating Network Backups via AWX Scheduler&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#scheduled-playbook-for-network-configuration-backup&#34; &gt;Scheduled Playbook for Network Configuration Backup&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#setting-up-the-playbook-in-awx&#34; &gt;Setting Up the Playbook in AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#event-driven-remediation-with-ansible-and-awx&#34; &gt;Event-Driven Remediation with Ansible and AWX&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automatic-diagnostics-on-ping-failure&#34; &gt;Automatic Diagnostics on Ping Failure&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#integrating-event-driven-automation-with-awx&#34; &gt;Integrating Event-Driven Automation with AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automatic-firewall-response-to-unauthorised-access&#34; &gt;Automatic Firewall Response to Unauthorised Access&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#triggering-this-playbook-automatically-using-awx&#34; &gt;Triggering This Playbook Automatically Using AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-awx-job-templates-for-auto-triggered-diagnostics&#34; &gt;Configuring AWX Job Templates for Auto-Triggered Diagnostics&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#monitoring-network-health-with-awx-dashboards&#34; &gt;Monitoring Network Health with AWX Dashboards&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#setting-up-awx-for-network-monitoring&#34; &gt;Setting Up AWX for Network Monitoring&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#detecting-configuration-drift-with-awx&#34; &gt;Detecting Configuration Drift with AWX&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-this-workflow-in-awx&#34; &gt;Automating This Workflow in AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;scheduled-playbook-execution-with-awx&#34;&gt;&#xA;  Scheduled Playbook Execution with AWX&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#scheduled-playbook-execution-with-awx&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;Once AWX is deployed and integrated with your Git repository, the typical onboarding sequence is straightforward: define an inventory, link your playbook source, then wire it to a schedule. The real value of AWX over raw Ansible CLI is the audit trail and scheduling engine — every job run is logged with its output, timing, and exit status, giving you the operational visibility that &lt;code&gt;cron&lt;/code&gt;-based automation lacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ansible Playbooks for Network Automation: From Basics to Production</title>
      <link>https://ducmt.netlify.app/posts/blogs/ansible-network-automation-playbooks/</link>
      <pubDate>Fri, 14 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/ansible-network-automation-playbooks/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#foundational-playbooks&#34; &gt;Foundational Playbooks&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#gathering-device-facts&#34; &gt;Gathering Device Facts&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#deploying-vlans-across-switches&#34; &gt;Deploying VLANs Across Switches&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#backing-up-network-configurations&#34; &gt;Backing Up Network Configurations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#production-grade-playbooks&#34; &gt;Production-Grade Playbooks&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-router-firmware-upgrades&#34; &gt;Automating Router Firmware Upgrades&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#monitoring-network-performance&#34; &gt;Monitoring Network Performance&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-security-policy-deployment&#34; &gt;Automating Security Policy Deployment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-network-issues&#34; &gt;Troubleshooting Network Issues&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-network-backup--recovery&#34; &gt;Automating Network Backup &amp;amp; Recovery&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;foundational-playbooks&#34;&gt;&#xA;  Foundational Playbooks&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#foundational-playbooks&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;h2 id=&#34;gathering-device-facts&#34;&gt;&#xA;  Gathering Device Facts&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#gathering-device-facts&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Gathering device facts is often the first playbook written in a new automation environment — and one of the most immediately useful. Running &lt;code&gt;ios_facts&lt;/code&gt; across your inventory gives you a structured snapshot of platform, version, interface state, and IP configuration without logging into a single device manually. The output can feed dashboards, validation checks, or change pre-conditions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Automation with Ansible and AWX: Setup, Playbooks, and Best Practices</title>
      <link>https://ducmt.netlify.app/posts/blogs/ansible-awx-netdevops-setup/</link>
      <pubDate>Thu, 13 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/ansible-awx-netdevops-setup/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#why-ansible-is-a-good-fit-for-network-automation&#34; &gt;Why Ansible Is a Good Fit for Network Automation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#key-benefits-of-ansible-for-network-operations&#34; &gt;Key Benefits of Ansible for Network Operations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#installing-ansible-and-configuring-inventory&#34; &gt;Installing Ansible and Configuring Inventory&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#install-ansible&#34; &gt;Install Ansible&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-ansible-inventory&#34; &gt;Configure Ansible Inventory&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#automating-network-tasks-with-playbooks&#34; &gt;Automating Network Tasks with Playbooks&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#awx-centralised-ansible-management&#34; &gt;AWX: Centralised Ansible Management&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-is-awx&#34; &gt;What is AWX?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#awx-features&#34; &gt;AWX Features&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#installing-awx&#34; &gt;Installing AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#managing-playbooks-using-awxs-web-ui&#34; &gt;Managing Playbooks Using AWX&amp;rsquo;s Web UI&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-1-create-an-inventory&#34; &gt;Step 1: Create an Inventory&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-2-import-playbooks&#34; &gt;Step 2: Import Playbooks&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-3-run-playbooks-via-awx&#34; &gt;Step 3: Run Playbooks via AWX&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#advanced-awx-features&#34; &gt;Advanced AWX Features&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#operational-best-practices&#34; &gt;Operational Best Practices&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#conclusion&#34; &gt;Conclusion&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;Network configuration is inherently repetitive: new devices get the same baseline hardening, VLANs get pushed to every switch in a fabric, ACLs get updated across all firewalls simultaneously. Manual execution of these tasks doesn&amp;rsquo;t scale, introduces inconsistency, and leaves no auditable record of what changed and when. Ansible addresses this by externalising configuration intent into playbooks that are version-controlled, idempotent, and executable across an entire inventory in a single run.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Incident Case Studies: DNS, DHCP, Bandwidth, and Firewall Failures</title>
      <link>https://ducmt.netlify.app/posts/blogs/network-incident-case-studies/</link>
      <pubDate>Mon, 11 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/network-incident-case-studies/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#incident-1-dns-single-point-of-failure--total-loss-of-external-connectivity&#34; &gt;Incident 1: DNS Single Point of Failure — Total Loss of External Connectivity&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-steps&#34; &gt;Troubleshooting Steps&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#incident-2-rogue-dhcp-server--ip-addressing-chaos-across-the-lan&#34; &gt;Incident 2: Rogue DHCP Server — IP Addressing Chaos Across the LAN&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-1&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-steps-1&#34; &gt;Troubleshooting Steps&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-1&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-1&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#incident-3-wan-bandwidth-saturation-from-a-single-host&#34; &gt;Incident 3: WAN Bandwidth Saturation from a Single Host&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-2&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-steps-2&#34; &gt;Troubleshooting Steps&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-2&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-2&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#incident-4-firewall-misconfiguration-blocking-legitimate-business-traffic&#34; &gt;Incident 4: Firewall Misconfiguration Blocking Legitimate Business Traffic&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-3&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-steps-3&#34; &gt;Troubleshooting Steps&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-3&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-3&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#preventive-controls-from-reactive-troubleshooting-to-proactive-operations&#34; &gt;Preventive Controls: From Reactive Troubleshooting to Proactive Operations&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#best-practices-for-network-troubleshooting&#34; &gt;Best Practices for Network Troubleshooting&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#investing-in-network-stability&#34; &gt;Investing in Network Stability&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#troubleshooting-vs-prevention-where-the-real-value-is&#34; &gt;Troubleshooting vs. Prevention: Where the Real Value Is&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;The most instructive network incidents are rarely the ones caused by hardware failure or DDoS attacks — the root cause is usually obvious. The difficult ones are caused by misconfigurations, overlooked dependencies, or single points of failure that nobody thought to protect. The cases below are representative of that category: failures that looked complex on the surface but resolved to a single traceable root cause.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Password Management with pass, GPG, and Git</title>
      <link>https://ducmt.netlify.app/posts/blogs/pass-gpg-git-password-store/</link>
      <pubDate>Wed, 07 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/pass-gpg-git-password-store/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#installing-pass-and-generating-a-gpg-keypair&#34; &gt;Installing pass and Generating a GPG Keypair&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#storing-and-retrieving-passwords&#34; &gt;Storing and Retrieving Passwords&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#add-a-password&#34; &gt;Add a Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#retrieve-a-password&#34; &gt;Retrieve a Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#remove-a-password&#34; &gt;Remove a Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#bulk-export-for-migration-or-audit&#34; &gt;Bulk Export for Migration or Audit&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#install-and-run-the-script&#34; &gt;Install and Run the Script&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#understand-mktemp-in-the-script&#34; &gt;Understand &lt;code&gt;mktemp&lt;/code&gt; in the Script&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#synchronising-the-password-store-across-devices-with-git&#34; &gt;Synchronising the Password Store Across Devices with Git&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#initialise-a-git-repository&#34; &gt;Initialise a Git Repository&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-up-a-password-store-on-a-new-machine&#34; &gt;Set Up a Password Store on a New Machine&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#common-failures-and-how-to-resolve-them&#34; &gt;Common Failures and How to Resolve Them&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#gpg-no-secret-key-error&#34; &gt;GPG &amp;ldquo;No Secret Key&amp;rdquo; Error&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#git-sync-issues&#34; &gt;Git Sync Issues&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#conclusion&#34; &gt;Conclusion&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;&lt;code&gt;password-store&lt;/code&gt; (commonly invoked as &lt;code&gt;pass&lt;/code&gt;) is the Unix-philosophy answer to credential management: passwords are stored as GPG-encrypted files, organised in a directory tree, with Git providing synchronisation and version history. There are no proprietary formats, no cloud lock-in, and no dependencies beyond tools that are standard in any Linux environment. The entire store is auditable, portable, and backed by well-understood cryptographic primitives.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IT Outage Case Studies: CrowdStrike, AWS, Facebook, and AT&amp;T</title>
      <link>https://ducmt.netlify.app/posts/blogs/it-outage-case-studies/</link>
      <pubDate>Tue, 25 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/it-outage-case-studies/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-crowdstrike-outage--a-software-update-gone-wrong&#34; &gt;The CrowdStrike Outage – A Software Update Gone Wrong&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#impact&#34; &gt;Impact&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-aws-outage--a-typo-that-cost-millions&#34; &gt;The AWS Outage – A Typo That Cost Millions&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-1&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#impact-1&#34; &gt;Impact&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-1&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-1&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-facebook-outage--a-system-bug-that-took-down-social-media&#34; &gt;The Facebook Outage – A System Bug That Took Down Social Media&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-2&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#impact-2&#34; &gt;Impact&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-2&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-2&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-att-outage--a-configuration-error-that-blocked-92-million-calls&#34; &gt;The AT&amp;amp;T Outage – A Configuration Error That Blocked 92 Million Calls&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened-3&#34; &gt;What Happened?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#impact-3&#34; &gt;Impact&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-3&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-3&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#preventive-architecture-how-to-reduce-blast-radius-before-the-next-incident&#34; &gt;Preventive Architecture: How to Reduce Blast Radius Before the Next Incident&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#best-practices-for-it-resilience&#34; &gt;Best Practices for IT Resilience&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#investing-in-it-stability&#34; &gt;Investing in IT Stability&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#prevention-over-response-the-common-thread-across-all-four-incidents&#34; &gt;Prevention Over Response: The Common Thread Across All Four Incidents&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;The most instructive outages are rarely caused by exotic failure modes. The cases below are representative of the incidents that define real-world IT risk: software updates that bypassed staging validation, human errors in high-stakes operational tooling, and configuration changes that hadn&amp;rsquo;t been tested against the failure scenarios they were meant to prevent. Each one is instructive not because it was unusual, but because the conditions that caused it are common.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GPG Encryption and Key Management in Practice</title>
      <link>https://ducmt.netlify.app/posts/blogs/gpg-encryption-and-key-management/</link>
      <pubDate>Sat, 20 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/gpg-encryption-and-key-management/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#gpg-and-the-openpgp-standard&#34; &gt;GPG and the OpenPGP Standard&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-gpg-encrypts-data-public-key-and-hybrid-cryptography&#34; &gt;How GPG Encrypts Data: Public-Key and Hybrid Cryptography&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#practical-use-cases-for-gpg&#34; &gt;Practical Use Cases for GPG&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#generating-a-gpg-keypair&#34; &gt;Generating a GPG Keypair&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#manage-your-gpg-keypair&#34; &gt;Manage Your GPG Keypair&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#backup-your-gpg-keys&#34; &gt;Backup Your GPG Keys&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#restore-the-gpg-keys&#34; &gt;Restore the GPG Keys&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#import-your-keypairs&#34; &gt;Import Your Keypairs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#encrypting-and-decrypting-with-gpg&#34; &gt;Encrypting and Decrypting with GPG&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#encrypt-messages-with-gpg&#34; &gt;Encrypt Messages with GPG&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#decrypt-messages-with-gpg&#34; &gt;Decrypt Messages with GPG&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#import-another-users-gpg-key&#34; &gt;Import Another User&amp;rsquo;s GPG Key&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;gpg-and-the-openpgp-standard&#34;&gt;&#xA;  GPG and the OpenPGP Standard&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#gpg-and-the-openpgp-standard&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;GNU Privacy Guard (GPG) is the de facto open-source implementation of the OpenPGP standard, widely used to secure emails, files, and digital communications. Built on asymmetric cryptography, it provides confidentiality, authenticity, and integrity — the three pillars of secure data exchange.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Printer Sharing via SMB: Operational Risks and the Case for Network Printers</title>
      <link>https://ducmt.netlify.app/posts/blogs/windows-printer-sharing-smb-risks/</link>
      <pubDate>Thu, 14 Mar 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/windows-printer-sharing-smb-risks/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#why-printer-sharing-looks-simple-and-isnt&#34; &gt;Why Printer Sharing Looks Simple and Isn&amp;rsquo;t&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-setup-usb-printer-shared-to-mixed-os-clients&#34; &gt;The Setup: USB Printer Shared to Mixed-OS Clients&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#failure-modes-in-practice-driver-auth-and-connectivity-issues&#34; &gt;Failure Modes in Practice: Driver, Auth, and Connectivity Issues&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#case-study-the-accounting-teams-shared-printer-disaster&#34; &gt;Case Study: The Accounting Team&amp;rsquo;s Shared Printer Disaster&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#smb-vulnerabilities-why-microsoft-is-closing-the-door-on-shared-printing&#34; &gt;SMB Vulnerabilities: Why Microsoft Is Closing the Door on Shared Printing&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#case-study-security-nightmare-in-a-smb-environment&#34; &gt;Case Study: Security Nightmare in a SMB Environment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-troubleshooting-cycle-temporary-fixes-that-dont-stay-fixed&#34; &gt;The Troubleshooting Cycle: Temporary Fixes That Don&amp;rsquo;t Stay Fixed&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#case-study-the-cross-architecture-driver-struggle&#34; &gt;Case Study: The Cross-Architecture Driver Struggle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#recommendation-invest-in-network-printers-asap&#34; &gt;Recommendation: Invest in Network Printers ASAP&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#advantages-of-network-printers&#34; &gt;Advantages of Network Printers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-about-costs&#34; &gt;What About Costs?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#stop-treating-printer-sharing-as-a-long-term-solution&#34; &gt;Stop Treating Printer Sharing as a Long-Term Solution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;why-printer-sharing-looks-simple-and-isnt&#34;&gt;&#xA;  Why Printer Sharing Looks Simple and Isn&amp;rsquo;t&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#why-printer-sharing-looks-simple-and-isnt&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;Shared printing via Windows Share is the kind of solution that looks reasonable in a pinch and becomes a recurring nightmare in practice. IT teams inherit these setups constantly — they work just well enough to avoid being prioritised for replacement, yet generate a disproportionate share of helpdesk tickets, usually at the worst possible times.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv4 Addressing Design: Subnetting, VLSM, and Operational Standards</title>
      <link>https://ducmt.netlify.app/posts/blogs/ipv4-addressing-design-and-subnetting/</link>
      <pubDate>Sun, 14 Jan 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/ipv4-addressing-design-and-subnetting/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#design-inputs-what-to-establish-before-allocating-subnets&#34; &gt;Design Inputs: What to Establish Before Allocating Subnets&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#device-categories-that-require-ip-addresses&#34; &gt;Device Categories That Require IP Addresses&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#static-versus-dynamic-addressing&#34; &gt;Static versus Dynamic Addressing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#subnet-allocation&#34; &gt;Subnet Allocation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#common-addressing-standards&#34; &gt;Common Addressing Standards&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#guidelines-for-vlsm&#34; &gt;Guidelines for VLSM&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;design-inputs-what-to-establish-before-allocating-subnets&#34;&gt;&#xA;  Design Inputs: What to Establish Before Allocating Subnets&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#design-inputs-what-to-establish-before-allocating-subnets&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;p&gt;A well-structured IP addressing plan is one of the most durable investments in any network design. Getting it right early avoids the painful process of re-addressing production networks — a task that, in large environments, can take months and carry significant risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS Router Initial Configuration Reference</title>
      <link>https://ducmt.netlify.app/posts/blogs/cisco-ios-router-initial-configuration/</link>
      <pubDate>Tue, 02 Jan 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/cisco-ios-router-initial-configuration/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#console-access-and-cli-entry-points&#34; &gt;Console Access and CLI Entry Points&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#physical-connection&#34; &gt;Physical Connection&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#access-the-router-cli&#34; &gt;Access the Router CLI&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-console-connection&#34; &gt;Verify Console Connection&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#baseline-hardening-hostname-passwords-and-access-controls&#34; &gt;Baseline Hardening: Hostname, Passwords, and Access Controls&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-a-hostname&#34; &gt;Set a Hostname&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-hostname&#34; &gt;Verify Hostname&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#secure-console-access&#34; &gt;Secure Console Access&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-console-security&#34; &gt;Verify Console Security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#secure-vty-lines-remote-access-via-sshtelnet&#34; &gt;Secure VTY Lines (Remote Access via SSH/Telnet)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vty-security&#34; &gt;Verify VTY Security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#create-a-strong-enable-password&#34; &gt;Create a Strong Enable Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-enable-password&#34; &gt;Verify Enable Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#interface-configuration-and-ip-assignment&#34; &gt;Interface Configuration and IP Assignment&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-ip-addresses-to-interfaces&#34; &gt;Assign IP Addresses to Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-interface-configuration&#34; &gt;Verify Interface Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#static-routing-and-ospf&#34; &gt;Static Routing and OSPF&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-static-routing&#34; &gt;Enable Static Routing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-routing-table&#34; &gt;Verify Routing Table&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dynamic-routing-ospf-example&#34; &gt;Enable Dynamic Routing (OSPF Example)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ospf-configuration&#34; &gt;Verify OSPF Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#dhcp-server-configuration&#34; &gt;DHCP Server Configuration&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dhcp-server&#34; &gt;Enable DHCP Server&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-dhcp-configuration&#34; &gt;Verify DHCP Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#natpat-for-internet-access&#34; &gt;NAT/PAT for Internet Access&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-nat-for-internet-access&#34; &gt;Enable NAT for Internet Access&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-nat-configuration&#34; &gt;Verify NAT Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#acls-and-ssh-hardening&#34; &gt;ACLs and SSH Hardening&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-access-control-lists-acls&#34; &gt;Enable Access Control Lists (ACLs)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-acl-configuration&#34; &gt;Verify ACL Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ssh-for-secure-remote-access&#34; &gt;Enable SSH for Secure Remote Access&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ssh-configuration&#34; &gt;Verify SSH Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#qos-for-traffic-prioritisation&#34; &gt;QoS for Traffic Prioritisation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-qos-globally&#34; &gt;Enable QoS Globally&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#classify-voip-traffic-using-access-lists&#34; &gt;Classify VoIP Traffic Using Access Lists&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#define-qos-classes--mark-voip-traffic&#34; &gt;Define QoS Classes &amp;amp; Mark VoIP Traffic&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#apply-qos-policy-to-interfaces&#34; &gt;Apply QoS Policy to Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-qos-configuration&#34; &gt;Verify QoS Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ipsec-vpn-configuration&#34; &gt;IPSec VPN Configuration&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ipsec-vpn&#34; &gt;Enable IPSec VPN&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#define-pre-shared-key&#34; &gt;Define Pre-Shared Key&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-ipsec-transform-set&#34; &gt;Configure IPSec Transform Set&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#apply-vpn-to-an-interface&#34; &gt;Apply VPN to an Interface&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vpn-configuration&#34; &gt;Verify VPN Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#redundancy&#34; &gt;Redundancy&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-hot-standby-router-protocol-hsrp-for-gateway-redundancy&#34; &gt;Configuring Hot Standby Router Protocol (HSRP) for Gateway Redundancy&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-hsrp-on-vlan-interfaces&#34; &gt;Enable HSRP on VLAN Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-hsrp-status&#34; &gt;Verify HSRP Status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-virtual-router-redundancy-protocol-vrrp-for-redundant-gateways&#34; &gt;Configuring Virtual Router Redundancy Protocol (VRRP) for Redundant Gateways&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-vrrp-on-vlan-interfaces&#34; &gt;Enable VRRP on VLAN Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vrrp-status&#34; &gt;Verify VRRP Status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-bgp-failover-for-redundant-internet-connectivity&#34; &gt;Configuring BGP Failover for Redundant Internet Connectivity&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-bgp-and-define-as-number&#34; &gt;Enable BGP and Define AS Number&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-bgp-neighbour-for-redundant-isp-connections&#34; &gt;Configure BGP Neighbour for Redundant ISP Connections&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-bgp-configuration&#34; &gt;Verify BGP Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#snmp-for-network-monitoring&#34; &gt;SNMP for Network Monitoring&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-snmp&#34; &gt;Enable SNMP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-snmp-configuration&#34; &gt;Verify SNMP Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#netflow-for-traffic-analysis&#34; &gt;NetFlow for Traffic Analysis&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-netflow&#34; &gt;Enable NetFlow&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-netflow-configuration&#34; &gt;Verify NetFlow Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ansible-integration-ssh-service-account-setup&#34; &gt;Ansible Integration: SSH Service Account Setup&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ssh-for-automation&#34; &gt;Enable SSH for Automation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ssh-access-for-automation&#34; &gt;Verify SSH Access for Automation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#multicast-routing-with-pim-sparse-mode&#34; &gt;Multicast Routing with PIM Sparse Mode&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-pim-sparse-mode-for-multicast-routing&#34; &gt;Enable PIM Sparse Mode for Multicast Routing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-up-a-rendezvous-point-rp-for-multicast-traffic&#34; &gt;Set Up a Rendezvous Point (RP) for Multicast Traffic&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-multicast-configuration&#34; &gt;Verify Multicast Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#layer-2-and-layer-3-security-mac-filtering-ip-source-guard-dai&#34; &gt;Layer 2 and Layer 3 Security: MAC Filtering, IP Source Guard, DAI&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-mac-address-filtering-for-higher-security&#34; &gt;Enable MAC Address Filtering for Higher Security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ip-source-guard-to-prevent-spoofing&#34; &gt;Enable IP Source Guard to Prevent Spoofing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dynamic-arp-inspection-mitigate-arp-attacks&#34; &gt;Enable Dynamic ARP Inspection (Mitigate ARP Attacks)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-security-features&#34; &gt;Verify Security Features&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#cloud-integration-for-hybrid-networking&#34; &gt;Cloud Integration for Hybrid Networking&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#integrate-external-multicast-services-with-aws&#34; &gt;Integrate External Multicast Services with AWS&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-aws-multicast-integration&#34; &gt;Verify AWS Multicast Integration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ipv6-routing-and-interface-configuration&#34; &gt;IPv6 Routing and Interface Configuration&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ipv6-routing&#34; &gt;Enable IPv6 Routing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-ipv6-addresses-to-interfaces&#34; &gt;Assign IPv6 Addresses to Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ipv6-configuration&#34; &gt;Verify IPv6 Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#vrf-for-network-segmentation&#34; &gt;VRF for Network Segmentation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#create-a-vrf-instance&#34; &gt;Create a VRF Instance&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-vrf-to-an-interface&#34; &gt;Assign VRF to an Interface&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vrf-configuration&#34; &gt;Verify VRF Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#gre-tunnel-for-site-to-site-connectivity&#34; &gt;GRE Tunnel for Site-to-Site Connectivity&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#create-a-gre-tunnel-interface&#34; &gt;Create a GRE Tunnel Interface&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-gre-tunnel&#34; &gt;Verify GRE Tunnel&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ospfv3-for-ipv6-dynamic-routing&#34; &gt;OSPFv3 for IPv6 Dynamic Routing&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ospfv3&#34; &gt;Enable OSPFv3&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-ospfv3-to-interfaces&#34; &gt;Assign OSPFv3 to Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ospfv3-configuration&#34; &gt;Verify OSPFv3 Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#load-balancing&#34; &gt;Load Balancing&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-load-balancing-with-hsrp-hot-standby-router-protocol&#34; &gt;Configuring Load Balancing with HSRP (Hot Standby Router Protocol)&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-multiple-hsrp-instances-for-load-balancing&#34; &gt;Enable Multiple HSRP Instances for Load Balancing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-hsrp-load-balancing&#34; &gt;Verify HSRP Load Balancing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-load-balancing-with-bgp-border-gateway-protocol&#34; &gt;Configuring Load Balancing with BGP (Border Gateway Protocol)&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-bgp-and-define-as-number-1&#34; &gt;Enable BGP and Define AS Number&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-bgp-neighbour-for-load-balancing&#34; &gt;Configure BGP Neighbour for Load Balancing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-bgp-load-balancing&#34; &gt;Verify BGP Load Balancing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configuring-dual-wan-load-balancing&#34; &gt;Configuring Dual WAN Load Balancing&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dual-wan-for-traffic-distribution&#34; &gt;Enable Dual WAN for Traffic Distribution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-load-balancing-mode&#34; &gt;Configure Load Balancing Mode&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-dual-wan-load-balancing&#34; &gt;Verify Dual WAN Load Balancing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#saving-configuration-and-connectivity-tests&#34; &gt;Saving Configuration and Connectivity Tests&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#save-configuration-to-startup-config&#34; &gt;Save Configuration to Startup-Config&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-configuration-save&#34; &gt;Verify Configuration Save&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#testing-connectivity&#34; &gt;Testing Connectivity&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;This guide covers first-time router configuration on Cisco IOS from console access through to production-ready hardening. Each section includes the relevant CLI commands and a verification step — in production, the verify commands matter as much as the configuration commands. An unverified config is an assumption.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS Switch Initial Configuration Reference</title>
      <link>https://ducmt.netlify.app/posts/blogs/cisco-ios-switch-initial-configuration/</link>
      <pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/cisco-ios-switch-initial-configuration/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#console-access-and-cli-entry-points&#34; &gt;Console Access and CLI Entry Points&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#step-by-step-process&#34; &gt;Step-by-Step Process&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#access-the-switch-cli&#34; &gt;Access the Switch CLI&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-console-connection&#34; &gt;Verify Console Connection&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#baseline-hardening-hostname-passwords-and-unused-port-shutdown&#34; &gt;Baseline Hardening: Hostname, Passwords, and Unused Port Shutdown&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-a-hostname&#34; &gt;Set a Hostname&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-hostname&#34; &gt;Verify Hostname&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#secure-console-access&#34; &gt;Secure Console Access&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-console-security&#34; &gt;Verify Console Security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#secure-vty-lines-remote-access-via-sshtelnet&#34; &gt;Secure VTY Lines (Remote Access via SSH/Telnet)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vty-security&#34; &gt;Verify VTY Security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#create-a-strong-enable-password&#34; &gt;Create a Strong Enable Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-enable-password&#34; &gt;Verify Enable Password&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#disable-unused-ports-security-best-practice&#34; &gt;Disable Unused Ports (Security Best Practice)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-port-shutdown&#34; &gt;Verify Port Shutdown&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#vlan-creation-port-assignment-and-trunk-configuration&#34; &gt;VLAN Creation, Port Assignment, and Trunk Configuration&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#creating-vlans-and-assigning-ports&#34; &gt;Creating VLANs and Assigning Ports&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vlan-creation&#34; &gt;Verify VLAN Creation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-vlans-to-specific-ports&#34; &gt;Assign VLANs to Specific Ports&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vlan-assignment&#34; &gt;Verify VLAN Assignment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-the-trunk-port-for-inter-vlan-communication&#34; &gt;Configure the Trunk Port (For Inter-VLAN Communication)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-trunk-configuration&#34; &gt;Verify Trunk Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#management-ip-and-default-gateway&#34; &gt;Management IP and Default Gateway&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-an-ip-to-the-vlan-interface&#34; &gt;Assign an IP to the VLAN Interface&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ip-assignment&#34; &gt;Verify IP Assignment&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-default-gateway&#34; &gt;Configure Default Gateway&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-default-gateway&#34; &gt;Verify Default Gateway&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ssh-configuration-for-secure-remote-management&#34; &gt;SSH Configuration for Secure Remote Management&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#generate-rsa-keys-for-ssh&#34; &gt;Generate RSA Keys for SSH&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-rsa-key-generation&#34; &gt;Verify RSA Key Generation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-ssh-version&#34; &gt;Set SSH Version&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ssh-version&#34; &gt;Verify SSH Version&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#define-a-local-username-for-ssh-authentication&#34; &gt;Define a Local Username for SSH Authentication&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-local-user&#34; &gt;Verify Local User&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#apply-ssh-access-to-vty-lines&#34; &gt;Apply SSH Access to VTY Lines&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ssh-access&#34; &gt;Verify SSH Access&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#spanning-tree-protocol-rstp-root-bridge-and-edge-port-hardening&#34; &gt;Spanning Tree Protocol: RSTP, Root Bridge, and Edge Port Hardening&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-rapid-spanning-tree-protocol-rstp&#34; &gt;Enable Rapid Spanning Tree Protocol (RSTP)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-stp-mode&#34; &gt;Verify STP Mode&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-root-bridge-priority&#34; &gt;Set Root Bridge Priority&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-root-bridge-priority&#34; &gt;Verify Root Bridge Priority&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-portfast-on-edge-ports-prevent-slow-booting&#34; &gt;Enable PortFast on Edge Ports (Prevent Slow Booting)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-portfast&#34; &gt;Verify PortFast&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#qos-for-traffic-prioritisation&#34; &gt;QoS for Traffic Prioritisation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-qos-globally&#34; &gt;Enable QoS Globally&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-interface-trust-levels&#34; &gt;Configure Interface Trust Levels&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-up-traffic-classification--prioritisation&#34; &gt;Set Up Traffic Classification &amp;amp; Prioritisation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#acls-for-inter-vlan-and-management-access-control&#34; &gt;ACLs for Inter-VLAN and Management Access Control&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#example-block-traffic-from-a-specific-ip-range&#34; &gt;Example: Block Traffic from a Specific IP Range&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#example-restrict-ssh-access-to-trusted-ips&#34; &gt;Example: Restrict SSH Access to Trusted IPs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#dhcp-snooping-blocking-rogue-dhcp-servers&#34; &gt;DHCP Snooping: Blocking Rogue DHCP Servers&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dhcp-snooping-globally&#34; &gt;Enable DHCP Snooping Globally&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#apply-dhcp-snooping-to-vlans&#34; &gt;Apply DHCP Snooping to VLANs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#trust-only-uplink-ports-block-rogue-dhcp-servers&#34; &gt;Trust Only Uplink Ports (Block Rogue DHCP Servers)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#port-security-mac-limiting-and-sticky-address-binding&#34; &gt;Port Security: MAC Limiting and Sticky Address Binding&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#example-allow-only-one-mac-per-port&#34; &gt;Example: Allow Only One MAC Per Port&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#example-sticky-mac-address-binding&#34; &gt;Example: Sticky MAC Address Binding&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#etherchannel-with-lacp-for-link-aggregation&#34; &gt;EtherChannel with LACP for Link Aggregation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-etherchannel-lacp-mode&#34; &gt;Configure EtherChannel (LACP Mode)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#snmp-for-network-monitoring&#34; &gt;SNMP for Network Monitoring&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-snmp&#34; &gt;Enable SNMP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-snmp-configuration&#34; &gt;Verify SNMP Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#ntp-time-synchronisation&#34; &gt;NTP Time Synchronisation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-ntp-to-sync-time&#34; &gt;Configure NTP to Sync Time&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-ntp&#34; &gt;Verify NTP&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#centralised-logging-with-syslog&#34; &gt;Centralised Logging with Syslog&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-syslog&#34; &gt;Enable Syslog&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-syslog-settings&#34; &gt;Verify Syslog Settings&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#netflow-for-traffic-analysis&#34; &gt;NetFlow for Traffic Analysis&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-netflow&#34; &gt;Enable NetFlow&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-netflow&#34; &gt;Verify NetFlow&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#advanced-layer-2-security-mac-filtering-ip-source-guard-and-dai&#34; &gt;Advanced Layer 2 Security: MAC Filtering, IP Source Guard, and DAI&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-mac-address-filtering-higher-security&#34; &gt;Enable MAC Address Filtering (Higher Security)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-ip-source-guard-prevent-ip-spoofing&#34; &gt;Enable IP Source Guard (Prevent IP Spoofing)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-dynamic-arp-inspection-mitigate-arp-attacks&#34; &gt;Enable Dynamic ARP Inspection (Mitigate ARP Attacks)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-security-features&#34; &gt;Verify Security Features&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#multicast-optimisation-igmp-snooping-and-pim-sparse-mode&#34; &gt;Multicast Optimisation: IGMP Snooping and PIM Sparse Mode&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-igmp-snooping-to-optimise-multicast-traffic&#34; &gt;Enable IGMP Snooping to Optimise Multicast Traffic&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-pim-sparse-mode-for-multicast-routing&#34; &gt;Configure PIM Sparse Mode for Multicast Routing&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#set-up-a-rendezvous-point-rp-for-multicast-traffic&#34; &gt;Set Up a Rendezvous Point (RP) for Multicast Traffic&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-multicast-configuration&#34; &gt;Verify Multicast Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#hsrp-for-first-hop-gateway-redundancy&#34; &gt;HSRP for First-Hop Gateway Redundancy&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-hsrp-on-vlan-interfaces&#34; &gt;Enable HSRP on VLAN Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-hsrp-status&#34; &gt;Verify HSRP Status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#private-vlans-for-intra-subnet-isolation&#34; &gt;Private VLANs for Intra-Subnet Isolation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#create-primary--secondary-vlans&#34; &gt;Create Primary &amp;amp; Secondary VLANs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#assign-vlan-roles&#34; &gt;Assign VLAN Roles&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-private-vlan-configuration&#34; &gt;Verify Private VLAN Configuration&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#storm-control-for-broadcast-and-multicast-flood-protection&#34; &gt;Storm Control for Broadcast and Multicast Flood Protection&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-storm-control-on-interfaces&#34; &gt;Enable Storm Control on Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-storm-control-settings&#34; &gt;Verify Storm Control Settings&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#8021x-port-based-network-access-control&#34; &gt;802.1X Port-Based Network Access Control&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-8021x-globally&#34; &gt;Enable 802.1X Globally&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#configure-authentication-on-interfaces&#34; &gt;Configure Authentication on Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-8021x-status&#34; &gt;Verify 802.1X Status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#vrrp-for-multi-vendor-gateway-redundancy&#34; &gt;VRRP for Multi-Vendor Gateway Redundancy&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#enable-vrrp-on-vlan-interfaces&#34; &gt;Enable VRRP on VLAN Interfaces&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-vrrp-status&#34; &gt;Verify VRRP Status&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#saving-configuration-and-backup&#34; &gt;Saving Configuration and Backup&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#save-configuration-to-startup-config&#34; &gt;Save Configuration to Startup-Config&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#verify-configuration-save&#34; &gt;Verify Configuration Save&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#final-steps-review--documentation&#34; &gt;Final Steps: Review &amp;amp; Documentation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;This guide covers Cisco IOS switch configuration from initial console access through to a production-hardened state. Each section pairs the configuration commands with a verification step — in operational environments, the verify commands are as important as the config commands. An unchecked config is an assumption.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Operational Cost of Legacy Systems: Security Debt, Maintenance Burden, and Scalability Limits</title>
      <link>https://ducmt.netlify.app/posts/blogs/legacy-system-technical-debt/</link>
      <pubDate>Wed, 29 Nov 2023 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/legacy-system-technical-debt/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#productivity-drain-manual-workflows-and-accumulated-workarounds&#34; &gt;Productivity Drain: Manual Workflows and Accumulated Workarounds&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#the-pattern&#34; &gt;The Pattern&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-world-example&#34; &gt;Real-World Example&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#maintenance-burden-escalating-costs-of-keeping-legacy-systems-running&#34; &gt;Maintenance Burden: Escalating Costs of Keeping Legacy Systems Running&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happens&#34; &gt;What Happens?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-world-example-1&#34; &gt;Real-World Example&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-1&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-1&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#security-exposure-unpatched-vulnerabilities-and-incompatible-tooling&#34; &gt;Security Exposure: Unpatched Vulnerabilities and Incompatible Tooling&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happens-1&#34; &gt;What Happens?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-world-example-2&#34; &gt;Real-World Example&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-2&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-2&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#scalability-ceiling-when-legacy-architecture-blocks-business-growth&#34; &gt;Scalability Ceiling: When Legacy Architecture Blocks Business Growth&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happens-2&#34; &gt;What Happens?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#real-world-example-3&#34; &gt;Real-World Example&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-it-was-fixed-3&#34; &gt;How It Was Fixed&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#lesson-learned-3&#34; &gt;Lesson Learned&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#why-businesses-delay-modernisation&#34; &gt;Why Businesses Delay Modernisation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#how-to-build-the-case-for-modernisation&#34; &gt;How to Build the Case for Modernisation&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#best-practices-for-modernisation&#34; &gt;Best Practices for Modernisation&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#investing-in-future-proof-technology&#34; &gt;Investing in Future-Proof Technology&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#conclusion-the-cost-of-staying-stagnant&#34; &gt;Conclusion: The Cost of Staying Stagnant&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;p&gt;The argument for keeping legacy systems is almost always framed as cost avoidance: migration is expensive, risky, and disruptive. What rarely appears in that calculation is the ongoing cost of staying — the accumulated inefficiencies, security debt, and operational friction that compound quietly over time until they become impossible to ignore.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Optus 2023 Outage: BGP Routing Failure and Network Resilience Lessons</title>
      <link>https://ducmt.netlify.app/posts/blogs/optus-2023-bgp-routing-outage/</link>
      <pubDate>Tue, 14 Nov 2023 00:00:00 +0000</pubDate>
      <guid>https://ducmt.netlify.app/posts/blogs/optus-2023-bgp-routing-outage/</guid>
      <description>&lt;!-- START doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;!-- DON&#39;T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE --&gt;&#xA;&lt;h1 id=&#34;table-of-contents&#34;&gt;&#xA;  Table of Contents&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#table-of-contents&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#what-happened&#34; &gt;What Happened&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#root-cause&#34; &gt;Root Cause&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#similar-incidents&#34; &gt;Similar Incidents&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#bgp-hardening-best-practices-to-prevent-recurrence&#34; &gt;BGP Hardening: Best Practices to Prevent Recurrence&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;#network-outage-taxonomy&#34; &gt;Network Outage Taxonomy&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;!-- END doctoc generated TOC please keep comment here to allow auto update --&gt;&#xA;&lt;h1 id=&#34;what-happened&#34;&gt;&#xA;  What Happened&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#what-happened&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;div class=&#34;notice info&#34;&gt;&#xA;  &lt;div class=&#34;notice-title&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-exclamation-circle&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;Info&#xA;  &lt;/div&gt;&#xA;  &lt;div class=&#34;notice-content&#34;&gt;The Optus 2023 outage was a major network failure affecting approximately 10 million customers on November 8, 2023, disrupting mobile voice, internet access, and emergency services for the better part of a day.&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h1 id=&#34;root-cause&#34;&gt;&#xA;  Root Cause&#xA;  &lt;a class=&#34;heading-link&#34; href=&#34;#root-cause&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-link&#34; aria-hidden=&#34;true&#34; title=&#34;Link to heading&#34;&gt;&lt;/i&gt;&#xA;    &lt;span class=&#34;sr-only&#34;&gt;Link to heading&lt;/span&gt;&#xA;  &lt;/a&gt;&#xA;&lt;/h1&gt;&#xA;&lt;div class=&#34;notice note&#34;&gt;&#xA;  &lt;div class=&#34;notice-title&#34;&gt;&#xA;    &lt;i class=&#34;fa-solid fa-sticky-note&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;Note&#xA;  &lt;/div&gt;&#xA;  &lt;div class=&#34;notice-content&#34;&gt;According to Optus&amp;rsquo;s post-incident disclosure, at approximately 4:05 AM, a routine software upgrade triggered a change in routing information received from an international peering network. These BGP updates propagated through multiple layers of the Optus IP core, exceeding preset safety thresholds on key routers. Unable to process the load, those routers withdrew from the IP core to protect themselves — a self-preservation mechanism that cascaded into a nationwide outage.&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;The underlying failure mode is a well-known class of BGP incident: a peer advertises an excessive number of prefixes or malformed route attributes, and the receiving network lacks adequate filtering or dampening to absorb the impact. In this case, the routing update volume wasn&amp;rsquo;t anomalous on its own — what failed was the chain of safeguards that should have caught it before it reached production infrastructure.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
