<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1434794436817977802</id><updated>2011-10-31T04:48:38.105-07:00</updated><category term='NAT'/><category term='AAA'/><category term='VPNS'/><category term='Routing'/><category term='INFO'/><category term='Windows'/><category term='General'/><category term='ASA'/><category term='Troubleshooting'/><title type='text'>Diary of a Network Engineer...</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>36</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1335908873741254914</id><published>2011-01-31T03:40:00.000-08:00</published><updated>2011-01-31T03:53:38.875-08:00</updated><title type='text'>Time and Chance - Lessons from Outliers</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;Hi everyone, and Happy (kinda belated) new year.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The last few months on the previous year had me questioning my definition of personal and career success. At the beginning of the year, I tried to make a list of books (non-tech) I had to study in the first half of this year.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;a href="http://www.amazon.com/Blink-Power-Thinking-Without/dp/0316172324"&gt;Blink&lt;/a&gt; - Malcolm Gladwell&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Outliers-Story-Success-Malcolm-Gladwell/dp/0316017922"&gt;Outliers&lt;/a&gt; - Malcolm Gladwell&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Tipping-Point-Little-Things-Difference/dp/0316346624"&gt;The Tipping Point&lt;/a&gt; - Malcolm Gladwell&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Freakonomics-Economist-Explores-Hidden-Everything/dp/006073132X"&gt;Freakonomics&lt;/a&gt; - Steve Levitt&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Fooled-Randomness-Hidden-Chance-Markets/dp/1587990717"&gt;Fooled by Randomness&lt;/a&gt; - Nassim Taleb&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/Good-Great-Companies-Leap-Others/dp/0066620996"&gt;Good to Great&lt;/a&gt; - Jim Collins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;I spent most of the last weekend reading outliers, where Malcolm Gladwell makes some salient points on the story of success.&lt;br /&gt;&lt;br /&gt;While I am still considering making a detailed review of this book, I can summarize most of the book into the words of Solomon from the scriptures in Ecclesiastes chapter 9 vs 11&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;"I returned, and saw under the sun, that the race [is] not to the swift, nor the battle to the strong, neither yet bread to the wise, nor yet riches to men of understanding, nor yet favour to men of skill; but time and chance happeneth to them all."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The role opportunity (being at the right place at the right time) plays in success is too huge to be neglected. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Well, even at that I still believe success is not entirely a function of chance, we must be able to recognize the opportunities and adapt so we can take advantage of them. The ability to do this is an extremely crucial factor in determining if we would be successful.&lt;br /&gt;&lt;br /&gt;I think Outliers was a good read. Up next is Blink.&lt;br /&gt;&lt;br /&gt;On the techy note, I'm considering picking up Juniper skills as a form of horizontal development as opposed to studying for another CCIE. Lets see how that goes.&lt;br /&gt;&lt;br /&gt;Cheers!&lt;br /&gt;Amplebrain.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1335908873741254914?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1335908873741254914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2011/01/time-and-chance-lessons-from-outliers.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1335908873741254914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1335908873741254914'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2011/01/time-and-chance-lessons-from-outliers.html' title='Time and Chance - Lessons from Outliers'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-8449487209794652655</id><published>2010-12-31T09:06:00.000-08:00</published><updated>2010-12-31T09:17:39.272-08:00</updated><title type='text'>And its a wrap! Thank God for 2010</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;Its been a great year for me - I hope you had a great year too&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To everyone that contributed in making my year awesome - Thanks!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To everyone that I had the privilege of meeting - Thanks!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To everyone that I might have offended - I apologize&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;And to everyone - Hope you all have a great 2011&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The next post would be in the new year! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Cheers!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Amplebrain&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-8449487209794652655?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/8449487209794652655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/12/and-its-wrap-thank-god-for-2010.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8449487209794652655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8449487209794652655'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/12/and-its-wrap-thank-god-for-2010.html' title='And its a wrap! Thank God for 2010'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2507131794192324656</id><published>2010-10-15T15:53:00.000-07:00</published><updated>2010-10-15T16:01:21.539-07:00</updated><title type='text'>What Next?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Hi Everyone! (Wonder if anyone still reads this blog)&lt;br /&gt;&lt;br /&gt;This is my first post after a long hiatus from blogging.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Its been four months since my Last major exam. I decided to take a very long break since the exam was very demanding and I had to make up for 'other parts of my life' that suffered while trying to obtain my second CCIE.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Now, Its time to answer the million dollar question: &lt;span style="font-weight: bold;"&gt;WHAT NEXT?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;At 21, with 2 CCIEs, I have just completed my year of 'compulsory' service to my country (finally),  and its time to make a major career decision.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;" &gt;Options?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. Pursue an academic (technical) degree: A Masters in Engineering or some related course looks appealing (the perfect icing on the cake for the Bachelors) but just doesn't seem to fit in the grand career plan at the moment. I do not see the relative advantage that a masters degree would offer me at the moment, so I'll pass.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. Pursue an MBA: A masters in Business Administration might expose me to the right business knowledge that would complement my technical skills but I dont think this is the right time for an MBA, I'm a techie at heart and I still love what I do. Maybe in the next 2 years but definitely not now. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. More CCIEs: I have been toying with the idea of taking another CCIE in SP or Voice. The challenge and the knowledge that comes with the CCIE study process is just too much fun to ignore. But if I have to do any more CCIEs, I need to have the experience to back it up, so I would wait for a few months before I launch out.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. CCDE: The CCDE exam intrigues me because of it acclaimed difficulty, some part of me wants to study for the exam while the other part is certain that the exam is not meant for mere mortals like me. After looking at Petr Lapukhov's &lt;a href="http://blog.ine.com/2010/09/26/ccde-practical-exam-recommended-reading/"&gt;recommended list of materials,&lt;/a&gt; I have decided that I would pass. That would take a few years to study :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. Nothing :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;span style="font-weight: bold;"&gt;Conclusion:&lt;/span&gt; I do not think I would be taking any milestone exams in the next few months. I would rather focus on getting enough experience and building my project profile. This might involve changing job-roles, changing organizations or even location as long as the goal is accomplished.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Please feel free to drop your comments, I actually need them :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Hope to post some more (non-techie) stuff soon.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Cheers!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2507131794192324656?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2507131794192324656/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/10/what-next.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2507131794192324656'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2507131794192324656'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/10/what-next.html' title='What Next?'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-8558122594155306361</id><published>2010-06-17T07:22:00.000-07:00</published><updated>2010-06-17T07:46:26.793-07:00</updated><title type='text'>It is done...Security Lab Passed!</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;Hi All,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;I passed the security lab yesterday in Lagos (mobile lab) on my first attempt. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Thanks to everyone that was a part of this journey.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;1. God: For grace, strength, courage, provision and favour.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. Family: For all the support. Thanks a million.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;3. Friends: You guys are the best. It's not easy to have so many friends when all you do is sit and stare at a screen all day.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;4. Study Partners: (&lt;/span&gt;&lt;a style="font-family: trebuchet ms;" href="http://www.tacack.com"&gt;Tacack&lt;/a&gt;&lt;span style="font-family: trebuchet ms;"&gt;, Deolu, Peter) It was fun studying with you guys. Wishing Peter all the best as he takes the lab today!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;5. Study groups: OSL totally rocks. Groupstudy, CLND and IEOC are also very helpful.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;6. Everyone that wished me Luck :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Study Materials&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;I used INE study materials (because I fell in love with them since my R&amp;amp;S) and they are very good. IPExpert also has some quality materials too. Yusuf's labs are also incredible and they show you what to look out for in the lab.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Once again, thanks for everything.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Cheers,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Amplebrain, CCIE R&amp;amp;S and Sec&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-8558122594155306361?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/8558122594155306361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/06/it-is-donesecurity-lab-passed.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8558122594155306361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8558122594155306361'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/06/it-is-donesecurity-lab-passed.html' title='It is done...Security Lab Passed!'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-3609309667792124485</id><published>2010-06-02T10:00:00.000-07:00</published><updated>2010-06-02T10:06:32.937-07:00</updated><title type='text'>XXI</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;In Real world,&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;1. We live in the 21st century&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;2. The legal adult age in most countries - Alcohol, rent-a-car etc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;In mathematics&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. A Fibonacci Number&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. A Triangular Number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;5. A star number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;6. An octagonal number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;7. composite Number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;8. A Harshad Number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;9. A Motzkin number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;Symbolism/Religion&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;10. Number of the perfection by excellence, 3 x 7, according to the Bible.&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;11. 21 chapters in the Gospel of St John&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;In Science/Networking :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;12. FTP port number&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;13. Atomic Number of Scandium&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;In entertainment &amp;amp; Sports:&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;14. Used to be a TV show&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;15. 21 points are required to win a game of badminton and tennis&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;16. A card game, also known as blackjack&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;17. Name of favorite movie :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;18. Number of spots on a cubical dice&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;Trivia:&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;19. Number of shots fired in a salute of Royalty&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;History&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;20. Number of demands sent to the Chinese my the Japanes in 1915&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;and finally.&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;21. That's how old I become today :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Yep, Happy birthday to me!&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; Thanks to everyone who has made the day special so far.&lt;br /&gt;Cheers!&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-3609309667792124485?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/3609309667792124485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/06/xxi.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/3609309667792124485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/3609309667792124485'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/06/xxi.html' title='XXI'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-6819280726698327719</id><published>2010-05-26T03:27:00.000-07:00</published><updated>2010-05-26T03:50:31.147-07:00</updated><title type='text'>7 wishes for 21</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Its exactly 7 days to my 21st, and I am very excited. I am trying to make a wish list and I am finding it so hard (I'm just not used to making wishes :)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Anyway, here's my list - Just 7 items.&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;7. A smartphone: I'ld like a device that would keep me away from my laptop. I spend approximately 16hrs with *her* per day. &lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;6. A PhotoAlbum: Yes, I intend to keep one :-)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;5. A book - I can never omit this. Learning is what keeps me alive :) I'ld let you choose the kind of book :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;4. A transition ceremony: I personally consider 21 as the full transition to adulthood. I'ld like to celebrate this transition in a special way :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;3. A sincere opportunity to give back: All my life, I have experienced divine and human help in all my endeavors. I believe in paying-it-forward so I am looking for a *sincere* opportunity to give back in the little way I can.&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;2. A special gift in exactly 21days from now :)&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;1. A gift from the maker: Something special from the one who started me on this journey and has kept me for the past 2 decades.&lt;br /&gt;&lt;br /&gt;That's it :-)&lt;br /&gt;Cheers!&lt;br /&gt;Amplebrain.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-6819280726698327719?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/6819280726698327719/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/05/7-wishes-for-21.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6819280726698327719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6819280726698327719'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/05/7-wishes-for-21.html' title='7 wishes for 21'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1061993762697120982</id><published>2010-05-08T07:31:00.001-07:00</published><updated>2010-05-08T08:42:26.948-07:00</updated><title type='text'>GETVPN With Multicast Rekeying</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Hi All,&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: trebuchet ms;" href="http://tacack.com/2010/05/08/getvpn-rekey-issue/"&gt;A post&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; by fellow CCIE-Sec Candidate &lt;/span&gt;&lt;a style="font-family: trebuchet ms;" href="http://twitter.com/TacAck"&gt;TacAck&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; made me do some research/revision on GETVPN Rekey.  I would highlight my findings in this post.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. There are 2 modes: Unicast and Multicast.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. The Rekey address command references an access-list that is downloaded to the group members which makes them automatically join the group (for multicast Rekeying)&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. With Rekey Authentication, The crypto keys must be generated&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Rekey is triggered by changing the SA access-list. Rekeys are retransmitted for a number of times n after a period p. This can be adjusted with the &lt;/span&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;" &gt;"rekey retransmit p n"&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; command&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Here is a sample config for the KS:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp policy 10&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;encr 3des&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;hash md5&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;authentication pre-share&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;crypto isakmp key CISCO address 192.168.123.1&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;crypto isakmp key CISCO address 192.168.123.2&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;crypto ipsec transform-set TRANS esp-3des esp-md5-hmac&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;crypto ipsec profile GET&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;set transform-set TRANS&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;crypto gdoi group GET&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;identity number 123&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;server local&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; rekey address ipv4 REKEY&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; rekey retransmit 10 number 2&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; rekey authentication mypubkey rsa GET&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; sa ipsec 1&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;  profile GET&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;  match address ipv4 GET&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; replay counter window-size 64&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt; address ipv4 192.168.32.3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ip access-list ext REKEY&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  permit udp host 192.168.32.3 ho 239.0.0.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. If an ASA is placed in between the KS and the GMs; two things must be considered.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  1. Allowing GETVPN traffic especially if GMs are outside since the GM initiate the registration process. A hole should be punched to allow udp destination 848&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt; 2. Multicast traffic should be forwarded by the ASA. If the GMs are directly connected as in a STUB, then the "igmp forward" should be enough to forward the traffic.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Nuff said, time to take a break :)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Cheers, Amplebrain&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1061993762697120982?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1061993762697120982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/05/getvpn-with-multicast-rekeying.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1061993762697120982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1061993762697120982'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/05/getvpn-with-multicast-rekeying.html' title='GETVPN With Multicast Rekeying'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2635342285401514597</id><published>2010-04-28T01:32:00.000-07:00</published><updated>2010-04-28T02:09:34.975-07:00</updated><title type='text'>My Favorite RFC</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Hi,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I have had to review several RFCs in the course of preparing for the security CCIE. Common ones include RFC &lt;a href="http://www.faqs.org/rfcs/rfc1918.html"&gt;1918&lt;/a&gt;, &lt;a href="http://www.faqs.org/rfcs/rfc2827.html"&gt;2827&lt;/a&gt;, &lt;a href="http://www.faqs.org/rfcs/rfc3704.html"&gt;3704&lt;/a&gt; and &lt;a href="http://www.faqs.org/rfcs/rfc3330.html"&gt;3330&lt;/a&gt; which are on the test. Other Fun RFCs include &lt;a href="http://www.faqs.org/rfcs/rfc2835.html"&gt;2385,&lt;/a&gt; &lt;a href="http://www.faqs.org/rfcs/rfc3715.html"&gt;3715&lt;/a&gt;, &lt;a href="http://www.faqs.org/rfcs/rfc3945.html"&gt;3945&lt;/a&gt; and &lt;a href="http://www.faqs.org/rfcs/rfc3947.html"&gt;3947&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Today, I stumbled on what I would call my favorite RFC &lt;a href="http://www.faqs.org/rfcs/rfc1882.html"&gt;1882&lt;/a&gt;&lt;a href="http://www.faqs.org/rfcs/rfc1882.html"&gt; - 12 Days of technology before Christmas.&lt;/a&gt; This is a classic geeky joke. :D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;Cheers, Amplebrain&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2635342285401514597?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2635342285401514597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/04/my-favorite-httpwwwbloggercomimgblankgi.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2635342285401514597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2635342285401514597'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/04/my-favorite-httpwwwbloggercomimgblankgi.html' title='My Favorite RFC'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2451694517891551797</id><published>2010-04-24T08:35:00.001-07:00</published><updated>2010-04-24T08:45:20.679-07:00</updated><title type='text'>Ups and Downs</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;Hi All,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I have been extremely busy with work and studies. I hardly find time to prepare a technical post. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I salute everyone who had their CCIE while working on a full-time job (well, almost everyone did :-) &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Sometimes, I feel ready, sometimes, like today, I just don't know. I definitely still have some work to do. In any case, I strongly feel that I'ld be ready for the beast if I can maximize the remaining 7weeks.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Nuff said, Time to get back to studying? Where are my routes :-)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2451694517891551797?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2451694517891551797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/04/ups-and-downs.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2451694517891551797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2451694517891551797'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/04/ups-and-downs.html' title='Ups and Downs'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5189241436280087012</id><published>2010-04-05T12:05:00.000-07:00</published><updated>2010-04-05T12:21:54.588-07:00</updated><title type='text'>Hardcore Studying</title><content type='html'>&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;Hi All,&lt;br /&gt;Happy Easter Celebrations to everyone.&lt;br /&gt;I have been extremely busy these past few weeks and I hardly have anytime to create a detailed post. Merging work with studies hasn't been as easy as I thought :(&lt;br /&gt;&lt;br /&gt;I am trying to see if i can put in approx 40hrs a week till my security lab in June...That should average to about 320 - 350 hrs of study before the security lab day. Currently using INE materials with gradedlabs rackrental. The Equipments are a little old though. Ild like to try out the proctorlabs if I can fit it into the budget.&lt;br /&gt;&lt;br /&gt;I noticed that when connecting to the Workstations remotely either using VNC or Remote desktop;&lt;br /&gt;&lt;br /&gt;1. Do not change the Adapter settings for the external interface.&lt;br /&gt;2. Do not set another default gateway for the Lab interface as multiple default gateways confuse the Windows operating system.&lt;br /&gt;3. Watch out for split tunnels when using EZVPN... You can lose your connection if you don't specify the split tunnel as the TestPC would attempt to route all INTERNET traffic through the EZVPN Tunnel.&lt;br /&gt;&lt;br /&gt;Have fun studying...&lt;br /&gt;&lt;br /&gt;Amplebrain&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5189241436280087012?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5189241436280087012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/04/hardcore-studying.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5189241436280087012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5189241436280087012'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/04/hardcore-studying.html' title='Hardcore Studying'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2747655651453956017</id><published>2010-03-11T02:53:00.000-08:00</published><updated>2010-03-11T03:08:22.430-08:00</updated><title type='text'>Cisco's New ASA 8.3(x)</title><content type='html'>&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;The newly released ASA 8.3(x) software released by Cisco. Many new features have been added. Notable features include:&lt;br /&gt;1. The Support of browser based VPN on Win7 and 64 but Windows&lt;br /&gt;2. Overhaul of NAT config - static, global, NAT-config and alias commands have been retired.&lt;br /&gt;3. Use of real (not NAT) addresses in the access-list configuration.&lt;br /&gt;&lt;br /&gt;The new features can be found &lt;a href="http://www.cisco.com/en/US/docs/security/asa/asa83/release/notes/asarn83.html#wp229690"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I haven't tested the features yet so I dont have any personal opinion. I think I would have preferred that they left NAT the same way though :-).&lt;br /&gt;&lt;br /&gt;The good news is that these 'features' would not appear on the Security lab for at least another six (6) months.&lt;br /&gt;&lt;br /&gt;Have fun studying and working!&lt;br /&gt;&lt;br /&gt;Cheers Amplebrain&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2747655651453956017?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2747655651453956017/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/03/newly-released-asa-8.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2747655651453956017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2747655651453956017'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/03/newly-released-asa-8.html' title='Cisco&apos;s New ASA 8.3(x)'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5221881808000328683</id><published>2010-03-09T08:45:00.000-08:00</published><updated>2010-03-09T12:42:30.573-08:00</updated><title type='text'>A Year After...</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Today makes it exactly one year since I became a Routing and Switching CCIE. I can't believe Its 365 days already. I can remeber my LAB day like it was yesterday. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Bruno was the Proctor. I walked into the lab feeling confident with my level of preparation but when I logged into my routers, they were all fully configured. I checked with Bruno (nice proctor) and he confirmed that it was their error - they failed to re-initialize the rack so the previous candidates configs were still on the rack. I had to wait for some minutes again. I lost all the composure I had.&lt;br /&gt;By the time I was called in, I was a bag of nerves. I just stared at the screen and try to see if I could continue with my strategy. I just had to hope that there wasn't going to be any more mistakes that would cost me my lab. I wasn't ready to throw away 1750 dollars (I took the mobile lab).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The lab went well, OEQ were okay, The config section was good too. Finished on time, verified and identified some careless mistakes. Fixed them and verified again. I went home and waited till 1:30am and there was no mail from cisco. Fell asleep and woke at 4:30 am with an IM from &lt;a href="http://amplebrain.blogspot.com/2009/10/ccie-21-interview-with-ccie-agent.html"&gt;my friend&lt;/a&gt;. He had passed. I logged in and there was it. PASS. I was so excited. Now i could focus on finishing school - I was in my final year in the University.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;In the past year, a lot has changed. I have realized that a CCIE isn't by any means the pinnacle. It just gives you the opportunity to see farther. In the last year;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I graduated from the University,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I got a full time Job&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I started this blog&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I have learnt so much about so much.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I have been asked more questions than the previous 19years of my life before I became a CCIE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Looking back at the last year? Has it been worth it? YES...I wish I had a little  more experience though but I am making up for that. :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Do I intend to take another CCIE? Yes: But the conditions are certainly different now - I am working (less time to study).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;I hope that by the next 'anniversary', I'ld be a dual CCIE.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Right now, Its time to get back to studying.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Thanks for reading!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;P.S: Cisco officially announced CRS-3 on my 'Anniversary'&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Cheers...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5221881808000328683?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5221881808000328683/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/03/year-after.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5221881808000328683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5221881808000328683'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/03/year-after.html' title='A Year After...'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-6469689263555785451</id><published>2010-02-26T02:34:00.000-08:00</published><updated>2010-03-02T14:17:29.499-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><title type='text'>Advertise maps in BGP</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;A recent discussion on groupstudy pushed me into labbing BGP again.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;In BGP, Advertise maps are used for two functions;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. Conditional Advertisement&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. Route aggregation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;In conditional advertisement, Advertise maps are with an EXIST-MAP (or NON-EXIST map) to perform conditonal advertisement. Here the advertise-map specifies a route-map that matches the prefixes that would be advertised ONLY if the prefixes in the EXIST-MAP exist in the routing table.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The syntax is &lt;/span&gt;&lt;span class="content"&gt;&lt;span style="font-family:trebuchet ms;"&gt;"neighbor &lt;/span&gt;&lt;em style="font-weight: bold; font-family: trebuchet ms;" class="cArgument"&gt;ip-address&lt;/em&gt;&lt;span style="font-family:trebuchet ms;"&gt; advertise-map map-name {exist-map|non-exist} map-name"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The other use of advertise-maps is in specifying what attribute would be carried along in the as-set attributes of an aggregate during summarization.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;Assume we have R1, R2,R3 and R4 in AS 1, 2,3 and 4 respectively&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R1 -- R4 --- R3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;                       |&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;                    R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R1, R2, and R3 advertise 150.1.x.0/24 into bgp where x is the router number.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R4 aggregates the routes to 150.1..0.0/16 with as-set attribute.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; By default, none of the routers get the update anymore since their&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; individual routes are a part of the summary.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; Using advertise map, we want to make R1 and R3 get the summary; so we&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; only advertise the attributes of the prefix form R2 with the summary.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; Using as path access-lists and route-maps on R4 we have,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; ip as-path access-list 1 permit ^2$&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; route-map adv permit 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;  match as-path 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; router bgp 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; aggregate-address 150.1.0.0 255.255.0.0 as-set summary-only advertise-map adv&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; Now, R1 and R3 get the summary, R2 doesn't because its AS number is&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt; carried along with the summary&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R1(config-router)#do sh ip bg | i 150.1.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; *&gt; 150.1.0.0        192.168.1.4              0             0 4 2 i&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R2(config-router)#do sh ip bg | i 150.1.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; R2(config-router)#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Ok. That's it for now. Back to security :-) I was trying to look into NAC with the CTA and CSA. Fun stuff :D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Cheers,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-6469689263555785451?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/6469689263555785451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/02/advertise-maps-in-bgp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6469689263555785451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6469689263555785451'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/02/advertise-maps-in-bgp.html' title='Advertise maps in BGP'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5293320047513792943</id><published>2010-02-05T05:10:00.000-08:00</published><updated>2010-03-02T14:17:51.044-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='General'/><title type='text'>Death of Dynamips...or NOT?</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;Hi All,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Cisco has introduces software licensing with the IOS 15.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;My first reaction was to mourn the exiit of my faithful friend...DYNAMIPS.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: trebuchet ms;"&gt;But on a closer look, the IOS licensing DOES NOT directly affect dynamips.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;"Cisco Software Activation is a simplified approach to software deployment and management, and is implemented on Cisco Catalyst 3750-E and 3560-E Switches and Cisco Integrated Services Routers Generation 2"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: trebuchet ms;" href="http://www.cisco.biz/en/US/products/ps9677/products_ios_technology_home.html"&gt;http://www.cisco.biz/en/US/products/ps9677/products_ios_technology_home.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Dynamips CANNOT emulate the devices with licenses yet.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The Licensing hasn't been implemented on the 7200s yet so we can still run the 15.0 on the 7200 routers.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Thanks to Ivan of "Cisco IOS Hints and Tricks" for pointing this out.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: trebuchet ms;" href="http://blog.ioshints.info/2010/02/death-of-dynamips-theyve-got-it-all.html#more"&gt;http://blog.ioshints.info/2010/02/death-of-dynamips-theyve-got-it-all.html#more&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;I guess we can still have fun studying afterall :-)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5293320047513792943?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5293320047513792943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/02/death-of-dynamipsor-not.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5293320047513792943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5293320047513792943'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/02/death-of-dynamipsor-not.html' title='Death of Dynamips...or NOT?'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-7131580671611040756</id><published>2010-02-02T08:03:00.000-08:00</published><updated>2010-02-02T08:24:02.439-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>Creating a Loopback Adapter on Windows 7</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family: trebuchet ms;"&gt;The Microsoft Loopback Adapter is a very useful tool for setting up networks with dynamips/gns3 when you need to connect the emulated network to the life system.&lt;br /&gt;Instances include; setting up a terminal Server, connecting to a AAA server, using a VPN Client etc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;With Windows XP/Vista, creating a Loopback Adapter is Pretty Easy;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;1. Go to control Panel&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. Click Add Hardware&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;3. Select Install Hardware from list,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;4. Select Network Adapters&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;5. Select Microsoft as the Manufacturer&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;6. Select Microsoft loopback Adapter&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;7. Click Next and Install...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;With Windows 7, there is a slight problem; "Add Hardware" is no longer in the Control Panel.&lt;br /&gt;It is now a hidden feature that has to be run by an adminstrator from command prompt.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To get to the Add Hardware program;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;1. Run command prompt as Administrator.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. From command prompt, Run "hdwwiz.exe"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;To install the Loopback Adapter, Follow steps 3 through 7 above.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Have fun studying.&lt;br /&gt;Cheers!&lt;br /&gt;Amplebrain.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-7131580671611040756?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/7131580671611040756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/02/creating-loopback-adapter-on-windows-7.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7131580671611040756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7131580671611040756'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/02/creating-loopback-adapter-on-windows-7.html' title='Creating a Loopback Adapter on Windows 7'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-6396064844196742385</id><published>2010-01-30T05:19:00.000-08:00</published><updated>2010-02-02T08:17:44.126-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='INFO'/><title type='text'>Cisco Mobile Lab in Nigeria</title><content type='html'>&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;The CCIE Mobile Lab would be in Nigeria between June 14 and 18. There are 6 R&amp;amp;S slots and a security slot per day.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;I hope I would be ready for my security lab by then :-)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;More info can be found &lt;/span&gt;&lt;a style="font-family: trebuchet ms;" href="https://learningnetwork.cisco.com/docs/DOC-3224"&gt;here&lt;/a&gt;&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;It's time to quit playing around and get into hardcore studying. This is barely 4 months away.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Wish you all the best with your studies. CCIE Security - here I come!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-family:trebuchet ms;" &gt;Amplebrain&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-6396064844196742385?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/6396064844196742385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/01/cisco-mobile-lab-in-nigeria.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6396064844196742385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/6396064844196742385'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/01/cisco-mobile-lab-in-nigeria.html' title='Cisco Mobile Lab in Nigeria'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-7609717462593758928</id><published>2010-01-25T14:41:00.000-08:00</published><updated>2010-02-02T08:17:44.126-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='INFO'/><title type='text'>Cisco Updates CCNP and introduces new Service Operations Track</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:trebuchet ms;"&gt;Hi All,&lt;/span&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Today, Cisco announced a big change in the Certifications path.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The CCNP has been entirely revised. There are now 3 exams;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Route - Replaces the BSCI&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Switch - Replaces BCMSN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;TShoot - Brings back troubleshooting into the game.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;All exams would be 120mins long and cost $200&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;While the BSCI and BCMSN exams are stil a valid for 3 years, the ISCW and ONT are only valid (count towards the completion of your CCNP) till end of July.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The Tshoot exam would a hands-on exam - barely 10% theory.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The exam focuses more on Routing and Switching and is a lot deeper. IPV6 also has its fair share on the exam.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Finally, My favorite Authors get to write the Cisco Press Cert guide: Wendell Odom, David Hucaby and Kevin Wallace&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The SP Operations track focuses on IP Carrier Ethernet NGN Networks. The SP Operations is a full track with Associate, Professional and Expert level Exams. Yes, anothe CCIE. Oh Damn Cisco! More info on the Cisco Learning Network.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Right now, It's tiime to focus on getting the CCIE Security before I am old enough to rent a car.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Study hard, Learn stuff and most importantly, have fun!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Cheers,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-7609717462593758928?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/7609717462593758928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/01/cisco-updates-ccnp-and-introduces-new.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7609717462593758928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7609717462593758928'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/01/cisco-updates-ccnp-and-introduces-new.html' title='Cisco Updates CCNP and introduces new Service Operations Track'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1614470272979404685</id><published>2010-01-11T08:03:00.000-08:00</published><updated>2010-01-11T08:16:25.935-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='ASA'/><title type='text'>ASA Transparent mode NAT</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;The ASA transparent mode acts as a bump in the wire (Placed in the layer 2 path of the traffic). There is no interface IP addressing with transparent mode. The ASA can be assigned an IP address for remote management and testing. In the transparent mode, there are still access rules and inspection rules. There are a few exceptions though. For instance, ARP and BPDU is allowed from lower security level interfaces by default. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;With the ASA 7.x code and lower, the ASA did not support address translation in transparent mode. In fact, the 'nat' and 'global' commands were disabled. The static command was available but the real and translated addresses must be the same. IMO, the command was enabled so that the static options can be used. An example would be the 'norandomseq' keyword that is used in BGP authentication.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;With the ASA code 8.x code, there is now support for NAT in transparent mode. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The NAT implementation has a few caveats:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. The alias command is NOT supported.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. Since there is no interface address, interface PAT is not allowed.&lt;/span&gt;&lt;br /&gt;3. Arp Inspection is not allowed&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Since the inside and outside interfaces are on the same 'subnet', if any of the addresses (real or translated) is NOT on the subnet, then static routes have to be used to point to the address so that routing can take place. This is from the configuration guide:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;"When the mapped addresses are not on the same network as the transparent firewall, then on the upstream router, you need to add a static route for the mapped addresses that points to the downstream router (through the security appliance) &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;If the real destination address is not directly-connected to the security appliance, then you also need to add a static route on the security appliance for the real destination address that points to the downstream router. Without NAT, traffic from the upstream router to the downstream router does not need any routes on the security appliance because it uses the MAC address table. NAT, however, causes the security appliance to use a route lookup instead of a MAC address lookup, so it needs a static route to the downstream router."&lt;br /&gt;&lt;br /&gt;With the Routing fixed, NAT with the ASA transparent mode should not be too different from the regular routed mode NAT.&lt;br /&gt;&lt;br /&gt;Further Reading:&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/cfgnat.html#wp1102744"&gt;ASA Configuration Guide: NAT in Transparent mode&lt;/a&gt;&lt;br /&gt;Amplebrain&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1614470272979404685?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1614470272979404685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2010/01/asa-transparent-mode-nat.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1614470272979404685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1614470272979404685'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2010/01/asa-transparent-mode-nat.html' title='ASA Transparent mode NAT'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2409354860928784589</id><published>2009-12-31T13:21:00.000-08:00</published><updated>2010-01-01T06:43:38.650-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='General'/><title type='text'>Goodbye '09</title><content type='html'>&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;Hi Everyone,&lt;br /&gt;&lt;br /&gt;As the year winds up, I figured I'ld steal a quick post  - the very last one for 2009.&lt;br /&gt;&lt;br /&gt;2009 was a quite a phenomenal one - You'ld probably be in 2010 by the time you are reading this ;)&lt;br /&gt;&lt;br /&gt;Highlights of the year include; GEM (Global Economic Meltdown), Graduation from the University, Passing the CCIE R&amp;amp;S lab, Serving my country, Starting this blog and a whole lot of other events.&lt;br /&gt;&lt;br /&gt;Looking back at the year, there is a lot to be happy about and I am immensely grateful to God and everyone that made the year a special one. Thank you to family, friends, peers, colleagues and everyone.&lt;br /&gt;&lt;br /&gt;Wish you all a great new year. Its about 90mins away from here. Let the fireworks begin :-)&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Amplebrain.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2409354860928784589?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2409354860928784589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/12/goodbye-09.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2409354860928784589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2409354860928784589'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/12/goodbye-09.html' title='Goodbye &apos;09'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2101452669664115436</id><published>2009-12-31T06:20:00.000-08:00</published><updated>2010-01-01T06:43:13.434-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAA'/><category scheme='http://www.blogger.com/atom/ns#' term='ASA'/><title type='text'>ASA Cut-Through Proxy Part 2: Radius Authorization</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;AAA Authorization and Authentication are two separate processes. Authorization must be performed after Authentication has taken place. That makes sense because we have to know who the user is before we can know what he can do right?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;While User Authentication and Authorization are separate processes, they are implemented together in the RADIUS server. The User is Authenticated and downloadable access-lists are used to perform Authorization for the user.&lt;br /&gt;From a configuration perspective, no further authorization command is needed on the ASA as the authentication and authorization is performed at once on the RADIUS server.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;From the radius server perspective, there are two ways to accomplish authoriztaion.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;1. The radius server can reference an ACL configured on the ASA which is now 'activated' after the user has authenticated. In this case, the access-list name is specified under the radius attribute 11 (filter-id). The access-list can also be specified under the cisco AV pair (009,001) attribute.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. The Access-list entries can be defined on the ACS server and downloaded unto the ASA after the user has authenticated.&lt;br /&gt;Downloadable access-lists can be created on the server using the Advanced downloadable access-list features, (This must be activated from the Interface configuration tab). Check the box for "group-level downloadable access-lists"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The other option is to specify the access-list entries in the cisco-av-pair using the "inbound access-list" syntax.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ip:inacl#[acl-line-number]=[acl permit/deny statement] for example:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;ip:inacll#1=permit ip any any&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Note that there must be an authentication protocol for authorization to work, if none of the authentication protocols (telnet, http(s) or ftp) is configured, then the virtual telnet/http command should be used.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Consider the following same topology as the &lt;a href="http://amplebrain.blogspot.com/2009/12/asa-cut-through-proxy-part-1.html"&gt;previous post&lt;/a&gt;;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;R1 --- (inside)ASA(outside) -- R2 where the Radius server is on the inside interface.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The user would be authorized to telnet from the outsude interface to R1 on port 3070.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;1. Configure the authentication AAA server on the ASA.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;aaa-server ACS protocol radius&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;aaa-server ACS (inside) host 10.10.10.5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; key bauxite&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. Configure the Authentication access-list&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;access-list AUTH extended permit tcp any host 2.2.2.2 eq telnet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;virtual telnet 2.2.2.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;3. Since it is on the outside the access-list must be configured to allow the authentication traffic:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;access-list OUTSIDE_IN permit tcp any host 2.2.2.2 eq telnet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;access-group OUTSIDE_IN in interface outside&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;4. Configure AAA for authentication&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;aaa authentication match AUTH inside ACS&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;5. Configure the AAA server: To keep things simple, we would define the access-list test_auth on the ASA and then refer to it through the filter-id attribute of the RADIUS server:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;access-list test_auth extended permit tcp any any eq 3070&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;access-list test_auth extended permit tcp any host 2.2.2.2 eq telnet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;The 2nd line of the acl is added so that the telnet session for authentication does not die after the authorization has taken place on the ASA. If the telnet session is not allowed by the authorization acl, though authorization would still take place, the telnet session would die immediately after the user is authorized and an error would be returned (though the process was successful), we would rather add the line for sanity sake. :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;On the Radius server:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/Szyz42coy2I/AAAAAAAAADE/rbrZzuE3ryw/s1600-h/radius.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 353px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/Szyz42coy2I/AAAAAAAAADE/rbrZzuE3ryw/s400/radius.jpg" alt="" id="BLOGGER_PHOTO_ID_5421405840716909410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;6. Enable Per-user override on the inbound access list on the outside interface;&lt;br /&gt;&lt;br /&gt; This makes the downloaded access-list take precedence over the existing interface access-list&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;access-group OUTSIDE_IN in interface outside per-user-override&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;7. Verification&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enable telnet on port 3070 on R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;line con 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;rotary 70&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;password cisco&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Before Authorization:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#telnet 10.10.10.3 3070&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 10.10.10.3, 3070 ...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;% Connection timed out; remote host not responding&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#telnet 2.2.2.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 2.2.2.2 ... Open&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;LOGIN Authentication&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Username: Amplebrain&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Password:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Authentication Successful&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;[Connection to 2.2.2.2 closed by foreign host]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#telnet 10.10.10.3 3070&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 10.10.10.3, 3070 ... Open&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;User Access Verification&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Password:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;R1&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Show User Authentication on the ASA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;ASA#sh uauth&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;&lt;br /&gt;                        Current    Most Seen&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;&lt;br /&gt;Authenticated Users       1          1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;Authen In Progress        0          1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;user 'Amplebrain' at 192.168.1.2, authenticated&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;   access-list test_auth (*)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;   absolute   timeout: 0:05:00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;   inactivity timeout: 0:00:00&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;br /&gt;As I mentioned earlier, Authorization can also be accomplished using the tacacs+ protocol but this is implented entirely differently. I hope to put up a post on this sometime in the future.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Anyway, this is the last technical post for the year 2009!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Wishing everyone a prosperous 2010...Cheers!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Amplebrain&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2101452669664115436?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2101452669664115436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/12/asa-cut-through-proxy-part-2-radius.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2101452669664115436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2101452669664115436'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/12/asa-cut-through-proxy-part-2-radius.html' title='ASA Cut-Through Proxy Part 2: Radius Authorization'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_V3Tfi7omYZI/Szyz42coy2I/AAAAAAAAADE/rbrZzuE3ryw/s72-c/radius.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-7588988752741637620</id><published>2009-12-29T03:23:00.000-08:00</published><updated>2009-12-31T03:51:10.402-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAA'/><category scheme='http://www.blogger.com/atom/ns#' term='ASA'/><title type='text'>ASA Cut-Through Proxy: Part 1</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;In the &lt;a href="http://amplebrain.blogspot.com/2009/12/ios-authentication-proxy.html"&gt;previous post&lt;/a&gt;, I discussed the IOS Authentication Proxy and hw it is used for 'authorization' using downloadable access-lists. In this post, I would describe the Cut-through proxy feature of the ASA.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The Proxy Authentication feature of the ASA is tied to the AAA process.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Authentication proxy can be configured for any protocol but authentication is performed by the telnet, http, https and FTP protocols. If any other protocol is requires authentication, one of the other "authentication protocols" (ftp, http(s) or telnet) MUST also be configured to authenticate the user before access can be granted.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Once a protocol is configured for authentication under the AAA process, unauthenticated users are not given access to the protocol. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The Authentication and Authorization processes are separate on the ASA&lt;/span&gt;.&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Users can be authenticated using the local database, tacas+ server and the RADIUS server. Users can only be authorized with Radius or Tacacs+ but not the local user database.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Unlike Auth-Proxy, the traffic required for authentication MUST be allowed in the access-lists otherwise Authentication/Authorization wouldnt be able to take place. Authorization can be used to allow further traffic.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Lets look at a simple example of proxy-authentication using the local database. Assuming we have the topology:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;R1 ---- (inside)ASA(outside) ---- R2&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Base configuration:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface Ethernet0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; nameif inside&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; security-level 100&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; ip address 10.10.10.1 255.255.255.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;interface Ethernet1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; nameif outside&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; security-level 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; ip address 192.168.1.1 255.255.255.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. Specify traffic to be Authenticated using an access-list&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;access-list AUTH extended permit icmp any any&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;fixup protocol icmp&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The fixup protocol is used to ensure icmp traffic is inspected. (It is a quick fix compared to using the MPF). Another option would be to allow icmp inbound on the outside interface.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. Configure AAA server: We would just add a user since we are using the local database.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;username Amplebrain password cisco&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;3. Configure AAA on the ASA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;aaa authentication match AUTH inside LOCAL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;auth-prompt prompt Authenticate Before Access&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;auth-prompt accept Access Granted&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;auth-prompt reject Access Denied&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The line "aaa authentication match AUTH inside LOCAL" means that traffic matched by the AUTH access-list on the inside interface must be authenticated using the local database before they can be allowed to pass through.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Test&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#ping 192.168.1.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;We cant reach R2. This is because we are authenticating icmp protocol but icmp is NOT one of the authentication protocols. At least one authentication protocol configured for authentication for this to work.&lt;br /&gt;The ASA uses the virtual &lt;protocol&gt; command for this. &lt;/protocol&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;5. Configure Virtual Telnet address and add 2.2.2.2 to the AUTH traffic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;virtual telnet 2.2.2.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;access-list AUTH extended permit tcp any host 2.2.2.2 eq telnet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The authenticating user must have a route to 2.2.2.2 for this to work properly.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;6. Test Again: Authenticate with virtual telnet and then ping.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#telnet 2.2.2.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Trying 2.2.2.2 ... Open&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LOGIN Authentication&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Authenticate Before Access&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Username: Amplebrain&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Password:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Access Granted&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Authentication Successful&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;[Connection to 2.2.2.2 closed by foreign host]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#ping 192.168.1.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max =&lt;br /&gt;24/88/196 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;On the ASA, we can show authenticated users&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ASA(config)# sh uauth&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                        Current    Most Seen&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Authenticated Users       1          1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Authen In Progress        0          1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;user 'Amplebrain' at 10.10.10.3, authenticated&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   absolute   timeout: 0:05:00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   inactivity timeout: 0:00:00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ASA(config)#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The next post would describe proxy-authorization using the Radius Server.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Compliments of the season :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-7588988752741637620?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/7588988752741637620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/12/asa-cut-through-proxy-part-1.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7588988752741637620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7588988752741637620'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/12/asa-cut-through-proxy-part-1.html' title='ASA Cut-Through Proxy: Part 1'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-7777760886202945477</id><published>2009-12-28T10:33:00.001-08:00</published><updated>2009-12-31T03:48:51.021-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AAA'/><title type='text'>IOS Authentication Proxy</title><content type='html'>&lt;div style="text-align: justify;"&gt;Authentication Proxy is a very useful cisco IOS Firewall Feature.&lt;br /&gt;IMO, It is a more 'advanced' form of dynamic access-list.&lt;br /&gt;Back with Dynamic access-lists, users were required to authenticate using Telnet and then the dynamic entry in the access-list is activated using the "access-enable" command. This can be automated using the autocommand feature either with the username command or under the line configuration.&lt;br /&gt;&lt;br /&gt;Drawbacks of Dynamic access-list include;&lt;br /&gt;1. It requires that the user first telnets into the router.&lt;br /&gt;2. You can only have one dynamic entry line in an access list. The work around was normally to give access to a bastion host that is now used to access further resources (or to use)&lt;br /&gt;3. You cannot have user specific (or group specific) profiles.&lt;br /&gt;&lt;br /&gt;Documentation for dynamic access-list can be found &lt;a href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scflock.html"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The IOS Auth-proxy feature was designed to fix these issues. It uses the ACS Server for Authentication and Authorization. Either the radius or tacacs+ server can be used for auth-proxy.&lt;br /&gt;&lt;br /&gt;The IOS auth-proxy service uses user/group specific downloadable acls that is downloaded from the ACS server unto the router. This access-lists are specified on the AAA and attached to the auth-proxy service. This is implemented a little differently on the radius and the tacacs+ server.&lt;br /&gt;&lt;br /&gt;On the Tacacs+ server, the auth-proxy service is first added, from the Interface Configuration Section, then access-list is specified under the user/group settings. The privilege level must be set to 15 for the access-list to be downloaded correctly. An example of the custom attributes of the auth-proxy service that would be defined in group settings would be:&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;priv-lvl=15&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;proxyacl#1=permit ip any any&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;With the Radius server, the downloadable access-list is set as the cisco-av-pair (9,1) as we would see in the example below.&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Assuming we have the topology below;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/SzkRKnGpvsI/AAAAAAAAACk/aXI09Flx9Gk/s1600-h/topology.jpeg.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 239px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/SzkRKnGpvsI/AAAAAAAAACk/aXI09Flx9Gk/s400/topology.jpeg.jpeg" alt="" id="BLOGGER_PHOTO_ID_5420382500510351042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;We want to implement AP for users in the inside network. We would use telnet and http as our protocols for authentication.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;Default configuration: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/0&lt;br /&gt;ip address 10.10.10.1 255.255.255.0&lt;br /&gt;ip access-group 101 in&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt;ip address 192.168.1.1 255.255.255.0&lt;br /&gt;access-list 101 permit ip host 10.10.10.5 host 10.10.10.1&lt;br /&gt;access-list 101 deny   ip any any&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Note that the address of the ACS server is allowed to communicate with the router so that authentication can take place&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;There are 5 steps in this configuration:&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;1. Configure AAA on the router&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FW#sh run | i aaa&lt;br /&gt;aaa new-model&lt;br /&gt;aaa authentication login default group radius&lt;br /&gt;aaa authentication login cons none&lt;br /&gt;aaa authorization auth-proxy default group radius&lt;br /&gt;radius-server host 10.10.10.5 auth-port 1645 acct-port 1646 key bauxite&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The 'cons' method is defined so as to exclude the console line from AAA authentication.&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;2. Configure AAA on the server. The radius configuration snapshot is shown below&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/SzkSWaSJk9I/AAAAAAAAACs/AunOILPImqo/s1600-h/authproxy3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/SzkSWaSJk9I/AAAAAAAAACs/AunOILPImqo/s400/authproxy3.jpg" alt="" id="BLOGGER_PHOTO_ID_5420383802738971602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. Configure auth-proxy on the router.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip auth-proxy auth-proxy-banner http #Authenticate before Access....#&lt;br /&gt;ip auth-proxy auth-proxy-banner telnet #Please Authenticate#&lt;br /&gt;ip auth-proxy name test http inactivity-time 60&lt;br /&gt;ip auth-proxy name test telnet inactivity-time 60&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Configure http-server for http&lt;/span&gt; authentication process&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip http server&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;ip http authentication aaa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;5. Apply Auth-proxy on the interface.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;int f0/0&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;ip auth-proxy test&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Verification:&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;From the Inside Router:&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;INSIDE#telnet 192.168.1.2&lt;br /&gt;Trying 192.168.1.2 ... Open&lt;br /&gt;&lt;br /&gt;Please Authenticate&lt;br /&gt;Username:Amplebrain&lt;br /&gt;Password:&lt;br /&gt;Firewall authentication Success.&lt;br /&gt;Connection will be closed if remote server does not respond&lt;br /&gt;Connecting to remote server...&lt;br /&gt;&lt;br /&gt;User Access Verification&lt;br /&gt;&lt;br /&gt;Password:&lt;br /&gt;OUTSIDE&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;For http: Here are snapsots from the From the inside host:&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_V3Tfi7omYZI/SzkTfr0_3EI/AAAAAAAAAC0/04vgTeY9n4I/s1600-h/authproxy1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 208px;" src="http://1.bp.blogspot.com/_V3Tfi7omYZI/SzkTfr0_3EI/AAAAAAAAAC0/04vgTeY9n4I/s400/authproxy1.jpg" alt="" id="BLOGGER_PHOTO_ID_5420385061578988610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;After Authentication:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_V3Tfi7omYZI/SzkV0TlTg2I/AAAAAAAAAC8/n4wjfwCZs28/s1600-h/authproxy2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 236px;" src="http://4.bp.blogspot.com/_V3Tfi7omYZI/SzkV0TlTg2I/AAAAAAAAAC8/n4wjfwCZs28/s400/authproxy2.jpg" alt="" id="BLOGGER_PHOTO_ID_5420387614871225186" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-7777760886202945477?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/7777760886202945477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/12/ios-authentication-proxy.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7777760886202945477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7777760886202945477'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/12/ios-authentication-proxy.html' title='IOS Authentication Proxy'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_V3Tfi7omYZI/SzkRKnGpvsI/AAAAAAAAACk/aXI09Flx9Gk/s72-c/topology.jpeg.jpeg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-4825484813361092554</id><published>2009-12-25T12:50:00.000-08:00</published><updated>2009-12-31T03:48:16.272-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='General'/><title type='text'>Merry Christmas!</title><content type='html'>&lt;span style="font-family: trebuchet ms;"&gt;Hi Everyone,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Merry Christmas.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Hope you all have fun and stay away from 'geeky' stuff :-)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;&lt;a href="http://www.youtube.com/watch?v=LESpmgXCz4Y"&gt;Here's&lt;/a&gt; what I'ld call a totally "cisco-geeky" xmas.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Thanks to Joe Astorino on GS for the link.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;As the year comes to an end, it's time to take stock and make resolutions for 2010.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Feliz Navidad guys!&lt;br /&gt;&lt;br /&gt;Amplebrain &lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-4825484813361092554?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/4825484813361092554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/12/merry-christmas.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/4825484813361092554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/4825484813361092554'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/12/merry-christmas.html' title='Merry Christmas!'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1877949672655558453</id><published>2009-10-22T03:06:00.000-07:00</published><updated>2010-01-11T08:14:21.703-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Routing'/><category scheme='http://www.blogger.com/atom/ns#' term='ASA'/><category scheme='http://www.blogger.com/atom/ns#' term='Troubleshooting'/><title type='text'>Configuring BGP through the PIX/ASA.</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;When configuring BGP through the ASA, a basic understanding of how the ASA works and how BGP is implemented is very important. I would highlight some of my findings about the BGP/ASA relationship in this post.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;1. The ASA (when in routed mode) is a HOP: This doesnt matter if we are configuring ibgp since BGP believes that the underlying IGP would take care of reachability to the neighbor but with ebgp, we need to explicitly state that the bgp neighbor is not on the same subnet. The ebgp multihop command is used to achieve this. Lets assume the following topology;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;R2(f0/0) --- (ins) ASA (out) --- (f0/0) R3.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;on R2 (and similarly on R3), we need to configure:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router bgp 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; neighbor 192.168.13.3 remote-as 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; neighbor 192.168.13.3 ebgp-multihop 2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;When configuring ebgp multihop, we should also ensure that there is a route to the neighbor with a length greater than 0 (default route will not work) in the routing table..&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Assuming we have on R2,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip route 0.0.0.0 0.0.0.0 192.168.12.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;When we try to negotiate the BGP connection, it would fail (except R3 configured properly -  which would always make R3 active). When we look at the debugs, we would see;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;BGP: 192.168.13.3 active open failed - no route to peer, open active delayed 29090ms (35000ms max, 28% jitter)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;But when we take a look at the routing table, sure enough, our default route is there...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:trebuchet ms;" &gt;R2(config-router)#do sh ip rou&lt;br /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;br /&gt;    D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;br /&gt;    N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;br /&gt;    E1 - OSPF external type 1, E2 - OSPF external type 2&lt;br /&gt;    i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;br /&gt;    ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;br /&gt;    o - ODR, P - periodic downloaded static route&lt;br /&gt;&lt;br /&gt;Gateway of last resort is 192.168.12.1 to network 0.0.0.0&lt;br /&gt;&lt;br /&gt;C    192.168.12.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;S*   0.0.0.0/0 [1/0] via 192.168.12.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;This is because the router actually searches for a route going to 192.168.13.3 and finds none.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#do sh ip rou 192.168.13.3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Network not in table&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;To fix this, we insert a route with a longer match in the routing table (doesnt have to be a host route, anything from a /1 would do)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#ip route 192.168.0.0 255.255.0.0 192.168.12.1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;That should fix things considerably and the BGP neighbor should come up.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;2. The ASA does NAT: If the ASA NATs the address of the BGP peer, the neighbor statement should reflect this. Assuming we had a static statement on the ASA,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;static (i,o)  192.168.13.2 192.168.12.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Then on R3, we would peer with 192.168.13.2 instead of 192.168.12.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;neigh 192.168.13.2 remote 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;This would work well if Authentication is NOT configured.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. Configuring BGP Authentication: BGP Authentication uses &lt;a href="http://www.iana.org/assignments/tcp-parameters/"&gt;special tcp option&lt;/a&gt; for MD5 (option 19) to carry the Authentication information. This is stated in rfc 2385. The 16-byte MAC is computed based on a one-way hash function (MD5) generated from TCP header, the IP header, the password and a key. The following must be considered when configuring BGP authentication through the ASA:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;a. Since the IP header is used in generating the hash, NAT cannot be used to change the ip address of the peers as this would break the authentication. If nat-control is enabled, the real and translated ip address must be the same.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;b. Since the tcp header is used, the sequence number must not be randomized (default behavior of the ASA.) To stop randomization we can append the norandomseq option behind a static address mapping (that does not change the IP address) of the neighbor. This would only work in routed mode (of course)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;static (inside,outside) 192.168.12.2 192.168.12.2 no randomseq&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;We can also disable random sequencing in the global_policy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;c. Finally, option 19 must be allowed to pass through the ASA for BGP traffic. This can be achieved by allowing it in the global_policy. The configuration on the ASA is shown below.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tcp-map BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  tcp-options range 19 19 allow&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;class-map BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; match port tcp eq bgp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;policy-map global_policy&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; class BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  set connection random-sequence-number disable&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  set connection advanced-options BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;That would be all for now.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Further Reading&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/tech/tk365/technologies_configuration_example09186a008009487d.shtml"&gt;&lt;span style="font-family:trebuchet ms;"&gt;BGP through ASA configuration exmaple&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.rfc-editor.org/rfc/rfc2385.txt"&gt;&lt;span style="font-family:trebuchet ms;"&gt;RFC 2385: Protection of BGP Sessions via the TCP MD5 Signature Option&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1877949672655558453?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1877949672655558453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/10/configuring-bgp-through-pixasa.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1877949672655558453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1877949672655558453'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/10/configuring-bgp-through-pixasa.html' title='Configuring BGP through the PIX/ASA.'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-9121985468409629494</id><published>2009-10-17T14:33:00.000-07:00</published><updated>2009-10-22T04:45:48.840-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='General'/><title type='text'>21 yr old CCIE : Interview with CCIE Agent</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;I was going thru &lt;a href="http://www.ccieflyer.com/"&gt;CCIE flyer&lt;/a&gt; October Edition when I stumbled on Peter Ehiwe's interview. Peter is my friend, classmate and study partner. Details of the interview can be found &lt;/span&gt;&lt;a style="font-family: trebuchet ms;" href="http://www.ccieflyer.com/2009-Oct-Peter-Ehiwe.php"&gt;here&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Quote of the day: "Peter you are so young just 21 years old.  I have shoes older than you!" - Eman Conde (CCIE Agent) :D&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Way to go bro!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-9121985468409629494?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/9121985468409629494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/10/ccie-21-interview-with-ccie-agent.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/9121985468409629494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/9121985468409629494'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/10/ccie-21-interview-with-ccie-agent.html' title='21 yr old CCIE : Interview with CCIE Agent'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1612130985239398158</id><published>2009-10-07T13:58:00.000-07:00</published><updated>2009-10-22T04:10:32.205-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Troubleshooting'/><title type='text'>Shooting yourself in the leg</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;When doing personal study/'research', whether for the CCIE lab or some other exam, we get used to some practices that save time and aid troubleshooting. Many students have a template of initial config on their routers. Here is an example of what I would have on mine.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;alias exec s sh ip interface brief&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;no ip domain-lookup&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;line con 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;logging synchronous&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;no exec-timeout&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;and a few other commands.&lt;br /&gt;&lt;br /&gt;It is also common to turn on debugs when trying to troubleshoot a problem or understand a protocol.&lt;br /&gt;&lt;br /&gt;While these practice definitely saves time, it should ONLY be used in a lab environment and the routers should be adequately CLEANED up before being put into production.&lt;br /&gt;&lt;br /&gt;Recently. I got a call from a friend, he just put in a box that he used to study sometime ago into production and his router stopped resolving hostnames to ip addresses. The DNS server was properly configured and he had pointed to it using the &lt;span style="font-weight: bold;font-family:courier new;" &gt;ip name server&lt;/span&gt; command.&lt;br /&gt;&lt;br /&gt;While reading through this post, the answer is obvious, but in a production environment with many issues and phone calls, it is a lot more difficult to decipher and you would probably need another pair of eyes going through your config.&lt;br /&gt;&lt;br /&gt;We figured out that he had the &lt;span style="font-weight: bold;font-family:courier new;" &gt;no ip domain-lookup&lt;/span&gt; configured from one of his practice sessions and forgot to take out the command during clean-up. The issue was resolved and everything was fine.&lt;br /&gt;&lt;br /&gt;Moral of the story: Cisco would arm you with a Gun and they wouldn't stop you from shooting yourself with a gun. Lab environment and production environments are totally different.&lt;br /&gt;&lt;br /&gt;Turning on debugs in a produvtion environment could be a lot worse, It is important for a network engineer to be able to handle logs appropriatelyy but that's going to be a post for another day.&lt;br /&gt;&lt;br /&gt;Have fun with your job and with your studies.&lt;br /&gt;&lt;br /&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1612130985239398158?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1612130985239398158/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/10/shooting-yourself-in-leg.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1612130985239398158'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1612130985239398158'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/10/shooting-yourself-in-leg.html' title='Shooting yourself in the leg'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1722095524968891250</id><published>2009-10-04T12:00:00.000-07:00</published><updated>2009-10-22T04:50:50.636-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='INFO'/><title type='text'>Is Cisco Superstitous?</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;a href="http://www.cisco.com/"&gt;Cisco systems&lt;/a&gt; has released the IOS 15.0M - Mainstream version.&lt;br /&gt;The sudden jump from the IOS 12.4T series to the 15.0 is remarkable. Why did they chose to skip 13.x and 14.x - could the software development team be &lt;a href="http://en.wikipedia.org/wiki/Tetraphobia"&gt;Tetraphobic&lt;/a&gt; or &lt;a href="http://en.wikipedia.org/wiki/Triskaidekaphobia"&gt;Triskaidekaphobic&lt;/a&gt;?&lt;br /&gt;I doubt that the are tetraphobic though - Since we had 12.4T :-)&lt;br /&gt;&lt;br /&gt;What's new? New Features in the 15.0 IOS release can be found &lt;a href="http://www.cisco.com/en/US/docs/ios/15_0/15_0_1_m/15_0_1_m_newfeatlist.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;More cool features. More fun stuff..&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;Amplebrain :-)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1722095524968891250?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1722095524968891250/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/10/is-cisco-superstitous.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1722095524968891250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1722095524968891250'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/10/is-cisco-superstitous.html' title='Is Cisco Superstitous?'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5183739315798269914</id><published>2009-09-08T07:54:00.000-07:00</published><updated>2009-10-22T04:43:49.734-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>NAT and IPSEC Interoperability</title><content type='html'>&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;After close to three weeks of silence... Here is the post I promised in my last post.&lt;br /&gt;&lt;br /&gt;I have decided to avoid configurations in this post. The theory is boring enough :-)&lt;br /&gt;&lt;br /&gt;We are going to examine two scenarios;&lt;br /&gt;&lt;br /&gt;Scenario 1: The VPN device also performs NAT.&lt;br /&gt;&lt;br /&gt;If the edge router/ASA does NAT and VPN, there are two basic options available;&lt;br /&gt;1. Exclude the interesting traffic from the NAT pool&lt;br /&gt;On a router, a route-map can be used to reference an access-list which excludes the VPN traffic from being 'NATTED'&lt;br /&gt;&lt;br /&gt;On the ASA, the nat 0 command is used for nat exemption&lt;br /&gt;&lt;br /&gt;2. If NAT is enabled for the VPN traffic. The order of operation must be understood.&lt;br /&gt;&lt;br /&gt;The Cisco IOS order of operations performs NAT Translation before the crypto map is matched. The access-list specified on the crypto map must match the GLOBAL (Translated) address. Encryption occurs after translation.&lt;br /&gt;&lt;br /&gt;The return traffic, decryption occurs before, before NAT Translation is performed.&lt;br /&gt;&lt;br /&gt;Scenario 2: There is a NAT device on the path.&lt;br /&gt;Remote Access VPN clients might have to establish a tunnel through a router (might be the local gateway) performing NAT. The inherent problems with this are described in RFC 3715.&lt;br /&gt;&lt;br /&gt;The solution to this problems are described in RFCs 3947 and 3948. From a configuring standpoint, there's little to be done. The peers automagically detect a NAT detects a NAT device in between and switches to UDP encapsulation for NAT by default. The new UDP packets must be allowed by any access-lists for this to work.&lt;br /&gt;&lt;br /&gt;Since NAT configuration is common in many network environments, It is required for network engineers to have a thorough understanding of the concept.&lt;br /&gt;&lt;br /&gt;For Further Reading:&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml"&gt;&lt;br /&gt;NAT Order of Operation&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftipsnat.html"&gt;IPSec NAT Transparency&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://tools.ietf.org/html/rfc3715"&gt;RFC 3715 IPsec-NAT Compatibility Requirements&lt;/a&gt;&lt;br /&gt;&lt;a href="http://tools.ietf.org/html/rfc3947"&gt;&lt;br /&gt;RFC 3947 Negotiation of NAT-Traversal in the IKE&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://tools.ietf.org/html/rfc3948"&gt;RFC 3945 UDP Encapsulation of IPsec ESP Packets&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5183739315798269914?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5183739315798269914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/09/nat-and-ipsec-interoperability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5183739315798269914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5183739315798269914'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/09/nat-and-ipsec-interoperability.html' title='NAT and IPSEC Interoperability'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5349730097197208263</id><published>2009-08-21T09:49:00.000-07:00</published><updated>2009-10-22T04:08:18.720-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>SSL VPNS Part 2: Anyconnect VPN Client</title><content type='html'>&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;The SSL VPNS can operate in three modes, I have discussed the first 2 in a &lt;a href="http://amplebrain.blogspot.com/2009/08/remote-access-vpns-ssl-vpns.html"&gt;previous post&lt;/a&gt;. In this post, I would describe the Anyconnect VPN Client.&lt;br /&gt;&lt;br /&gt;To set up the anyconnect VPN client, The Anyconnect VPN Client is stored on the flash and then downloaded and installed on the client. The VPN client can be removed after the session is terminated and can be left on the client PC depending on the router configuration. If the VPN client is left on the PC, subsequent connections would not require downloading the anyconnect client on the PC.&lt;br /&gt;&lt;br /&gt;The anyconnect-win-2.3.2016-k9.pkg is the latest release of the anyconnect client on cisco site. You need a CCO account to download this.&lt;br /&gt;&lt;br /&gt;Steps.&lt;br /&gt;1. Copy the VPN Client to the memory of the Router.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;font-size:100%;"&gt;WEBGATEWAY#copy tftp flash:/webvpn/svc.pkg&lt;br /&gt;Address or name of remote host []? 10.10.10.2&lt;br /&gt;Source filename []? anyconnect-win-2.3.2016-k9.pkg&lt;br /&gt;Destination filename [/webvpn/svc.pkg]?&lt;br /&gt;Loading anyconnect-win-2.3.2016-k9.pkg from 10.10.10.2 (via FastEthernet0/0): !!!!!!!!!!!&lt;br /&gt;[OK - 2672571 bytes]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Verifying checksum... CCCCC OK&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;&lt;br /&gt;2. Install the client on the router&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;WEBGATEWAY(config)#webvpn install svc flash:/webvpn/svc.pkg&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;SSLVPN Package SSL-VPN-Client : installed successfully&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;WEBGATEWAY(config)#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;3. Set up the local pool&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;WEBGATEWAY(config)#ip local pool ANYCONNECT 192.168.1.5 192.168.1.50&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;4. Configure the webvpn context to support anyconnect.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-size:100%;" &gt;WEBGATEWAY(config)#webvpn context SSL&lt;br /&gt;WEBGATEWAY(config-webvpn-context)#policy gr SSLVPN&lt;br /&gt;WEBGATEWAY(config-webvpn-group)#function svc?&lt;br /&gt;svc-enabled  svc-required&lt;br /&gt;&lt;br /&gt;WEBGATEWAY(config-webvpn-group)#function svc-enabled&lt;br /&gt;! svc-enabled allows fall back to thinclient and clientless mode if ! anyconnect fails.&lt;br /&gt;WEBGATEWAY(config-webvpn-group)#svc address-pool ANYCONNECT&lt;br /&gt;WEBGATEWAY(config-webvpn-group)#svc keep-client-installed&lt;br /&gt;! keeps the vpn client on the client after the session has been terminated&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;TEST&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;Here are some snapshots from my PC&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_V3Tfi7omYZI/So7TUkP-icI/AAAAAAAAABk/-ugTjlNb7TM/s1600-h/anyconnect.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 478px; height: 298px;" src="http://1.bp.blogspot.com/_V3Tfi7omYZI/So7TUkP-icI/AAAAAAAAABk/-ugTjlNb7TM/s400/anyconnect.jpg" alt="" id="BLOGGER_PHOTO_ID_5372463755781114306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_V3Tfi7omYZI/So7USHrgXqI/AAAAAAAAABs/HpWRhP4XpuU/s1600-h/annysetup.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 299px;" src="http://1.bp.blogspot.com/_V3Tfi7omYZI/So7USHrgXqI/AAAAAAAAABs/HpWRhP4XpuU/s400/annysetup.jpg" alt="" id="BLOGGER_PHOTO_ID_5372464813263838882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7UkG7KywI/AAAAAAAAAB0/tIboaU-bJHE/s1600-h/ANN.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 326px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7UkG7KywI/AAAAAAAAAB0/tIboaU-bJHE/s400/ANN.jpg" alt="" id="BLOGGER_PHOTO_ID_5372465122298743554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7U3EW-yaI/AAAAAAAAAB8/acRJD0PuGdg/s1600-h/annyprespl.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 230px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7U3EW-yaI/AAAAAAAAAB8/acRJD0PuGdg/s400/annyprespl.jpg" alt="" id="BLOGGER_PHOTO_ID_5372465448027605410" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;Test connectivity to the internal network&lt;/span&gt;..&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7VOLWCAKI/AAAAAAAAACE/uAjLhGBWefI/s1600-h/anytest.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 201px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/So7VOLWCAKI/AAAAAAAAACE/uAjLhGBWefI/s400/anytest.jpg" alt="" id="BLOGGER_PHOTO_ID_5372465845039661218" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;But connectivity to the local LAN is lost...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/So7VoqwH0SI/AAAAAAAAACM/LMdZMKt3OGA/s1600-h/no+spl.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 201px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/So7VoqwH0SI/AAAAAAAAACM/LMdZMKt3OGA/s400/no+spl.jpg" alt="" id="BLOGGER_PHOTO_ID_5372466300147192098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;To configure split Tunneling&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;WEBGATEWAY(config-webvpn-group)#svc split include 192.168.1.0 255.255.255.0&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;&lt;br /&gt;TEST&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;Disconnect and reconnect. ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/So7WO6KOOnI/AAAAAAAAACU/iVeb9Syu3T0/s1600-h/annyspl.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 203px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/So7WO6KOOnI/AAAAAAAAACU/iVeb9Syu3T0/s400/annyspl.jpg" alt="" id="BLOGGER_PHOTO_ID_5372466957118225010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Anyconnect is up and running! :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;N.B: When setting up SSLVPN on GNS3 using windows vista (like I did), ensure that the VPN client is copied to flash:/webvpn/svc.pkg as the router would not be able to modify the file system of the flash when you use the webvpn install command.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;2. You might need to recreate a trustpoint after reloading the router.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;3. If you are using the self signed certificate and Internet explorer, ensure that the webvpn gateway address is added to your trusted sites otherwise the anyconnect download would fail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;In real world scenarios, we might need to setup VPN and NAT for enhanced security (and connectivity), In the next post, I would discuss the nteroperability of NAT and VPNs.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Ciao.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5349730097197208263?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5349730097197208263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/ssl-vpns-part-2-anyconnect-vpn-client.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5349730097197208263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5349730097197208263'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/ssl-vpns-part-2-anyconnect-vpn-client.html' title='SSL VPNS Part 2: Anyconnect VPN Client'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_V3Tfi7omYZI/So7TUkP-icI/AAAAAAAAABk/-ugTjlNb7TM/s72-c/anyconnect.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-3329791591532765923</id><published>2009-08-20T09:20:00.000-07:00</published><updated>2009-10-22T04:06:08.915-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>Remote Access VPNS: SSL VPNS</title><content type='html'>&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;The SSL VPN (aka webvpn) is the most flexible kind of Remote access VPN connection. All you need is an SSL enabled browser - Internet Explorer, Mozilla, Safari etc. I would go right to the configuration.&lt;br /&gt;&lt;br /&gt;Network Diagram:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_V3Tfi7omYZI/So2Be07letI/AAAAAAAAAA8/GeR20WQZTHY/s1600-h/ssl.jpeg.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 239px;" src="http://4.bp.blogspot.com/_V3Tfi7omYZI/So2Be07letI/AAAAAAAAAA8/GeR20WQZTHY/s400/ssl.jpeg.jpeg" alt="" id="BLOGGER_PHOTO_ID_5372092297127492306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;&lt;br /&gt;Web Gateway Configuration:&lt;br /&gt;&lt;br /&gt;-Configure AAA for authenticaton:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;font-size:100%;" &gt;aaa new-model&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;aaa authentication login VPN local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;&lt;br /&gt;Configure the webvpn gateway and put it INSERVCIE&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;webvpn gateway GATE&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;ip address 12.12.12.1 port 443&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; http-redirect port 80 &lt;span style="font-family: trebuchet ms;"&gt;!makes the router to listen on port 80&lt;/span&gt;&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;inservice&lt;/span&gt; &lt;span style="font-family:courier new;"&gt; !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Immediately after a webvpn gateway command is entered, a self-signed certificate is generated. This CA can be changed using the &lt;span style="font-family: courier new;"&gt;ssl trustpoint&lt;/span&gt; command.&lt;/span&gt;  &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;Next the webvpn context is created...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;webvpn context SSL&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;secondary-color blue&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;secondary-text-color white&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt; Next, a URL-List is created;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;url-list "list1"&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;  &lt;br /&gt;heading "Available Pages"&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;  &lt;br /&gt;url-text "Home Page" url-value "books.durable.com"&lt;/span&gt; &lt;span style="font-family:courier new;"&gt; !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;For Thin client connection, a port-forwarding list is created.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; !&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;port-forward "Ports"&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;  &lt;br /&gt;local-port 3065 remote-server "TELNET" remote-port 23 description "telnet"&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The pieces are tied together using the policy group command.&lt;/span&gt;&lt;br /&gt;!&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;policy group SSLVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   url-list "list1"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   port-forward "Ports"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;  banner "Login Successful"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   timeout idle 300&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;  &lt;br /&gt;timeout session 3600&lt;/span&gt;&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Next we set the default group policy, the AAA authentication list and add a gateway to the context.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; default-group-policy SSLVPN&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;aaa authentication list VPN&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;gateway GATE&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;inservice&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;TESTING&lt;/span&gt; &lt;span style="font-family:trebuchet ms;"&gt;&lt;br /&gt;I prefer to test with the end user - Here are some snapshots.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_V3Tfi7omYZI/So2CJ6oNjaI/AAAAAAAAABE/YWcP0LKovKY/s1600-h/webvpn1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 461px; height: 288px;" src="http://4.bp.blogspot.com/_V3Tfi7omYZI/So2CJ6oNjaI/AAAAAAAAABE/YWcP0LKovKY/s400/webvpn1.jpg" alt="" id="BLOGGER_PHOTO_ID_5372093037391220130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After successful authentication, we have;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2Cvx23NNI/AAAAAAAAABM/N9vSJXsQy_o/s1600-h/webvpn2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 495px; height: 309px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2Cvx23NNI/AAAAAAAAABM/N9vSJXsQy_o/s400/webvpn2.jpg" alt="" id="BLOGGER_PHOTO_ID_5372093687871780050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;When you click start, you have;&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2DSZXpk1I/AAAAAAAAABU/z_uh-Z-La_A/s1600-h/wevpn-thinclient.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 273px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2DSZXpk1I/AAAAAAAAABU/z_uh-Z-La_A/s400/wevpn-thinclient.jpg" alt="" id="BLOGGER_PHOTO_ID_5372094282593833810" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Finally, lets try to telnet to localhost port 3065&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2EBcNtrDI/AAAAAAAAABc/kCegGICk24w/s1600-h/wevpn-thinclient2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 276px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/So2EBcNtrDI/AAAAAAAAABc/kCegGICk24w/s400/wevpn-thinclient2.jpg" alt="" id="BLOGGER_PHOTO_ID_5372095090811317298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Just as we want it :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Up Next: Anyconnect :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Ciao.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-3329791591532765923?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/3329791591532765923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/remote-access-vpns-ssl-vpns.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/3329791591532765923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/3329791591532765923'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/remote-access-vpns-ssl-vpns.html' title='Remote Access VPNS: SSL VPNS'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_V3Tfi7omYZI/So2Be07letI/AAAAAAAAAA8/GeR20WQZTHY/s72-c/ssl.jpeg.jpeg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1341666019981922835</id><published>2009-08-17T09:53:00.000-07:00</published><updated>2009-10-22T04:06:08.916-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>GET VPN - Implementation Issues</title><content type='html'>&lt;span style="font-family: trebuchet ms;font-size:100%;" &gt;Cisco's implementation of GETVPN uses "header preservation" - the header of the IP Packet is preserved and the payload is encrypted. As a result, GETVPN is not suitable for IPSEC VPN across the internet (except the inside network uses public ip addresses). A workaround is to use GRE tunnels.&lt;br /&gt;Besides this obvious caveat, there are some more subtle security issues with GETVPN. Jan Bervar highlights some of these issues in &lt;a href="http://blogs.nil.com/blog/2009/02/17/as-good-as-it-gets/"&gt;Fragments&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;That said, IMHO, GETVPN is still a nice implementation of VPNs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1341666019981922835?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1341666019981922835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/get-vpn-implementation-issues.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1341666019981922835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1341666019981922835'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/get-vpn-implementation-issues.html' title='GET VPN - Implementation Issues'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-1532485268413590332</id><published>2009-08-15T09:30:00.000-07:00</published><updated>2009-10-22T04:06:08.916-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>Site to Site VPNS - Introducing Cisco's GETVPN</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;As I mentioned in a previous post, there are many kinds of Site to Site VPNS that can be implemented on a cisco router.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;There are many resource materials on the internet on Basic Point-to-Point Site-to-Site IPSEC VPNS. I do not intend to add to the tons of materials already out there.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;GRE/IPSEC VPNS are implemented similarly as all traffic is passed through the GRE tunnel (encapsulated with GRE) and the GRE traffic is now encapsulated with IPSEC. Here the GRE traffic is the Interesting traffic.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;DMVPN involves setting up VPNS when they are needed between sites. This involves a combination of NHRP, mGRE, CEF and IPSEC. &lt;a href="http://www.internetworkexpert.com/about-petr.htm"&gt;Petr Lapukhov&lt;/a&gt;, 4xCCIE, an instructor at INE has a detailed technical post on DMVPN, which can be found on the &lt;a href="http://blog.internetworkexpert.com//2008/08/02/dmvpn-explained/#more-214"&gt;INE blog&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;a href="http://www.nil.com/go/ccie_experts"&gt;Boštjan Šuštar&lt;/a&gt; also has another technical article on DMVPN that explains it from a real world perspective. It can be found at the &lt;a href="http://www.nil.com/ipcorner/IPsecVPN4/"&gt;NIL IPCorner&lt;/a&gt;. I strongly recommend that you go through both materials. I dont think I have anything to add to these; they have everything on DMVPNs covered :-)&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;Besides, Boštjan was probably a CCIE before i could even spell a router ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;And now, GETVPN :-)&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;GETVPN is cisco's new VPN technology (from IOS 12.4(6)T). The concept is simple.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;VPN Sites for an organisation are in a group. The group consists of one or more key servers (more than one key server is advised for redundancy).&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;The group memers would request for the SAs from the server. The server is actually configured with all the SA parameters. the server just sends out the SA to the members, The server also sends the traffic to be considered INTERESTING to the members. they DO NOT negotiate SAs between each other. This Hub and spoke mechanism is used to download the SAs.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;The actual IPSEC communicaion occurs on a full mesh topology as the spokes just encrypt the traffic based on the information downloaded fron the key server.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;Implementation:&lt;br /&gt;Diagram:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/SobkQDJCEoI/AAAAAAAAAA0/o8Rp4tsTb4s/s1600-h/getvpn1.jpeg.jpeg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 238px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/SobkQDJCEoI/AAAAAAAAAA0/o8Rp4tsTb4s/s400/getvpn1.jpeg.jpeg" alt="" id="BLOGGER_PHOTO_ID_5370230570058125954" border="0" /&gt;&lt;/a&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;br /&gt;Basic Configuration&lt;br /&gt;Key Server:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;conf t&lt;br /&gt;hostname R1&lt;br /&gt;interface Serial 0/0&lt;br /&gt;ip address 172.16.14.1 255.2552.255.0&lt;br /&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Group member 1&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;conf t&lt;br /&gt;hostname R2&lt;br /&gt;interface Serial0/0&lt;br /&gt;ip address 172.16.24.2 255.255.255.0&lt;br /&gt;end&lt;br /&gt;interface Loopback0&lt;br /&gt;ip address 192.168.2.1 255.255.255.0&lt;br /&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Group Member 2&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;conf t&lt;br /&gt;hostname R3&lt;br /&gt;interface Serial0/0&lt;br /&gt;ip address 172.16.24.2 255.255.255.0&lt;br /&gt;end&lt;br /&gt;int loopback 0&lt;br /&gt;ip address 192.168.3.1 255.255.255.0&lt;br /&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Server Configuration;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;access-list 103 permit ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp policy 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; encr 3des&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; authentication pre-share&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; group 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp key cisco address 172.16.24.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp key cisco address 172.16.34.3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto ipsec transform-set TRANSF esp-3des esp-md5-hmac&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto ipsec profile GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; set transform-set TRANSF&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto gdoi group VPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; identity number 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; server local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  rekey retransmit 10 number 3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  registration interface Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  sa ipsec 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   !&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   profile GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   match address ipv4 103&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Group Member Configuration (Identical on both sides):&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp policy 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; encr 3des&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; authentication pre-share&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; group 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp key cisco address 172.16.14.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto gdoi group VPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; identity number 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; server address ipv4 172.16.14.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto map GETVPN 10 gdoi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; set group VPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface s0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;crypto map GETVPN&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Test :-)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#do sh cry ipsec sa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface: Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Crypto map tag: GETVPN, local addr 172.16.24.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   protected vrf: (none)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   local  ident (addr/mask/prot/port): (192.168.0.0/255.255.0.0/0/0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   remote ident (addr/mask/prot/port): (192.168.0.0/255.255.0.0/0/0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   current_peer 172.16.14.1 port 848&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     PERMIT, flags={}&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;    #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;    #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts compressed: 0, #pkts decompressed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts not compressed: 0, #pkts compr. failed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts not decompressed: 0, #pkts decompress failed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #send errors 0, #recv errors 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     local crypto endpt.: 172.16.24.2, remote crypto endpt.: 172.16.14.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     path mtu 1500, ip mtu 1500, ip mtu idb Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     current outbound spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound esp sas:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;      spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        transform: esp-3des esp-md5-hmac ,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        in use settings ={Tunnel, }&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        conn id: 5, flow_id: SW:5, crypto map: GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        sa timing: remaining key lifetime (k/sec): (4415223/1967)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        IV size: 8 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        replay detection support: Y&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        Status: ACTIVE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound ah sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound pcp sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound esp sas:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;      spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        transform: esp-3des esp-md5-hmac ,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        in use settings ={Tunnel, }&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        conn id: 6, flow_id: SW:6, crypto map: GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        sa timing: remaining key lifetime (k/sec): (4415223/1960)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        IV size: 8 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        replay detection support: Y&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        Status: ACTIVE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound ah sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound pcp sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Next, we would try to Ping and watch the encaps/decaps field&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#do ping 192.168.3.1 sou lo0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.3.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Packet sent with a source address of 192.168.2.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 176/356/552 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#do sh cry ipsec sa&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface: Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Crypto map tag: GETVPN, local addr 172.16.24.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   protected vrf: (none)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   local  ident (addr/mask/prot/port): (192.168.0.0/255.255.0.0/0/0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   remote ident (addr/mask/prot/port): (192.168.0.0/255.255.0.0/0/0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   current_peer 172.16.14.1 port 848&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     PERMIT, flags={}&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;    #pkts encaps: 5, #pkts encrypt: 5, #pkts digest: 5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;    #pkts decaps: 5, #pkts decrypt: 5, #pkts verify: 5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts compressed: 0, #pkts decompressed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts not compressed: 0, #pkts compr. failed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #pkts not decompressed: 0, #pkts decompress failed: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    #send errors 0, #recv errors 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     local crypto endpt.: 172.16.24.2, remote crypto endpt.: 172.16.14.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     path mtu 1500, ip mtu 1500, ip mtu idb Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     current outbound spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound esp sas:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;      spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        transform: esp-3des esp-md5-hmac ,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        in use settings ={Tunnel, }&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        conn id: 5, flow_id: SW:5, crypto map: GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        sa timing: remaining key lifetime (k/sec): (4415222/1920)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        IV size: 8 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        replay detection support: Y&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        Status: ACTIVE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound ah sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     inbound pcp sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound esp sas:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;      spi: 0x38FEDAF9(956226297)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        transform: esp-3des esp-md5-hmac ,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        in use settings ={Tunnel, }&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        conn id: 6, flow_id: SW:6, crypto map: GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        sa timing: remaining key lifetime (k/sec): (4415222/1917)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        IV size: 8 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        replay detection support: Y&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        Status: ACTIVE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound ah sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     outbound pcp sas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The icmp packets are encrypted in IPSEC&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#do sh cry isa sa&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IPv4 Crypto ISAKMP SA&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;dst             src             state          conn-id slot status&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;172.16.14.1     172.16.24.2     GDOI_IDLE         1003    0 ACTIVE&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IPv6 Crypto ISAKMP SA&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;On the server.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#sh cry gdoi&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Group Information&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Name                  : VPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Identity              : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Members Registered    : 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Server                : Local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Rekey Lifetime        : 86400 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Rekey Retransmit Period     : 10 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Rekey Retransmit Attempts   : 3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   IPSec SA Number             : 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     IPSec SA Rekey Lifetime   : 3600 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     Profile Name              : GETVPN&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   SA Rekey&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       Remaining Lifetime      : 3010 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   access-list 103 permit ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Group Member List for Group VPN :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Member ID                   : 172.16.24.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Member ID                   : 172.16.34.3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Everything is up and running. :-)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-family:trebuchet ms;"&gt;I have already posted on EZVPNS, so the only VPN configuration left is the SSL VPN. I would try to get that done in the coming week. :-)&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Ciao.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Amplebrain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-1532485268413590332?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/1532485268413590332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/site-to-site-vpns-introducing-ciscos.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1532485268413590332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/1532485268413590332'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/site-to-site-vpns-introducing-ciscos.html' title='Site to Site VPNS - Introducing Cisco&apos;s GETVPN'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_V3Tfi7omYZI/SobkQDJCEoI/AAAAAAAAAA0/o8Rp4tsTb4s/s72-c/getvpn1.jpeg.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-8063267936786025951</id><published>2009-08-14T10:49:00.000-07:00</published><updated>2009-10-22T04:50:50.636-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='INFO'/><title type='text'>Cloud Computing - Security Threats?</title><content type='html'>Cloud computing appears to be the next phase of computing. The new Google operating system would operate on the cloud computing platform.&lt;br /&gt;&lt;br /&gt;While it definitely has its pros, the black hat USA conference last week has drawn our attention to some security threats with cloud computing. More info can be found on &lt;a href="http://www.readwriteweb.com/archives/the_cloud_isnt_safe_or_did_blackhat_just_scare_us.php"&gt;readwriteweb&lt;/a&gt;&lt;a href="http://www.readwriteweb.com/archives/the_cloud_isnt_safe_or_did_blackhat_just_scare_us.php"&gt;.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Again, we have to deal with it :-)&lt;br /&gt;&lt;br /&gt;Ciao.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-8063267936786025951?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/8063267936786025951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/cloud-computing-security-threats.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8063267936786025951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/8063267936786025951'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/cloud-computing-security-threats.html' title='Cloud Computing - Security Threats?'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-7208626673905906842</id><published>2009-08-13T11:14:00.000-07:00</published><updated>2009-10-22T04:06:08.916-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>Why cant we just trust the internet??</title><content type='html'>&lt;div style="text-align: justify; font-family: trebuchet ms;"&gt;Hello,&lt;br /&gt;I have been studying Internet and WAN security lately and I just think it would be a lot better if the internet was secure. So let's start a campaign for "Ethical Internet Practices ;)".&lt;br /&gt;Well, I have to come to terms with reality. The internet is going to remain UNSAFE for a long time. So we are going to deal with it. What options do we have?&lt;br /&gt;&lt;br /&gt;1. Provide WAN infrastructure for all our private traffic: While this would be 'SAFE', it is no longer scalable as we have branch offices everywhere and even telecommuters. Some employees don't even know the location of the corporate offices anymore (they all work from home :-) ). Besides, this way too expensive, I'm sure your boss would not buy that either!&lt;br /&gt;&lt;br /&gt;2. Secure our traffic and use the internet as our WAN infrastructure. We would kill two birds with one stone and we would still be friends with the finance department. :-) Welcome to the world of VIRTUAL PRIVATE NETWORKING&lt;br /&gt;As a network engineer, i know VPNS have been around for a while and they have grown and become very scalable. Thankfully cisco gives us many options to suite our peculiar needs.&lt;br /&gt;Broadly we have two kinds of VPN&lt;br /&gt;&lt;br /&gt;1. Site to Site VPNS:&lt;br /&gt;        -IPSec VPNS&lt;br /&gt;        -GRE/IPSEC for communiction of routing protocols&lt;br /&gt;        -Dynamic Multipoint VPNS (Hub and Spoke and Spoke to Spoke)&lt;br /&gt;        -Group Encrypted Transport (GET) VPNS&lt;br /&gt;&lt;br /&gt;2. Remote Access VPNS (for telecommuters)&lt;br /&gt;       -SSL VPN (also known as webVPN)&lt;br /&gt;       -Easy VPN&lt;br /&gt;&lt;br /&gt;I don't want to get into the configuration details yet but I would post some more technical details soon.&lt;br /&gt;As you must have already noticed, I am a cisco advocate and my configuration would be mostly cisco-oriented.&lt;br /&gt;Feel free to post your personal experience with these technologies.&lt;br /&gt;&lt;br /&gt;Later.&lt;br /&gt;&lt;br /&gt;Amplebrain.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-7208626673905906842?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/7208626673905906842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/why-cant-we-just-trust-internet.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7208626673905906842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/7208626673905906842'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/why-cant-we-just-trust-internet.html' title='Why cant we just trust the internet??'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-5981408755443336185</id><published>2009-08-12T07:04:00.000-07:00</published><updated>2009-10-22T04:06:08.916-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPNS'/><title type='text'>Easy VPN Configuration – Paradox</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;I have always wondered what was easy about the EzVPN, I got my hands dirty with it and found out that Easy VPN doesn't live up to its name (from the network engineer's perspective). Its pretty easy from the end user's perspective.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;The cisco easy VPN solution involves two parties; The Easy VPN Server and The Easy VPN Remote.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;The Easy VPN Server contains all the configurations and pushes the VPN settings to the client.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;The Easy VPN Remote side can be a cisco device (Router, PIX/ASA firewall) or a PC with the Cisco VPN Client installed.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:100%;"  &gt;There are many parts to the EzVPN configuration. I do not intend to make this post unecessarily long and boring so I would try to keep things simple.&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/SoLOG6BLSBI/AAAAAAAAAAM/C1um7HeThhw/s1600-h/ezvpn.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 465px; height: 261px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/SoLOG6BLSBI/AAAAAAAAAAM/C1um7HeThhw/s320/ezvpn.jpg" alt="" id="BLOGGER_PHOTO_ID_5369080323827779602" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;p  style="text-align: justify;font-family:courier new;" class="MsoNormal"&gt;&lt;span style="font-size:85%;"&gt;&lt;img src="file:///C:/Users/Tohluh/AppData/Local/Temp/moz-screenshot.jpg" alt="" /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" face="courier new" style="margin-bottom: 0.0001pt; line-height: normal; text-align: justify;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face  {font-family:"Cambria Math";  panose-1:2 4 5 3 5 4 6 3 2 4;  mso-font-charset:1;  mso-generic-font-family:roman;  mso-font-format:other;  mso-font-pitch:variable;  mso-font-signature:0 0 0 0 0 0;} @font-face  {font-family:Calibri;  panose-1:2 15 5 2 2 2 4 3 2 4;  mso-font-charset:0;  mso-generic-font-family:swiss;  mso-font-pitch:variable;  mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-unhide:no;  mso-style-qformat:yes;  mso-style-parent:"";  margin-top:0in;  margin-right:0in;  margin-bottom:10.0pt;  margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Calibri;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} .MsoChpDefault  {mso-style-type:export-only;  mso-default-props:yes;  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:Calibri;  mso-fareast-theme-font:minor-latin;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} .MsoPapDefault  {mso-style-type:export-only;  margin-bottom:10.0pt;  line-height:115%;} @page Section1  {size:8.5in 11.0in;  margin:1.0in 1.0in 1.0in 1.0in;  mso-header-margin:.5in;  mso-footer-margin:.5in;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin-top:0in;  mso-para-margin-right:0in;  mso-para-margin-bottom:10.0pt;  mso-para-margin-left:0in;  line-height:115%;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;} &lt;/style&gt; &lt;![endif]--&gt;&lt;/p&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Base configuration:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Server&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Hostname VPNSERVER&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface Serial0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip address 172.16.1.2 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip ospf 1 area 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface Loopback0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip address 192.168.1.1 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface Loopback2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip address 192.168.3.1 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Client&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Hostname VPNCLIENT&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip address 10.10.10.1 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface Serial0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip address 172.16.2.2 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip ospf 1 area 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Easy VPN Server Configuration&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create a local pool&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip local pool EZVPNPOOL 192.168.1.15 192.168.1.50&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Configure AAA&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;aaa new-model&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;aaa authorization network VPNGRP local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create Access List for Split tunneling (Without Split tunneling, all traffic is sent to the server and the clients would lose access to the internet - In the case of VPN CLIENTS, access to the LAN is lost)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ip access-list extended SPL&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;permit ip 192.168.0.0 0.0.255.255 any&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create the Client Configuration on the server. The groupname and key must match on the client side&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp client configuration group EZVPNGRP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;key s3cr3t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;dns 192.168.1.5&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;wins 192.168.1.6&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;pool EZVPNPOOL&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;acl SPL&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create the ISAKMP Policy&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp policy 10&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;encr 3des&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;hash md5&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;authentication pre-share&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;group 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Note: Only Diffie-Helman group 2 is supported in EZVPN Configuration.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create the dynamic crypto map&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto dynamic-map EZVPNDYN 10&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;set transform-set TRANSFORM&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;reverse-route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!reverse route is set so that the server can learn of client networks automatically&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Create the ‘Real’ Crypto map and attach the dynamic crypto map&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto map EZVPNMAP isakmp authorization list VPNGRP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto map EZVPNMAP client configuration address respond&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto map EZVPNMAP 65535 ipsec-isakmp dynamic EZVPNDYN&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Configure Xauth to authenticate the clients&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;aaa authentication login EZVPN local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;username amplebrain password 0 cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto isakmp client configuration group EZVPNGRP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;save-password&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!The save password feature allows the clients authentication to be saved throughout !the process of establishing the VPN tunnel&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;-Apply the Configuration to the interfaces.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;int s0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto map EZVPNMAP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;THE EASY VPN REMOTE: The easy VPN Remote can be in three modes;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;1. client: Here an address is assigned to the router (from the local pool configured) using an available loopback interface and the inside network is automatically translated to the that address using PAT.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;2. Network-Extension: the inside network is considered to be an extension of the VPN Server's network. No address is allocated from the pool.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;3. Network-Extension-Plus: the inside network is still considered to be an extension of the VPN Server's network. An address is allocated from the pool to a loopback interface of the router for testing connectivity. Only the inside network and the loopback interface can reach the VPN network.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;The configuration:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto ipsec client ezvpn EZVPN&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;connect auto&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;group EZVPNGRP key s3cr3t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;mode network-plus&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;peer 172.16.1.2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;username amplebrain password cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;xauth userid mode local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto ipsec client ezvpn EZVPN inside&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;interface Serial0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;crypto ipsec client ezvpn EZVPN&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;The xauth userid mode local command tells the router to use the locally configured username and password for extended authentication.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;TEST&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;VPNCLIENT#sh ip int br&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Interface IP-Address OK? Method Status Protocol&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;FastEthernet0/0 10.10.10.1 YES manual up up&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Serial0/0 172.16.2.2 YES NVRAM up up&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;NVI0 unassigned NO unset up up&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Loopback0 192.168.1.20 YES manual up up&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Notice that loopback 0 has been added with IP address 192.168.1.20 from the local pool.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;On the Server,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;VPNSERVER(config)#do sh ip rou&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;172.16.0.0/24 is subnetted, 2 subnets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;C 172.16.1.0 is directly connected, Serial0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;O 172.16.2.0 [110/128] via 172.16.1.1, 01:39:56, Serial0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;10.0.0.0/24 is subnetted, 1 subnets&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;S 10.10.10.0 [1/0] via 172.16.2.2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;192.168.1.0/24 is variably subnetted, 2 subnets, 2 masks&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;C 192.168.1.0/24 is directly connected, Loopback0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;S 192.168.1.20/32 [1/0] via 172.16.2.2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;C 192.168.3.0/24 is directly connected, Loopback2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;The Routes are a result of the RRI. You have to redistribute static if you are running a routing protocol on the inside of the VPN server.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Back on the Remote Router,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;VPNCLIENT#ping 192.168.1.1 Type escape sequence to abort.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;U.U.U&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;The Packets are lost in the cloud.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;VPNCLIENT#ping 192.168.1.1 so lo0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Packet sent with a source address of 192.168.1.20&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 264/342/480 ms&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;On the Inside Host, &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V3Tfi7omYZI/SoLXmuFfXvI/AAAAAAAAAAU/ZZnFXuuLukg/s1600-h/host1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 564px; height: 316px;" src="http://2.bp.blogspot.com/_V3Tfi7omYZI/SoLXmuFfXvI/AAAAAAAAAAU/ZZnFXuuLukg/s320/host1.jpg" alt="" id="BLOGGER_PHOTO_ID_5369090765985111794" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;To test Split Tunelling,&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_V3Tfi7omYZI/SoMD-gorzRI/AAAAAAAAAAs/_IMruQV5C3A/s1600-h/host3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 469px; height: 281px;" src="http://3.bp.blogspot.com/_V3Tfi7omYZI/SoMD-gorzRI/AAAAAAAAAAs/_IMruQV5C3A/s320/host3.jpg" alt="" id="BLOGGER_PHOTO_ID_5369139553203113234" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: courier new;font-size:100%;" &gt;Now, its all up and running.&lt;br /&gt;I would post more VPN stuff later.&lt;br /&gt;Amplebrain&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="line-height: 115%;font-family:&amp;quot;;font-size:100%;"  &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;  &lt;span style="font-size:100%;"&gt;&lt;img src="file:///C:/Users/Tohluh/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-5981408755443336185?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/5981408755443336185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/easy-vpn-configuration-paradox.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5981408755443336185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/5981408755443336185'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/easy-vpn-configuration-paradox.html' title='Easy VPN Configuration – Paradox'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_V3Tfi7omYZI/SoLOG6BLSBI/AAAAAAAAAAM/C1um7HeThhw/s72-c/ezvpn.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1434794436817977802.post-2579552543370808780</id><published>2009-08-12T06:51:00.000-07:00</published><updated>2009-10-22T04:45:48.840-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='General'/><title type='text'>Hello</title><content type='html'>&lt;span style="font-family:webdings;"&gt;&lt;span style="font-family: courier new;font-size:100%;" &gt;Hi All,&lt;br /&gt;I am a Network Engineer.&lt;br /&gt;This blog reflects my experience in my personal study and career as a network engineer. I intend to post technical articles on enterprise networking, network security, datacenters, network management and everyday life.&lt;br /&gt;I am currently studying cisco security technologies and these would be reflected in my posts.&lt;br /&gt;Feel free to post comments and corrections.&lt;br /&gt;&lt;br /&gt;Rgds,&lt;br /&gt;&lt;br /&gt;Amplebrain.&lt;br /&gt;CCIE R&amp;amp;S&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1434794436817977802-2579552543370808780?l=amplebrain.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://amplebrain.blogspot.com/feeds/2579552543370808780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://amplebrain.blogspot.com/2009/08/hello.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2579552543370808780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1434794436817977802/posts/default/2579552543370808780'/><link rel='alternate' type='text/html' href='http://amplebrain.blogspot.com/2009/08/hello.html' title='Hello'/><author><name>amplebrain</name><uri>http://www.blogger.com/profile/13678317702353489314</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
