<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TacAck - My security journey! &#187; Uncategorized</title>
	<atom:link href="http://tacack.com/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://tacack.com</link>
	<description></description>
	<lastBuildDate>Mon, 06 Jun 2011 05:49:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>DMVPN webinar!</title>
		<link>http://tacack.com/2011/06/06/dmvpn-webinar-for-adults-only/</link>
		<comments>http://tacack.com/2011/06/06/dmvpn-webinar-for-adults-only/#comments</comments>
		<pubDate>Mon, 06 Jun 2011 05:35:03 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=839</guid>
		<description><![CDATA[Hello All,
I was recently part of a project in which i did some teaching, and guess what, i LOVED it! Teaching gets me real excited and motivated to work hard and i&#8217;m seriously considering it as a full time profession.
But i&#8217;ve to overcome some things before i can start confidently teaching!
1) Get better.Technically.
2) Try real [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I was recently part of a project in which i did some teaching, and guess what, i LOVED it! Teaching gets me real excited and motivated to work hard and i&#8217;m seriously considering it as a full time profession.</p>
<p>But i&#8217;ve to overcome some things before i can start confidently teaching!</p>
<p>1) Get better.Technically.</p>
<p>2) Try real hard to not swear during the classes</p>
<p>3) Get better.Technically. Have i said that already?</p>
<p>As you all might/might not know, i have restarted my CCIE-security study and i&#8217;m now digging deep into VPNs. I spent about 2-3 days last week reading up and labbing about DMVPNs and i thought it&#8217;d be cool if i can share all the stuff that i had learnt with others. Hence, the idea for the webinar.</p>
<p>It&#8217;s going to be a live session and i&#8217;m going to try and keep it as informal and fun as possible <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  . I&#8217;d really appreciate it if you can join me as i go through what DMVPN is all about and how to kick some ass using this technology.</p>
<p>Here&#8217;s the link using which you can register -&gt; ﻿<a href="http://tacack-dmvpn.eventbrite.com/">http://tacack-dmvpn.eventbrite.com/</a> .</p>
<p>As the date for webinar nears, i will provide more details about the medium i&#8217;m going to be using to teach this topic.</p>
<p>So go ahead, tune-in , grab a beer , get comfortable and join me as we tear DMVPN apart!</p>
<p>Cheers,<br />
TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2011/06/06/dmvpn-webinar-for-adults-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aloha!</title>
		<link>http://tacack.com/2011/04/09/aloha/</link>
		<comments>http://tacack.com/2011/04/09/aloha/#comments</comments>
		<pubDate>Sat, 09 Apr 2011 16:27:14 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=823</guid>
		<description><![CDATA[Hello All,
I thought it&#8217;d be a cool idea to say hi to all of you instead of just typing it out here, so please listen to the small clip .
Cheers,
TacACK
]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I thought it&#8217;d be a cool idea to say hi to all of you instead of just typing it out here, so please listen to the <a href="http://tacack.com/wp-content/uploads/2011/04/hello1.wav">small clip</a> .</p>
<p>Cheers,</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2011/04/09/aloha/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Feedback required!</title>
		<link>http://tacack.com/2010/10/20/feedback-required/</link>
		<comments>http://tacack.com/2010/10/20/feedback-required/#comments</comments>
		<pubDate>Wed, 20 Oct 2010 09:11:15 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=772</guid>
		<description><![CDATA[Hello All,
I&#8217;m planning to start a new project and i need your help with a question that&#8217;s been bothering me. I kindly request you to take the poll (below) and let me know what you think is a good option.
Cheers and thanks!
TacACK
]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I&#8217;m planning to start a new project and i need your help with a question that&#8217;s been bothering me. I kindly request you to take the poll (below) and let me know what you think is a good option.</p>
Note: There is a poll embedded within this post, please visit the site to participate in this post's poll.
<p>Cheers and thanks!</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/10/20/feedback-required/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vol 1.5 labs -&gt; A/A Failover , IOS SSL-VPN , AUTH PROXY</title>
		<link>http://tacack.com/2010/04/10/vol-1-5-labs-aa-failover-ios-ssl-vpn-auth-proxy/</link>
		<comments>http://tacack.com/2010/04/10/vol-1-5-labs-aa-failover-ios-ssl-vpn-auth-proxy/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 14:10:59 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=441</guid>
		<description><![CDATA[Hey all,
I&#8217;m starting off my &#8220;Vol 1.5&#8243; series labs from today, where will be posting labs which i&#8217;m doing . These labs are slightly larger than the vol1 labs and they focus on multiple technologies at the same time. My aim is to get as close to Vol 2 labs as possible   Also [...]]]></description>
			<content:encoded><![CDATA[<p>Hey all,</p>
<p>I&#8217;m starting off my &#8220;Vol 1.5&#8243; series labs from today, where will be posting labs which i&#8217;m doing . These labs are slightly larger than the vol1 labs and they focus on multiple technologies at the same time. My aim is to get as close to Vol 2 labs as possible <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Also  <a href="http://www.routsec.com">Ryan</a> is my CCIE-sec study-partner and we&#8217;re following a systematic approach to nail the beast! Thanks, Ryan. <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I use Graded labs for my rack-rentals. So the inital configurations are all modified to suit graded-labs.</p>
<p><strong>TARGET TIME</strong> :<span style="color: #000000;"> 4</span> hours</p>
<p><strong>TOPOLOGY</strong> :</p>
<p><a href="http://tacack.com/wp-content/uploads/2010/04/7s.jpeg"><img class="size-full wp-image-442 alignleft" title="7s" src="http://tacack.com/wp-content/uploads/2010/04/7s.jpeg" alt="" width="729" height="346" /></a></p>
<p><strong><a href="http://tacack.com/wp-content/uploads/2010/04/7s-INITIAL-CONFIGS.zip">INITIAL CONFIGS</a></strong><a href="http://tacack.com/wp-content/uploads/2010/04/7s-INITIAL-CONFIGS.zip"> </a></p>
<p><strong><a href="http://tacack.com/wp-content/uploads/2010/04/TASKS.pdf">TASKS</a></strong><a href="http://tacack.com/wp-content/uploads/2010/04/TASKS.pdf"> </a></p>
<p>Please let me know if you have any issues with the configuration,etc and please forgive any mistakes in the initial configurations.</p>
<p>Cheers,</p>
<p>TacACK</p>
<p>P.S : Please use either a AAA server or local authentication/authorization for the tasks. I&#8217;ll post a lab soon where it uses only the AAA server</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/04/10/vol-1-5-labs-aa-failover-ios-ssl-vpn-auth-proxy/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>3 Topics done</title>
		<link>http://tacack.com/2010/03/29/3-topics-done/</link>
		<comments>http://tacack.com/2010/03/29/3-topics-done/#comments</comments>
		<pubDate>Mon, 29 Mar 2010 08:29:52 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=432</guid>
		<description><![CDATA[Hello All,
I&#8217;m starting with all tasks that i&#8217;ve rated 7. So i did Filtering, Failover and Tranparent IOS and ASA firewalls. I&#8217;ve updated the schedule with the links to the notes that i made  
This will ensure that they are easily availble when we wanna check them out later. I&#8217;m yet to update the [...]]]></description>
			<content:encoded><![CDATA[<p>Hello All,</p>
<p>I&#8217;m starting with all tasks that i&#8217;ve rated 7. So i did Filtering, Failover and Tranparent IOS and ASA firewalls. I&#8217;ve updated the schedule with the links to the notes that i made <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>This will ensure that they are easily availble when we wanna check them out later. I&#8217;m yet to update the blueprint according to the latest expanded blueprint announced by cisco. I will do that in time <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ( Too bored )</p>
<p>Cheers and happy studying. Please let me know as to how your studies are going and what you&#8217;d like to see here?</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/03/29/3-topics-done/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Awesome announcement from Cisco!</title>
		<link>http://tacack.com/2010/03/28/awesome-announcement-from-cisco/</link>
		<comments>http://tacack.com/2010/03/28/awesome-announcement-from-cisco/#comments</comments>
		<pubDate>Sun, 28 Mar 2010 02:47:21 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=425</guid>
		<description><![CDATA[Hey guys and girls!
I was just about to post a new article on some of the notes that i had made recently. As you all know i recently posted up the CCIE-blueprint as a checklist and i&#8217;ve started ticking things off , as i finish them ! Well, here&#8217;s the good news..
Cisco, did EXACTLY the [...]]]></description>
			<content:encoded><![CDATA[<p>Hey guys and girls!</p>
<p>I was just about to post a new article on some of the notes that i had made recently. As you all know i recently posted up the CCIE-blueprint as a checklist and i&#8217;ve started ticking things off , as i finish them ! Well, here&#8217;s the good news..</p>
<p>Cisco, did EXACTLY the same thing and their new( and expanded ) CCIE-v3 blueprint rocks my face! <a href="https://learningnetwork.cisco.com/docs/DOC-6861">HERE</a>&#8217;s the link to it ( Registered customers only ). If you want it in a PDF format, you can find it <a href="https://learningnetwork.cisco.com/docs/DOC-6861.pdf">HERE</a>.</p>
<p>This is really awesome, as i no longer have to keep guessing about the topics that might be included under a particular section. It&#8217;s always a good feeling when you hear it from *THE MAN* himself, rather than providers <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I will be updating the CCIE-sec blueprint later today to match this new and improved list.</p>
<p>Cheers!</p>
<p>TacACK</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2010/03/28/awesome-announcement-from-cisco/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inactivity Explained!</title>
		<link>http://tacack.com/2009/08/04/inactivity-explained/</link>
		<comments>http://tacack.com/2009/08/04/inactivity-explained/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 14:03:49 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=69</guid>
		<description><![CDATA[Hey all,
I&#8217;m taking a break from Cisco for 2 weeks or so.. ( 2nd week running ) as i prepare for the CWNA cert. Hold on, i&#8217;ma be back  
]]></description>
			<content:encoded><![CDATA[<p>Hey all,</p>
<p>I&#8217;m taking a break from Cisco for 2 weeks or so.. ( 2nd week running ) as i prepare for the CWNA cert. Hold on, i&#8217;ma be back <img src='http://tacack.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2009/08/04/inactivity-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Certificate Based ACL&#8217;s</title>
		<link>http://tacack.com/2009/07/29/certificate-based-acls/</link>
		<comments>http://tacack.com/2009/07/29/certificate-based-acls/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 10:08:43 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=62</guid>
		<description><![CDATA[Today i was researching if there are any ways to block users have Valid certificates from making VPN connections to a Router. I found that this can be achieved using an IOS feature called Certificate-based ACL&#8217;s.( CALC&#8217;s ).
Using a CALC we can define a filtering condition for the user certificates , such that only users [...]]]></description>
			<content:encoded><![CDATA[<p>Today i was researching if there are any ways to block users have Valid certificates from making VPN connections to a Router. I found that this can be achieved using an IOS feature called Certificate-based ACL&#8217;s.( CALC&#8217;s ).</p>
<p>Using a CALC we can define a filtering condition for the user certificates , such that only users having certificates which match the filter criteria are permitted to pass through Certificate Authentication and VPN setup. The other users do not even go through the certificate checking process, they are immediately denied VPN access.</p>
<p><strong>SYNTAX</strong></p>
<blockquote><p> (conf-t)#<strong>crypto pki certificate map</strong> &lt;<em>certificate-map-name</em>&gt; <em>&lt;entry-number&gt;</em> </p></blockquote>
<p><em> </em>Certificate-map-name : Represents the name of the CALC</p>
<p>After creating the CALC, we can specify match conditions  or ACE&#8217;s.</p>
<blockquote><p># <em>&lt;<strong>field-name</strong>&gt; &lt;<strong>match-criteria</strong>&gt; &lt;<strong>match-value</strong>&gt;</em></p></blockquote>
<p><strong><em> field-name</em></strong> : Represents which field in the certificate will be used for the filter. There are many options here:</p>
<ul>
<li><strong>alt-subject-name</strong><a name="wp1049090"></a></li>
<li><strong>expires-on</strong></li>
<li><strong>issuer-name</strong></li>
<li><strong>name</strong></li>
<li><span style="FONT-WEIGHT: bold; COLOR: black; FONT-STYLE: normal">serial-number</span></li>
<li>s<strong>ubject-name</strong></li>
<li><strong>unstructured-subject-name</strong></li>
<li><strong>valid-start</strong></li>
</ul>
<p><strong><em>match-criteria</em></strong> : This will indicate &#8220;how&#8221; the match will take place. This tells how the value indicated in the field- name will be used. The various possibilities are :</p>
<ul>
<li>eq , ne , co ( contains ) , nc ( does not contain ) , lt ( less-than ), ge ( greater then or equal to )</li>
</ul>
<p><strong><em>match-value</em></strong> : Value which will be used to match against the field-name using the criteria mentioned in match-criteria.</p>
<p><strong>EXAMPLE</strong></p>
<blockquote><p>#crypto pki certificate map <strong>Certs_TB_blocked</strong> 10</p>
<p style="PADDING-LEFT: 30px">#subject-name co Marketing</p>
</blockquote>
<p>The above CALC will only permit dudes having a &#8220;marketing&#8221; certificate to create VPN connections to the Router.</p>
<p>In order to apply this CALC, we need to apply this to the trustpoint definition in our Central Router. When the Central router receives a certificate from a user, it checks with it&#8217;s trustpoint if the certificate is valid or not. At this junction, the CALC can be applied to identify which certificates should be even checked ( ex : from marketing ) and which should be shown the door ( ex : other deparments who are not eligible to make VPN connections ).</p>
<blockquote><p>#crypto pki trustpoint <strong>Tacack</strong></p>
<p style="PADDING-LEFT: 30px">#<strong>match certificate Certs_TB_blocked</strong></p>
<p style="padding-left: 60px;">#enrollment-url&#8230; ( bla bla bla&#8230; )</p>
</blockquote>
<p>Using this, a powerful certificate filtering feature can be enforced on a Router to limit or police the VPN connections from various users in a company.</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2009/07/29/certificate-based-acls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Switching in a router ! ( Part 1/2 )</title>
		<link>http://tacack.com/2009/07/22/switching-in-a-router-part-12/</link>
		<comments>http://tacack.com/2009/07/22/switching-in-a-router-part-12/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 14:50:14 +0000</pubDate>
		<dc:creator>TacAck</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://tacack.com/?p=51</guid>
		<description><![CDATA[ 
No , that wasn&#8217;t a typo. The first time i heard that, i nearly gave up Cisco studies. I mean C&#8217;mon! What next? Voice in an ASA? Jupiter on MARS ( get the pun?   ) . But thanks to @packetu&#8217;s discussion on CLN is started reading about this and it&#8217;s super insightful into how routers [...]]]></description>
			<content:encoded><![CDATA[<div class="mceTemp"> </div>
<p>No , that wasn&#8217;t a typo. The first time i heard that, i nearly gave up Cisco studies. I mean C&#8217;mon! What next? Voice in an ASA? Jupiter on MARS ( get the pun? <img src='http://tacack.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  ) . But thanks to <a title="Paul Stewart's Twitter Page" href="http://www.twitter.com/packetu" target="_blank">@packetu&#8217;s </a>discussion on CLN is started reading about this and it&#8217;s super insightful into how routers work. What i&#8217;m writing here is mercilessly and shamelessly copied from Cisco documentation which can be found <a title="Cisco's origical article" href="http://www.cisco.com/en/US/tech/tk827/tk831/technologies_white_paper09186a00800a62d9.shtml" target="_blank">here</a>. Here&#8217;s what i learnt:</p>
<p>Hokay! Some clarfications first!</p>
<p>Uno : By switching inside a router, i don&#8217;t mean a &#8220;L-2 Router&#8221; ( Even if that exists! )</p>
<p>Dos : No, It&#8217;s not a new technology</p>
<p>Now that we&#8217;ve got that outta the way. Lemme tell you what switching here refers to. In simple terms, switching refers the &#8220;mechanism&#8221; employed by the routers to get a packet from the source-interface to the destination-interface with all the make-up required. Clear enough? This is a totally internal process( which happens inside a router when it recieves a packet ). There are a couple of steps which happen when a packet arrives :</p>
<ul>
<li>The router checks if the packet&#8217;s destination is reachable.</li>
<li>If yes, to the previous question- How the F does it get there? Which&#8217;s the next hop of the packet.</li>
<li>If the next hop has been determined, Send it. But hold on- bef0re sending , the source MAC address of the packet must be re-written to the MAC-address of the outgoing interface of the router.</li>
</ul>
<p>In-order to do this the router can choose between 2 methods:</p>
<ul>
<li>Process switching
<ul>
<li>The packet is switched by a &#8220;process&#8221; running among other processes in a router</li>
<li>It IOS doesn&#8217;t give a rats ass if the packet arrives. It will switch it when it wants to ( i.e when the &#8220;switching process&#8221; gets priority to run )</li>
<li>Not -very good &#8216;coz an overloaded router can cause problems to the switching</li>
<li>Uses the Routing Information Base ( fancy name for &#8220;routing table&#8221; ) and the ARP cache , to get hold of the MAC-address of reachable hosts.</li>
</ul>
</li>
<li>Interrupt Context Switching
<ul>
<li>Them packets are worshipped. Aka they are switched on demand</li>
<li>When a packet arrives, an interrupt is raised and all other processes stop, and the switching process switches the packet.</li>
<li>Unlike Process switching ( which referes to the RIB and ARP cache ), ICS refers to a separate Route-Cache to get the MAC-Address of the destination .</li>
<li>Getting this data from the route-cache can be done in one of the 3 following methods:
<ul>
<li>Fast switching</li>
<li>Optimum switching</li>
<li>Cisco Express Forwarding ( Ta-Da!!!)</li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong><em>Fast Switching</em></strong></p>
<p>The point as we all know is to find the MAC-Address of the destination using the IP address of the destination. This as we learnt earlier is done using a &#8220;route-cache&#8221;. The Fast-switching route-cache comprises of the following</p>
<ul>
<li>A Gigantic <a title="Wiki - Binary Tree" href="http://en.wikipedia.org/wiki/Binary_tree" target="_blank">Binary Tree</a> ( 32 levels ) having a leaf node for every IP address imaginable.
<div class="mceTemp"> </div>
</li>
<li>The MAC-address of the IP ( if reachable ) is stored in the leaf as payload.</li>
<li>For the router to find the MAC corresponding to a destination IP, it has a to do a lookup through all the entries based on the bit pattern of the IP address.</li>
<li>It&#8217;s obvious at this point that there is no link between the tree and the Routing Information Base ( Routing table ) and the ARP table.</li>
<li>This leads to the following problems:
<ul>
<li>So suppose in the future some routing entry changes in the RIB or the MAC-address of a destination changes and it&#8217;s updated in the ARP table, the change will not be reflected in the Route-cache.</li>
<li>If the tree has to be as up-to-date as possible, the entries have to be renewed continuosly. This leads to additional overhead.</li>
<li>Suppose there is some route-recursion between the destinations, it&#8217;s impossible to represent here in the cache because the MAC-addresses of the destinations are burnt in.</li>
</ul>
</li>
<li>So a better solution was developed</li>
</ul>
<p><strong><em>Optimum Switching</em></strong></p>
<p>The disadvantages in the previous caching method had to countered here. So the following method is followed:</p>
<ul>
<li>Instead of having <strong>one</strong> huge Binary tree having all the MAC-address related information, they are broken down into 4 hierarchical multiway (not binary) trees.</li>
</ul>
<div id="attachment_53" class="wp-caption aligncenter" style="width: 395px"><img class="size-full wp-image-53 " title="optimum-switching" src="http://tacack.com/wp-content/uploads/2009/07/optimum-switching.gif" alt="Optimum-switching structure" width="385" height="446" /><p class="wp-caption-text">Optimum-Switching</p></div>
<ul>
<li>So, now the router&#8217;s job has become easy. It only needs to do 4 checks. ( 1 for every octet of the IP address ).</li>
<li>Similar to Fast-switching, the MAC address of the destination is stored in the payload of the corresponding leaf-node .</li>
<li>The problems which plague fast-switching still exist here as there is not relation between this and the routing and arp tables.</li>
<li>So the problems of Mac-address changes and aging still exist.</li>
<li>Even the route-recursion issue still exists</li>
</ul>
<p>The better way to do this is through or friend <strong>CEF!</strong></p>
<p>Continued in Part 2&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://tacack.com/2009/07/22/switching-in-a-router-part-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

