Archive for April, 2010
IPsec HA almost done —> MPF
Posted by TacAck in CCIE-Security on April 27th, 2010
Hey all!
I did some IPsec HA configuration today and also made notes ( will share tomorrow morning ). I couldn’t get stateless IPSec failover to happen ( using RRI and HSRP ). There was a wierd IKE Phase 2 error. I really wanted to get it working tonight, but i guess i’m too drained to debug stuff now.. :/ I hope Ryan ( www.routsec.com ) had better luck!
So i’m going to do the next best thing and shift to a new topic ,i.e MPF and then trying to complete both MPF and IPsec HA by tomorrow evening.
I really wanted to do some AAA configuration, which i’m pretty weak at , but unfortunately all the INE rack rentals slots are booked all the way till 31st April. So i’ve booked a session on 1st May and 2nd May. Hoping to get some good AAA configuration during that time
For now, it’s going to be MPF and i’m going to taking notes!
Cheers,
TacACK
IPsec HA study
Posted by TacAck in CCIE-Security on April 27th, 2010
Ah, it’s been a long time since i posted here. I need to be get back into the “90 day countdown” , atleast that way i’ll post everyday.
My day started off well
. A bus was relatively empty so i could focus on the studies. I did some IPSec HA study yesterday and i fired up a GNS3 lab and was testing basic HSRP and REVERSE ROUTE High-avalability capabilities.
This evening i’m going to re-read the doc-cd section and this time i’m going to make notes. I’m also going to lab the SSO section in GNS3. Wish me luck!
Cheers,
TacACK
Vol 1.5 labs -> A/A Failover , IOS SSL-VPN , AUTH PROXY
Posted by TacAck in Uncategorized on April 10th, 2010
Hey all,
I’m starting off my “Vol 1.5″ series labs from today, where will be posting labs which i’m doing . These labs are slightly larger than the vol1 labs and they focus on multiple technologies at the same time. My aim is to get as close to Vol 2 labs as possible
Also Ryan is my CCIE-sec study-partner and we’re following a systematic approach to nail the beast! Thanks, Ryan.
I use Graded labs for my rack-rentals. So the inital configurations are all modified to suit graded-labs.
TARGET TIME : 4 hours
TOPOLOGY :
Please let me know if you have any issues with the configuration,etc and please forgive any mistakes in the initial configurations.
Cheers,
TacACK
P.S : Please use either a AAA server or local authentication/authorization for the tasks. I’ll post a lab soon where it uses only the AAA server

