<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TacAck - My security journey! &#187; CCIE-Security</title>
	<atom:link href="http://tacack.com/category/ccie-sec/feed/" rel="self" type="application/rss+xml" />
	<link>http://tacack.com</link>
	<description></description>
	<lastBuildDate>Mon, 06 Jun 2011 05:49:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CCIE-sec INSTRUCTOR interview &#8211; Brandon Carroll</title>
		<link>http://tacack.com/2011/01/12/ccie-sec-instructor-interview-brandon-carroll/</link>
		<comments>http://tacack.com/2011/01/12/ccie-sec-instructor-interview-brandon-carroll/#comments</comments>
		<pubDate>Wed, 12 Jan 2011 04:04:39 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>
		<category><![CDATA[CCIE-sec candidate Interviews]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=815</guid>
		<description><![CDATA[Hello All,
It&#8217;s been a long time since i posted a CCIE-sec candidate interview and what better way to start things off again other than an AWESOME interview with CCIE instructor &#8220;Brandon Carroll&#8221;.

I was fortunate enough to interview Brandon regarding a while back and because of a lot of reasons i got held up doing my [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>It&#8217;s been a long time since i posted a CCIE-sec candidate interview and what better way to start things off again other than an AWESOME interview with CCIE instructor &#8220;Brandon Carroll&#8221;.</p>
<p><a href="http://tacack.com/wp-content/uploads/2011/01/image004.jpg"><img class="aligncenter size-full wp-image-816" title="Brandon Carroll" src="http://tacack.com/wp-content/uploads/2011/01/image004.jpg" alt="" width="165" height="160" /></a></p>
<p>I was fortunate enough to interview Brandon regarding a while back and because of a lot of reasons i got held up doing my own stuff and i couldn&#8217;t post it. However, i felt it was about time i posted this article and i&#8217;m sure you&#8217;ll enjoy this as much as i do. So here we go!</p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: Hello Brandon! How are you doing today?</p>
<p style="padding-left: 30px;"><em>I&#8217;m doing well.  I&#8217;m working on a number of projects and getting ready for TechFieldDay so its a pretty busy week.</em></p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: For the few CCIE-sec candidates who do not know about Brandon, he&#8217;s a CCIE(Security) and a CCSI. Brandon, could you please tell us a little about your CCIE(sec) preparation?</p>
<p style="padding-left: 30px;"><em>Sure thing.  I&#8217;ve been an instructor with a security focus for a number of years.  I teach all the CCSP, now CCNP Security, courses and that was my initial primary preparation method.  I used the knowledge gained there, along with the CCIE Security Written Exam Guide by CCBootcamp to pass the written.  I then used a combination of INE and IPexpert material for the lab.  I own all the workbooks from both vendors as well as the Audio products and Video Products.  I took a 5-day online class from INE and a 5-day live Instructor-led class from IPexpert.  My instructor at INE was Brian Mcgahn and my instructor at IPexpert was Jared Scrivener.  Bot were great instructors.</em></p>
<p><strong><span style="color: #ff0000;">TacACK</span></strong> : Did you clear the lab on your first attempt? If not , what do you think was missing in your prep?</p>
<p style="padding-left: 30px;"><em>No I didnt.  The frist time I took the lab was more of a test run to see how it was.  I had no formal training and was in way over my head.  I simply had no time to learn about stuff I had not seen prior to that lab.  The second attempt was after the INE class and I was well prepared for the technology but had no strategy.  The final attempt was after the IPexpert class and I had the perfect strategy and without it I would not have passed.</em></p>
<p><strong><span style="color: #ff0000;">TacACK</span></strong> : For many candidates (including me) , who couldn&#8217;t pass the CCIE on their first attempt, what would your advice to them be? What is the one or many &#8220;special&#8221; thing(s) that we have to study/lab to cross the hurdle?</p>
<p style="padding-left: 30px;"><em>Have a plan and stick with it.  Its easy to get sidetracked when you get nervous and frustrated.  If you say you will only spend 10 minutes on a task you MUST move on, even if you will need to come back to it later.  Just stick with the plan.  Also, your life should be spent on the racks.  You should be dreaming about the lab before you go to the lab.  It sounds goofy, but thats how it is.</em></p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: Haha <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I know a good friend of mine (<a href="http://www.routsec.com"> Ryan Schuett</a> ) has dreams about configurations! Alright,  now coming to the OEQs. Are there any pointers that you could give us regarding prep for them?</p>
<p style="padding-left: 30px;"><em>Use Yusufs flash cards.  Other than that, if you know your material they OEQs are a non-issue.</em></p>
<p><span style="color: #ff0000;"><strong>TacACK </strong></span>: What according to you are the most difficult/tricky sections in the CCIE(sec) blueprint?</p>
<p style="padding-left: 30px;"><em>The ones you don&#8217;t know well.  It varies by the person.  For me, it was probably DMVPN troubleshooting.  I think FPM is giving people a run for their money along with GET VPN and multicast rekeying.  Its all fun stuff though!</em></p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: What changes do you see in the near-future in the CCIE(sec) track?</p>
<p style="padding-left: 30px;"><em>At the moment, not much.  Eventually IOS 15 will need to be introduced along with ASA 8.3 and IPS 7 or 8.  Depending on when things change.  I cant see much in the way of technology being added unless more focus if give to datacenter security which I doubt.  Cisco has been in a bit of a lull with Security in general and i think that drives what the program does.</em></p>
<p><strong><span style="color: #ff0000;">TacACK</span></strong> : What do you feel is the #1 mistake that CCIE(sec) candidates make?</p>
<p style="padding-left: 30px;"><em>They overthink some things and underthing others.  You have to find a balance.  Yes you only do what you are told, but you better think about what is affected by what you change.</em></p>
<p><span style="color: #ff0000;"><strong>TacACK </strong></span>: That&#8217; s a tough one. I have the same problem. Ok moving onto more lighter things, what is your daily schedule like? <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p style="padding-left: 30px;"><em>Basically I&#8217;m up at 6 or so, sometimes earlier.  I spend about an hour reviewing email, twitter, facebook and so on.  If I&#8217;m teaching a class its basically start teaching at 8:30, lecture / break/ email/ read RSS feeds/ Start a new blog post.  At lunch I typicall schedule all my conference calls or I read and lab.When students are doing labs so am I.After work I hang out with my kids a bit, read some more, blog some more, lab some more.I head to bed around midnight every day.</em></p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: On an average, how much time do you spend reading everyday?</p>
<p style="padding-left: 30px;"><em>I couldn&#8217;t even guess.  I read off and on all day long and its usually multiple sources, books, blogs, etc.</em></p>
<p><strong><span style="color: #ff0000;">TacACK</span></strong> : What are the 5 things that you recommend every CCIE(sec) candidate to do</p>
<p style="padding-left: 30px;"><em>Read, Lab, Listen to VoD and Audio, Rest, and take at least one class with a live instructor</em></p>
<p><span style="color: #ff0000;"><strong>TacACK </strong></span>: That&#8217;s great advice  Brandon! Thanks a lot for the interview , where can one reach you if they wanted to talk to you/take some of your classes?</p>
<p style="padding-left: 30px;"><em>Im on twitter @brandoncarroll, of my blog at <a href="http://www.globalconfig.net/" target="_blank">http://www.globalconfig.net</a>.  You can find my contact info there for links to facebook, linkedin and so on.</em></p>
<p><strong><span style="color: #ff0000;">TacACK </span></strong>: Again, thanks a lot for the interview Brandon. I really appreciate this and i bet so will all the CCIE(sec) candidates who read this!</p>
<p style="padding-left: 30px;"><em>Thank you! I appreciate being able to assist people in their journey to CCIE!</em></p>
<p>Wasn&#8217;t that a great interview! One thing i absolutely admire in Brandon and many other CCIE instructors is the fact that , despite their hectic schedules, they still keep aside time to talk to their students and answer their questions patiently. I guess that&#8217;s the difference between an instructor who is good and an instructor who is just plain Awesome. Brandon definitely falls into the latter category! <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Cheers,<br />
TacACK</p>
<div><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><br />
</span></div>
<div><span style="font-family: arial, sans-serif; line-height: normal; border-collapse: collapse;"><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2011/01/12/ccie-sec-instructor-interview-brandon-carroll/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>IP fragmentation over IPSEC and GRE tunnels</title>
		<link>http://tacack.com/2011/01/10/ip-fragmentation-over-ipsec-and-gre-tunnels/</link>
		<comments>http://tacack.com/2011/01/10/ip-fragmentation-over-ipsec-and-gre-tunnels/#comments</comments>
		<pubDate>Mon, 10 Jan 2011 01:06:13 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=809</guid>
		<description><![CDATA[Hello All!
There was recently a question on OSL regarding fragmentation on IPSEC and GRE tunnels. This was a shady topic to me and i decided to do some study on it. After some search, i found this incredible whitepaper from Cisco which had all the details that i was looking for. You can find the [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All!</p>
<p>There was recently a question on OSL regarding fragmentation on IPSEC and GRE tunnels. This was a shady topic to me and i decided to do some study on it. After some search, i found this incredible whitepaper from Cisco which had all the details that i was looking for. You can find the link to the document below.</p>
<p><a href="http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml">http://www.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00800d6979.shtml</a></p>
<p>I love the graphics on the whitepaper which give us a detailed picture of the fragmentation process in tunnels and the different places where the packet can get fragmented in a GRE tunnel . I must say, this is DEFINITELY one of the most informative documents that i&#8217;ve come across and i hope it helps you as much as it did to me.</p>
<p>Cheers,</p>
<p>TacACK</p>
<p><span style="color: #ff0000;">EDIT </span>: I have to admit, this paper pretty lengthy and time-consuming , so i would suggest giving it about 1.5 &#8211; 2 hours of quiet time for all of it to seep in . Again, that&#8217;s just what works for me <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2011/01/10/ip-fragmentation-over-ipsec-and-gre-tunnels/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful Control-plane links</title>
		<link>http://tacack.com/2011/01/06/useful-control-plane-links/</link>
		<comments>http://tacack.com/2011/01/06/useful-control-plane-links/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 14:29:00 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=803</guid>
		<description><![CDATA[Hello All,
I have come across many awesome links through the course of the last 2 years of study and i will try and share them with you as much as i can.
Here are 3 of them which i was reading today:

Control Plane Policing

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtrtlimt.html


Control Plane Protection

http://www.cisco.com/en/US/docs/ios/12_4t/12_4t4/htcpp.html#wp1121935


Control Plane Logging

http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_cpl.html



These will not be available as a part of [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I have come across many awesome links through the course of the last 2 years of study and i will try and share them with you as much as i can.</p>
<p>Here are 3 of them which i was reading today:</p>
<ul>
<li><strong>Control Plane Policing</strong>
<ul>
<li><a href="http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtrtlimt.html">http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtrtlimt.html</a></li>
</ul>
</li>
<li><strong>Control Plane Protection</strong>
<ul>
<li><a href="http://www.cisco.com/en/US/docs/ios/12_4t/12_4t4/htcpp.html#wp1121935">http://www.cisco.com/en/US/docs/ios/12_4t/12_4t4/htcpp.html#wp1121935</a></li>
</ul>
</li>
<li><strong>Control Plane Logging</strong>
<ul>
<li><a href="http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_cpl.html">http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_cpl.html</a></li>
</ul>
</li>
</ul>
<p>These will not be available as a part of the standard CCIE-LAB documentation, but nonetheless,  i find these documents very good. They drive home the concepts very well and i&#8217;m sure they&#8217;ll help the reader get a clearer picture about the different Control plane protection mechanisms.</p>
<p>Cheers,<br />
TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2011/01/06/useful-control-plane-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The hard truth</title>
		<link>http://tacack.com/2010/12/21/the-hard-truth/</link>
		<comments>http://tacack.com/2010/12/21/the-hard-truth/#comments</comments>
		<pubDate>Tue, 21 Dec 2010 03:24:15 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=790</guid>
		<description><![CDATA[Hello All,
It&#8217;s been a while since my 2nd attempt ( about a week ) and i&#8217;m still wondering what went wrong. Yes, i failed my second attempt . What made it even worse was the fact that like my previous attempt, i flunked in both the OEQ section and the lab section. I guess that&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>It&#8217;s been a while since my 2nd attempt ( about a week ) and i&#8217;m still wondering what went wrong. Yes, i failed my second attempt . What made it even worse was the fact that like my previous attempt, i flunked in both the OEQ section and the lab section. I guess that&#8217;s what makes this so hard for me to digest.</p>
<p>I was hoping to atleast clear the lab section if not for the crazy OEQs . But to be honest, i&#8217;m not sure what went wrong. I thought i&#8217;d done all the right prep, done my share of vol-1 labs , vol -2 labs. I might not be super-smart, but i&#8217;ve tried to squeeze every minute of my daily schedule to work on this for the last 2 years.</p>
<p>That&#8217;s what makes it disheartening.</p>
<p>I know there are some who have attempted many times and yet failed, but what i badly want to know is why i failed. Since cisco doesn&#8217;t tell us why, there&#8217;s fat chance of that happening.</p>
<p>Overall, i still think taking this positively is the right way to go for me, but that&#8217;s going to take sometime. Right now, i&#8217;m still a little down about the whole thing. But , one thing is for certain, i&#8217;m not taking another lab anytime soon. I want to master each and every topic before i even think of going for another attempt.</p>
<p>Secondly, i WILL not do dumps no matter how many times i flunk this. I hate dumps. I do not think people who do dumps deserve their CCIE digits. I don&#8217;t care if i become a ccie at 67 , but no dumps.</p>
<p>My plan of doing some tutorials is still on, but at the moment, i honestly don&#8217;t know when i&#8217;m going to be starting it. It will be soon though ( within the first 2 weeks of January ) .</p>
<p>Sorry to go emo on you, but since this blog reflects my CCIE-sec journey, so i put this blogpost in too.</p>
<p>Cheers,<br />
TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/12/21/the-hard-truth/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>I require 2 brave volunteers</title>
		<link>http://tacack.com/2010/11/06/i-require-2-brave-volunteers/</link>
		<comments>http://tacack.com/2010/11/06/i-require-2-brave-volunteers/#comments</comments>
		<pubDate>Sat, 06 Nov 2010 13:00:15 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=777</guid>
		<description><![CDATA[Hello All,
I&#8217;m hoping to launch a new project , for which i&#8217;m holding some test-runs very soon. I will be taking on a  topic in the CCIE-sec blueprint and i&#8217;ll be holding a full 5-6 class on it. Again, i&#8217;m not a professional and this is going to be the first time i&#8217;m going to [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I&#8217;m hoping to launch a new project , for which i&#8217;m holding some test-runs very soon. I will be taking on a  topic in the CCIE-sec blueprint and i&#8217;ll be holding a full 5-6 class on it. Again, i&#8217;m not a professional and this is going to be the first time i&#8217;m going to be doing something like this. This trial-run is designed so that i can judge my strenghts , weaknesses , etc.</p>
<p>For this, i would like to request <strong><span style="color: #ff0000;">2</span></strong> ccie-sec candidates ( the ideal audience would be people who are just starting out with their CCIE-sec study ) , to be my guinea pigs <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  . This will be a 5-6 hour session and i will try and cover as much about the topic as possible with detailed slides , labs and explanation. I will also have sometime reserved for questions/doubts that you might like to throw at me. I would be super happy if you can maybe spare the allotted time in your busy-schedule and take a seat in my e-class. Also, what i&#8217;m looking for is feedback on how the experience could be improved, etc.</p>
<p>Of course, all of this is free and i&#8217;m really looking forward to meeting you online and having a wonderful discussion about a CCIE-sec topic. If you&#8217;re interested , you can either shoot me an e-mail at tacack at tacack.com , or you can leave a comment to this post.</p>
<p>Cheers,</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/11/06/i-require-2-brave-volunteers/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>FTP Inspection on the ASA &#8211; VoD</title>
		<link>http://tacack.com/2010/10/10/ftp-inspection-on-the-asa-vod/</link>
		<comments>http://tacack.com/2010/10/10/ftp-inspection-on-the-asa-vod/#comments</comments>
		<pubDate>Sat, 09 Oct 2010 18:57:29 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=760</guid>
		<description><![CDATA[Hello All,
I spent a couple of hours tooling with FTP inspection on the ASA today. To be honest, prior to today, i didn&#8217;t know how exactly things worked. Anyways , after doing some study i now feel pretty confident about the technology , so i recorded a small video to share it with the rest [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I spent a couple of hours tooling with FTP inspection on the ASA today. To be honest, prior to today, i didn&#8217;t know how exactly things worked. Anyways , after doing some study i now feel pretty confident about the technology , so i recorded a small video to share it with the rest of the ccie-sec community. Here it is!</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="385" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/p/ECEBE14845393548?hl=en_US&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="385" src="http://www.youtube.com/p/ECEBE14845393548?hl=en_US&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Please feel free to contact me by either leaving comments to this post or sending me an email ( tacack at tacack dot com ). I&#8217;d really appreciate it if you could maybe point out some mistakes in my explanation/understanding.</p>
<p>Take care and have a great weekend! <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/10/10/ftp-inspection-on-the-asa-vod/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>70 days to go</title>
		<link>http://tacack.com/2010/10/05/70-days-to-go/</link>
		<comments>http://tacack.com/2010/10/05/70-days-to-go/#comments</comments>
		<pubDate>Tue, 05 Oct 2010 03:41:15 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=754</guid>
		<description><![CDATA[As the title says, i have 70 more days to go before the 2nd attempt. How am i feeling? To be honest, i&#8217;ve no clue! A part of me thinks that i can do it this time, but on the other hand i also worry about my chances of clearing . My main question being, &#8220;What [...]]]></description>
			<content:encoded><![CDATA[<p>As the title says, i have 70 more days to go before the 2nd attempt. How am i feeling? To be honest, i&#8217;ve no clue! A part of me thinks that i can do it this time, but on the other hand i also worry about my chances of clearing . My main question being, &#8220;What am i doing different this time around to help me pass?&#8221;. I&#8217;ve thought about this for sometime now and here&#8217;s a brief overview.</p>
<p>I&#8217;m just going to keep up the same study plan that i had followed for my first attempt but i&#8217;m going to add a couple of extra features in there which i didn&#8217;t do the last time around :</p>
<ul>
<li><strong>Go through the solutions</strong>. I can&#8217;t believe i messed this up the first time around and believe me when i tell you, even if you&#8217;ve got the answer, it always pays to look through the solutions</li>
<li><strong>Participate in forums</strong>. If you&#8217;ve gone through Kingsley&#8217;s interview ( previous blog-post ) , you must have realized how much forums can activate one&#8217;s thought process. I find it very helpful and i plan on continuing to participate in OSL and CLND</li>
<li><strong>Try and watch all the tutorial videos that i can find my hands on</strong></li>
<li><strong>Finish the online bootcamp that i&#8217;ve ordered from INE</strong></li>
<li><strong>Go through Yusuf&#8217;s book prior to the lab</strong>. This will prove invaluable in getting the OEQs right  ( Atleast that&#8217;s my belief <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )(and finally!)</li>
<li><strong>Go through all the configuration examples in the doc-cd</strong>.</li>
</ul>
<p>After a 2 week forced break, i&#8217;m happy that i&#8217;m back to labbing. Although my brain&#8217;s kinda rusty at this point, i&#8217;m doing my best to keep it greased and running by labbing <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . I did the INE IOS-Firewall Vol1 lab yesterday and i&#8217;m going to do the IPX vol 2A lab today ( pure evil! ).</p>
<p>Also, i hope you&#8217;re all doing well and kicking some serious ccie-sec butt! Do let me know about your study techniques and i&#8217;d be glad to put them up here.</p>
<p>Cheers and have a wonderful day!<br />
TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/10/05/70-days-to-go/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>L2TP over IPSec : Configuration and Theory VoD</title>
		<link>http://tacack.com/2010/09/24/l2tp-over-ipsec-configuration-and-theory-vod/</link>
		<comments>http://tacack.com/2010/09/24/l2tp-over-ipsec-configuration-and-theory-vod/#comments</comments>
		<pubDate>Thu, 23 Sep 2010 21:20:00 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=739</guid>
		<description><![CDATA[Hello All,
In an earlier blogpost , i&#8217;ve explained the basics of L2TP . In this video, we&#8217;re going to be talking about L2TP over IPSec , which is a configuration task in the CCIE-Security Lab blueprint. I thought it would be better if i did a video rather than write about it.
So here it is. [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>In an earlier <a href="http://tacack.com/?p=703">blogpost</a> , i&#8217;ve explained the basics of L2TP . In this video, we&#8217;re going to be talking about L2TP over IPSec , which is a configuration task in the CCIE-Security Lab blueprint. I thought it would be better if i did a video rather than write about it.</p>
<p>So here it is. </p>
<p><object width="480" height="385"><param name="movie" value="http://www.youtube.com/p/2E8C21C899A6F17C?hl=en_US&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/p/2E8C21C899A6F17C?hl=en_US&#038;fs=1" type="application/x-shockwave-flash" width="480" height="385" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>I&#8217;d love to hear feedback on how you found the video and what things i could do to improve my technical/presentation skills.</p>
<p>Cheers,</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/09/24/l2tp-over-ipsec-configuration-and-theory-vod/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Some great videos</title>
		<link>http://tacack.com/2010/09/20/some-great-videos/</link>
		<comments>http://tacack.com/2010/09/20/some-great-videos/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 04:03:33 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=735</guid>
		<description><![CDATA[Hello All!
I&#8217;m working on an article ( for a change i&#8217;m taking time out to write this   ) and i thought i&#8217;d share some great videos with you. These videos are not created by me, they are created by Brandon Carroll ( CCIE #23837 (security) ).
As you might already know, Brandon Carroll is [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All!</p>
<p>I&#8217;m working on an article ( for a change i&#8217;m taking time out to write this <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ) and i thought i&#8217;d share some great videos with you. These videos are not created by me, they are created by Brandon Carroll ( CCIE #23837 (security) ).</p>
<p>As you might already know, Brandon Carroll is an awesome instructor who worked for IPX and is now working for Ascolta Training. He runs a very informative <a href="http://globalconfig.net/">blog </a>and he regularly posts articles there and i find them very helpful.</p>
<p>Yesterday, i came across some videos on his blogsite which were very impressive. He shows us how to configure Anyconnect VPN on the ASA, using the ASDM. If you&#8217;re an ASDM fanboy, then this video is a must-watch! Even otherwise, i&#8217;d highly recommend watching this because you&#8217;re getting free lessons from Brandon who is very well known for his deep technical knowledge and excellent explanation skills. I&#8217;ve loved all the IPX videos that Brandon has done and i hope to meet him someday <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . So, here are the videos!</p>
<p>PART 1 -&gt; <a href="http://globalconfig.net/2010/09/10/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2/">http://globalconfig.net/2010/09/10/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2/</a></p>
<p>PART 2 -&gt; <a href="http://globalconfig.net/2010/09/13/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2-part-2/">http://globalconfig.net/2010/09/13/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2-part-2/</a></p>
<p>Again, many thanks to Brandon for posting such great material .</p>
<p>Cheers and Happy studying,</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/09/20/some-great-videos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IOS NAT v/s ASA NAT</title>
		<link>http://tacack.com/2010/09/14/ios-nat-vs-asa-nat/</link>
		<comments>http://tacack.com/2010/09/14/ios-nat-vs-asa-nat/#comments</comments>
		<pubDate>Tue, 14 Sep 2010 18:29:47 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[CCIE-Security]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=722</guid>
		<description><![CDATA[EDIT : I had forgotten to add a couple of points in the list, i&#8217;ve added them now. The changes i&#8217;ve made are in the IOS list where i&#8217;ve addressed the lexicographic ordering of route-maps and how it affects precedence.
Hello All,
I have a treat for you today. Well, to be honest , it&#8217;s more like [...]]]></description>
			<content:encoded><![CDATA[<address><strong><span style="color: #000000;"><em><span style="text-decoration: underline;">EDIT</span></em></span><span style="color: #000000;"><em><span style="text-decoration: underline;"> </span></em></span></strong><span style="color: #000000;"><em>:</em></span><em><span style="font-weight: normal;"> I had forgotten to add a couple of points in the list, i&#8217;ve added them now. The changes i&#8217;ve made are in the IOS list where i&#8217;ve addressed the lexicographic ordering of route-maps and how it affects precedence.</span></em></address>
<p>Hello All,</p>
<p>I have a treat for you today. Well, to be honest , it&#8217;s more like a treat for myself , but i thought someone might find it useful too! It&#8217;s the NAT IOS order of operation . I&#8217;ve tried , tried and tried unsuccessfully to find the exact order of IOS Nat in the Doc-CD. So, this morning, i decided the only way i&#8217;m going to find it out is by labbing up a test-scenario where i could manually test out the order of IOS NAT. What better way to learn than by practice right?</p>
<p>Ok, as a foreword, the NAT order of operation on the ASA is fairly easy to find in the Doc-CD and it&#8217;s as follows :</p>
<ul>
<blockquote>
<li><span style="color: #ff6600;"><strong>NAT exemption </strong></span></li>
<li><span style="color: #99cc00;"><strong>Static NAT, Static Policy NAT</strong></span></li>
<li><span style="color: #99cc00;"><strong>Static PAT , Static Policy PAT</strong></span></li>
<li><span style="color: #ff6600;"><strong>Policy NAT</strong></span></li>
<li><span style="color: #ff6600;"><strong>Dynamic NAT</strong></span></li>
</blockquote>
</ul>
<p>For the IOS , i found that the order is as follows :</p>
<ul>
<blockquote>
<li><strong><span style="color: #99cc00;">Static NAT</span></strong></li>
<li><strong><span style="color: #99cc00;">Static PAT</span></strong></li>
<li><strong><span style="color: #ff6600;">Dynamic NAT using Access lists</span></strong></li>
<li><strong><span style="color: #ff6600;">Dynamic PAT using Access lists</span></strong></li>
<li><strong><span style="color: #ff6600;"><span style="color: #99cc00;">Static NAT using Route-maps</span> / Dynamic NAT using Route-maps .<br />
</span></strong></li>
<ul>
<li>
<ul>
<li><span style="color: #000000;">If both Static NAT using route-maps and Dynamic NAT using route-maps is configured, then the precedence works as follows :</span>
<ul>
<li><span style="color: #000000;">The ROUTE-MAP names are compared lexicographically. The NAT entry with a route-map which has a higher lexicographic value than the other is preferred.</span></li>
</ul>
<ul>
<li><span style="color: #000000;">If the ROUTE-MAPs are identical lexicographically, then Static NAT gets preference over Dynamic NAT<br />
</span></li>
</ul>
</li>
</ul>
</li>
</ul>
<li><strong><span style="color: #ff6600;"><span style="color: #99cc00;">Static PAT using Route-maps</span> /Dynamic PAT using Route-maps<br />
</span></strong></li>
<ul>
<li>
<ul>
<li><span style="color: #000000;">Same as the previous point.<br />
</span></li>
</ul>
</li>
</ul>
</blockquote>
</ul>
<p>Again, if you feel i&#8217;ve erred somewhere, please feel free to point out the mistakes either in the comments section or by leaving a small message on the chatbox on the right-hand-bar.</p>
<p>I&#8217;m really happy i finally figured this out, because i can now know exactly how the NAT statements are processed in the IOS. Hope you find this helpful too!</p>
<p>Cheers,<br />
TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/09/14/ios-nat-vs-asa-nat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

