<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cisco on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/cisco/</link>
    <description>Recent content in Cisco on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Tue, 15 Sep 2026 09:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/cisco/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Webex Is Looking For Your Certificates On A Cisco Build Server</title>
      <link>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</link>
      <pubDate>Tue, 15 Sep 2026 09:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</guid>
      <description>Webex on Linux says &amp;#34;Offline - No internet connection&amp;#34; on a machine whose network is fine: the OpenSSL Cisco ship looks for its trust store inside their own build container. What breaks, the fixes that fail, the one that works, what the build process got wrong, and how a security appliance vendor ships a client that cannot check a certificate.</description>
    </item>
    <item>
      <title>IPsec Was a Good Idea. It Is Time to Turn It Off.</title>
      <link>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</link>
      <pubDate>Sun, 13 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</guid>
      <description>IPsec bound security to the IP address, then the industry took the address away. NAT, double NAT under CGNAT, NAT64 that will not carry it at all, no ports so no load balancing, the MTU tax, L2TP, PPTP and Windows interop — with diagrams, Cisco and Juniper documentation, a full diagnostic method, and the case for retiring it.</description>
    </item>
    <item>
      <title>Is Your MSP Lying To You To Sell You Premium Products?</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</link>
      <pubDate>Fri, 28 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</guid>
      <description>Part 1 of 3. Some MSPs lie; most never have to, because the vendors whose products they recommend pay them and nobody must tell you. The tells that you are being sold to rather than engineered for: the free fix refused, requirements never written down, one option on the shortlist, no open source line, and the addresses you rent forever.</description>
    </item>
    <item>
      <title>What Your MSP Built You, And Who Else Can Reach It</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</link>
      <pubDate>Fri, 28 Aug 2026 17:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</guid>
      <description>Part 2 of 3. Cloud for a business all in one building. The firewall brand with the most exploited vulnerabilities on CISA&amp;#39;s list. Backups nobody has restored, reports that never reach you, an agent on every machine answering to a console you have never seen. What the ICO found at Advanced and Capita, and the keys that open all of it.</description>
    </item>
  </channel>
</rss>
