This curriculum spans the full operational lifecycle of network devices within a Configuration Management Database, comparable in scope to a multi-workshop program for establishing CMDB governance across network, security, and operations teams in a large enterprise.
Module 1: Defining Network Device Scope in the CMDB
- Determine which network devices (routers, switches, firewalls, load balancers, WAPs) require inclusion based on business criticality and change frequency.
- Establish criteria for excluding transient or edge devices such as IoT endpoints or guest access points from full CMDB lifecycle tracking.
- Define ownership boundaries between network operations, security, and cloud teams for hybrid infrastructure devices.
- Resolve conflicts between network topology diagrams and actual device inventories during initial CMDB scoping.
- Classify devices by environment (production, staging, DR) to align with change control and access policies.
- Decide whether virtual network functions (VNFs) and cloud-native appliances (e.g., AWS Transit Gateway) are modeled as discrete CIs.
- Implement tagging standards for device purpose, tier, and regulatory classification (e.g., PCI, HIPAA).
- Document exceptions for legacy or unsupported devices that cannot be automatically discovered.
Module 2: Data Modeling for Network Configuration Items
- Design CI classes to reflect network device hierarchies (chassis, modules, interfaces) while avoiding over-normalization.
- Map vendor-specific attributes (e.g., IOS version, ASIC type) to standardized CMDB fields without losing operational context.
- Define relationship types (e.g., "connected to", "upstream of", "managed by") with cardinality and directionality rules.
- Integrate power, location, and rack elevation data from DCIM systems into network device records.
- Model redundancy relationships (e.g., VRRP pairs, stacking) to support impact analysis during outages.
- Establish inheritance rules for firmware, configuration templates, and compliance baselines across device groups.
- Balance granularity of interface-level data against CMDB performance and update frequency constraints.
- Define lifecycle states (planned, in maintenance, decommissioned) and transition workflows for network hardware.
Module 3: Automated Discovery and Data Synchronization
- Select discovery methods (SNMP, CLI, NETCONF, API) based on device capabilities, security policies, and scale.
- Configure discovery schedules to minimize network load during peak utilization periods.
- Resolve discrepancies between discovery tool output and manually entered CMDB records using reconciliation rules.
- Implement credential management for secure access to network device command-line interfaces.
- Filter out transient interfaces (e.g., dialer, loopback) from discovery results to reduce noise.
- Integrate firewall rule metadata from vendor consoles (e.g., Palo Alto Panorama, Cisco FMC) into related device records.
- Handle devices behind NAT or management VLANs by deploying distributed discovery probes.
- Validate discovered topology links against LLDP/CDP data to correct miswirings in the CMDB.
Module 4: Change Management Integration
- Enforce pre-change CMDB snapshotting for network devices involved in change advisory board (CAB) reviews.
- Link change tickets to specific device CIs and validate change scope against configuration drift reports.
- Automatically trigger CMDB updates upon successful change implementation using post-change scripts.
- Prevent unauthorized configuration changes by integrating CMDB status with network automation gateways.
- Map change types (standard, emergency, normal) to different approval and documentation requirements in the CMDB.
- Correlate change records with configuration backup timestamps to ensure audit trail completeness.
- Flag devices with pending changes to prevent conflicting maintenance windows.
- Generate pre-CAB impact reports using CMDB relationships to downstream services and connected devices.
Module 5: Configuration Drift Detection and Remediation
- Define acceptable configuration variance thresholds (e.g., NTP servers, logging levels) to reduce false positives.
- Compare running vs. startup configurations and flag discrepancies that indicate uncommitted changes.
- Integrate with version-controlled configuration repositories to identify unauthorized deviations.
- Automate drift reporting for devices not compliant with enterprise hardening baselines.
- Escalate persistent drift to network owners using ticketing system integrations.
- Exclude environment-specific settings (IP addresses, hostnames) from cross-device compliance checks.
- Use checksums or hashing to detect binary configuration changes in firmware or bootloaders.
- Define remediation workflows for drift: auto-correct, manual review, or exception approval.
Module 6: Access Control and Role-Based Permissions
- Assign CMDB access levels based on network team roles (engineer, architect, operator, auditor).
- Restrict write access to device records based on network domain or geographical region.
- Implement read-only views for support teams needing impact analysis without modification rights.
- Log all CMDB modifications to network CIs for forensic and compliance auditing.
- Enforce dual control for updates to critical infrastructure devices (e.g., core routers).
- Integrate with enterprise identity providers (LDAP, SSO) for consistent role synchronization.
- Define time-limited access grants for third-party vendors performing network maintenance.
- Separate responsibilities between CMDB administrators and network operations to prevent privilege overlap.
Module 7: Integration with Monitoring and Incident Management
- Populate incident tickets with device CI data (owner, location, dependencies) during alert creation.
- Use CMDB relationships to enrich network alerts with potential service impact context.
- Synchronize device maintenance windows between monitoring tools and the CMDB.
- Suppress alerts for devices marked as decommissioned or in maintenance in the CMDB.
- Update device status in the CMDB based on prolonged monitoring downtime events.
- Map SNMP trap sources to CMDB CIs using DNS and IP resolution workflows.
- Validate incident root cause analysis against recent configuration or change records in the CMDB.
- Automatically link related incidents to shared network devices for trend analysis.
Module 8: Reporting, Audits, and Compliance
- Generate inventory reports for hardware refresh planning using device age and EOL/EOS dates.
- Produce compliance evidence for regulations (e.g., SOX, NIST) showing configuration consistency across device fleets.
- Run gap analyses to identify network devices missing from the CMDB but present in monitoring.
- Validate that all firewall rules are associated with authorized change tickets and service records.
- Archive CMDB snapshots prior to major network overhauls for retrospective audits.
- Measure CMDB accuracy through periodic manual verification spot-checks of device records.
- Report on configuration drift trends across device models and network segments.
- Support internal and external auditors with filtered exports of network CI data and change histories.
Module 9: Lifecycle Management and Decommissioning
- Trigger decommissioning workflows when devices reach end-of-support or fail reliability thresholds.
- Validate removal of all service dependencies before approving device retirement in the CMDB.
- Archive configuration backups and logs associated with decommissioned devices.
- Update physical asset records and coordinate with procurement for hardware disposal.
- Remove devices from monitoring and discovery scopes in a coordinated sequence.
- Retain CMDB records in historical mode with metadata on disposal date and method.
- Conduct post-decommission reviews to assess impact on network performance and redundancy.
- Update network diagrams and runbooks to reflect topology changes after device removal.