• Human Infrastructure
  • Posts
  • Human Infrastructure 454: FortiBleed, Hero Culture Sucks, NAF's Network Automation Framework

Human Infrastructure 454: FortiBleed, Hero Culture Sucks, NAF's Network Automation Framework

In honor of summer vacations (at least in the northern hemisphere), touching grass, and taking breaks, this fine newsletter will be taking a two week break. We’ll see you again on 16-July-2026.

For this week, we offer an abbreviated version of the most interesting things we found on the packet Internet. Please enjoy! - Ethan

THIS WEEK’S MUST-READ BLOGS 🤓

Chris Grundemann points out the systemic business risk of IT hero culture, suggesting that building processes around teams & outcomes instead of individuals is the right way to go. But how does an organization make that shift? Leadership driving the proper changes.

Hero culture is self-reinforcing because it produces real value in the short term. The engineer who stays until 3am to restore service is genuinely valuable in that moment. The problem is that celebrating that moment, without also asking why the 3am call happened, trains the organization to produce more 3am calls. It trains engineers to be available for emergencies rather than to eliminate them. It trains management to tolerate the underlying fragility because the hero is always there to absorb the consequences.

Breaking that cycle requires leadership to make the structural work visible and valued.

Lots more thoughtful prose from Chris on the click. - Ethan

Tony Mattke summarizes a talk by Jeff Doyle at CHI-NOG 13 about the Network Automation Forum’s Network Automation Framework project.

From Jeff’s presentation as shared on Tony’s blog.

Tony was quite thoughtful about NAF framework and shared many insights as to how the framework maps to the real world. You should click through and read his post, but if you need the TL;DR, Tony’s a fan.

The Network Automation Framework is one of the more useful pieces of vendor-neutral thinking that’s come out of the operator community in the last few years. Take it into your next vendor evaluation and use it as a checklist. Take it into your own DIY effort and use it to audit your own coverage. Either way it gives you a structure for the conversation that doesn’t depend on whoever’s pitching you this week.

I attended NAF’s AutoCon5 event in Munich recently, and there was an entire track devoted to the Network Automation Framework. If you want to explore further, all the AC5 talks will find their way to YouTube (although not yet as I write this). - Ethan

What are collective communications? Phil Gervasi explains.

At a high level, collective communication operations allow groups of accelerators to exchange, aggregate, synchronize, and distribute information very efficiently. Instead of treating communication as a series of independent point-to-point flows, collective operations coordinate communication across entire groups of participants simultaneously.

That means the network is no longer merely transporting application traffic. Instead, the network is an active participant in the computational process itself. As John Gage of Sun Microsystems famously said in 1984, “the network is the computer.”

This paradigm is crucial for AI workloads, where large numbers of GPUs must be tightly coupled as they work on complex math problems together. With his usual diagrams and thoughtful sections, Phil explains the key concepts clearly. - Ethan

Larry Peterson summarizes the state of network management, and how he and Bruce Davie opted to cover gNMI instead of NETCONF in their discussion of network operations in their book. The piece ends up as an insightful analysis worth pondering. - Ethan

MORE BLOGS

Browse Bravely.
In a brave new world of AI and the cloud, your secure browser is the new edge. Meet the Secure Browser from Prisma® Access that's designed for the future. Want to learn how Prisma® Access Browser can enable your team to browse bravely? Contact Palo Alto Networks today and experience the secure browser.
https://start.paloaltonetworks.com/contact-us-pab.html

TECH NEWS 📣

FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide - NetworkWorld
https://www.networkworld.com/article/4186794/fortibleed-campaign-exposes-75000-fortinet-firewalls-worldwide-2.html

If you admin an Internet-facing FortiGate box, be aware that many thousands of FortiGate credentials have been leaked into the wild by the bad guys.

According to independent analyses, including by SOCRadar, Hudson Rock, and security researcher Kevin Beaumont, the threat actors systematically collected configuration files from internet-facing Fortinet FortiGate firewalls and used them to recover working administrator credentials. The initial access vector is presently unknown.

If you believe you might be affected, here’s a Fortinet blog that should help you formulate a remediation plan. - Ethan

FOR THE LULZ 🤣

Kaj Niemi shared this in the Packet Pushers community Slack. 😆

RESEARCH & RESOURCES 📒

EVE-NG is a popular network labbing platform that follows the freemium model. Version 7 is the result of a need to model a 600 node network. This was a major challenge, but the EVE-NG team got it done, as Alain reports.

EVE-NG V7 is not only about a new interface. It is not only about Ubuntu 24.04. It is not only about new features.

EVE-NG V7 represents a deeper evolution of the platform.

It confirms that EVE-NG can be used not only for training, certification, and classic network labs, but also as a serious foundation for large-scale digital twin scenarios, architecture validation, and complex network simulation.

Check out the release notes here. - Ethan

Didactic Phil Gervasi offers you a solid foundation upon which to build your EVPN/VXLAN knowledge.

Traditional networks (campus, legacy data center, etc) rely mostly on flooding and MAC learning. Switches learn MAC addresses by observing traffic and then flooding unknown unicast traffic throughout a Layer 2 domain, also known as flood-and-learn. That works well at a small scale, but it becomes very inefficient when we scale up to large data centers with hundreds or thousands of switches.

EVPN replaces many of these data-plane learning mechanisms with a control-plane approach. Instead of waiting for switches to discover information through flooding, endpoint information is distributed proactively through BGP EVPN, which is an extension of BGP.

To do this, EVPN uses several specialized route types that communicate different categories of information:

  • MAC addresses

  • IP addresses

  • VXLAN tunnel endpoints (VTEPs)

  • Gateway MAC/IP information

  • Multicast and broadcast handling

  • Layer 3 routing information

What we get is a network fabric that converges quickly, scales efficiently, and minimizes (or eliminates) unnecessary flooding.

Phil goes on to explain each route type, annotating with diagrams and CLI output along the way. Bookmark this one. This is the sort of information you usually have to buy a book to get. (Hey…is Phil writing a book?? 🧐) - Ethan

If you’re pursuing the elusive Cisco Certified Design Expert certification, Jerome has compiled a valuable (and long) list of reading material for you.

This post is the CCDE reading list I actually used to pass the CCDE written (400-007) and practical exams. I have organized everything into my O’Reilly playlist, publicly accessible, so you can follow it directly if you have an O’Reilly subscription.

This list includes full books, individual chapters, and video courses. Some chapters were selected for their specific content, while the video courses provide a complementary perspective on subjects covered in the books.

Thank you, Jerome! - Ethan

MORE RESOURCES

UPCOMING LIVE EVENTS 🍕🍻

A curated list of near-future meatspace events of interest to network engineers. Sometimes a Packet Pusher or two will be there (noted below).

Subscribe to events.packetpushers.net in your calendar software.

JULY 2026

Wi-Co Lyon
2 July | Lyon, France

NetUK3
6-7 July | London, England

SharkFest’26 | WireShark User Conference
18 - 23 July | Nashville, Tennessee

IETF 126 | Internet Engineering Task Force
18 - 24 July | Vienna, Austria

(PA)NUG | Pennsylvania Networking User Group (USNUA)
23 July | Pittsburgh, Pennsylvania

AUGUST 2026

SEPTEMBER 2026

NLNAM Meetup 3 | NL Network Automation Meetup
9 September | Utrecht, Netherlands

Wi-Co Manchester
9 - 10 September | Manchester, UK

Zeek Workshop
10 - 11 September | Berkeley, California

(MO)NUG | Missouri Networking User Group (USNUA)
23 September | St. Louis, Missouri

Wi-Co Cleveland
24 September | Cleveland, OH

LAST LAUGH 😆

Shared by Chris Emerick in the Packet Pushers community Slack. 😂