RE: logging the access on a router [7:34346]

2002-02-04 Thread Alex Lei
Hello, You can use access lists to log it. You can use either logging buffered (limited in number of entries) or use a dedicated log server. Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=34353&t=34346 -- FAQ, list archives

RE: 3DES [7:34756] AES? [7:34863]

2002-02-08 Thread Alex Lei
FIPS197 was declared as the new AES in November, 2001. The standard will be in effect in May, 2002. When do we see it in actual products... not too sure. http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=34865&t=34863 --

RE: Need Cisco guru help [7:34864]

2002-02-08 Thread Alex Lei
I have a feeling this is a mismatch type of problem. Please see the link below: http://www.cisco.com/univercd/cc/td/doc/cisintwk/itg_v1/tr1918.htm Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=34866&t=34864 -- FAQ, list archives

RE: CIT Test [7:34856]

2002-02-08 Thread Alex Lei
I don't think it was difficult, it was simply illy - organized and poorly worded. As always, if it's too confusing to reason, process of elimination works great. Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=34867&t=34856 -

Cisco Symposium 2002 [7:36673]

2002-02-27 Thread Alex Lei
Not sure if most of you already received this. https://www.cisco-eventreg.com/cpn2002/ Training sessions, free test, and if are already a qualified lab candidate, free CCIE lab test. Hurry up, the sessions are filling up really quickly. Alex Message Posted at: http://www.groupstudy.com/form/r

concentrator 3000 vs. checkpoint vpn [7:37474]

2002-03-06 Thread Alex Lei
Group, Has anyone used both concentrator 3000 and checkpoint vpn (either software or hardware)? What are each's advantages and disadvantages? I am interested in the following factors: Ease of installation and configuration, security, manageability, reporting and logging, scalability, and pricing.

RE: Embryonic connections [7:38451]

2002-03-15 Thread Alex Lei
I think it refers to half open TCP connections. For example, you may have a whole bunch of SYN requests that your box has ACKed, but has not received a SYN ACK from. Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=38461&t=38451 -

RE: MCNS Boson test [7:40224]

2002-04-02 Thread Alex Lei
Hello, I used Bernard Omrani's test (#2, I think). I liked the questions, and Bernard replied promptly when I took issue with one of the questions. Alex Ole Drews Jensen wrote: > > This doesn't answer your question perfectly, but could be a > good advise. > > What I do is to take all the test

RE: BGP question [7:40525]

2002-04-04 Thread Alex Lei
Steve, Why is redistribution into an IGP a big no - no? My understanding is that this is what people usually do. If you use OSPF and E2 routes on the third router, then OSPF should find the optimal route. Alex Steven A. Ridder wrote: > > If I had 2 7206 routers dual homed to two different ISP

RE: BGP question [7:40525]

2002-04-04 Thread Alex Lei
That pretty much rules out redistributing into IGP. I am thinking that Steve's original suggestion is the only way to go, but I feel that there may be a problem accepting full routes from two different providers. Any comments? Alex [EMAIL PROTECTED] wrote: > > I'm no BGP guru, but I would have

RE: vpn [7:26452]

2001-11-16 Thread Alex Lei
If I understand you correctly, yes. The real destination IP is hidden, and the destination IP address visible to the internet is the VPN server on the other side. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=26511&t=26452 -- FAQ

RE: OSPF and E2's, why default? [7:27390]

2001-11-26 Thread Alex Lei
Hello Christopher, If I am not mistaken, E2 is always used by default, but if E1 and E2 are both available for the same destination, E1 will be used. http://www.cisco.com/warp/public/104/3.html Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=27403&t=27390 -

RE: 2500 Router problem [7:27695]

2001-11-29 Thread Alex Lei
Hello James, Since your router 2 IP is on a different subnet you need to have either routes set up; or run some kind of routing protocol. Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=27696&t=27695 -- FAQ, list archives, a

RE: Diffle-Hellman Exchange Question [7:27952]

2001-12-03 Thread Alex Lei
Hello Hunt, In my understanding the shared key never go across the network. Each peer computes it out separately. Where did you see in CCO saying that the DES key is sent across the internet? Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=27998&t=27952 --

RE: Diffle-Hellman Exchange Question [7:27952]

2001-12-03 Thread Alex Lei
I have a link here for your reference. Read the section on RSA. http://www.cisco.com/warp/public/105/IPSECpart3.html Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=27999&t=27952 -- FAQ, list archives, and subscription info: http:

OT: outlook bashing [7:28107]

2001-12-04 Thread Alex Lei
I wish it was easier to be security - conscious with Microsoft products.. but outlook is very difficult to secure. For a lot of users, it's tedious for them to disable preview panel and automatic preview; increase attachment security level and macros security level. These features should have neve

RE: CCIE written questions [7:28862]

2001-12-11 Thread Alex Lei
Hello Ike, >From your email address I know you are based in China. Perhaps you are not very aware of Cisco's lawyer's fearsome powers due to geographical distance. I mean no ill will and this is simply a friendly reminder, but please refrain from posting actual test questions. You signed the Non

RE: CCIE Lab Book Review [7:28991]

2001-12-12 Thread Alex Lei
I thought it was OK, but not in depth enough. It covered a pretty wide range of topics, so most of the labs seem to only scratch the surface. Not sure about the mistakes part. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=28992&t=28991 -

RE: need advice [7:29392]

2001-12-18 Thread Alex Lei
Hello Festus: 1. This is a persistent and difficult problem. The short answer is, you can't. There are a lot of products like Cyberpatrol, but they are not on the router. Usually they are on the proxy servers, end PC's and firewalls. They can block a lot of sites but not all. Filtering based on w

RE: How to disable NAT in Cisco PIX? [7:29641]

2001-12-19 Thread Alex Lei
Hello David, I think your config should work, too. But here are a few suggestions nevertheless: 1. use "nat (inside) 0 0 0" instead of "nat (inside) 0 129.174.1.0 255.255.255.0" 2. delete "static (inside, outside) 129.174.1.0 129.174.1.0", it's not really needed. 3. Like Ejay said, do a tracerou

Re: DSL [7:30032]

2001-12-24 Thread Alex Lei
Hello Farhn, www.dslreports.com can tell you a lot of about your provider. Like who provides the loop, the distance between you and the CO... Check it out. Alex Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=30038&t=30032 -- FAQ

RE: Puzzles -> WAS RE: My interview story [7:40553]

2002-04-09 Thread Alex Lei
> > If you have 2 20' poles, a 32' rope strung between them, and > the > > lowest point of the rope is 4' off of the ground, how far > apart are > > the poles? > > If I understand correctly, I think the answer to this one is 16'. If the rope is attached to the ends of the poles, then the d

RE: dial up problem [7:44244]

2002-05-14 Thread Alex Lei
Yoschii, This sounds more like the so - called "blind dial". Some countries will not have the dial tone when you connect the modem to it. In order to use dial up you have to disable the "wait for dial tone" feature otherwise your modem would just wait forever. Alex supernet wrote: > > When I t

RE: VTP Concentrator - client to client [7:44276]

2002-05-14 Thread Alex Lei
Gaz, I think there might be some routing problems. IPSEC is not like a serial link, it will not pass all traffic, it only passed traffic from one endpoint of the tunnel to the other endpoint of the tunnel. In your scenario, once the packet gets to the concentrator, the concentrator wouldn't know

RE: Pix don't route [7:46356]

2002-06-12 Thread Alex Lei
Wayne, Why not use the router to terminate the links, and put the PIX behind the router? The PIX will inspect the traffic, and the router can send traffic to different links depending on where it originated from. Usually a 515 may be a better solution because it has a DMZ interface where the serv

RE: Latency on the local access circuit [7:26263]

2001-11-14 Thread Alex Lei
Paul, I have a feeling that you might have tried the below, but just for a suggestion: Is the ping time always high, or does it vary depending on the time of the day? If it's the latter, it might be a congestion problem, and you can check for the presence of FECN's on the frame switch. This happ

Re: Networkers Power Slides [7:47900]

2002-07-02 Thread Alex Lei
Thanks Steve. The slides are very helpful. Alex Steven A. Ridder wrote: > > Oops, wrong link. > > pad > pad > pad > > http://www.cisco.com/networkers/nw02/presos.html > > > -- > RFC 1149 Compliant > > > > > ""Clayton Dukes"" wrote in message > [EMAIL PROTECTED]">news:[EMAIL PROTECTED]

RE: PIX 520 Motherboard repair replace [7:48959]

2002-07-16 Thread Alex Lei
I don't know the details, but I would imagine that the boot roms are different. I can't really see Cisco using a Phoenix bios... Finesse is the original OS used in PIXes, the boot roms probably have the Finesse kernel inside. Larry Letterman would probably know for sure. Alex Calorifer Gogu wro

RE: PIX 520 Motherboard repair replace [7:48959]

2002-07-16 Thread Alex Lei
Facts have spoken. I retract my prior statements. By extension, could you have used a differenet MB / CPU? Alex Mike Sweeney wrote: > > Special drivers? bunk- > > http://www.packetattack.com/frankenpix.html > > > It can be replaced with a normal, garden varity Intel SE440BX > motherboard.

Re: Huawei routers - a.k.a. futurewei.com [7:49778]

2002-07-26 Thread Alex Lei
Groupstudy, I'd be very very surprised if Huawei violated Cisco's rights, simply because Huawei is the largest networking gear company in China, if they did anything suspicious, Cisco would surely find them. From what I know, Huawei is a pretty ethical company for a multi national corporation, an

RE: Kind suggestion is Needed! [7:50317]

2002-07-31 Thread Alex Lei
Mr. Ahmad, I have found Tanenbaum's Computer Networks, 2nd edition to be a very good book. Radia Perlman's Bridges and Switches is also a classic. Alex a. ahmad wrote: > > Dear All, > > I just want to work on my basic concepts of networking and for > that I need the name of some valuable book