Re: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-28 Thread NKP
Hi John ,
I finally cleared my SAFE exam today in second attempt , i had
underestimated this test in the first attempt and failed about 2 weeks ago .
   I did not use any Boson , I had read the White Papers for SAFE for
both SMR and Enterprise , and referred to a few notes from some of my
friends  they were both quite good  , the questions are quite tricky in this
exam .
  know the details of  models , setup and functionalities of all
Security  Devices offered by Cisco . Read the  first few chapters of the
MCNS book as well .
  All the best for your test .

  I am on the way to prepare for the R/S lab next .

 Cheers
Navin Parwal


""John Smith""  wrote in message
news:[EMAIL PROTECTED]
> I'm planning on writing the Cisco Safe exam 9E0-131 in the next few weeks
> before it changes to the new exam. Anyone written this and have any hints?
>
> How does it stack up to the other CCSP exams or any hints?
> I'm using cisco.com/safe white papers, Boson to study.
>
> The main reason I'm writing is to upgrade my CSS1 ( u have until Sept 2003
> to do this)  to CCSP before the 9E0-131 changes to the new format.The
> 9E0-131 expires June 17th.
>
> 
>
> CCIE Security contains, but is not limited to:
>
> Catalyst 3550 Switch Configuration
> Frame-Relay
> ISDN
> ATM
> RIPv1
> RIPv2
> EIGRP
> OSPF
> Integrated IS-IS
> BGP
> AAA
> Route Redistribution
> Routing Protocol Authentication
> Routing Protocols Across PIX
> RIP On PIX
> NAT
> Transparent Bridging
> Limiting Router HTTP Access
> Limiting Router SNMP Access
> Committed Access Rate
> Traffic Shaping
> Weighted Random Early Detection
> RFC 1918 And 2827 Filtering
> Logging To Syslog
> URL Filtering On PIX
> Router To Router VPN
> Router To PIX VPN
> IPsec With Manual Keying
> IPsec With ISAKMP
> IPsec Tunnel Redundancy
> Tunnel Endpoint Discovery
> Certificate Authority Support On Routers And PIX
> Disabling NAT On PIX
> DNS Doctoring On PIX
> IDENT Protocol
> Java, ActiveX Filtering
> Setting Up PIX With AAA For HTTP, Ftp And Telnet Cut-Through-Proxy
> IOS Firewall With Audit Trails, Session Deletion With Blocking, Java
> Applet Filtering
> TCP Intercept
> AAA On Routers And PIX (RADIUS, TACACS+)
> IOS IDS With Director And Syslog Logging, Email Spam, Attack And
> Info Signatures
> IDS Signature Tuning
> IDS On PIX
> PPTP On PIX
> NAT On Router With Timeouts
> NAT Load Sharing
> NTP Across PIX
> ISAKMP And IPsec Lifetimes
> Time-Based Access Control Lists
> Dynamic And Reflexive Access Control Lists
> Traffic Monitoring With Span
> Privilege Levels On Routers
> Auth-Proxy On Routers
>
>
> -
> Do you Yahoo!?
> The New Yahoo! Search - Faster. Easier. Bingo.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69641&t=69520
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Messagess Popup on workstation [7:69643]

2003-05-28 Thread Rohit Sundriyal
Hi All

I am facing Starb=nge Problem on my lan. i am receving Popup messages on
workstation .anyidea how to block these messages on pix .

For more information Please visit http://http://www.4vsoft.com



Rohit




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69643&t=69643
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


BGP Beta Exam - Thorough! [7:69644]

2003-05-28 Thread Mwalie W
Hi All,

Today, I did BGP Beta towards CCIP.

A very thorough exam, with some bugs and grammatical mistakes here and there.

It is so thorough and long that if you are not well prepared, you will pass
with difficulty. No time to thinkeven a faster reader like me had
problems.

The first question took me about 10 minutes (should take about 1.5 minutes).
>From then on, I knew that I was always going to struggle.

It is a nice exam to prepare for, full of diagrams and configurations! We
need such kind of exams for certifying competent professionals.

If I do not pass, I will gladly have the same experience again. Very nice
intellectual challenge, I thought!

To Cisco Nuts, Thanks for the hints!! I appreciate that so much.

Good Luck!


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69644&t=69644
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: BGP Load Balance [7:69611]

2003-05-28 Thread Brian W.
heres the cisco guide on it.

http://www.cisco.com/univercd/cc/td/doc/cisintwk/ics/icsbgp4.htm#2351

Bri

- Original Message - 
From: "Salvatore De Luca" 
To: 
Sent: Tuesday, May 27, 2003 7:15 PM
Subject: Re: BGP Load Balance [7:69611]


> I personally prefer Peering with Loops myself.. the EBGP multihop command
> has absolutley nothing to do with loadbalancing. It it used for peering
with
> neighbors whom are not directly connected.. There are various ways of
> performing BGP load balancing.. Metric..route-maps.. etc.. Pick your
flavor.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69646&t=69611
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: BGP Load Balance [7:69611]

2003-05-28 Thread YASSER ALY
Yes you can load-balance traffic to the same destination over 2 equal 
logical paths using
"maximum-paths 2"

Using Loopback address ip to peer and acheive load-balancing to the same 
destination will require
either to use process-switching - not recommended - or enable CEF and do " 
per-packet load-balancing "


Regards,
Yasser


>From: "Brian W." 

>The way I've seen 2 paths used is by peering with a loopback interface and
>using
>neighbor peerip ebgp-multihop in the config.
>
> Brian
>
>- Original Message -
>From: "Azhar Teza"
>To:
>Sent: Tuesday, May 27, 2003 3:16 PM
>Subject: BGP Load Balance [7:69611]
>
>
> > If BGP route has two equal paths to the same destination, can it do load
> > balance by installing the command? maximum-paths 2
> >
> > ___
> > Join Excite! - http://www.excite.com
> > The most personalized portal on the Web!
_
Add photos to your messages with MSN 8. Get 2 months FREE*. 
http://join.msn.com/?page=features/featuredemail




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69645&t=69611
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-28 Thread Marcin Strzyzewski
NKP wrote:

>Hi John ,
>I finally cleared my SAFE exam today in second attempt , i had
>underestimated this test in the first attempt and failed about 2 weeks ago .
>   I did not use any Boson , I had read the White Papers for SAFE for
>both SMR and Enterprise , and referred to a few notes from some of my
>friends  they were both quite good  , the questions are quite tricky in this
>exam .
>  know the details of  models , setup and functionalities of all
>Security  Devices offered by Cisco . Read the  first few chapters of the
>MCNS book as well .
>  All the best for your test .
>  
>
i passed it on monday..
it covers SMR in DETAILthere is also simulation but its easy. i got 
880..not to high but i havent to much time to study

good luck to anyone in road to the CCSP :)


-- 
Marcin Strzyzewski

Warsaw University of Technology
Faculty of Electronics and Information Technology
Institute of Telecommunication




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69647&t=69520
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: default-information originate with route-map [7:69558]

2003-05-28 Thread GM
Hi Maroun,

I have a number of suggestions that you could look into:

-Without the always keyword the ospf router will originate a default route
if there is one in the routing table. So check if you have a default route,
and if not include the always keyword in your default-information orginate
command.

-the route-map keyword specifies the conditions the default route must meet
before being distributed. Hence if you specify a route-map with the match
interface cmd, the default route must have its next-hop interface as the
interface specified in the match interface statement. That could explain why
the default route is not being distributed to any neighbor. It is does not
meet the conditions specified in the route map.

-IMHO, if your ospf neighbor is on a p2p connection you can use the
distibute-list out  cmd and filter out the default route.
But if you have a p2mp configuration, i am not too sure how you would filter
out the default route, for only one of the multipoint peers.

Anyone with any other ideas?

Cheers
GM

""Maroun Waked""  wrote in message
news:[EMAIL PROTECTED]
> hi,
>
> I have a router running ospf that needs to send a
> default route to its neighbors. For this, I have used
> the command default-information originate.
> Then I wanted one of the neighbors not to receive the
> default route. I thought that the route-map option at
> the end of the default-information originate, would
> help.
> However, each time I create a route-map, the default
> route will not be advertised to any of the neigbors.
> I tried using match interface, but I never got any
> matches.
> In brief, things didn't work.
> Can anyone help
>
> thank you
>
> __
> Do you Yahoo!?
> The New Yahoo! Search - Faster. Easier. Bingo.
> http://search.yahoo.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69648&t=69558
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: port/duplex configs [7:69582]

2003-05-28 Thread ian williams
This has come up in the ccie written.
If I understand this subject correctly AUTO , sends out packets to try and
match the 2 devices up with regards to speed and duplex.
If your getting connection problems this would be a speed issue. If its some
sort of packet loss/error then this could be a duplex problem.
I have always configured the CAT port manually so there isnt any problems.

Why would you choice AUTO?



- Original Message - 
From: "John Neiberger" 
To: 
Sent: Tuesday, May 27, 2003 5:35 PM
Subject: Re: port/duplex configs [7:69582]


>  ian williams 5/27/03 10:29:21 AM >>>
> >I have always configured ports on CAT switch to 100/full manually instead
> of
> >AUTO.
> >What is recommended when asked this question for the CCIE written. Should
> >both the end
> >device ( NIC ) and switch both be configured to 100/FULL?
>
> I can't imagine why such a question would be asked on any exam since the
> correct answer is that you configure whatever is necessary to establish a
> connection with the end device.  In my opinion, you should always use AUTO
> unless this causes problems, in which case you hard-set your devices to
> 100/HALF, not 100/FULL.  If you'd like the rationale for that I refer you
to
> the archives for my previous rantings on this subject.
>
> I'd fall over in shock if you were to be asked a question like this on
your
> exam, but as long as you understand the issues involved you should be
> adequately prepared for whatever question of this type that they throw at
> you.
>
> Regards,
> John




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69649&t=69582
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: BGP Beta Exam - Thorough! [7:69644]

2003-05-28 Thread khan shahryar
Hi,

I am also taking it on 30th. Can you please advice me a little bit further
on the format. Are there any simulation based questions??

Regards

ShahryarMwalie W wrote:
> 
> Hi All,
> 
> Today, I did BGP Beta towards CCIP.
> 
> A very thorough exam, with some bugs and grammatical mistakes
> here and there.
> 
> It is so thorough and long that if you are not well prepared,
> you will pass with difficulty. No time to thinkeven a
> faster reader like me had problems.
> 
> The first question took me about 10 minutes (should take about
> 1.5 minutes). From then on, I knew that I was always going to
> struggle.
> 
> It is a nice exam to prepare for, full of diagrams and
> configurations! We need such kind of exams for certifying
> competent professionals.
> 
> If I do not pass, I will gladly have the same experience again.
> Very nice intellectual challenge, I thought!
> 
> To Cisco Nuts, Thanks for the hints!! I appreciate that so much.
> 
> Good Luck!




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69650&t=69644
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Virtual Link Problem [7:69640]

2003-05-28 Thread ian williams
I cant see a problem here, but I have been caught on this one before when
using MD5 authentication.
Remember when using MD5 authentication in Area 0 the R2 will have a direct
connection into Area 0 after the virtual link has been made
so needs to have MD5 authentication as well. You can also do MD5
authentication on the virtual link itself, this was what I was trying to do
and got confused with the MD5 authentication between R2 and Area 0.
When I removed all the MD5 authentication it still would come up. In the end
I removed the config and started again, bingo it came up


- Original Message - 
From: "Kevin Love" 
To: 
Sent: Wednesday, May 28, 2003 5:37 AM
Subject: Virtual Link Problem [7:69640]


> Hey Team,
>
> I cannot figure this out.  I've configured lots of virtual links, but no
> matter what I do this isn't working.  I had md5 authentication configured
> for Area 0, but to isolate the problem, I removed authentication and the
> virtual link still isn't up.  I need another set of eyes (or two) looking
at
> this.  Please help if you can!
>
> Here's the topology:
>
> Area 2 (Loopback 0)
>  |
>  R2
>\
> \
>  FR
>Area 1
>  /\
> R5R6
>  \/
>Area 0
>   Ethernet
>
> Here are the salient config snippets:
>
> R2
> !
> interface Loopback0
>  ip address 192.168.2.2 255.255.255.255
>  ip ospf network point-to-point
> !
> interface Serial1.256 multipoint
>  ip address 172.16.56.2 255.255.255.248
>  ip ospf priority 255
>  frame-relay map ip 172.16.56.2 105
>  frame-relay map ip 172.16.56.5 105 broadcast
>  frame-relay map ip 172.16.56.6 106 broadcast
>  no frame-relay inverse-arp
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.5.5
>  area 1 virtual-link 192.168.6.6
>  network 172.16.56.0 0.0.0.7 area 1
>  network 192.168.2.2 0.0.0.0 area 2
> !
>
> R5
>
> interface Ethernet0
>  ip address 172.16.200.5 255.255.255.128
>  ip ospf hello-interval 15
> !
> interface Serial0
>  ip address 172.16.56.5 255.255.255.248
>  encapsulation frame-relay
>  ip ospf network point-to-multipoint
>  frame-relay map ip 172.16.56.2 501 broadcast
>  frame-relay map ip 172.16.56.5 501
>  frame-relay map ip 172.16.56.6 501 broadcast
>  no frame-relay inverse-arp
>  frame-relay lmi-type cisco
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.2.2
>  network 172.16.56.0 0.0.0.7 area 1
>  network 172.16.200.0 0.0.0.127 area 0
>  network 192.168.5.5 0.0.0.0 area 5
> !
>
> R6
>
> interface Serial0
>  ip address 172.16.56.6 255.255.255.248
>  encapsulation frame-relay
>  ip ospf network point-to-multipoint
>  frame-relay map ip 172.16.56.2 601 broadcast
>  frame-relay map ip 172.16.56.5 601 broadcast
>  frame-relay map ip 172.16.56.6 601
>  no frame-relay inverse-arp
>  frame-relay lmi-type cisco
> !
> interface FastEthernet0
>  ip address 172.16.200.6 255.255.255.128
>  ip ospf hello-interval 15
>  half-duplex
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.2.2
>  network 172.16.56.0 0.0.0.7 area 1
>  network 172.16.200.0 0.0.0.127 area 0
>  network 192.168.6.6 0.0.0.0 area 6
> !
>
> R2#sh ip ospf vir
> Virtual Link OSPF_VL5 to router 192.168.5.5 is down
>   Run as demand circuit
>   DoNotAge LSA allowed.
>   Transit area 1, Cost of using 65535
>   Transmit Delay is 1 sec, State DOWN,
>   Timer intervals configured, Hello 10,  40, Wait 40, Retransmit 5
> Virtual Link OSPF_VL4 to router 192.168.6.6 is down
>   Run as demand circuit
>   DoNotAge LSA allowed.
>   Transit area 1, Cost of using 65535
>   Transmit Delay is 1 sec, State DOWN,
>   Timer intervals configured, Hello 10,  40, Wait 40, Retransmit 5
> R2#
>
> Trust me on the router-IDs for the virtual link statements - I have
> triple-checked them.  I have reloaded the routers with no luck.  What am I
> missing here?!
>
> Thanks!
> Kevin




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69653&t=69640
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: BGP Load Balance [7:69611]

2003-05-28 Thread ian williams
No

- Original Message - 
From: "Azhar Teza" 
To: 
Sent: Tuesday, May 27, 2003 11:16 PM
Subject: BGP Load Balance [7:69611]


> If BGP route has two equal paths to the same destination, can it do load
> balance by installing the command? maximum-paths 2
>
> ___
> Join Excite! - http://www.excite.com
> The most personalized portal on the Web!




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69651&t=69611
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Recall: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-28 Thread Andrew Larkins
Andrew Larkins would like to recall the message, "Anyone written CSI 9E0-131
Cisco Safe? [7:69520]".




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69657&t=69520
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: new ccnp exams [7:69621]

2003-05-28 Thread Nikolay Abromov
Hi, 


you can see new topics in cisco site:
http://www.cisco.com/en/US/learning/le3/le2/le37/le10/learning_certification_type_home.html

i'm prepare for ccnp too and i'm useing "CCNP preparation books" from
ciscopress
"
http://www.ciscopress.com/catalog/product.asp?product_id={E565D23F-F066-44A3-B212-D96D4A11EBB1}
 "

there are very good but they give you only that you
need to pass the exam nothing else, of course that's my misunderstanding for
these ,)






Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69654&t=69621
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-28 Thread Andrew Larkins
-Original Message-
From: Andrew Larkins 
Sent: 28 May 2003 11:18
To: Andrew Larkins
Subject: RE: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]


Not sure what I was thinking here when I sent think - Speed reading is not
always good!! - I got 800 last time

-Original Message-
From: Andrew Larkins 
Sent: 28 May 2003 11:15
To: 'Marcin Strzyzewski'; [EMAIL PROTECTED]
Subject: RE: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]


I got 880 last time and failed. I need to re-sit this one again soon, but
have been too busy lately


-Original Message-
From: Marcin Strzyzewski [mailto:[EMAIL PROTECTED]
Sent: 28 May 2003 09:35
To: [EMAIL PROTECTED]
Subject: Re: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]


NKP wrote:

>Hi John ,
>I finally cleared my SAFE exam today in second attempt , i had
>underestimated this test in the first attempt and failed about 2 weeks ago
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-28 Thread Andrew Larkins
I got 880 last time and failed. I need to re-sit this one again soon, but
have been too busy lately


-Original Message-
From: Marcin Strzyzewski [mailto:[EMAIL PROTECTED]
Sent: 28 May 2003 09:35
To: [EMAIL PROTECTED]
Subject: Re: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]


NKP wrote:

>Hi John ,
>I finally cleared my SAFE exam today in second attempt , i had
>underestimated this test in the first attempt and failed about 2 weeks ago
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Voice chat behind PIX firewall, How to?? [7:69656]

2003-05-28 Thread Magdy Ibrahim
Hi all,
I protected my system by using PIX 515 and all my system and Network behind
that PIX,
I am trying to configure my PIX to allow the voice chat to allow my internal
users to talk with external people using MSN and Yahoo messenger Voice chat
service...
Actually I failed to get it up
Can any one provide me help to get it work

Thanx in advance

Regards,,

Magdy




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69656&t=69656
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: CCIE Home Lab [7:69580]

2003-05-28 Thread Troy Leliard
i agree with Jeff, try and get slightly newer kit if you can, or anything
that will at least run 12.2.  Nothing wrong with the 4000 tho, if you are
using it as a FR switch.

jeff sicuranza wrote:
> 
> do not bother with any 2500 series if you are starting out now.
> IOS improvements and requriements are slowly phasing them out,
> look into 1750, 2600, 3600 series only. 12.3 does not even run
> on any 4000 or 4500 series and only IP plus for 2500 series. Do
> not limit yourself


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69662&t=69580
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: BGP Load Balance [7:69611]

2003-05-28 Thread Troy Leliard
Folllowing on from everyone else, we often make use of loopbacks for
internal peering, that way you will always have redundant paths to iBGP
peers, however when peering with external peers / isp we make use of the
external facing interface ip.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69661&t=69611
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: port/duplex configs [7:69582]

2003-05-28 Thread Troy Leliard
I have seen this too, and like Ian I would normally go with 100/Full
manually configured on botht he Cat and the end device (obviously assuming
both devices support this settings).  In real life, I have often found that
setting the cat to Auto will often lead to duplex / speed mismatches
(especially with Sun kit)  The only time I have made use of Auto is when I
am not 100% sure if the end device support 100MB, some of our legacy
printers are 10MB half duplex, and indeed a number of the 2511's are only
10MB too.]

ian williams wrote:
> 
> This has come up in the ccie written.
> If I understand this subject correctly AUTO , sends out packets
> to try and
> match the 2 devices up with regards to speed and duplex.
> If your getting connection problems this would be a speed
> issue. If its some
> sort of packet loss/error then this could be a duplex problem.
> I have always configured the CAT port manually so there isnt
> any problems.
> 
> Why would you choice AUTO?
> 
> 
> 
> - Original Message - 
> From: "John Neiberger" 
> To: 
> Sent: Tuesday, May 27, 2003 5:35 PM
> Subject: Re: port/duplex configs [7:69582]
> 
> 
> >  ian williams 5/27/03 10:29:21 AM >>>
> > >I have always configured ports on CAT switch to 100/full
> manually instead
> > of
> > >AUTO.
> > >What is recommended when asked this question for the CCIE
> written. Should
> > >both the end
> > >device ( NIC ) and switch both be configured to 100/FULL?
> >
> > I can't imagine why such a question would be asked on any
> exam since the
> > correct answer is that you configure whatever is necessary to
> establish a
> > connection with the end device.  In my opinion, you should
> always use AUTO
> > unless this causes problems, in which case you hard-set your
> devices to
> > 100/HALF, not 100/FULL.  If you'd like the rationale for that
> I refer you
> to
> > the archives for my previous rantings on this subject.
> >
> > I'd fall over in shock if you were to be asked a question
> like this on
> your
> > exam, but as long as you understand the issues involved you
> should be
> > adequately prepared for whatever question of this type that
> they throw at
> > you.
> >
> > Regards,
> > John
> 
> 


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69660&t=69582
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: Virtual Link Problem [7:69640]

2003-05-28 Thread Troy Leliard
Dont really have time at the moment to look into this, but something that
you may want to investigate is the different LSA adverts sent out by
different interface types in OSPF.  Depending on the type of interface OSPF
behaves different;y, ie different HELO timers, differnet DEAD timers etc. 
You need to ensure that all neighbors within the area are using the same
type.  You can change this using the interface command ip ospf network

Full details of of various interface types and how they affect OSPF can be
found on http://www.chuckslongroad.info/OSPF_Frame_Reference.htm

Kevin Love wrote:
> 
> Hey Team,
> 
> I cannot figure this out.  I've configured lots of virtual
> links, but no matter what I do this isn't working.  I had md5
> authentication configured for Area 0, but to isolate the
> problem, I removed authentication and the virtual link still
> isn't up.  I need another set of eyes (or two) looking at
> this.  Please help if you can!
> 
> Here's the topology:
> 
> Area 2 (Loopback 0)
>  |
>  R2
>\
> \
>  FR
>Area 1
>  /\
> R5R6
>  \/
>Area 0
>   Ethernet
> 
> Here are the salient config snippets:
> 
> R2
> !
> interface Loopback0
>  ip address 192.168.2.2 255.255.255.255
>  ip ospf network point-to-point
> !
> interface Serial1.256 multipoint
>  ip address 172.16.56.2 255.255.255.248
>  ip ospf priority 255
>  frame-relay map ip 172.16.56.2 105
>  frame-relay map ip 172.16.56.5 105 broadcast
>  frame-relay map ip 172.16.56.6 106 broadcast
>  no frame-relay inverse-arp
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.5.5
>  area 1 virtual-link 192.168.6.6
>  network 172.16.56.0 0.0.0.7 area 1
>  network 192.168.2.2 0.0.0.0 area 2
> !
> 
> R5
> 
> interface Ethernet0
>  ip address 172.16.200.5 255.255.255.128
>  ip ospf hello-interval 15
> !
> interface Serial0
>  ip address 172.16.56.5 255.255.255.248
>  encapsulation frame-relay
>  ip ospf network point-to-multipoint
>  frame-relay map ip 172.16.56.2 501 broadcast
>  frame-relay map ip 172.16.56.5 501
>  frame-relay map ip 172.16.56.6 501 broadcast
>  no frame-relay inverse-arp
>  frame-relay lmi-type cisco
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.2.2
>  network 172.16.56.0 0.0.0.7 area 1
>  network 172.16.200.0 0.0.0.127 area 0
>  network 192.168.5.5 0.0.0.0 area 5
> !
> 
> R6
> 
> interface Serial0
>  ip address 172.16.56.6 255.255.255.248
>  encapsulation frame-relay
>  ip ospf network point-to-multipoint
>  frame-relay map ip 172.16.56.2 601 broadcast
>  frame-relay map ip 172.16.56.5 601 broadcast
>  frame-relay map ip 172.16.56.6 601
>  no frame-relay inverse-arp
>  frame-relay lmi-type cisco
> !
> interface FastEthernet0
>  ip address 172.16.200.6 255.255.255.128
>  ip ospf hello-interval 15
>  half-duplex
> !
> router ospf 1
>  log-adjacency-changes
>  area 1 virtual-link 192.168.2.2
>  network 172.16.56.0 0.0.0.7 area 1
>  network 172.16.200.0 0.0.0.127 area 0
>  network 192.168.6.6 0.0.0.0 area 6
> !
> 
> R2#sh ip ospf vir
> Virtual Link OSPF_VL5 to router 192.168.5.5 is down
>   Run as demand circuit
>   DoNotAge LSA allowed.
>   Transit area 1, Cost of using 65535
>   Transmit Delay is 1 sec, State DOWN,
>   Timer intervals configured, Hello 10,  40, Wait 40,
> Retransmit 5
> Virtual Link OSPF_VL4 to router 192.168.6.6 is down
>   Run as demand circuit
>   DoNotAge LSA allowed.
>   Transit area 1, Cost of using 65535
>   Transmit Delay is 1 sec, State DOWN,
>   Timer intervals configured, Hello 10,  40, Wait 40,
> Retransmit 5
> R2#
> 
> Trust me on the router-IDs for the virtual link statements - I
> have triple-checked them.  I have reloaded the routers with no
> luck.  What am I missing here?!
> 
> Thanks!
> Kevin


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69663&t=69640
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Leased line/1721 problem [7:69573]

2003-05-28 Thread James Gosnold
Dear all,

Thank you all for your help and suggestions. Unfortunately when this line
went down I lost connectivity (because my company are a bunch of
tight-fisted *7^%$£" who rejected my suggestion of getting an ISDN card for
the 1721 to act as back-up in the event of the leased line dropping) to the
remote site and wasn't able to check the remote router.

I drove there this morning and couldn't even ping the router, so consoled
into it, and got a screen full of:

System Bootstrap, Version 12.2(7r)XM1, RELEASE SOFTWARE (fc1)
TAC Support: http://www.cisco.com/tac
Copyright (c) 2001 by cisco Systems, Inc.

*** Software Emulation Exception ***
PC = 0xfff13e40, Vector = 0x1000, SP = 0xff002500

*** Software Emulation Exception ***
PC = 0xfff16e54, Vector = 0x1000, SP = 0xff0024c8

*** Software Emulation Exception ***
PC = 0xfff16e48, Vector = 0x1000, SP = 0xff002490

*** Software Emulation Exception ***
PC = 0xfff16e48, Vector = 0x1000, SP = 0xff002458

*** Software Emulation Exception ***
PC = 0xfff16e48, Vector = 0x1000, SP = 0xff002420

*** Software Emulation Exception ***
PC = 0xfff16e48, Vector = 0x1000, SP = 0xff0023e8

Which I assume is the routers own little way of telling me that it has a
serious problem. I can't even send a 'break' or Ctrl + Brk to access the rom
monitor.

Thanks!


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69664&t=69573
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: new ccnp exams [7:69621]

2003-05-28 Thread GM
But the books you have described below do not cover all the exam objectives
for the new exams. What are you using as supplements?

Cheers
GM

""Nikolay Abromov""  wrote in message
news:[EMAIL PROTECTED]
> Hi,
>
>
> you can see new topics in cisco site:
>
http://www.cisco.com/en/US/learning/le3/le2/le37/le10/learning_certification_type_home.html
>
> i'm prepare for ccnp too and i'm useing "CCNP preparation books" from
> ciscopress
> "
>
http://www.ciscopress.com/catalog/product.asp?product_id={E565D23F-F066-44A3-B212-D96D4A11EBB1}
 "
>
> there are very good but they give you only that you
> need to pass the exam nothing else, of course that's my misunderstanding
for
> these ,)




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69665&t=69621
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Messagess Popup on workstation [7:69643]

2003-05-28 Thread GM
Hi,

If i recall correctly there was an extensive discussion in this regard on
this list. Have you tried searching the archives?

Cheers
GM

""Rohit Sundriyal""  wrote in message
news:[EMAIL PROTECTED]
> Hi All
>
> I am facing Starb=nge Problem on my lan. i am receving Popup messages on
> workstation .anyidea how to block these messages on pix .
>
> For more information Please visit http://http://www.4vsoft.com
>
>
>
> Rohit




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69666&t=69643
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: new ccnp exams [7:69621]

2003-05-28 Thread Nikolay Abromov
i'm not sure, i compare the indexes witch is on ciscopress site with
objectives from cisco.com and i think there is evrything what you can need.

about supplements, yes i use additional materials from my archive 
i have CBT simulators and training software and ofcourse lab for
testing.

that's for BSCI

http://www.ciscopress.com/isapi/product_id~{867573A8-E521-495D-B4EC-E5729B663071}/selectDescTypeId~{236B6D55-AB77-451A-92CA-F73B80E75B27}/st~{5A64A969-247A-47E1-8200-E6CA04EEDDA1}/session_id~{AA30C72E-D216-4FB2-B76B-CDF7F07DE0C1}/content/images/1587050846/index/1587050846Index.pdf








Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69667&t=69621
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Urgent Help Needed [7:69669]

2003-05-28 Thread Rohit Sundriyal
Hi All

I am facing very Strange Problem .My lan is behind Pix and for the last few
weeks i am receiving some popup messages on my lan pc from internet even
thought i am not browsing any site.Can anybudy tell how to block this kinda
messages on pix ???

For more information please visit http://www.4vsoft.com
(Software that is used for sending this kinda messages.)



Thanks
Rohit




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69669&t=69669
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Messagess Popup on workstation [7:69643]

2003-05-28 Thread Rohit Sundriyal
Nope havent see any till now .

rohit
""GM""  wrote in message
news:[EMAIL PROTECTED]
> Hi,
>
> If i recall correctly there was an extensive discussion in this regard on
> this list. Have you tried searching the archives?
>
> Cheers
> GM
>
> ""Rohit Sundriyal""  wrote in message
> news:[EMAIL PROTECTED]
> > Hi All
> >
> > I am facing Starb=nge Problem on my lan. i am receving Popup messages on
> > workstation .anyidea how to block these messages on pix .
> >
> > For more information Please visit http://http://www.4vsoft.com
> >
> >
> >
> > Rohit




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69670&t=69643
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: CCNP Re-certification [7:69556]

2003-05-28 Thread Jurkouich, Brett, CNTR, DCAA
What is the passing score?  Is this a new style test?  I need to renew
mine in October and am not looking forward to it.

Brett

-Original Message-
From: Kevin Wigle [mailto:[EMAIL PROTECTED] 
Sent: Tuesday, May 27, 2003 7:32 PM
To: [EMAIL PROTECTED]
Subject: Re: CCNP Re-certification [7:69556]


Replying to my own post

The exam is 2 hours, Prometric must have issues with it's database.

Failed it again today but with a lot better score - don't exactly feel
good about that though.

I still have issues with the router simulator questions.

There are problems with it.  It does not give the same results as the
real thing.  For one scenario it didn't even respond properly but the
command worked.  You couldn't tell the command worked until you looked
at the config.

However, knowing the quirks helped me get a better score this time, I
hope 3rd time lucky.

I'll be trying it again soon.  CCNP expires in June.

Kevin Wigle

- Original Message -
From: "Kevin Wigle" 
To: 
Sent: Monday, May 26, 2003 10:36 PM
Subject: CCNP Re-certification [7:69556]


> I failed my first attempt 2 weeks ago.  Back then the exam was 2 hours

> - also confirmed by a review by Priscilla.
>
> A recently booked a second attempt and both the web page at the time 
> of booking and the confirmation email now says that the exam is 3 
> hours.
>
> There have not been many positive reviews of this exam.
>
> Has anybody heard that Cisco might be fiddling with it? Like giving 
> more time?
>
> Kevin Wigle




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69668&t=69556
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


Re: Re: BGP Load Balance [7:69611]

2003-05-28 Thread ramesh_cisco
BGP load balancing can be done using BGP peering on loopback address .And
you have to add static routes in


your routing table for loopback ip address and mention next-hop as serial
links ip addresses/serial interface


example:


nei loopbackip remote-as asnumber


nei loopbackip ebgp-multihop number 


and then


 


ip route loopback ip 255.255.255.255 serialx


ip route loopback ip 255.255.255.255 serialy


 


hope this will help you


Ramesh

"Brian W." wrote:



The way I've seen 2 paths used is by peering with a loopback interface and
using
neighbor peerip ebgp-multihop in the config.

Brian

- Original Message - 
From: "Azhar Teza" 
To: 
Sent: Tuesday, May 27, 2003 3:16 PM
Subject: BGP Load Balance [7:69611]


> If BGP route has two equal paths to the same destination, can it do load
> balance by installing the command? maximum-paths 2
>
> ___
> Join Excite! - http://www.excite.com
> The most personalized portal on the Web!
Get Your Private, Free E-mail from Indiatimes at  http://email.indiatimes.com
Buy The Best In BOOKS at http://www.bestsellers.indiatimes.com
Bid for Air Tickets @ Re.1 on Air Sahara Flights. Just log on to
http://airsahara.indiatimes.com and Bid Now !




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69671&t=69611
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]


RE: Cisco Switches with Stonebeat [7:69505]

2003-05-28 Thread Ross McCormick
Have you checked on Stonebeat's site?  They have a number of articles
relating to Cisco equipment and Stonebeat depending on the equipment involved.

In particular,
http://www.stonesoft.com/estone/support/knowledgebase/view.html?id=000475&q=cisco

HTH


Bikespace wrote:
> 
> Hi All,
> 
> Anybody got tales to tell about working with Stonebeat?
> 
> I've been having some fun recently. Everything else seems to be
> able to see
> the firewall, but the Cisco is struggling, so devices on the
> same VLAN
> manage OK, because they ARP straight for the firewall. Devices
> on other
> VLAN's don't get through (the firewalls are connected to the
> Cisco
> directly).
> 
> I've put static ARP entries in for the Firewall. The crunch is
> the multicast
> address used by the FIrewall (It's not VRRP which would be fine
> - it's
> definitely a Multicast 01005e)
> 
> Cisco suggested enabling IP IGMP snooping. Yeah great - it's on
> by default
> on the 4500.
> 
> I know Cisco's can not ARP for multicast addresses. I know you
> can't add
> static MAC entries for multicast, but this wouldn't help me too
> much anyway
> as the virtual address will obviously move.
> 
> The switch must know where to forward the packets to as devices
> on the same
> VLAN are working, although it did not work until I put IP
> redirects on. I
> would have expected it to forward every packet individually
> even without IP
> redirect???
> 
> It's a bit of a sod as the customers switch is allowed about
> half an hours
> down time when organised a week ahead and its a couple of hours
> away anyway.
> Didn't give my brain time to churn before time was up.
> 
> I may not get round this without actually setting up Stonebeat
> in full to
> test with, so I'm looking for "ANY" tips hints tricks before I
> bite the
> bullet.
> 
> 
> I've prattled on enough for now.
> 
> Cheers,
> 
> Bikespace
> 
> 




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=69672&t=69505
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]