Archive for June 26th, 2010
INE Vol 1 – ID Mgmt
Posted by TacAck in CCIE-Security on June 26th, 2010
Ah, it’s a great feeling to finish a lab
I did the INE vol 1 lab yesterday and apart from the last 2 NAC configurations, everything went smoothly. Infact , i didn’t even attempt the NAC configurations. That’s because i’m yet to study the theory properly and i thought i’d best wait for next weekend ( NAC WEEKEND! ).
A couple of things that i learned were :
- When doing Cut-through-proxy on the ASA to permit telnet connections going across the firewall using TACACS+
- Just do a “aaa authentication include telnet inside 0 0 <NAME>”
- Don’t include an authorization command . I always end up doing this mistake .
- Also when doing dot1x, make sure you include the aaa authorization network command. Only after issuing this, will the VLAN assignments from the ACS start working.
What i am doing today? Unfortunately not much! I have to go to this bank to do GOD knows what! Then i’m going shopping. Joy!
Hopefully , i’ll atleast get some Doc-CD study done today and if i do, i’ll definitely post about it tomorrow.
Cheers and have a great weekend!
TacACK
