Sunday, May 17, 2009

CCIE Security Open Ended Question Live Date

The Open Ended Questions Live Date was announced for CCIE Security Labs.

From Cisco:
"Effective June 15, 2009, the Cisco CCIE Security lab exam will feature a new type of question format in a section called Core Knowledge. In this new section, candidates will be asked a series of four open-ended questions that require a short, typewritten response (typically several words). The questions will be randomly drawn from a pool of questions on topics currently eligible for testing on the CCIE Security lab exam. No new topics are being added. Candidates will have up to 30 minutes to complete the Core Knowledge section of the exam, and may not return to the questions later. First introduced to the CCIE Routing and Switching lab exam in February 2009, Core Knowledge questions will eventually be added to all CCIE tracks. The changes allow Cisco to maintain strong exam security, and they help ensure that only qualified candidates are awarded CCIE certification."

Saturday, May 16, 2009

CCIE Security Book List


Information taken from:
http://www.cisco.com/web/learning/le3/ccie/security/book_list.html

Cisco Press Titles

Other Publications

Friday, May 15, 2009

CCIE Routing & Switching Book List

Information taken from:
https://cisco.hosted.jivesoftware.com/docs/DOC-4601

CCIE R&S Reading List

This page lists books on topics appearing on the CCIE Written and Lab Exam. These books are not required study resources, however, they can be used to build knowledge in certain areas.

Many of the Cisco Press books are available to certified individuals and Cisco customers at prices discounted up to 30% off. To check for discounts, visit the Cisco Marketplace, click on (Cisco Press) Bookstore, and login with your Cisco CCO ID. Search for the titles using the ISBN number indicated.

1. CCIE Routing and Switching Exam Certification Guide, Third Edition

2. CCIE Routing and Switching Exam Quick Reference

3. CCIE Routing and Switching Practice Labs

4. Routing TCP/IP, Volume I, 2/e

5. Routing TCP/IP, Volume II

6. Troubleshooting IP Routing Protocols

7. Inside Cisco IOS Software Architecture

8. Cisco LAN Switching

9. Cisco OSPF Command and Configuration Handbook

10. Cisco BGP-4 Command and Configuration Handbook

11. Cisco Field Manual: Router Configuration

12. Cisco Field Manual: Catalyst Switch Configuration

13. Developing IP Multicast Networks, Volume I

14. Internet Routing Architectures, Second Edition

15. MPLS and VPN Architectures

16. MPLS and VPN Architectures, Volume II

17. Cisco Catalyst QoS

18. End-to-End QoS Network Design

19. Deploying IPv6 Networks

20. Network Security Technologies and Solutions


The following titles are no longer for sale in print format, but are available for free online view at the InformIT Reference Library:

1. CCIE Practical Studies, Volume I

2. CCIE Practical Studies, Volume II

3. Troubleshooting Remote Access Networks

4. Troubleshooting VPNs

Tuesday, May 5, 2009

CCIE R & S Exam Updates

The following announcements were made for the CCIE Routing and Switching Exam Updates:


Cisco® Revises its Popular CCIE® R&S Certification

Cisco has revised the certification requirements for CCIE Routing & Switching (CCIE R&S)-the expert level certification for network engineers.

The new certification standards reflect the job skills employers look for at the expert level and are outlined on the Cisco Learning Network at CCIE R&S v4.0 written exam topics and CCIE R&S v4.0 lab exam topics. The revised CCIE R&S v4.0 exams are scheduled for release on October 18, 2009 and will immediately replace the currently available v3.0 exams.

To support the certification changes, the Cisco 360 Learning Program for CCIE R&S is being updated with new lessons on MPLS and Troubleshooting, additions to the instructor-led workshops, new lab exercises for self-paced practice, and new performance assessments. The Program is the only authorized expert training currently aligned to CCIE R&S v4.0. The program is delivered globally by Cisco Learning Partners .

Save the Date: Two Live CCIE R&S Certification Webinars, May 20, 2009
Cisco will conduct two live webinars on Wednesday, May 20, 2009 covering enhancements made to the CCIE R&S certification and to the Cisco 360 Learning Program for CCIE R&S to align with the updates. Attendees can choose from calls at 8:00 AM and 7:00 PM PST. Click here to register.

For more information on the updates, the Cisco 360 Learning Program for CCIE R&S, and how to locate an authorized Learning Partner, access the Cisco Learning Network.

Saturday, May 2, 2009

FTP Multiline 221 Bug in FWSM

This is one I ran into recently.

Link to Cisco Bug Toolkit
Will need CCO Login
CSCsi27512 Bug Details
FTP with multiline 221 lines closes the connection too early
Symptom:
FTP client / server do not close their connection in some cases when the server
uses multiline 221 closure sequence.

Conditions:
When some OS is used (not all of them, not identified properly) and the server uses
multi line 221 closure sequence like:

221-You have transferred 0 bytes in 0 files.
221-Total traffic for this session was 2551 bytes in 1 transfers.
221-Thank you for using the FTP service on orbi.
221 Goodbye.

instead of the classic
221 Goodbye;

Workaround:
1. Disable ftp inspection OR disable 221 mutliline.
or
2. if running a version of FWSM code where the command is supported, you can disable the TCP Normalizer feature which has minimal impact. Disable the normalizer with the command:
"no control-point tcp-normalizer"
or
3. If running in an active/standby failover mode setup, a forced switchover should alleviate the problem. If not running a failover mode that is if there i no failover pair, but have failover enabled, then a "no failover" and "failover" [i.e disabling and enabling failover] should help.

Wednesday, April 1, 2009

Cisco ASA "vpnsetup" Command

A neat little help command built into the ASA to help with VPN steps and setup.

ASA(config)# vpnsetup ?
configure mode commands/options:
ipsec-remote-access Display IPSec Remote Access Configuration Commands
l2tp-remote-access Display L2TP/IPSec Configuration Commands
site-to-site Display IPSec Site-to-Site Configuration Commands
ssl-remote-access Display SSL Remote Access Configuration Commands


ASA(config)# vpnsetup ipsec-remote-access steps
Steps to configure a remote access IKE/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha

3. Setup an address pool

ip local pool client-pool 192.168.1.1-192.168.1.254

4. Configure authentication method

aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y

5. Define tunnel group

tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss

6. Setup ipsec parameters

crypto ipsec transform-set myset esp-aes esp-sha-hmac

7. Setup dynamic crypto map

crypto dynamic-map dynmap 1 set transform-set myset
crypto dynamic-map dynmap 1 set reverse-route

8. Create crypto map entry and associate dynamic map with it

crypto map mymap 65535 ipsec-isakmp dynamic dynmap

9. Attach crypto map to interface

crypto map mymap interface outside

10. Enable isakmp on interface

crypto isakmp enable outside


ASA(config)# vpnsetup l2tp-remote-access steps
Steps to configure a remote access L2TP/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha

3. Setup an address pool

ip local pool client-pool 192.168.1.1-192.168.1.254

4. Configure authentication method

aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y

5. Define tunnel group

tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss
tunnel-group DefaultRAGroup ppp-attributes
authentication pap

6. Setup ipsec parameters

crypto ipsec transform-set myset esp-aes esp-sha-hmac
crypto ipsec transform-set myset mode transport

7. Setup dynamic crypto map

crypto dynamic-map dynmap 1 set transform-set myset

8. Create crypto map entry and associate dynamic map with it

crypto map mymap 65535 ipsec-isakmp dynamic dynmap

9. Attach crypto map to interface

crypto map mymap interface outside

10. Enable isakmp on interface

crypto isakmp enable outside


ASA(config)# vpnsetup site-to-site steps
Steps to configure a site-to-site IKE/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 10
authentication pre-share
encryption aes
hash sha

3. Configure transform-set

crypto ipsec transform-set myset esp-aes esp-sha-hmac

4. Configure ACL

access-list L2LAccessList extended permit ip 192.168.0.0 255.255.255.0 192.168.50.0 255.255.255.0

5. Configure Tunnel group

tunnel-group 10.20.20.1 type ipsec-l2l
tunnel-group 10.20.20.1 ipsec-attributes
pre-shared-key P@rtn3rNetw0rk

6. Configure crypto map and attach to interface

crypto map mymap 10 match address L2LAccessList
crypto map mymap 10 set peer 10.10.4.108
crypto map mymap 10 set transform-set myset
crypto map mymap 10 set reverse-route
crypto map mymap interface outside

7. Enable isakmp on interface

crypto isakmp enable outside

ASA(config)# vpnsetup ssl-remote-access steps
Steps to configure a remote access SSL VPN remote access connection and AnyConnect with examples:

1. Configure and enable interface

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Enable WebVPN on the interface

webvpn
enable outside

3. Configure default route

route outside 0.0.0.0 0.0.0.0 10.10.4.200

4. Configure AAA authentication and tunnel group

tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL

5. If using LOCAL database, add users to the Database

username test password t3stP@ssw0rd
username test attributes
service-type remote-access

Proceed to configure AnyConnect VPN client:

6. Point the ASA to an AnyConnect image

webvpn
svc image anyconnect-win-2.1.0148-k9.pkg

7. enable AnyConnect

svc enable

8. Add an address pool to assign an ip address to the AnyConnect client

ip local pool client-pool 192.168.1.1-192.168.1.254 mask 255.255.255.0

9. Configure group policy

group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol svc webvpn

Monday, March 9, 2009

Wednesday, February 18, 2009

Cisco IOS XE End-of-Life Guidelines

Introduction

This product bulletin describes the end-of-sale and end-of-life (EoL) guidelines for Cisco IOS® XE Software on the Cisco® ASR 1000 Series Aggregation Services Router.
Cisco IOS XE Software is a time-based release as opposed to a feature-based release. Consequently, these end-of-sale and EoL guidelines of the Cisco IOS XE Software differ from the guidelines of other traditional Cisco IOS Software releases. This product bulletin outlines these differences and describes the standard end-of-sale and EoL milestones.

Cisco IOS XE Software Release

Cisco is introducing a new software release and a specific EoL guidelines with the introduction of the first Cisco IOS XE Software release. Cisco IOS XE Software provides for more frequent releases and quicker obsolescence of individual software releases, enabling Cisco to introduce a greater number of stable IOS XE Software releases with fewer new features in each release. As a result, the customer release qualification time of each release may be reduced.
The architecture of the Cisco ASR 1000 Series Aggregation Services Router is designed with In-Service Software Upgrade (ISSU) capabilities. End users can usually perform hitless software upgrades while the system is in service.
The Cisco IOS XE Software releases are time-based, each with a fixed release date, as opposed to feature-based releases, with a variable release date. The schedule specifies three individual software releases at 4-month intervals within a 12-month cycle.

Cisco IOS XE Software Support

Each Cisco IOS XE software release is classified as either a Standard-Support or Extended-Support release. A Standard-Support release has a sustaining support lifetime of one year from FCS with two scheduled rebuilds. These rebuilds are typically released at a two month interval after First-Customer-Ship (FCS) of the affected IOS XE software release.
The Extended-Support release provides a sustaining support lifetime of two years from FCS with four scheduled rebuilds. The first two of these rebuilds are released at two-month intervals after FCS of the subject IOS XE software release while the second two rebuilds are released at a four-month interval thereafter.
Cisco makes no commitment to introduce software fixes to the affected IOS XE Software release after the final planned rebuild release.
Software issues found after the final rebuild release will be fixed in a subsequent major IOS XE Software releases until the End of Software Maintenance Support (EoSWM) milestone. An exception may arise to address mission-critical, high-severity software fixes and security vulnerabilities which may result in an additional rebuild release after the final scheduled rebuild date (but before the EoSWM milestone) on an as-needed basis at the discression of Cisco. No software fixes will be introduced to the affected IOS XE software release after the EoSWM milestone.
After the EoSWM milestone, the Cisco Technical Assistance Center (TAC) will provide customer support on the affected IOS XE Software release within the guidelines set by existing Cisco EoL policies at the EoSW milestone.

Cisco IOS XE Software Release Schedule

Cisco IOS XE Software releases 2.1 through 2.3 are Standard-Support releases. Release 2.4 is the first Extended-Support release. After release 2.4, every third IOS XE Software release will be an Extended-Support release. Table 1 defines the support models used by each of the IOS XE Software releases through Release 2.13.

Table 1. Cisco IOS XE Software Release Support

Support Model

IOS XE Release

Standard-Support

2.1, 2.2, 2.3, 2.5, 2.6, 2.8, 2.9, 2.11, 2.12

Extended-Support

2.4, 2.7, 2.10, 2.13

End-of-Sale and End-of-Life Guideline Definition

The Cisco IOS XE Software's end-of-sale and EoL guidelines have pre-set time intervals for each of the EoL milestones. These time intervals are based on the support model of the affected Cisco IOS XE Software version. Table 2 summarizes the end-of-sale and EoL milestones for Cisco IOS XE Software releases.

Table 2. Cisco IOS XE Software End-of-Sale and End-of-Life Milestones by Release

Milestone

Definition

Timing

First-Customer-Ship (FCS)

The date at which the affected Cisco IOS XE Software release is made available to Cisco customers.

Begins affected Cisco IOS XE software release lifetime.

End-of-Life Announcement Date

The date the document that announces the end of sale and end of life of a product is distributed to the general public.

At FCS for Standard-Support releases.

Six (6) months after FCS for Extended-Support releases.

End of Planned SW Maintenance Release Date*

The last date that Cisco Engineering may release a software maintenance release in an affected Cisco IOS XE Software release. After this date, maintenance rebuilds and software-fix support will be provided only through subsequent major Cisco IOS XE Software releases until the End of Software Engineering Maintenance Support (EoE) date of the affected release.

Four (4) months after FCS for Standard-Support releases.

One (1) year after FCS for Extended-Support releases.

End-of-Sale Date

The last date to order the product through Cisco point-of-sale mechanisms. The product is no longer for sale after this date.

Nine (9) months after FCS for Standard-Support releases.

One (1) year after FCS for Extended-Support releases.

End of Software Maintenance Support (EoSWM) Date

Date when Cisco Engineering no longer provides bug fixes to software.

One (1) year after FCS for Standard-Support releases.

Two (2) years after FCS for Extended-Support releases.

Last Date of Support

The last date to receive service and support for the product. After this date, all support services for the product are unavailable, and the product becomes obsolete.

Five (5) years after End-of-Sale date for either Standard-Support or Extended-Support releases.

* An additional rebuild release may be released after the final rebuild date to address mission-critical, high-severity software fixes and security vulnerabilities (before the EoSWM date) on an as-needed basis at the discretion of Cisco Systems, Inc.
The Cisco IOS XE Software end-of-sale and End of Software Maintenance Support (EoSWM) timeline for Standard-Support releases shown in Figure 1.

Figure 1. Cisco ASR 1000 Series Router Standard-Support Software End-of-Life Timeline

The Cisco IOS XE Software end-of-sale and End of Software Maintenance Support (EoSWM) timeline for Extended-Support releases shown in Figure 2.

Figure 2. Cisco ASR 1000 Series Router Extended-Support Software End-of-Life Timeline

Upgrade Paths

Customers are encouraged to migrate to one of the Extended-Support releases (Cisco IOS XE Software release 2.4,2.7, 2.10, 2.13, etc.) when the release becomes available with appropriate features for the applications.

Customer Notifications

Cisco will issue individual EoL bulletins for each software release affected by an EoL plan. Standard-Support releases will have an EoL announcement published at FCS. Extended-Support releases will have an EoL announcement published six months after FCS.

Cisco Services

Cisco offers a wide range of services programs to accelerate customer success. These innovative services programs are delivered through a unique combination of resources, processes, tools, and partners, resulting in high levels of customer satisfaction. Cisco services help you protect your network investment, optimize network operations, and prepare your network for new applications to extend network intelligence and the power of your business. For more information about Cisco Services, refer to Cisco Technical Support Services at: http://www.cisco.com/en/US/products/svcs/ps3034/serv_category_home.html or Cisco Advanced Services at: http://www.cisco.com/go/services.

For More Information

Please refer to product bulletin PB448387, "Cisco IOS XE Software for Cisco ASR 1000 Series Routers", for more information about the overall software release strategy for the Cisco ASR 1000 Series products.
For more information about the Cisco ASR 1000 Series Routers, visit http://www.cisco.com/en/US/products/ps9343/index.html or contact your local Cisco account manager.
For information about Cisco service and support programs and benefits, visit: http://www.cisco.com/public/Support_root.shtml.

Thursday, February 12, 2009

6509 Dual SUP File Copy

A little tidbit about copying files from the primary SUP to the redundant SUP when doing an IOS upgrade or for any other reason. You need to copy that same file to the redundant SUP to make sure it boots up as well. If not it will not boot and show up as Other status and a diagnostics of not applicable.

General Copy from TFTP to Flash
6509#copy ftp flash
Address or name of remote host [10.1.1.1]?
Source filename [s72033-ipservicesk9_wan-mz.122-33.SXH5.bin]? /desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Destination filename [flash]? s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Accessing ftp://10.1.1.1//desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin...
Loading /desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[OK - 74788836/4096 bytes]

74788836 bytes copied in 184.176 secs (406073 bytes/sec)


Now Copy from the file from the Primary SUP to the Redundant SUP
6509#copy disk0: slavedisk0:
Source filename []? s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Destination filename [s72033-ipservicesk9_wan-mz.122-33.SXH5.bin]?
Copy in progress... CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
74788836 bytes copied in 262.984 secs (284385 bytes/sec)


If you have (Other) instead of (Hot) in the top section and a Not Applicable in the bottom section when executing a show module command, your Redundant SUP likely did not boot properly. This will happen if you forget to copy over the IOS to the Redundant SUP module.

Tuesday, February 10, 2009

Look at Cisco IOS XE

Micheal Morris posted a nice article on Cisco IOS XE over at Network World Cisco Subnet.

http://www.networkworld.com/community/node/37762