Craig Tompkins - CCIE #16921
The Network Expert is a blog about computer networking focusing on routing, switching, security, the Expert Cisco Certifications, CCIE & CCDE, and their topics. It's goal to is to document these topics for study and continued knowledge.
Sunday, May 17, 2009
CCIE Security Open Ended Question Live Date
From Cisco:
"Effective June 15, 2009, the Cisco CCIE Security lab exam will feature a new type of question format in a section called Core Knowledge. In this new section, candidates will be asked a series of four open-ended questions that require a short, typewritten response (typically several words). The questions will be randomly drawn from a pool of questions on topics currently eligible for testing on the CCIE Security lab exam. No new topics are being added. Candidates will have up to 30 minutes to complete the Core Knowledge section of the exam, and may not return to the questions later. First introduced to the CCIE Routing and Switching lab exam in February 2009, Core Knowledge questions will eventually be added to all CCIE tracks. The changes allow Cisco to maintain strong exam security, and they help ensure that only qualified candidates are awarded CCIE certification."
Saturday, May 16, 2009
CCIE Security Book List

Information taken from:
http://www.cisco.com/web/learning/le3/ccie/security/book_list.html
Cisco Press Titles
- Advanced Host Intrusion Prevention with CSA (Asher, Mauvais, Sullivan, ISBN# 1587052520)
- CCIE Practical Studies: Security (CCIE Self-Study) (Bokotey, Mason, Morrow, ISBN# 1587051109)
- CCIE Security Exam Certification Guide (CCIE Self-Study), 2nd Edition (Benjamin, ISBN: 1587201356)
- CCIE Security Practice Labs (CCIE Self-Study) (Bhaiji, ISBN# 1587051346)
- CCSP IPS Exam Certification Guide (Carter, ISBN# 1587201461)
- Cisco Access Control Security: AAA Administration Services (Carroll, ISBN# 1587051249)
- Cisco ASA: All-in-One Firewall, IPS, and VPN Adaptive Security Appliance (Frahim, Santos, ISBN# 1587052091)
- Cisco ASA and PIX Firewall Handbook (Hucaby, ISBN# 1587051583)
- Cisco Network Security Troubleshooting Handbook (Hoda, ISBN# 1587051893)
- Cisco Router Firewall Security (Deal, ISBN# 1587051753)
- Cisco Security Agent (Sullivan, ISBN# 1587052059)
- Comparing, Designing, and Deploying VPNs (Lewis, ISBN# 1587051796)
- Designing Network Security, Second Edition (Kaeo, ISBN# 1587051176)
- Intrusion Prevention Fundamentals (Carter, Hogue, ISBN# 1587052393)
- IPSec VPN Design (Bollapragada, Khalid, Wainner, ISBN# 1587051117)
- Network Security Architectures (Convery, ISBN# 158705115X)
- Network Security Fundamentals (De Laet, Schauwers, ISBN# 1587051672)
- Network Security Principles and Practices (Malik, ISBN# 1587050250)
- Penetration Testing and Network Defense (Newman, Whitaker, ISBN# 1587052083)
- Routing TCP/IP, Volume I, Second Edition (Carroll, Doyle, ISBN# 1587052024)
- Routing TCP/IP, Volume 2 (Doyle, DeHaven Carroll, ISBN# 1578700892)
- Securing Your Business with Cisco ASA and PIX Firewalls (Abelar, ISBN# 1587052148)
- The Complete Cisco VPN Configuration Guide (Deal, ISBN# 1587052040)
- Troubleshooting Virtual Private Networks (VPN) (Lewis, ISBN# 1587051044)
- Troubleshooting IP Routing Protocols (Aziz, Liu, Martey, Shamim, ISBN# 1587050196)
- Router Security Strategies: Securing IP Network Traffic Planes (Schudel, Smith, ISBN# 1587053365)
- Network Security Technologies and Solutions (Bhaiji, ISBN# 1587052466)
Other Publications
- Cisco Security Architectures (Held and Hundley, McGraw Hill, ISBN# B00005UMKL)
- Firewalls and Internet Security, Second Edition (Cheswick, Bellovin, and Rubin, Addison-Wesley, ISBN# 020163466X)
- Internetworking with TCP/IP Volume I: Principles, Protocols, and Architecture (4th Edition) (Comer and Stevens, Prentice Hall, ISBN# 0130183806)
- Internet Security Protocols : Protecting IP Traffic (Black, Prentice Hall, ISBN# 0130142492)
- IPSec: The New Security Standard for the Internet, Intranet and Virtual Private Networks (Doraswamy and Harkins, Prentice Hall, ISBN# 013046189X)
- ISDN : Concepts, Facilities, and Services (Kessler and Southwick, McGraw Hill, ISBN# 0070342490)
- Network Security: Private Communication in a Public World, Second Edition (Kaufman, Perlman, Speciner, Prentice Hall, ISBN# 0130460192)
- The Protocols (TCP/IP Illustrated : Volume 1)(Stevens, Addison Wesley, ISBN# 0201633469)
- The Implementation (TCP/IP Illustrated : Volume 2) (Stevens and Wright, Addison Wesley, ISBN# 020163354X)
- TCP for Transactions, HTTP, NNTP, and the UNIX(R) Domain Protocols (TCP/IP Illustrated : Volume 3) (Stevens, Addison Wesley, ISBN# 0201634953)
Friday, May 15, 2009
CCIE Routing & Switching Book List
https://cisco.hosted.jivesoftware.com/docs/DOC-4601
CCIE R&S Reading List
This page lists books on topics appearing on the CCIE Written and Lab Exam. These books are not required study resources, however, they can be used to build knowledge in certain areas.
Many of the Cisco Press books are available to certified individuals and Cisco customers at prices discounted up to 30% off. To check for discounts, visit the Cisco Marketplace, click on (Cisco Press) Bookstore, and login with your Cisco CCO ID. Search for the titles using the ISBN number indicated.
1. CCIE Routing and Switching Exam Certification Guide, Third Edition
2. CCIE Routing and Switching Exam Quick Reference
3. CCIE Routing and Switching Practice Labs
4. Routing TCP/IP, Volume I, 2/e
6. Troubleshooting IP Routing Protocols
7. Inside Cisco IOS Software Architecture
9. Cisco OSPF Command and Configuration Handbook
10. Cisco BGP-4 Command and Configuration Handbook
11. Cisco Field Manual: Router Configuration
12. Cisco Field Manual: Catalyst Switch Configuration
13. Developing IP Multicast Networks, Volume I
14. Internet Routing Architectures, Second Edition
15. MPLS and VPN Architectures
16. MPLS and VPN Architectures, Volume II
18. End-to-End QoS Network Design
20. Network Security Technologies and Solutions
The following titles are no longer for sale in print format, but are available for free online view at the InformIT Reference Library:
1. CCIE Practical Studies, Volume I
2. CCIE Practical Studies, Volume II
Tuesday, May 5, 2009
CCIE R & S Exam Updates
The following announcements were made for the CCIE Routing and Switching Exam Updates:
Cisco® Revises its Popular CCIE® R&S Certification
Cisco has revised the certification requirements for CCIE Routing & Switching (CCIE R&S)-the expert level certification for network engineers.
The new certification standards reflect the job skills employers look for at the expert level and are outlined on the Cisco Learning Network at CCIE R&S v4.0 written exam topics and CCIE R&S v4.0 lab exam topics. The revised CCIE R&S v4.0 exams are scheduled for release on October 18, 2009 and will immediately replace the currently available v3.0 exams.
To support the certification changes, the Cisco 360 Learning Program for CCIE R&S is being updated with new lessons on MPLS and Troubleshooting, additions to the instructor-led workshops, new lab exercises for self-paced practice, and new performance assessments. The Program is the only authorized expert training currently aligned to CCIE R&S v4.0. The program is delivered globally by Cisco Learning Partners .
Save the Date: Two Live CCIE R&S Certification Webinars, May 20, 2009
Cisco will conduct two live webinars on Wednesday, May 20, 2009 covering enhancements made to the CCIE R&S certification and to the Cisco 360 Learning Program for CCIE R&S to align with the updates. Attendees can choose from calls at 8:00 AM and 7:00 PM PST. Click here to register.
For more information on the updates, the Cisco 360 Learning Program for CCIE R&S, and how to locate an authorized Learning Partner, access the Cisco Learning Network.
Saturday, May 2, 2009
FTP Multiline 221 Bug in FWSM
Link to Cisco Bug Toolkit
Will need CCO Login
CSCsi27512 Bug Details
| FTP with multiline 221 lines closes the connection too early | |
| Symptom: FTP client / server do not close their connection in some cases when the server uses multiline 221 closure sequence. Conditions: When some OS is used (not all of them, not identified properly) and the server uses multi line 221 closure sequence like: 221-You have transferred 0 bytes in 0 files. 221-Total traffic for this session was 2551 bytes in 1 transfers. 221-Thank you for using the FTP service on orbi. 221 Goodbye. instead of the classic 221 Goodbye; Workaround: 1. Disable ftp inspection OR disable 221 mutliline. or 2. if running a version of FWSM code where the command is supported, you can disable the TCP Normalizer feature which has minimal impact. Disable the normalizer with the command: "no control-point tcp-normalizer" or 3. If running in an active/standby failover mode setup, a forced switchover should alleviate the problem. If not running a failover mode that is if there i no failover pair, but have failover enabled, then a "no failover" and "failover" [i.e disabling and enabling failover] should help. | |
Wednesday, April 1, 2009
Cisco ASA "vpnsetup" Command
ASA(config)# vpnsetup ?
configure mode commands/options:
ipsec-remote-access Display IPSec Remote Access Configuration Commands
l2tp-remote-access Display L2TP/IPSec Configuration Commands
site-to-site Display IPSec Site-to-Site Configuration Commands
ssl-remote-access Display SSL Remote Access Configuration Commands
ASA(config)# vpnsetup ipsec-remote-access steps
Steps to configure a remote access IKE/IPSec connection with examples:
1. Configure Interfaces
interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown
interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown
2. Configure ISAKMP policy
crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha
3. Setup an address pool
ip local pool client-pool 192.168.1.1-192.168.1.254
4. Configure authentication method
aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y
5. Define tunnel group
tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss
6. Setup ipsec parameters
crypto ipsec transform-set myset esp-aes esp-sha-hmac
7. Setup dynamic crypto map
crypto dynamic-map dynmap 1 set transform-set myset
crypto dynamic-map dynmap 1 set reverse-route
8. Create crypto map entry and associate dynamic map with it
crypto map mymap 65535 ipsec-isakmp dynamic dynmap
9. Attach crypto map to interface
crypto map mymap interface outside
10. Enable isakmp on interface
crypto isakmp enable outside
ASA(config)# vpnsetup l2tp-remote-access steps
Steps to configure a remote access L2TP/IPSec connection with examples:
1. Configure Interfaces
interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown
interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown
2. Configure ISAKMP policy
crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha
3. Setup an address pool
ip local pool client-pool 192.168.1.1-192.168.1.254
4. Configure authentication method
aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y
5. Define tunnel group
tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss
tunnel-group DefaultRAGroup ppp-attributes
authentication pap
6. Setup ipsec parameters
crypto ipsec transform-set myset esp-aes esp-sha-hmac
crypto ipsec transform-set myset mode transport
7. Setup dynamic crypto map
crypto dynamic-map dynmap 1 set transform-set myset
8. Create crypto map entry and associate dynamic map with it
crypto map mymap 65535 ipsec-isakmp dynamic dynmap
9. Attach crypto map to interface
crypto map mymap interface outside
10. Enable isakmp on interface
crypto isakmp enable outside
ASA(config)# vpnsetup site-to-site steps
Steps to configure a site-to-site IKE/IPSec connection with examples:
1. Configure Interfaces
interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown
interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown
2. Configure ISAKMP policy
crypto isakmp policy 10
authentication pre-share
encryption aes
hash sha
3. Configure transform-set
crypto ipsec transform-set myset esp-aes esp-sha-hmac
4. Configure ACL
access-list L2LAccessList extended permit ip 192.168.0.0 255.255.255.0 192.168.50.0 255.255.255.0
5. Configure Tunnel group
tunnel-group 10.20.20.1 type ipsec-l2l
tunnel-group 10.20.20.1 ipsec-attributes
pre-shared-key P@rtn3rNetw0rk
6. Configure crypto map and attach to interface
crypto map mymap 10 match address L2LAccessList
crypto map mymap 10 set peer 10.10.4.108
crypto map mymap 10 set transform-set myset
crypto map mymap 10 set reverse-route
crypto map mymap interface outside
7. Enable isakmp on interface
crypto isakmp enable outside
ASA(config)# vpnsetup ssl-remote-access steps
Steps to configure a remote access SSL VPN remote access connection and AnyConnect with examples:
1. Configure and enable interface
interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown
interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown
2. Enable WebVPN on the interface
webvpn
enable outside
3. Configure default route
route outside 0.0.0.0 0.0.0.0 10.10.4.200
4. Configure AAA authentication and tunnel group
tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL
5. If using LOCAL database, add users to the Database
username test password t3stP@ssw0rd
username test attributes
service-type remote-access
Proceed to configure AnyConnect VPN client:
6. Point the ASA to an AnyConnect image
webvpn
svc image anyconnect-win-2.1.0148-k9.pkg
7. enable AnyConnect
svc enable
8. Add an address pool to assign an ip address to the AnyConnect client
ip local pool client-pool 192.168.1.1-192.168.1.254 mask 255.255.255.0
9. Configure group policy
group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol svc webvpn
Monday, March 9, 2009
Subnetting Practice Program
http://faculty.valleycollege.net/rpowell/jscript/subnet2.htm
Wednesday, February 18, 2009
Cisco IOS XE End-of-Life Guidelines
http://www.cisco.com/en/US/prod/collateral/routers/ps9343/product_bulletin_c25-448258.html
Introduction
Cisco IOS XE Software Release
Cisco IOS XE Software Support
Cisco IOS XE Software Release Schedule
Table 1. Cisco IOS XE Software Release Support
| Support Model | IOS XE Release |
| Standard-Support | 2.1, 2.2, 2.3, 2.5, 2.6, 2.8, 2.9, 2.11, 2.12 |
| Extended-Support | 2.4, 2.7, 2.10, 2.13 |
End-of-Sale and End-of-Life Guideline Definition
Table 2. Cisco IOS XE Software End-of-Sale and End-of-Life Milestones by Release
Figure 1. Cisco ASR 1000 Series Router Standard-Support Software End-of-Life Timeline

Figure 2. Cisco ASR 1000 Series Router Extended-Support Software End-of-Life Timeline

Upgrade Paths
Customer Notifications
Cisco Services
For More Information
Thursday, February 12, 2009
6509 Dual SUP File Copy
General Copy from TFTP to Flash
6509#copy ftp flash
Address or name of remote host [10.1.1.1]?
Source filename [s72033-ipservicesk9_wan-mz.122-33.SXH5.bin]? /desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Destination filename [flash]? s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Accessing ftp://10.1.1.1//desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin...
Loading /desktop/s72033-ipservicesk9_wan-mz.122-33.SXH5.bin !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
[OK - 74788836/4096 bytes]
74788836 bytes copied in 184.176 secs (406073 bytes/sec)
Now Copy from the file from the Primary SUP to the Redundant SUP
6509#copy disk0: slavedisk0:
Source filename []? s72033-ipservicesk9_wan-mz.122-33.SXH5.bin
Destination filename [s72033-ipservicesk9_wan-mz.122-33.SXH5.bin]?
Copy in progress... CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC
74788836 bytes copied in 262.984 secs (284385 bytes/sec)
If you have (Other) instead of (Hot) in the top section and a Not Applicable in the bottom section when executing a show module command, your Redundant SUP likely did not boot properly. This will happen if you forget to copy over the IOS to the Redundant SUP module.
Tuesday, February 10, 2009
Look at Cisco IOS XE
http://www.networkworld.com/community/node/37762