RE: SAFE and the Holy Hand Grenade of Antioch [7:74304]

2003-08-26 Thread Charlie Wehner
This is an excellent example of why I hated taking the SAFE exam. I found myself for several questions thinking... Well, I depends on what you mean by this term. I agree with Fred though. I believe the answers they are looking for are Unstructured, Structured, External and Internal. Message

RE: SAFE and the Holy Hand Grenade of Antioch [7:74304]

2003-08-25 Thread Charlie Wehner
Not sure if this what there looking for but in my MCNS book they have the following threat types: Security Threat Types: -Reconnaissance -Unauthorized access -Denial of Service -Data Manipulation The 4 remote users designs are the following: • Software access—Remote user with a software VPN

RE: QoS Exam 642-641 [7:74081]

2003-08-18 Thread Charlie Wehner
Yea! I passed. It was pretty easy though. (No tricks or hazy questions in this test.) I guess I'm still bitter after having to take the Safe Exam 2x to pass. Now onto the CCNP recert which I hear is quite fun. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74132t=74081

RE: QoS Exam 642-641 [7:74081]

2003-08-18 Thread Charlie Wehner
I used the knowledgenet QoS training course and Boson #1 QoS practice test to study for the test. (I probably could have gotten away with just using the knowledgenet QoS training course though.) Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74142t=74081

RE: wireless security and VPN software? [7:73988]

2003-08-17 Thread Charlie Wehner
the author by replying to this message. If you are not the named recipient, you are not authorized to use, disclose, distribute, copy, print or rely on this email, and should immediately delete it from your computer. -Original Message- From: Charlie Wehner [mailto:[EMAIL PROTECTED

QoS Exam 642-641 [7:74081]

2003-08-17 Thread Charlie Wehner
Taking this bad boy tomorrow... and advice? All of the new exams seem to be quite a bit more painful than the old ones. Or at least more difficult in my opinion... Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74081t=74081 --

RE: wireless security and VPN software? [7:73988]

2003-08-16 Thread Charlie Wehner
One more quick note on using VPN solutions. If your using a VPN solution with a Cisco AP be sure to enable PSPF. Everyone misses that setting... but it's important. :) Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74049t=73988

RE: wireless security and VPN software? [7:73988]

2003-08-14 Thread Charlie Wehner
What type of applications do they need to support? What devices and OS's do they need to support? -Watch out for PDAs. Most PDAs have limited support for VPN clients. What type of users are they? (Techie or basic AOL users?) These are the main questions in my opinion. VPNs aren't so bad.

Re: Keeping my head up [7:71800]

2003-07-16 Thread Charlie Wehner
There is no shame in failing a Cisco written test these days (not that there ever was). I passed the CCIE Lab on the second attempt and a few months later failed the Cisco Pix Firewall Exam again and again (after having always passed Cisco written tests on the first try.) The Cisco written tests

RE: Anyone written CSI 9E0-131 Cisco Safe? [7:69520]

2003-05-27 Thread Charlie Wehner
It's kind of a pain. I just passed it. Read the Safe whitepaper very carefully. Pay attention to the way it's worded... The exam is very picky with some questions and a bit vague on others. The 2 Boson practice tests help out a lot. I would highly recommend using them to study with.

Re: CCNP Re-certification [7:69556]

2003-05-27 Thread Charlie Wehner
I've noticed that the simulation questions perform terrible and sometimes lock up when run on low-end computers. They need to raise the minimum PC requirements for Prometric test centers in my opinion. Don't be afraid to email Cisco about any problems with the exam. Message Posted at:

access-list logging rate-limited [7:66520]

2003-03-30 Thread Charlie Wehner
Two quick questions: I've configured an access-list to only permit certain tcp and udp ports above 1024. At the end of the access-list I have the following commands: access-list 101 deny tcp any any log access-list 101 deny udp any any log access-list 101 deny ip any any log Question 1: Do I

RE: access-list logging rate-limited [7:66520]

2003-03-30 Thread Charlie Wehner
I found the answer to question 2: It's not usually a good idea to configure logging for access list entries that will match very large numbers of packets. Doing so will cause log files to grow excessively large, and may cut into system performance. However, access list log messages are

UDLD Questions [7:66461]

2003-03-29 Thread Charlie Wehner
Will UDLD prevent duplex mismatches from occurring on end user devices? (Disabling a ports that are detected to be mismatched) Or does UDLD only work between switches? Thanks in Advance Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=66461t=66461

RE: UDLD Questions [7:66461]

2003-03-29 Thread Charlie Wehner
Very good explanation Priscilla. Thanks! Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=66466t=66461 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure

RE: CCIE Vs. BS or MS dergree [7:59481]

2002-12-19 Thread Charlie Wehner
What's more difficult? a) Memorizing configuration scenerios and commands on a Cisco router b) Understanding Calculus, Differential Equations, Numerical Analysis, Chemistry, Physics and Electrical Engineering well enough to create a meaningful experiment. One of my friends is working on his

RE: Aironet 1200 [7:59310]

2002-12-16 Thread Charlie Wehner
What type of throughput does the remote office need? With two 1200 series access points you can: a) Run one AP as Root and the other in Repeater mode. b) Blast the signal across the street with just one AP I don't think you can bridge with 1200s series APs. You might be better off buying 350

RE: Question for designers (WLAN) [7:59216]

2002-12-16 Thread Charlie Wehner
If your not going to run 802.11a then there might not be a significant advantage to going with the 1200 series AP. However, hospitals normally have a lot of long hallways that are perfect for using a patch antenna. (A lot of times you can cover an area with one diversity 6.5dBi patch that might

RE: Question for designers (WLAN) [7:59216]

2002-12-16 Thread Charlie Wehner
Forgot to ask... what country are you from? I know some countries put restrictions on the power and antennas that are available. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=59336t=59216 -- FAQ, list archives, and subscription

RE: WLANFE [7:59278]

2002-12-16 Thread Charlie Wehner
When was the WLANFE 9E0-581 exam first available? Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=59337t=59278 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and

Off Topic - Quietest Cisco Switch [7:53800]

2002-09-21 Thread Charlie Wehner
I'm looking to buy a switch for my apartment. (Right now, the 2950T 24port 10/100/1000Base-T looks promising.) However, the amount of noise this thing produces is a concern. I want to put it in my living room (Actually, it's the only room... I live in a studio.) so I can't have this thing

Re: Off Topic - Quietest Cisco Switch [7:53800]

2002-09-21 Thread Charlie Wehner
***they're all VERY quiet when you unplug 'em! :- --Very very true, but what's the fun of having a killer home network unless you put it to good use. For example, right now, I'm hosting 2 websites and let my friends VPN-in and download/upload interesting freeware applications. :)(Stuff

Re: ADSL routers [7:51250]

2002-08-15 Thread Charlie Wehner
the 827 can do many things, including 3DES and firewall feature set, but supports only RIP and EIGRP --No fair, mine doesn't support EIGRP. Only RIP. The 827 looks like it supports all of the routing protocols but when you enter them it always reads unknown routing protocol. (Except for RIP.)

LEAP/ACS configuration [027] Session-Timeout [7:48301]

2002-07-07 Thread Charlie Wehner
PROBLEM/QUESTION Users are currently authenticated by an ACS server when remotely accessing the network through a VPN. So their user accounts have been created and there is currently no value for [027]Session-Timeout RADIUS attribute. What will happen if I modify the [027]Session-Timeout

RE: Securing a Aironet 350 [7:44152]

2002-05-14 Thread Charlie Wehner
What is the best way to secure a Aironet 350 from hackers? ***Keep it unplugged. ***Seriously though, LEAP is a good option if you want ease of use and pretty good security. It can be brute-forced if there isn't a user lock-out policy though. (You also need a Cisco ACS server or

RE: Can anyone break this Cisco 4912G password? [7:40505]

2002-04-07 Thread Charlie Wehner
I just ran both of the hashes against a 20Mb wordlist using John the Ripper with no luck. (Looks like you might have to perform some password recovery.) Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=40753t=40505 -- FAQ, list

Aironet 350 Wireless Security Question [7:38051]

2002-03-12 Thread Charlie Wehner
How safe am I if I'm using the aironet 350 Series access points running the following: -version 11.10T -EAP authentication with a Radius server -MIC enabled -Broadcast Key Rotation -WEP with key hashing Does anyone know any good links that give a 'very' detailed explanation of how the 'WEP key

RE: Aironet 350 Wireless Security Question [7:38051]

2002-03-12 Thread Charlie Wehner
I think I just answered my own question. Just found an excellent link... Here it is if anyone is curious: http://www.cisco.com/warp/public/cc/so/cuso/epso/sqfr/safwl_wp.htm Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=38060t=38051

Aironet 350 APs and Security Concerns [7:35686]

2002-02-17 Thread Charlie Wehner
Does anyone know which software versions of the Aironet 350 APs use added Hashing to help resolve the weaknesses discovered in the RC4 algorithm? Is version 11.07 safe from the Berkley and Fuhrer attacks? Thanks, Charlie Message Posted at:

RE: Aironet 350 APs and Security Concerns [7:35686]

2002-02-17 Thread Charlie Wehner
Thanks Tom, So all versions before 11.10T don't use hashing in addition to the RC4 algorithm? (11.08T1, 11.07a, 11.06.a, 11.05a etc...) Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=35699t=35686 -- FAQ, list archives, and

RE: ISDN dialer watch VS floating static routes [7:31609]

2002-01-13 Thread Charlie Wehner
Thanks for the advice Benjamin and Jenny. It sounds like you have to be careful when implementing dialer watch. (Especially, if you only want to bring up the link for 'interesting traffic'. I guess since 'dialer watch' is fairly new most people have 'floating static routes' in place. Message

ISDN dialer watch VS floating static routes [7:31609]

2002-01-10 Thread Charlie Wehner
When configuring an ISDN backup for a frame relay circuit do most people typically use dialer watch or floating static routes. In my scenerio, it's for an eigrp network and a single router. I've seen the following article on Cisco's website: