I keep trying to steer myself toward Security, and I can never seem to get motivated to start working on it.
The bottom line is my current role has little to do with security. I'm primarily working with service provider technologies. Little did I know just how much the SP CCIE would help me. I'm ahead of the curve now on mpls and the time and effort I put into the lab has already paid off nicely.
So, the more I think about it, combined with my current lack of motivation to get going in Security, tells me it's time to switch to another track. The new SP Operations ccie should be right up my alley. I'm sure there will be a lot of carry over from R&S and SP, and I have a bunch of NGN experience as well.
The big issue with SPO is there is practically NO training material for it yet. So I'll be running with this one almost completely on my own--at least until the training providers catch up.
So that being said, I'm going all the way down to the associate level and am beginning to study for CCNA-SPO.
Friday, July 16, 2010
Monday, April 12, 2010
Stay Tuned...
I've been busy with other things and decided to hold off on the studying for a bit. My wife and I had a baby last month, and that definitely took priority over ccie #3.
Once things start to settle down (relatively) I'll be trying to get back into the groove.
Once things start to settle down (relatively) I'll be trying to get back into the groove.
Saturday, December 5, 2009
.net file for INE CCIE Security volume I
I've had a request for the .net file for volume 1. Here is what I have been using, more or less. For assistance getting the pix setup, see blindhog's blog at http://www.blindhog.net/category/pemu/
Note: I've removed the serial number and registration key. This is a linux version of the Dynagen.
begin file
----------------------------------------
model = 2620
ghostios = True
sparsemem = True
[localhost]
workingdir = /home/ccie/working
[[2620]]
ram = 64
image = /opt/images/C2600-IK.BIN
idlepc = 0x804a39b8
[[ROUTER R1]]
fa0/0 = sw 1
model = 2620
[[ROUTER R2]]
fa0/0 = sw 2
model = 2620
[[ROUTER R3]]
fa0/0 = sw 3
model = 2620
[[ROUTER R4]]
fa0/0 = sw 4
model = 2620
[[ETHSW sw]]
1 = dot1q 121
2 = dot1q 122
3 = access 123
4 = access 124
10 = access 123
11 = dot1q 1
12 = access 124
[pemu localhost]
[[525]]
#for pix 7 & 8
serial = xxx
license = 0xyyy 0xyyy 0xyyy 0xyyy
image = /opt/images/pix804.bin
[[fw fw1]]
# Connect the firewall's e2 interface to the virtual switch, which will bridge it
# to the real network
e0 = sw 10
e1 = sw 11
e2 = sw 12
Note: I've removed the serial number and registration key. This is a linux version of the Dynagen.
begin file
----------------------------------------
model = 2620
ghostios = True
sparsemem = True
[localhost]
workingdir = /home/ccie/working
[[2620]]
ram = 64
image = /opt/images/C2600-IK.BIN
idlepc = 0x804a39b8
[[ROUTER R1]]
fa0/0 = sw 1
model = 2620
[[ROUTER R2]]
fa0/0 = sw 2
model = 2620
[[ROUTER R3]]
fa0/0 = sw 3
model = 2620
[[ROUTER R4]]
fa0/0 = sw 4
model = 2620
[[ETHSW sw]]
1 = dot1q 121
2 = dot1q 122
3 = access 123
4 = access 124
10 = access 123
11 = dot1q 1
12 = access 124
[pemu localhost]
[[525]]
#for pix 7 & 8
serial = xxx
license = 0xyyy 0xyyy 0xyyy 0xyyy
image = /opt/images/pix804.bin
[[fw fw1]]
# Connect the firewall's e2 interface to the virtual switch, which will bridge it
# to the real network
e0 = sw 10
e1 = sw 11
e2 = sw 12
Sunday, November 29, 2009
INE Vol 1 Access Control and Configuring NAT Complete
Nothing too difficult here. I did run into a little bit of an issue getting DNS doctoring to work, but it was because my inspect dns was turned off. Once I got the inspect rules right, everything worked as it should.
Friday, November 27, 2009
INE Vol 1 labs underway
Over Thanksgiving I did 9 or 10 of INE's vol 1 labs. It's quite nice to have such a small topology for a change. My laptop has no problems running 3 routers and a Pix in Dynamips/pemu, which is plenty of devices for the first part of vol 1. With the SP laps I needed another dedicated box to get all 12 routers running smoothly.
I haven't really touched any security devices in a year and a half, although I did spend several years with Pix/ASAs, 3000 series vpn concentrators/clients, IDS, etc. For the most part Vol 1 is encompassing getting back in the groove on the old equipment, and is showing me how to do the CCIE level configs on these devices.
I'm really not in a rush at all. If I get Vol 1 done by the end of the year I'd be pretty happy with my progress.
I haven't really touched any security devices in a year and a half, although I did spend several years with Pix/ASAs, 3000 series vpn concentrators/clients, IDS, etc. For the most part Vol 1 is encompassing getting back in the groove on the old equipment, and is showing me how to do the CCIE level configs on these devices.
I'm really not in a rush at all. If I get Vol 1 done by the end of the year I'd be pretty happy with my progress.
Friday, November 20, 2009
And Away We Go
Two down, four to go. I don't know if I'll actually make it through all six, but continuing down the CCIE road still feels like the best road for me to follow. None of the alternatives are very appealing at this time: PhD, MBA, open source development, or CCDE. So I'll keep getting CCIEs until my priorities change.
I think I've learned a lot in the process of getting R&S and SP and can hopefully apply it to Security.
First, I tried to fly through SP way too fast. It still ended up taking about a year to complete. This is covered in rfc 1925: you can't make a baby in much less than 9 months.
Second, I should have begun labbing much sooner. Personally, I NEED experience before I get theory thrown at me. I'm not going to touch the class on demand, books, or written exam before I go through volume 1. Otherwise, the theory is over my head and I end up zoning out for much of it. I do better learning the how's first, and then getting to the why's after the fact.
Third, I need to do full scale labs from both IPX and INE before my first lab attempt. Last time I tried to just use INE first, and I had a lot of gaps going into my first attempt.
That being said, my rough schedule is something like this:
November 09 - March 10: INE Vol 1
April - May: Written
May - June: INE Vol 2
July - August: IPX Vol 2
September: Lab Attempt #1
I think I've learned a lot in the process of getting R&S and SP and can hopefully apply it to Security.
First, I tried to fly through SP way too fast. It still ended up taking about a year to complete. This is covered in rfc 1925: you can't make a baby in much less than 9 months.
Second, I should have begun labbing much sooner. Personally, I NEED experience before I get theory thrown at me. I'm not going to touch the class on demand, books, or written exam before I go through volume 1. Otherwise, the theory is over my head and I end up zoning out for much of it. I do better learning the how's first, and then getting to the why's after the fact.
Third, I need to do full scale labs from both IPX and INE before my first lab attempt. Last time I tried to just use INE first, and I had a lot of gaps going into my first attempt.
That being said, my rough schedule is something like this:
November 09 - March 10: INE Vol 1
April - May: Written
May - June: INE Vol 2
July - August: IPX Vol 2
September: Lab Attempt #1
Thursday, November 12, 2009
How to get from R&S to SP
From my experience, these are the most beneficial steps to pass the CCIE SP, assuming you already have R&S.
1. Don't believe the rumors you've heard that SP is easy once you have R&S. It's NOT true. While there are a few overlaps, about 60% of the SP exam is completely different. And that 60% is going to be tough. Don't go into this lightly.
2. There really isn't much benefit in getting the CCIP first. However, I would strongly recommend passing the BGP+MPLS exam. This covers the MPLS foundation and some of the BGP topics geared towards SP. If you can read some books and pass exams, do so. If you need more hands on, do some Vol 1 labs and come back to this before attempting the SP written.
3. Unlike R&S, there really isn't a single book that prepares you well. I didn't mind Configuring MPLS on Cisco IOS Software, but it wasn't nearly as good as the Doyle books for R&S were. I really felt pretty lost going after the written. But with R&S knowledge and passing BGP+MPLS, you'll be pretty close.
4. Just like R&S, the Internetwork Expert Videos are a must. Nearly everything you need to pass the lab are covered in these 40 hours. These videos give you a great foundation, you'll just need to remember it all and learn to apply it.
5. Go through all the Volume 1 labs from your provider of choice (in my case INE or IPX). These give you a great foundation for covering the full scale labs. Don't get lazy, do them all!
6. Focus on the Following labs, in order:
a. Start off with IPX Volume 3 labs 1-4. These are great for getting you ramped up to full scale labs. I didn't care for lab 5 much.
b. Do the INE Vol 2 labs. These are especially important for having interesting VPN topologies to configure. They are tough, but keep at it until you fully understand them.
c. Do IPX lab Vol 2 lab 1. If there is a reason to spend the money on the IPX workbook, this is it. INE teaches the toplogies well, but IPX teaches the knobs and question style well. Do this lab!
d. Attend the INE SP Bootcamp. Their labs 1 and 2 are great and cover some topics that aren't really covered well anywhere else.
7. Once again, don't think you can rush through this. It's going to take a lot of work. But, once you're finished you're going to have a real respect for MPLS and the things that can be accomplished with it.
1. Don't believe the rumors you've heard that SP is easy once you have R&S. It's NOT true. While there are a few overlaps, about 60% of the SP exam is completely different. And that 60% is going to be tough. Don't go into this lightly.
2. There really isn't much benefit in getting the CCIP first. However, I would strongly recommend passing the BGP+MPLS exam. This covers the MPLS foundation and some of the BGP topics geared towards SP. If you can read some books and pass exams, do so. If you need more hands on, do some Vol 1 labs and come back to this before attempting the SP written.
3. Unlike R&S, there really isn't a single book that prepares you well. I didn't mind Configuring MPLS on Cisco IOS Software, but it wasn't nearly as good as the Doyle books for R&S were. I really felt pretty lost going after the written. But with R&S knowledge and passing BGP+MPLS, you'll be pretty close.
4. Just like R&S, the Internetwork Expert Videos are a must. Nearly everything you need to pass the lab are covered in these 40 hours. These videos give you a great foundation, you'll just need to remember it all and learn to apply it.
5. Go through all the Volume 1 labs from your provider of choice (in my case INE or IPX). These give you a great foundation for covering the full scale labs. Don't get lazy, do them all!
6. Focus on the Following labs, in order:
a. Start off with IPX Volume 3 labs 1-4. These are great for getting you ramped up to full scale labs. I didn't care for lab 5 much.
b. Do the INE Vol 2 labs. These are especially important for having interesting VPN topologies to configure. They are tough, but keep at it until you fully understand them.
c. Do IPX lab Vol 2 lab 1. If there is a reason to spend the money on the IPX workbook, this is it. INE teaches the toplogies well, but IPX teaches the knobs and question style well. Do this lab!
d. Attend the INE SP Bootcamp. Their labs 1 and 2 are great and cover some topics that aren't really covered well anywhere else.
7. Once again, don't think you can rush through this. It's going to take a lot of work. But, once you're finished you're going to have a real respect for MPLS and the things that can be accomplished with it.
Subscribe to:
Posts (Atom)