Thursday, May 21, 2009

CCIE Routing & Switching Written Blueprint v4.0

Version 4.0 of the CCIE Routing & Switching Written Exam Blueprint.

This includes the latest modification on May 18th, and adds specifics to the previous announcement.

Information taken from:
https://cisco.hosted.jivesoftware.com/docs/DOC-4374

CCIE ® Routing and Switching Written Exam Topics (Blueprint) v4.0

The comprehensive CCIE R&S Written Exam (#350-001) has 100 multiple-choice questions and is two hours in duration. The topic areas listed are general guidelines for the type of content that is likely to appear on the exam. Please note, however, that other relevant or related topic areas may also appear. Login to access this content

Download PDF now


Exam Sections and Sub-task Objectives
1.00Implement Layer 2 Technologies√
1.10Implement Spanning Tree Protocol (STP)

(a) 802.1d

(b) 802.1w

(c) 801.1s

(d) Loop guard

(e) Root guard

(f) Bridge protocol data unit (BPDU) guard

(g) Storm control

(h) Unicast flooding

(i) Port roles, failure propagation, and loop guard operation
1.20Implement VLAN and VLAN Trunking Protocol (VTP)
1.30Implement trunk and trunk protocols, EtherChannel, and load-balance
1.40Implement Ethernet technologies

(a) Speed and duplex

(b) Ethernet, Fast Ethernet, and Gigabit Ethernet

(c) PPP over Ethernet (PPPoE)
1.50Implement Switched Port Analyzer (SPAN), Remote Switched Port Analyzer (RSPAN), and flow control
1.60Implement Frame Relay

(a) Local Management Interface (LMI)

(b) Traffic shaping

(c) Full mesh

(d) Hub and spoke

(e) Discard eligible (DE)
1.70Implement High-Level Data Link Control (HDLC) and PPP
2.00Implement IPv4
2.10Implement IP version 4 (IPv4) addressing, subnetting, and variable-length subnet masking (VLSM)
2.20Implement IPv4 tunneling and Generic Routing Encapsulation (GRE)
2.30Implement IPv4 RIP version 2 (RIPv2)
2.40Implement IPv4 Open Shortest Path First (OSPF)

(a) Standard OSPF areas

(b) Stub area

(c) Totally stubby area

(d) Not-so-stubby-area (NSSA)

(e) Totally NSSA

(f) Link-state advertisement (LSA) types

(g) Adjacency on a point-to-point and on a multi-access network

(h) OSPF graceful restart
2.50Implement IPv4 Enhanced Interior Gateway Routing Protocol (EIGRP)

(a) Best path

(b) Loop-free paths

(c) EIGRP operations when alternate loop-free paths are available, and when they are not available

(d) EIGRP queries

(e) Manual summarization and autosummarization

(f) EIGRP stubs
2.60Implement IPv4 Border Gateway Protocol (BGP)

(a) Next hop

(b) Peering

(c) Internal Border Gateway Protocol (IBGP) and External Border Gateway Protocol (EBGP)
2.70Implement policy routing
2.80Implement Performance Routing (PfR) and Cisco Optimized Edge Routing (OER)
2.90Implement filtering, route redistribution, summarization, synchronization, attributes, and other advanced features
3.00Implement IPv6
3.10Implement IP version 6 (IPv6) addressing and different addressing types
3.20Implement IPv6 neighbor discovery
3.30Implement basic IPv6 functionality protocols
3.40Implement tunneling techniques
3.50Implement OSPF version 3 (OSPFv3)
3.60Implement EIGRP version 6 (EIGRPv6)
3.70Implement filtering and route redistribution
4.00Implement MPLS Layer 3 VPNs
4.10Implement Multiprotocol Label Switching (MPLS)
4.20Implement Layer 3 virtual private networks (VPNs) on provider edge (PE), provider (P), and customer edge (CE) routers
4.30Implement virtual routing and forwarding (VRF) and Multi-VRF Customer Edge (VRF-Lite)
5.00Implement IP Multicast
5.10Implement Protocol Independent Multicast (PIM) sparse mode
5.20Implement Multicast Source Discovery Protocol (MSDP)
5.30Implement interdomain multicast routing
5.40Implement PIM Auto-Rendezvous Point (Auto-RP), unicast rendezvous point (RP), and bootstrap router (BSR)
5.50Implement multicast tools, features, and source-specific multicast
5.60Implement IPv6 multicast, PIM, and related multicast protocols, such as Multicast Listener Discovery (MLD)
6.00Implement Network Security
6.01Implement access lists
6.02Implement Zone Based Firewall
6.03Implement Unicast Reverse Path Forwarding (uRPF)
6.04Implement IP Source Guard
6.05Implement authentication, authorization, and accounting (AAA) (configuring the AAA server is not required, only the client-side (IOS) is configured)
6.06Implement Control Plane Policing (CoPP)
6.07Implement Cisco IOS Firewall
6.08Implement Cisco IOS Intrusion Prevention System (IPS)
6.09Implement Secure Shell (SSH)
6.10Implement 802.1x
6.11Implement NAT
6.12Implement routing protocol authentication
6.13Implement device access control
6.14Implement security features
7.00Implement Network Services
7.10Implement Hot Standby Router Protocol (HSRP)
7.20Implement Gateway Load Balancing Protocol (GLBP)
7.30Implement Virtual Router Redundancy Protocol (VRRP)
7.40Implement Network Time Protocol (NTP)
7.50Implement DHCP
7.60Implement Web Cache Communication Protocol (WCCP)
8.00Implement Quality of Service (QoS)
8.10Implement Modular QoS CLI (MQC)

(a) Network-Based Application Recognition (NBAR)

(b) Class-based weighted fair queuing (CBWFQ), modified deficit round robin (MDRR), and low latency queuing (LLQ)

(c) Classification

(d) Policing

(e) Shaping

(f) Marking

(g) Weighted random early detection (WRED) and random early detection (RED)

(h) Compression
8.20Implement Layer 2 QoS: weighted round robin (WRR), shaped round robin (SRR), and policies
8.30Implement link fragmentation and interleaving (LFI) for Frame Relay
8.40Implement generic traffic shaping
8.50Implement Resource Reservation Protocol (RSVP)
8.60Implement Cisco AutoQoS
9.00Troubleshoot a Network
9.10Troubleshoot complex Layer 2 network issues
9.20Troubleshoot complex Layer 3 network issues
9.30Troubleshoot a network in response to application problems
9.40Troubleshoot network services
9.50Troubleshoot network security
10.00Optimize the Network
10.01Implement syslog and local logging
10.02Implement IP Service Level Agreement SLA
10.03Implement NetFlow
10.04Implement SPAN, RSPAN, and router IP traffic export (RITE)
10.05Implement Simple Network Management Protocol (SNMP)
10.06Implement Cisco IOS Embedded Event Manager (EEM)
10.07Implement Remote Monitoring (RMON)
10.08Implement FTP
10.09Implement TFTP
10.10Implement TFTP server on router
10.11Implement Switch-module Configuration Protocol (SCP)
10.12Implement HTTP and HTTPS
10.13Implement Telnet
11.00Evaluate proposed changes to a Network
11.01Evaluate interoperability of proposed technologies against deployed technologies

(a) Changes to routing protocol parameters

(b) Migrate parts of a network to IPv6

(c) Routing Protocol migration

(d) Adding multicast support

(e) Migrate spanning tree protocol

(f) Evaluate impact of new traffic on existing QoS design
11.02Determine operational impact of proposed changes to an existing network

(a) Downtime of network or portions of network

(b) Performance degradation

(c) Introducing security breaches
11.03Suggest Alternative solutions when incompatible changes are proposed to an existing network

(a) Hardware/Software upgrades

(b) Topology shifts

(c) Reconfigurations

Tuesday, May 19, 2009

CCIE Storage Book List

Information taken from: (Word Document)
http://www.cisco.com/web/learning/le3/ccie/docs/CCIEStoragerecommendedtraining1.doc

This information contains some other links and courses useful to the Storage Exams.

1. Books: Cisco Press Titles
• Storage Networking Fundamentals (Farley, ISBN# 1587051621)
• Storage Networking Protocol Fundamentals (Long, ISBN# 1587051605)

2. Books: Other Publications
• Fibre Channel: A Comprehensive Introduction (Kembel, Northwest Learning Assoc. Inc., ISBN# 0931836840)
• Fibre Channel Arbitrated Loop (Kembel, Truestedt, Northwest Learning Assoc. Inc., ISBN# 0931836824)
• Fibre Channel Switched Fabric (Kembel, Northwest Learning Assoc. Inc., ISBN# 0931836719)
• Fibre Channel for SANs (Benner, McGraw-Hill, ISBN# 0071374132 )
• IBM FICON Native Implementation and Reference Guide (IBM Redbooks)
• iSCSI: The Universal Storage Connection (Hufferd, Addison-Wesley Professional, ISBN# 020178419X)
• Storage Network Performance Analysis (Simitci, Wiley, ISBN# 076451685X)
• Storage Security: Protecting, SANs, NAS and DAS (Chirillo, Wiley, ISBN# 0764516884)

3. Courses
• SNIA courses: (www.snia.org), Access the page http://www.snia.org/education/education_continuum/courses/ and select your choice of course
• SAN ACCELERATE: Go to www.cisco.com/go/pec, Search for SAN Accelerate. You will land on http://cisco.partnerelearning.com/peclms/lang-en/management/TAX_Search.asp?SearchStr=San%20accelerate&UserMode=0&SelectedNodeID=0&VSC=TAX_CiscomView_All&VSO=A&View=0&SearchNodeID=0&AdvType=2&FindBy=1&UpcomingDays=180&SelectedNodeID=0#Results. PEC Login required.
• ICSNS Implementing Cisco Storage Networking Solutions: http://tools.cisco.com/E-Learning-IT/LPCM/LpcmLLController?action=CourseDesc&COURSE_ID=5059
• IASNS Implementing Cisco Advanced Storage Networking Solutions: http://tools.cisco.com/E-Learning-IT/LPCM/LpcmLLController?action=CourseDesc&COURSE_ID=5061
• DCSNS Designing Cisco Storage Network Solutions: http://tools.cisco.com/E-Learning-IT/LPCM/LpcmLLController?action=CourseDesc&COURSE_ID=5060
• CMSS Cisco Mainframe Storage Solution: http://www.cisco.com/web/learning/le31/le46/products/products-storage-networking.html

4. Links
• Comprehensive set of information:
http://www.cisco.com/en/US/products/hw/ps4159/ps4358/tsd_products_support_series_home.html
• MDS Configuration Guides:
http://www.cisco.com/en/US/products/hw/ps4159/ps4358/products_installation_and_configuration_guides_list.html
• Configuration examples:
http://www.cisco.com/en/US/products/hw/ps4159/ps4358/prod_configuration_examples_list.html
• Troubleshooting Guides:
http://www.cisco.com/en/US/products/hw/ps4159/ps4358/prod_troubleshooting_guides_list.html
• Design guides:
http://www.cisco.com/en/US/products/ps5989/products_implementation_design_guides_list.html
• Interoperability Information:
http://www.cisco.com/en/US/products/ps5989/products_device_support_tables_list.html

• White Papers links:
http://www.cisco.com/en/US/products/ps5989/prod_white_papers_list.html
http://www.cisco.com/en/US/products/hw/ps4159/ps4358/prod_white_papers_list.html

6. Standards:
• T-11 http://www.t11.org/index.html FC-SW , FC-GS, FC-PH, FC-BB, FC-SB, FC-FS
• iSCSI RFC 3720 http://www.ietf.org/rfc/rfc3720.txt
• IPFC RFC 3821 http://tools.ietf.org/html/rfc3821

Monday, May 18, 2009

CCIE Service Provider Book List

Information taken from:
http://www.cisco.com/web/learning/le3/ccie/sp/book_list.html

Cisco Press Titles

DSL

IP Telephony

Dial

Optical

MPLS


Service Provider


Other Publications

Sunday, May 17, 2009

CCIE Voice Book List

Information taken from:
https://cisco.hosted.jivesoftware.com/docs/DOC-3640

CCIE Voice Lab v3.0 Reading List

The following list is a compilation of recommended reading to assist in the preparation for the Lab exam. It is not required to read all of the books on this list.

Cisco Press Titles

Cisco CallManager Fundamentals, Second Edition (Alexander, Pearce, Smith,

Whetten, ISBN# 1587051923)

Cisco Catalyst QoS: Quality of Service in Campus Networks (Flannagan, Froom,

Turek, ISBN# 1587051206)

Cisco Frame Relay Solutions Guide (Chin, ISBN# 1587051168)

Cisco IP Telephony (Lovell, ISBN# 1587050501)

Cisco IP Telephony: Planning, Design, Implementation, Operation, and Optimization(Asadullah, Kaza, ISBN# 1587051575)

Cisco Voice Gateways and Gatekeepers (Donohue, Mallory, Salhoff, ISBN#

158705258X)

Cisco Voice over Frame Relay, ATM, and IP (McQuerry, Foy, McGrew, ISBN#

1578702275)

Configuring CallManager and Unity: A Step-by-Step Guide (Bateman, ISBN# 1587051966)

Deploying Cisco Voice over IP Solutions (Davidson, ISBN# 1587050307)

Integrating Voice and Data Networks (Keagy, ISBN# 1578701961)

Troubleshooting Cisco IP Telephony (Giralt, Hallmark, Smith, ISBN# 1587050757)

Voice Over IP Fundamentals (Davidson, Peters, Gracely, ISBN# 1578701686)

Voice-Enabling the Data Network: H.323, MGCP, SIP, QoS, SLAs, and Security (Durkin, ISBN# 1587050145)

CCIE Security Open Ended Question Live Date

The Open Ended Questions Live Date was announced for CCIE Security Labs.

From Cisco:
"Effective June 15, 2009, the Cisco CCIE Security lab exam will feature a new type of question format in a section called Core Knowledge. In this new section, candidates will be asked a series of four open-ended questions that require a short, typewritten response (typically several words). The questions will be randomly drawn from a pool of questions on topics currently eligible for testing on the CCIE Security lab exam. No new topics are being added. Candidates will have up to 30 minutes to complete the Core Knowledge section of the exam, and may not return to the questions later. First introduced to the CCIE Routing and Switching lab exam in February 2009, Core Knowledge questions will eventually be added to all CCIE tracks. The changes allow Cisco to maintain strong exam security, and they help ensure that only qualified candidates are awarded CCIE certification."

Saturday, May 16, 2009

CCIE Security Book List


Information taken from:
http://www.cisco.com/web/learning/le3/ccie/security/book_list.html

Cisco Press Titles

Other Publications

Friday, May 15, 2009

CCIE Routing & Switching Book List

Information taken from:
https://cisco.hosted.jivesoftware.com/docs/DOC-4601

CCIE R&S Reading List

This page lists books on topics appearing on the CCIE Written and Lab Exam. These books are not required study resources, however, they can be used to build knowledge in certain areas.

Many of the Cisco Press books are available to certified individuals and Cisco customers at prices discounted up to 30% off. To check for discounts, visit the Cisco Marketplace, click on (Cisco Press) Bookstore, and login with your Cisco CCO ID. Search for the titles using the ISBN number indicated.

1. CCIE Routing and Switching Exam Certification Guide, Third Edition

2. CCIE Routing and Switching Exam Quick Reference

3. CCIE Routing and Switching Practice Labs

4. Routing TCP/IP, Volume I, 2/e

5. Routing TCP/IP, Volume II

6. Troubleshooting IP Routing Protocols

7. Inside Cisco IOS Software Architecture

8. Cisco LAN Switching

9. Cisco OSPF Command and Configuration Handbook

10. Cisco BGP-4 Command and Configuration Handbook

11. Cisco Field Manual: Router Configuration

12. Cisco Field Manual: Catalyst Switch Configuration

13. Developing IP Multicast Networks, Volume I

14. Internet Routing Architectures, Second Edition

15. MPLS and VPN Architectures

16. MPLS and VPN Architectures, Volume II

17. Cisco Catalyst QoS

18. End-to-End QoS Network Design

19. Deploying IPv6 Networks

20. Network Security Technologies and Solutions


The following titles are no longer for sale in print format, but are available for free online view at the InformIT Reference Library:

1. CCIE Practical Studies, Volume I

2. CCIE Practical Studies, Volume II

3. Troubleshooting Remote Access Networks

4. Troubleshooting VPNs

Tuesday, May 5, 2009

CCIE R & S Exam Updates

The following announcements were made for the CCIE Routing and Switching Exam Updates:


Cisco® Revises its Popular CCIE® R&S Certification

Cisco has revised the certification requirements for CCIE Routing & Switching (CCIE R&S)-the expert level certification for network engineers.

The new certification standards reflect the job skills employers look for at the expert level and are outlined on the Cisco Learning Network at CCIE R&S v4.0 written exam topics and CCIE R&S v4.0 lab exam topics. The revised CCIE R&S v4.0 exams are scheduled for release on October 18, 2009 and will immediately replace the currently available v3.0 exams.

To support the certification changes, the Cisco 360 Learning Program for CCIE R&S is being updated with new lessons on MPLS and Troubleshooting, additions to the instructor-led workshops, new lab exercises for self-paced practice, and new performance assessments. The Program is the only authorized expert training currently aligned to CCIE R&S v4.0. The program is delivered globally by Cisco Learning Partners .

Save the Date: Two Live CCIE R&S Certification Webinars, May 20, 2009
Cisco will conduct two live webinars on Wednesday, May 20, 2009 covering enhancements made to the CCIE R&S certification and to the Cisco 360 Learning Program for CCIE R&S to align with the updates. Attendees can choose from calls at 8:00 AM and 7:00 PM PST. Click here to register.

For more information on the updates, the Cisco 360 Learning Program for CCIE R&S, and how to locate an authorized Learning Partner, access the Cisco Learning Network.

Saturday, May 2, 2009

FTP Multiline 221 Bug in FWSM

This is one I ran into recently.

Link to Cisco Bug Toolkit
Will need CCO Login
CSCsi27512 Bug Details
FTP with multiline 221 lines closes the connection too early
Symptom:
FTP client / server do not close their connection in some cases when the server
uses multiline 221 closure sequence.

Conditions:
When some OS is used (not all of them, not identified properly) and the server uses
multi line 221 closure sequence like:

221-You have transferred 0 bytes in 0 files.
221-Total traffic for this session was 2551 bytes in 1 transfers.
221-Thank you for using the FTP service on orbi.
221 Goodbye.

instead of the classic
221 Goodbye;

Workaround:
1. Disable ftp inspection OR disable 221 mutliline.
or
2. if running a version of FWSM code where the command is supported, you can disable the TCP Normalizer feature which has minimal impact. Disable the normalizer with the command:
"no control-point tcp-normalizer"
or
3. If running in an active/standby failover mode setup, a forced switchover should alleviate the problem. If not running a failover mode that is if there i no failover pair, but have failover enabled, then a "no failover" and "failover" [i.e disabling and enabling failover] should help.

Wednesday, April 1, 2009

Cisco ASA "vpnsetup" Command

A neat little help command built into the ASA to help with VPN steps and setup.

ASA(config)# vpnsetup ?
configure mode commands/options:
ipsec-remote-access Display IPSec Remote Access Configuration Commands
l2tp-remote-access Display L2TP/IPSec Configuration Commands
site-to-site Display IPSec Site-to-Site Configuration Commands
ssl-remote-access Display SSL Remote Access Configuration Commands


ASA(config)# vpnsetup ipsec-remote-access steps
Steps to configure a remote access IKE/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha

3. Setup an address pool

ip local pool client-pool 192.168.1.1-192.168.1.254

4. Configure authentication method

aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y

5. Define tunnel group

tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss

6. Setup ipsec parameters

crypto ipsec transform-set myset esp-aes esp-sha-hmac

7. Setup dynamic crypto map

crypto dynamic-map dynmap 1 set transform-set myset
crypto dynamic-map dynmap 1 set reverse-route

8. Create crypto map entry and associate dynamic map with it

crypto map mymap 65535 ipsec-isakmp dynamic dynmap

9. Attach crypto map to interface

crypto map mymap interface outside

10. Enable isakmp on interface

crypto isakmp enable outside


ASA(config)# vpnsetup l2tp-remote-access steps
Steps to configure a remote access L2TP/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 65535
authentication pre-share
encryption aes
hash sha

3. Setup an address pool

ip local pool client-pool 192.168.1.1-192.168.1.254

4. Configure authentication method

aaa-server MyRadius protocol radius
aaa-server MyRadius host 192.168.0.254
key $ecretK3y

5. Define tunnel group

tunnel-group client type remote-access
tunnel-group client general-attributes
address-pool client-pool
authentication-server-group MyRadius
tunnel-group client ipsec-attributes
pre-shared-key VpnUs3rsP@ss
tunnel-group DefaultRAGroup ppp-attributes
authentication pap

6. Setup ipsec parameters

crypto ipsec transform-set myset esp-aes esp-sha-hmac
crypto ipsec transform-set myset mode transport

7. Setup dynamic crypto map

crypto dynamic-map dynmap 1 set transform-set myset

8. Create crypto map entry and associate dynamic map with it

crypto map mymap 65535 ipsec-isakmp dynamic dynmap

9. Attach crypto map to interface

crypto map mymap interface outside

10. Enable isakmp on interface

crypto isakmp enable outside


ASA(config)# vpnsetup site-to-site steps
Steps to configure a site-to-site IKE/IPSec connection with examples:

1. Configure Interfaces

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Configure ISAKMP policy

crypto isakmp policy 10
authentication pre-share
encryption aes
hash sha

3. Configure transform-set

crypto ipsec transform-set myset esp-aes esp-sha-hmac

4. Configure ACL

access-list L2LAccessList extended permit ip 192.168.0.0 255.255.255.0 192.168.50.0 255.255.255.0

5. Configure Tunnel group

tunnel-group 10.20.20.1 type ipsec-l2l
tunnel-group 10.20.20.1 ipsec-attributes
pre-shared-key P@rtn3rNetw0rk

6. Configure crypto map and attach to interface

crypto map mymap 10 match address L2LAccessList
crypto map mymap 10 set peer 10.10.4.108
crypto map mymap 10 set transform-set myset
crypto map mymap 10 set reverse-route
crypto map mymap interface outside

7. Enable isakmp on interface

crypto isakmp enable outside

ASA(config)# vpnsetup ssl-remote-access steps
Steps to configure a remote access SSL VPN remote access connection and AnyConnect with examples:

1. Configure and enable interface

interface GigabitEthernet0/0
ip address 10.10.4.200 255.255.255.0
nameif outside
no shutdown

interface GigabitEthernet0/1
ip address 192.168.0.20 255.255.255.0
nameif inside
no shutdown

2. Enable WebVPN on the interface

webvpn
enable outside

3. Configure default route

route outside 0.0.0.0 0.0.0.0 10.10.4.200

4. Configure AAA authentication and tunnel group

tunnel-group DefaultWEBVPNGroup type remote-access
tunnel-group DefaultWEBVPNGroup general-attributes
authentication-server-group LOCAL

5. If using LOCAL database, add users to the Database

username test password t3stP@ssw0rd
username test attributes
service-type remote-access

Proceed to configure AnyConnect VPN client:

6. Point the ASA to an AnyConnect image

webvpn
svc image anyconnect-win-2.1.0148-k9.pkg

7. enable AnyConnect

svc enable

8. Add an address pool to assign an ip address to the AnyConnect client

ip local pool client-pool 192.168.1.1-192.168.1.254 mask 255.255.255.0

9. Configure group policy

group-policy DfltGrpPolicy internal
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol svc webvpn