ccbootcamp is down [7:74046]

2003-08-17 Thread Leon Zhao
anyone know why? Thanks.

Regards,
Leon




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74046t=74046
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: BSCI 640-901 [7:74056]

2003-08-17 Thread Aspiring Cisco Gurl
Can you please inform us of what did you download on the web regarding the
IS-IS?  I heard there was a sample chapter on IS-IS but is this what you are
referring to?  Please help, I am going for my BSCI now.  I only have the
Sybex book but I am looking for good labs for these.


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74067t=74056
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: Trunking ISl and 802.1q [7:74059]

2003-08-17 Thread Aspiring Cisco Gurl
How much or how did you pick up a 3550?  I thought they were so expensive? 
Please do tell...


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74066t=74059
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: Books for CCNP [7:74010]

2003-08-17 Thread Nakul Malik
I recommend :

 Sam halabi - OSPF Design Guide
 Jeff Doyle - The OSPF part

EIGRP - Cisco Press - BSCI
Jeff Doyle - EIGRP Part (just sections, not the whole thing)

Sam Halabi - BGP Case Studies
Avi Freedman's Slides (I recommend printing them and getting them spiral
bound)

-Nakul



June Domingo  wrote in message
news:[EMAIL PROTECTED]
 Robert, thanks for your advice


 Regards,

 Bernie
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74068t=74010
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: BSCI 640-901 [7:74056]

2003-08-17 Thread Nakul Malik
there are sites which let u download ISIS slides and tutorials.
put this in google:

IS-IS wrote in message
news:[EMAIL PROTECTED]
 Can you please inform us of what did you download on the web regarding the
 IS-IS?  I heard there was a sample chapter on IS-IS but is this what you
are
 referring to?  Please help, I am going for my BSCI now.  I only have the
 Sybex book but I am looking for good labs for these.
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74070t=74056
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Spare Catalyst 4506 IOS [7:74071]

2003-08-17 Thread lat tos
Hi,
I have some 4506 (Sup IV module with enhanced L3 IOS) on the network and I
want to purchase spare modules and chasis for them.
My question is do I have to purchase IOS for the spare supervisor engine
modules?
I feel I need to purchase IOS for only the ones active/installed on the
network but I am not too sure about it. I wouldnt like to violate any
licensing agreements.
Thanx


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74071t=74071
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: Trying run ISIS on 2600 [7:74051]

2003-08-17 Thread Jens Neelsen
Hi,

I checked on cisco.com and found IS-IS is supported in IOS
software feature sets Enterprise Plus and Service Provider.

With kind regards
Jens Neelsen

--- irfan siddiqui  wrote:
 I am trying to run ISIS on a 2600 series router however it
 does not accept 
 the CLNS and ISIS routing commands at the Config mode. I am
 using IOS IP 
 version only? Do i need IP plus version to configure ISIS??
 
 Thanks
 

_
 The new MSN 8: smart spam protection and 2 months FREE*  
 http://join.msn.com/?page=features/junkmail
 **Please support GroupStudy by purchasing from the GroupStudy
 Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74072t=74051
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


When are CCIP Course Books Coming out? [7:74073]

2003-08-17 Thread Mwalie W
Hello Members,

Just asking whether anyone out there knows when course books for Cisco's
CCIP certification are coming out, especially for BGP and QoS.

I hope to get a BGP one as a reference, because the course (and hence the
course book) covers more than what is available in Sam's Internet Routing
Architectures.

Thanks.

Mwalie




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74073t=74073
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: wireless security and VPN software? [7:73988]

2003-08-17 Thread Charlie Wehner
Very true.  The clients are the most vulnerable before the VPN session is
established.  Without PSPF enabled clients can attack other clients on an
access point.  Even with PSPF enabled an attacker could put up a rogue with
the same SSID and WEP key if used and try to attack/trojan the client.

It's interesting though, the new IOS firmware has crypto map statements
available.  I wonder if Cisco will eventually allow VPN sessions to
terminate directly on the access points.  That would be pretty cool.  Much
like what Colubris does right now.

Reimer, Fred wrote:
 
 Hmm, PSPF definitely sounds interesting, but I'd recommend
 requiring the
 integrated Cisco firewall in the VPN client, and not allowing
 split
 tunneling.
 
 Also, there is apparently a working group working on VPN
 multicast...
 
 Fred Reimer - CCNA
 
 
 Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA
 30338
 Phone: 404-847-5177  Cell: 770-490-3071  Pager: 888-260-2050
 
 
 NOTICE; This email contains confidential or proprietary
 information which
 may be legally privileged. It is intended only for the named
 recipient(s).
 If an addressing or transmission error has misdirected the
 email, please
 notify the author by replying to this message. If you are not
 the named
 recipient, you are not authorized to use, disclose, distribute,
 copy, print
 or rely on this email, and should immediately delete it from
 your computer.
 
 
 -Original Message-
 From: Charlie Wehner [mailto:[EMAIL PROTECTED] 
 Sent: Saturday, August 16, 2003 4:14 PM
 To: [EMAIL PROTECTED]
 Subject: RE: wireless security and VPN software? [7:73988]
 
 One more quick note on using VPN solutions.  If your using a
 VPN solution
 with a Cisco AP be sure to enable PSPF.  Everyone misses that
 setting...
 but it's important.  :)
 **Please support GroupStudy by purchasing from the GroupStudy
 Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
 http://www.groupstudy.com/list/cisco.html
 
 




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74074t=73988
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: When are CCIP Course Books Coming out? [7:74073]

2003-08-17 Thread Karl HUTCHINSON
The Sybex ones got a bit stalled on the MPLS Book Exam #640-910.  See my
review on Amazon.com..quite frankly you would think the proof readers
were on something mind bending.  I've come across a couple of people who
reckon MPLS is a real pig of an exam and have failed it several times...so
be warned.


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74075t=74073
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: OT Microsoft worm [7:74045]

2003-08-17 Thread Reimer, Fred
I agree with you.  Again, without naming names, I know several customers
that have not upgraded their IOS software to patch the IPv4 vulnerability,
and some don't even have a plan or schedule to do so!  We upgraded to
appropriate code quite quickly after we were aware of the problem.

Imagine if the recent worm had a timer set not to attack Microsoft's site,
but instead to attack Cisco routers with that vulnerability.  Use a
Microsoft bug to DDoS on Cisco gear!  That would have been catastrophic.

Fred Reimer - CCNA


Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA 30338
Phone: 404-847-5177  Cell: 770-490-3071  Pager: 888-260-2050


NOTICE; This email contains confidential or proprietary information which
may be legally privileged. It is intended only for the named recipient(s).
If an addressing or transmission error has misdirected the email, please
notify the author by replying to this message. If you are not the named
recipient, you are not authorized to use, disclose, distribute, copy, print
or rely on this email, and should immediately delete it from your computer.


-Original Message-
From: Chuck Whose Road is Ever Shorter [mailto:[EMAIL PROTECTED] 
Sent: Saturday, August 16, 2003 11:26 PM
To: [EMAIL PROTECTED]
Subject: Re: OT Microsoft worm [7:74045]

Reimer, Fred  wrote in message
news:[EMAIL PROTECTED]
 For reasons of confidentiality I won't and can't name any names, but I am
 aware of several hospitals that were affected pretty seriously.  Everyone
 here knows that Cisco Call Manager runs on Windows, so imagine what
happens
 to your entire phone infrastructure if you are running VoIP.  Network
grinds
 to a halt and admitting can't access the applications to admit people in
the
 ER.  Lab orders don't go through, so meds can't be dispersed based on the
 results of tests.  Everything goes back to a paper fall-back scheme until
 the Windows administrators patch the systems like they should have done
 weeks ago.

 So no, don't assume that even large organizations have a handle on things.
 Especially hospitals which are notoriously on the low end as far as
 adequately staffing, at the right levels, their IT staff.

 One thing I sincerely hope is changed in our lexicon is calling Windows
 administrators network administrators.  It makes me physically ill,
 because those folks don't administer the network, if anything they
 actually do can be classified as competent administration.  They should be
 called what they are systems administrators, or, if you want to be more
 specific, Windows administrators.  I personally think they deserve a
 classification of their own.

 All I can say is that the Windows systems that our group has to use and is
 responsible for were patched long ago, and did not exhibit any issues.


in fairness to all, Cisco is starting to be hit with attacks geared
specifically towards Cisco routers and Cisco IOS. Seems to me I saw a couple
of serious attacks announced the other day.

We can chuckle and snicker and point fingers at Microsoft, but all vendors
are vulnerable. When the hacker community wants to turn its attention to
Linux, or Solaris, or MacOS, those systems will take it in the shorts too.




 Fred Reimer - CCNA


 Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA 30338
 Phone: 404-847-5177  Cell: 770-490-3071  Pager: 888-260-2050


 NOTICE; This email contains confidential or proprietary information which
 may be legally privileged. It is intended only for the named recipient(s).
 If an addressing or transmission error has misdirected the email, please
 notify the author by replying to this message. If you are not the named
 recipient, you are not authorized to use, disclose, distribute, copy,
print
 or rely on this email, and should immediately delete it from your
computer.


 -Original Message-
 From: Priscilla Oppenheimer [mailto:[EMAIL PROTECTED]
 Sent: Saturday, August 16, 2003 1:22 PM
 To: [EMAIL PROTECTED]
 Subject: OT Microsoft worm [7:74045]

 Just wondering, is this new LOVSAN msblast worm as big as it seems to be?
 I've been helping lots of Windows users clean up their machines. They all
 had the worm. These are mostly home users. I can't believe they would use
 broadband, always-on access and not have a firewall, but they didn't!

 What are you all seeing? Is this a big one? I suppose enterprise networks
 are much better protected (hopefully) than the home networks I've been
 helping out with.

 One has to wonder if the huge power outage could be related. I can imagine
a
 Windows computer somewhere in Ohio that played a surprisingly important
role
 in keeping the grid working and had been infected. But I read a lot of
 science fiction. :-)

 By the way, the stupid worm is attacking the wrong Microsoft URL! So that
 aspect of it isn't going to be as bad as once thought.

 Comments?

 Priscilla
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and 

Exam #642-891 BSCN/BCMSN Composite Exam. [7:74077]

2003-08-17 Thread Karl HUTCHINSON
Has anyone taken #642-891 the BSCI and BCMSN Composite exam?  I have tried
to find it on the www.2test.com site to no avail either to book or its cost
in US Dollars, UK Pounds or Euros.  It seems to be replacing #642-841
Foundations which does not seem to be re-incarnated in any other form as
BCRAN has now to be taken seperately like CIT has to be.

The other strange thing I noted was that the CCNP recertification for the
future specifies #642-891 alone!  No BCRAN questions it appears on
re-certification.  What is happening to BCRAN?  This exam also is slightly
strange as it is only 60 minutes instead of the usual 75 or 90.  With the
dropping of BCRAN in CCDP where is remote access off to, no more Modems or
ISDN?  Isn't progress rapid or wonderful...


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74077t=74077
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: can't ping any ip on the network from SC0 [7:74064]

2003-08-17 Thread Reimer, Fred
There are know bugs in the IOS/CatOS hybrid code where the cef adjacencies
are not updated correctly.  Basically, the MSFC thinks it programmed the SUP
caches correctly, when it did not.  If you are on an old version of code, I
would suggest upgrading to a later version.  I don't have the bug ID
handy...

Other than that, we would need more information on your setup.  Change the
IPs if necessary.

Fred Reimer - CCNA


Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA 30338
Phone: 404-847-5177  Cell: 770-490-3071  Pager: 888-260-2050


NOTICE; This email contains confidential or proprietary information which
may be legally privileged. It is intended only for the named recipient(s).
If an addressing or transmission error has misdirected the email, please
notify the author by replying to this message. If you are not the named
recipient, you are not authorized to use, disclose, distribute, copy, print
or rely on this email, and should immediately delete it from your computer.


-Original Message-
From: Hitesh Pathak R [mailto:[EMAIL PROTECTED] 
Sent: Saturday, August 16, 2003 10:18 PM
To: [EMAIL PROTECTED]
Subject: can't ping any ip on the network from SC0 [7:74064]

Dear Group,
 
I am having a strange issue out here, I have a network running with 2 x 6506
core switches conencted back2back. I can ping all the IPs on my metwork from
the one of the switches MSFC console but not from the SC0 of the same
switch. If I completly shutdown my problematic switch then everything comes
up properly including inter vlan routing. I am having cat 3500XL in my
access layer conected to both the core switches with fibre redundant
uplinks.
 
Does any body faced similar problem ??
Many thnx in advance..
 
Regds
Hitesh
 

**Disclaimer

Information contained in this E-MAIL being proprietary to Wipro Limited is 
'privileged' and 'confidential' and intended for use only by the individual
 or entity to which it is addressed. You are notified that any use, copying 
or dissemination of the information contained in the E-MAIL in any manner 
whatsoever is strictly prohibited.

***
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74080t=74064
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Passed my CCNP [7:74076]

2003-08-17 Thread Kenneth
Hiyah everyone,

Been quite busy of late, preparing for the exams, so I haven't checked this
site for ages, and my e-mail was full...

Neway, as the subject heading, I just wanted to say that I'm now a CCNP. 

Took 3 papers in bout 2 weeks, before the changes took effect. I found
Support to be the most challenging.

Well, time to end the festivities and begin preparing for the fearful CCIE..
though I'm not sure whether I should head off into Security or RS.


Kenneth
CCNP, CCDA


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74076t=74076
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: Exam #642-891 BSCN/BCMSN Composite Exam. [7:74077]

2003-08-17 Thread Karl HUTCHINSON
Sorry should have read #642-891 BSCI/BCMSN Composite Exam!


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74078t=74077
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: ccbootcamp is down [7:74046]

2003-08-17 Thread Marc Russell
We are back up now. We were hit with the electrical Blackout.

Marc Russell
www.ccbootcamp.com (Cisco Training)



Leon Zhao  wrote in message
news:[EMAIL PROTECTED]
 anyone know why? Thanks.

 Regards,
 Leon
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74069t=74046
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


QoS Exam 642-641 [7:74081]

2003-08-17 Thread Charlie Wehner
Taking this bad boy tomorrow...  and advice?  All of the new exams seem to
be quite a bit more painful than the old ones.  Or at least more difficult
in my opinion...


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74081t=74081
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: ACL for DMVPN [7:74028]

2003-08-17 Thread mccloud mike
looks like tcp 47, 50 and udp 500
http://www.cisco.com/en/US/customer/products/hw/routers/ps4081/products_tech_note09186a0080094267.shtml

Mike

Thomas N wrote:
 
 I got a lab setup simulating DMVPN with IPSec over GRE.  I
 would like to
 apply an access control list to the outside interface of the
 routers to
 block everything, except for TCP/UPD ports that are needed for
 GRE, IPSec,
 IKE and those related to DMVPN implementation.  Does someone
 know what ports
 should I open on the ACL?  Thanks!
 
 Thomas
 
 




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74084t=74028
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: ACL for DMVPN [7:74028]

2003-08-17 Thread mccloud mike
Thomas N wrote:
 
 I got a lab setup simulating DMVPN with IPSec over GRE.  I
 would like to
 apply an access control list to the outside interface of the
 routers to
 block everything, except for TCP/UPD ports that are needed for
 GRE, IPSec,
 IKE and those related to DMVPN implementation.  Does someone
 know what ports
 should I open on the ACL?  Thanks!
 
 Thomas
 
 




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74083t=74028
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: BSCI 640-901 [7:74056]

2003-08-17 Thread Nakul Malik
it seems that the message got garbled somehow.
I will post the search terms again tomorrow.
-Nakul

Nakul Malik  wrote in message
news:[EMAIL PROTECTED]
 there are sites which let u download ISIS slides and tutorials.
 put this in google:

 IS-IS wrote in message
 news:[EMAIL PROTECTED]
  Can you please inform us of what did you download on the web regarding
the
  IS-IS?  I heard there was a sample chapter on IS-IS but is this what you
 are
  referring to?  Please help, I am going for my BSCI now.  I only have the
  Sybex book but I am looking for good labs for these.
  **Please support GroupStudy by purchasing from the GroupStudy Store:
  http://shop.groupstudy.com
  FAQ, list archives, and subscription info:
 http://www.groupstudy.com/list/cisco.html
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74082t=74056
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: GRE Tunnel Recursive Routing Error [7:74035]

2003-08-17 Thread Dain Deutschman
I would think security point of view...there would be better
solutions...however...this is just a lab scenario. Thanks so much for your
help though. I see the problem now and changed the static route to point to
tunnel destination.

Thanks!

Dain

Zsombor Papp  wrote in message
news:[EMAIL PROTECTED]
 r1 (bb2) learns the route to the destination of the GRE tunnel,
150.50.22.2,
 via that same GRE tunnel. Add a static route like this to r1's
configuration:

 ip route 150.50.22.2 255.255.255.255 Ethernet0

 As a side note, is this (GRE tunnel through the PIX) a good design from
the
 security point of view?

 Thanks,

 Zsombor

 Dain Deutschman wrote:
 
  Hi all,
 
  I'm getting a recursive routing error when trying to tunnel
  with gre.
 
  r1-pix-r2
 
  The error follows along with my configs and route tables.
 
  Thanks!
 
 
  00:52:21: %LINEPROTO-5-UPDOWN: Line protocol on Interface
  Tunnel0, changed
  state
   to down
  bb2#
  00:53:21: %LINEPROTO-5-UPDOWN: Line protocol on Interface
  Tunnel0, changed
  state
   to up
  00:53:30: %TUN-5-RECURDOWN: Tunnel0 temporarily disabled due to
  recursive
  routin
  g
  00:53:31: %LINEPROTO-5-UPDOWN: Line protocol on Interface
  Tunnel0, changed
  state
   to down
  00:54:31: %LINEPROTO-5-UPDOWN: Line protocol on Interface
  Tunnel0, changed
  state
   to up
  00:54:40: %TUN-5-RECURDOWN: Tunnel0 temporarily disabled due to
  recursive
  routin
  g
 
  bb2#wr t
  Building configuration...
 
  Current configuration : 913 bytes
  !
  version 12.1
  service timestamps debug uptime
  service timestamps log uptime
  no service password-encryption
  !
  hostname bb2
  !
  !
  !
  !
  !
  !
  ip subnet-zero
  ip domain-name hellocomputers.com
  ip name-server 4.1.1.1
  !
  !
  !
  !
  !
  !
  interface Loopback0
   ip address 112.112.112.112 255.255.255.0
  !
  interface Tunnel0
   ip address 172.16.22.112 255.255.255.0
   tunnel source 10.10.112.112
   tunnel destination 150.50.22.2
  !
  interface Ethernet0
   ip address 10.10.112.112 255.255.255.0
  !
  interface Serial0
   no ip address
   shutdown
   no fair-queue
  !
  interface Serial1
   no ip address
   shutdown
  !
  interface BRI0
   no ip address
   shutdown
   isdn x25 static-tei 0
  !
  router eigrp 100
   network 172.16.0.0
   no auto-summary
   no eigrp log-neighbor-changes
  !
  ip classless
  ip route 0.0.0.0 0.0.0.0 10.10.112.12
  ip route 172.16.22.2 255.255.255.255 Ethernet0
  ip http server
  !
  !
  alias exec c config t
  !
  line con 0
  line aux 0
  line vty 0 4
   login
  !
  end
 
  bb2#
 
  r2#wr t
  Building configuration...
 
  Current configuration : 2557 bytes
  !
  version 12.2
  service timestamps debug uptime
  service timestamps log uptime
  service password-encryption
  !
  hostname r2
  !
  logging buffered 4096 debugging
  !
  username all
  memory-size iomem 10
  ip subnet-zero
  !
  !
  ip domain name hellocomputers.com
  ip name-server 4.1.1.1
  !
  ip audit notify log
  ip audit po max-events 100
  !
  !
  !
  key chain keyr2
   key 1
key-string 7 151A0E000825
  !
  voice call carrier capacity active
  !
  !
  !
  !
  !
  !
  !
  !
  !
  mta receive maximum-recipients 0
  !
  !
  !
  !
  interface Loopback0
   ip address 22.22.22.22 255.255.255.0
  !
  interface Tunnel0
   ip address 172.16.22.2 255.255.255.0
   tunnel source 150.50.22.2
   tunnel destination 150.50.22.112
  !
  interface FastEthernet0/0
   ip address 150.50.22.2 255.255.255.0
   ip rip authentication mode md5
   ip rip authentication key-chain keyr2
   duplex auto
   speed auto
  !
  interface Serial0/0
   no ip address
   encapsulation frame-relay
   frame-relay lmi-type ansi
  !
  interface Serial0/0.21 point-to-point
   ip address 150.50.12.2 255.255.255.0
   ip ospf authentication message-digest
   ip ospf message-digest-key 1 md5 7 04530E0A032E
   ip ospf network point-to-point
   frame-relay interface-dlci 121
  !
  interface Serial0/0.23 point-to-point
   ip address 150.50.23.2 255.255.255.0
   ip ospf authentication message-digest
   ip ospf message-digest-key 1 md5 7 130D121E0703
   frame-relay interface-dlci 123
  !
  interface Serial0/0.24 point-to-point
   ip address 150.50.24.2 255.255.255.0
   ip ospf authentication message-digest
   ip ospf message-digest-key 1 md5 7 011B03085704
   frame-relay interface-dlci 124
  !
  interface FastEthernet0/1
   no ip address
   shutdown
   duplex auto
   speed auto
  !
  interface Serial0/1
   no ip address
   shutdown
  !
  router eigrp 100
   network 150.50.0.0
   network 172.16.0.0
   no auto-summary
   no eigrp log-neighbor-changes
  !
  router ospf 100
   router-id 22.22.22.22
   log-adjacency-changes
   area 1 virtual-link 11.11.11.11
   network 22.22.22.0 0.0.0.255 area 1
   network 150.50.12.0 0.0.0.255 area 1
   network 150.50.23.0 0.0.0.255 area 2
   network 150.50.24.0 0.0.0.255 area 1
  !
  router rip
   version 2
   passive-interface Serial0/0.21
   passive-interface Serial0/0.23
   passive-interface Serial0/0.24
   network 150.50.0.0

My CCNP expired about a week ago ? [7:74085]

2003-08-17 Thread johnman johnman
My CCDP is valid for a year. Can I  take the CIT exam and get a CCNP which 
expired about a week ?

_
Add photos to your messages with MSN 8. Get 2 months FREE*.  
http://join.msn.com/?page=features/featuredemail




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74085t=74085
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: ACL for DMVPN [7:74028]

2003-08-17 Thread Reimer, Fred
I don't know about the DMVPN, or what it even is, but for a standard IPsec
VPN the ports would be UDP 500, and PROTOCOLS 50 and 51.  Now, that is
assuming that there is no NAT going on, and you are using tunnel mode, so
that you don't see the GRE tunnel in the first header.  If there is NAT,
then you need to know what type of NAT you are using.  If you are using
standard NAT-T translation, then the port number would be UDP 4500, and you
would not need PROTOCOL 50 or 51 (I think).  You would still need UDP 500
which is IKE and is used to setup the IPsec tunnel and negotiate NAT
translation, etc.

Fred Reimer - CCNA


Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA 30338
Phone: 404-847-5177  Cell: 770-490-3071  Pager: 888-260-2050


NOTICE; This email contains confidential or proprietary information which
may be legally privileged. It is intended only for the named recipient(s).
If an addressing or transmission error has misdirected the email, please
notify the author by replying to this message. If you are not the named
recipient, you are not authorized to use, disclose, distribute, copy, print
or rely on this email, and should immediately delete it from your computer.


-Original Message-
From: mccloud mike [mailto:[EMAIL PROTECTED] 
Sent: Sunday, August 17, 2003 4:18 PM
To: [EMAIL PROTECTED]
Subject: RE: ACL for DMVPN [7:74028]

looks like tcp 47, 50 and udp 500
http://www.cisco.com/en/US/customer/products/hw/routers/ps4081/products_tech
_note09186a0080094267.shtml

Mike

Thomas N wrote:
 
 I got a lab setup simulating DMVPN with IPSec over GRE.  I
 would like to
 apply an access control list to the outside interface of the
 routers to
 block everything, except for TCP/UPD ports that are needed for
 GRE, IPSec,
 IKE and those related to DMVPN implementation.  Does someone
 know what ports
 should I open on the ACL?  Thanks!
 
 Thomas
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74087t=74028
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: Trunking ISl and 802.1q [7:74059]

2003-08-17 Thread Paul Ingram
They are very expensive!  I was able to get one through our purchase of an
AVVID solution at work.  I got it for training and I can run home and get it
for a hot spare if needed.  I was told if I get my CCNP and Voice Specialist
I could have it so...
We did get these at a very good price.  CISCO was really pushing to install
the IPCC over the AVAYA  3Com solutions we where looking at.  I just hope
we did not jump in over our heads.  But anything has to be better then the
old ROLM we had.

~Paul~

 -Original Message-
 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
 Sent: Sunday, August 17, 2003 1:42 AM
 To: [EMAIL PROTECTED]
 Subject: RE: Trunking ISl and 802.1q [7:74059]
 
 How much or how did you pick up a 3550?  I thought they were so expensive?
 Please do tell...
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
 http://www.groupstudy.com/list/cisco.html

---
{This E-mail scanned for viruses by Declude Virus/McAfee}




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74088t=74059
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


Re: My CCNP expired about a week ago ? [7:74085]

2003-08-17 Thread Kevin Wigle
Nope, you're out of luck.

http://www.cisco.com/application/pdf/en/us/guest/learning/le3/c585/ccmigration_09186a00800a32c8.pdf

The following is a copy/paste from the above link:

14. What is the impact on me when my certification expires?
You may no longer represent yourself as a holder of that certification or
use the designation on your business card. And once your certification
expires, you will no longer be able to recertify with a single exam. If you
want the same certification, you will have to start over and complete all
prerequisites and exams.

This has been talked about previously on this list.

Kevin Wigle

- Original Message - 
From: johnman johnman 
To: 
Sent: Sunday, August 17, 2003 4:34 PM
Subject: My CCNP expired about a week ago ? [7:74085]


 My CCDP is valid for a year. Can I  take the CIT exam and get a CCNP which
 expired about a week ?

 _
 Add photos to your messages with MSN 8. Get 2 months FREE*.
 http://join.msn.com/?page=features/featuredemail
 **Please support GroupStudy by purchasing from the GroupStudy Store:
 http://shop.groupstudy.com
 FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74089t=74085
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html


RE: When are CCIP Course Books Coming out? [7:74073]

2003-08-17 Thread Mwalie W
Karl,

Thanks.

I think I have to give MPLS sufficient time; like you have said, I hear that
failing it is normal.

Thanks.


Message Posted at:
http://www.groupstudy.com/form/read.php?f=7i=74090t=74073
--
**Please support GroupStudy by purchasing from the GroupStudy Store:
http://shop.groupstudy.com
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html