Archive for category CCIE-Security

Fasttrack?

Hello All,

I was doing some Vol 1 labs yesterday and the task asked me to block Kazaa/Grokster traffic. I was going to use NBAR on the IOS , but i found that there are no PDLMs for Kazza, Grokster . After racking my brains from sometime, i gave up and checked the solutions ( insert Sheepish grin here ). The solution had the following config :

class-map XXX
match protocol fasttrack

policy-map YYY
class XXX
drop

I didn’t understand what fasttrack was doing there. After googling ( again, insert sheepish grin ), i found this http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00801e419a.shtml#c4.

This could be a question  asked in the lab and i hope this helps us remember that we have to use “fasttrack” whenever we are asked to block Kazaa/Grokster . Hope this helps!

Cheers,

TacACK

No Comments

Kick-starting the Config section of the brain

Hello All!

It’s time to start studies in full swing and i work best when i have a schedule in front of me. So here it is :) For the next 20 days, i’m going to be just doing Vol 1 labs and reading the Doc-CD , just to serve as a refresher. Then i will start Vol 2 labs and also try and lab as many hard configurations as possible.

For the detailed schedule , please have a look at the Google Calendar Widget on the bar to the right ( Just below the chatbox ).

I hope to have lots of fun and try and get into the routine of configuration and debugging :)

Cheers and Happy studying,
TacACK

P.S : I’ve a great study partner in Ryan, but if there’s anyone else who is also restarting their CCIE-Sec studies and is attempting their lab sometime in December, i would love to hear more about the approach that you are going to follow and what topics you need to focus on.

No Comments

L2TP Overview – VoD

Hello All!

I was going through a couple of L2TP documents yesterday and i thought it would be helpful if i made a small video which just outlined all the stuff that i had studied. As CCIE security candidates we know that L2TP is a topic that is included in the written, can be asked in the OEQs and could be a part of the CCIE-Security Lab ( L2TP over IPSec ). So, i wanted this video to serve as a sort of revision / basic-tutorial for L2TP NoobS ( like me :) ) .

The doc-cd links that i used to study were :

http://www.cisco.com/en/US/docs/ios/12_0t/12_0t1/feature/guide/l2tpT.html

http://www.cisco.com/warp/public/cc/pd/iosw/tech/l2pro_tc.htm

The video is split into 3 small videos ( thanks to Youtube’s time-limit for each video ). Please find embedded the Playlist for all 3 videos :)

Hope you like the video. Please feel to correct me if i’m committed a mistake anywhere in my explanation. There are many more to come. Next in the series , L2TP over IPSec.

Cheers,

TacACK

1 Comment

Back from the dead

Hello All!

My apologies for not blogging actively for the last couple of weeks. I really missed blogging and talking to all of you :)

As you might(not)? know  i had my CCIE-security lab last week and i regret to inform you all that i did not clear it this time. The lab was tougher than my expectations and although i knew i would be flunking it right at the beginning ( thanks to the OEQs) , i was feeling good after the lab because i felt i did the lab portion of it correctly. But, sadly, i later found out that i did’nt clear both the lab and the OEQ sections. This was a little suprising because i thought i had fared well in atleast the configuration section of the lab.

Well, if life has taught us all one lesson , it is to never look back and to work harder to achieve our goals. That’s exactly what i’m going to do.

It’s very overwhelming to receive the amount of support that i’ve received after i announced my results on twitter and OSL. I’m very very thankful to each and every one of you for believing in me and for motivating me to keep the hard-work going. Thank you!

I will be more active and i will post a lot more videos on complex topics which i hope to master too :) .

Cheers and Happy studying!

TacACK

2 Comments

INE Lab 8 today!

Hello Hello!

I’ve been busy for the last couple of days doing some ccie-sec stuff and also getting some work done. I did INE lab 5 first and i found it REALLY REALLY hard! I don’t think there’s anyway the real exam is going be this hard.

After that, i did INE Lab 7 and i found it pretty fair. Some sections were tough, but most sections were doable. I found some confidence after doing them and i think i need to work a little bit more on my speed.

Later tonight, i’ll be posting a video about how i actually start the lab. This will include how i draw the diagram, how i take down notes ,etc. If you feel i should do anything differently, please feel free to let me know! :)

Yesterday, i did  a lot of Doc-CD study. I studied/did-some labs on IOS NAT, went through the great free whitepapers available on the INE website! I also did some VPN configurations but i just couldn’t get EZVPN to work. :/ I wanted to debug this but couldn’t find the time yesterday.

In about 30 mins time, my rack-rental session starts and i intend to do INE Lab 8 today. Hopefully, it’ll be fun! :)

P.S : I’m sorry if my blogs don’t have much techy stuff these days, it’s just because there’s so much going on and i’m finding it a little hard to collect it all and blog it. But i promise, after my 1st attempt, i will start blogging in depth about the technologies ( and a little less about my feelings ;) )

Cheers and have fun!

TacACK

No Comments