Archive for April, 2010

IPsec HA almost done —> MPF

Hey all!

I did some IPsec HA configuration today and also made notes ( will share tomorrow morning ). I couldn’t get stateless IPSec failover to happen ( using RRI and HSRP ). There was a wierd IKE Phase 2 error. I really wanted to get it working tonight, but i guess i’m too drained to debug stuff now.. :/ I hope Ryan ( www.routsec.com ) had better luck!

So i’m going to do the next best thing and shift to a new topic ,i.e MPF and then trying to complete both MPF and IPsec HA by tomorrow evening.

I really wanted to do some AAA configuration, which i’m pretty weak at , but unfortunately all the INE rack rentals slots are booked all the way till 31st April. So i’ve booked a session on 1st May and 2nd May. Hoping to get some good AAA configuration during that time :)

For now, it’s going to be MPF and i’m going to taking notes! :)

Cheers,

TacACK

1 Comment

IPsec HA study

Ah, it’s been a long time since i posted here. I need to be get back into the “90 day countdown” , atleast that way i’ll post everyday.

My day started off well :) . A bus was relatively empty so i could focus on the studies. I did some IPSec HA study yesterday and i fired up a GNS3 lab and was testing basic HSRP and REVERSE ROUTE  High-avalability capabilities.

This evening i’m going to re-read the doc-cd section and this time i’m going to make notes. I’m also going to lab the SSO section in GNS3. Wish me luck! :)

Cheers,

TacACK

No Comments

Vol 1.5 labs -> A/A Failover , IOS SSL-VPN , AUTH PROXY

Hey all,

I’m starting off my “Vol 1.5″ series labs from today, where will be posting labs which i’m doing . These labs are slightly larger than the vol1 labs and they focus on multiple technologies at the same time. My aim is to get as close to Vol 2 labs as possible :) Also  Ryan is my CCIE-sec study-partner and we’re following a systematic approach to nail the beast! Thanks, Ryan. :)

I use Graded labs for my rack-rentals. So the inital configurations are all modified to suit graded-labs.

TARGET TIME : 4 hours

TOPOLOGY :

INITIAL CONFIGS

TASKS

Please let me know if you have any issues with the configuration,etc and please forgive any mistakes in the initial configurations.

Cheers,

TacACK

P.S : Please use either a AAA server or local authentication/authorization for the tasks. I’ll post a lab soon where it uses only the AAA server

5 Comments