CCIE Security
CCIE Security Practice Labs
Table of By Fahim Hussain Yusuf Bhaiji About the Technical Reviewers Acknowledgments Foreword Why Security Certifications Why CCIE Security Introduction Icons Used in This Book Command Syntax Conventions Chapter 1. Practice Lab 1 Equipment List General Guidelines Setting Up the Lab Practice Lab 1 Exercises Section 1.0 Basic Configuration (10 points) Section 2.0 Routing Configuration (25 points) Section 3.0 ISDN Configuration (8 points) Section 4.0 PIX Configuration (5 points) Section 5.0 IPSec...
Overview of the CCIE Certification
CCIE is widely considered the industry's highest-level IT certification program, commonly referred to as the doctorate of networking. It equips candidates with excellent internetworking skills that are simply the best in the industry. CCIE certification was recently voted 1 by IT professionals in the CertCities.com annual survey, The Hottest Certifications for 2003a ranking attributed to the growing importance of certifications in a tight job market. Furthermore, it also grabbed the title of...
Verify IPSec configuration by pinging 19216811 from R2 sourcing from 19216821 loopbackl Verify tunnel on R2 and
R2 show crypto engine connections active Interface < none> Ethernet0 Ethernet0 175.1.2.2 set HMAC MD5+DES 56 CB dst src state conn-id slot 175.1.2.5 175.1.2.2 QM IDLE 1 0 local ident (addr mask prot port) remote ident (addr mask prot port) current_peer 175.1.2.5 (192.168.2.0 2 55.255.255.0 0 0) (192.168.1.0 2 55.255.255.0 0 0) PERMIT, flags origin_is_acl, pkts encaps 102, pkts encrypt 102, pkts digest 102 pkts decaps 102, pkts decrypt 102, pkts verify 102 pkts compressed 0, pkts...
Load Sharing Using HSRP
Configure two HSRP groups on R5 and R6 for load balancing traffic in VLAN-7. See Example 4-53. Configure preempt for both groups to fail over in the event Active is Dead for any group. Test HSRP failover by shutting the EthernetO on R5. See Example 4-54. Example 4-53. Two HSRP Groups Between R5 and R6 for Load Balancing Snip configuration from R6 interface Fast 0 0 0 standby 1 ip 142.52.0.50 standby 1 priority 110 standby 1 preempt standby 2 ip 142.52.0.51 standby 2 preempt Snip configuration...
Equipment List
To perform the practice labs in this book, you need the following devices 8 routersThe routers can be of any modelthat is, 2500, 2600 or 3600 series. But prefer modular routers so you can swap modules and adapt to different lab topologies. You need the following interfaces cables for different lab topologies. For more details, refer to the Equipment list in each chapter. o DTE-DCE back-to-back cable for serial ports ATM fiber cable (depending on the modules GBIC) NOTE Most labs in this book...
Rommon Security
Disclaimer The author and Cisco Press are not liable for any damage to routers when using this feature. Please use this feature with extreme caution, and read all related materials and the following recovery procedure. The 2600 3600 series (and newer versions of ROMMON for the 1700 series) all have what is known as a ROMMON security feature. ROMMON security is designed to prevent a person with physical access to the router (2600 or 3600) from viewing the configuration file. ROMMON security...
Practice Lab
One of the key elements for success in passing the CCIE exam is time management. A well-planned approach will go a long way in assisting you to achieve this. The elements of perfection and accuracy will come with much practice. Do not be discouraged if you have found the previous labs difficult. Your aim should be to move on through these exercises, making improvements in your approach and identifying areas of development. Following the previous chapters, this lab is a multiprotocol,...
Configure NAT on PIX for VLAN2 to 16415420 as demonstrated in the following example
Access-list nonat permit ip 10.1.1.0 255.255.255.0 10.1.2.0 255.255.255.0 nat (inside) 0 access-list nonat nat (inside) 2 10.1.1.0 255.255.255.0 0 0 nat (inside) 1 0.0.0.0 0.0.0.0 0 0 global (outside) 1 164.15.4.254 global (outside) 2 164.15.4.20 Ping from R1 to anywhere on the network sourcing from VLAN2 network. eg 22.22.22.22 Source address or interface 10.1.1.1 Loose, Strict, Record, Timestamp, Verbose none Sweep range of sizes n Type escape sequence to abort. Sending 5, 100-byte ICMP Echos...
Configure local authentication for Telnet with username ADMIN password cisco
Aaa authentication login vty local-case username ADMIN password 7 00071A150754 access-list 110 permit tcp any any eq telnet time-range work-hours line vty 0 4 access-class 110 in login authentication vty time-range work-hours periodic weekdays 9 00 to 17 00 Verify Telnet from R2 to R1. r1 clock set 14 40 00 May 21 2003 r1 show clock 00 00 09 172.16.1.10 Idle Peer Address time-range entry work-hours (active) periodic weekdays 9 00 to 17 00 used in IP ACL entry r1 show access-lists 110 Extended...



