Re: can we NAT the destination IP using IOS's NAT nature? [7:7037]

2001-06-03 Thread Michael Jia
Hi, I guess you can config a static nat mapping and reverse the inside and outside interface. that is , ip nat inside source static 192.168.3.31 50.100.167.102 interface e0 ip nat outside interface e1 ip nat inside -Michael "Sim, CT (Chee Tong)" wrote in message ... >Hi..dear all, > >

Re: Question for NetRanger experts - ever build your own sensor [7:9483]

2001-06-21 Thread Michael Jia
Hi, I want information on this too. Thanks Michael >I am trying to set up a cheap IDS lab, and I don't want to pay through the >nose for sensors, I'd rather "make" my own, if this is possible. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=9483&t=9483

Re: Question about fast switching and layer 3 switching [7:14044]

2001-07-27 Thread Michael Jia
Hi, Dovelet Fast switching is implemented in software(IOS). It is a in-memory cache. Layer-3 switching normally is implemented in hardware, such as hardware cache or ASIC chip. Michael "dovelet" wrote in message ... >Hi all, > >I have a question and I hope someone can help me. As I know, Cisco

Re: access lists [7:13928]

2001-07-28 Thread Michael Jia
If CBAC is available, use it along with access-list ip inspect name tcp ip inspect name ucp It will give you a stateful firewall. -Michael "Joe Morabito" wrote in message ... >How can you apply an access list to a serial interface to block all internet >traffic without disabling the inside peop

Re: Netmeeting and PIX [7:15002]

2001-08-06 Thread Michael Jia
As far as I know, the answer is no. However, you may use the "establish " command to customize the PIX box if you know the Netmeeting protocol. regards Michael "Patrick Donlon" wrote in message ... >Does anyone know if PIX will work with Netmeeting audio and video traffic >through using NAT? C

Re: PIX - NAT 0 problems this weekend [7:18471]

2001-09-04 Thread Michael Jia
Hi, Very insightful discussion! Does 6.0's NAT 0 0 0 functions better? The benefit of NAT 0 is simple. You use one command to turn off translation. Using static(), you have to enter a CLI for every subnet. if there something like static(inside, outside) 0 0 0? Anybody tried it? Michael Me

CCIE Security [7:19904]

2001-09-13 Thread Michael Jia
Hi, Has anybody took CCIE security recently? What books/training material do you use? Is there some books like the Exam Cram book? Is there any useful URLs,sample tests? I have passed the Routing Switching exam and working on a security exam. Thanks Michael Message Posted at: http://www.gro

GRE with IPsec [7:71959]

2003-07-06 Thread Michael Jia
Hi, Anyone has good reference doc about GRE with Ipsec . I am a little confused about 2 flavors of crypto ACL used: A) permit ip B) permit gre any any It seems option A is encry first then GRE encap, while option B is encap first then encrypt. Is there a good ref about these setups? Thanks

RE: GRE with IPsec [7:71965]

2003-07-06 Thread Michael Jia
Hi, Joe There is a sligt difference between A and B. Could you share some insights as well? Thanks Michael -Original Message- From: Joe Deleonardo [mailto:[EMAIL PROTECTED] Sent: Sunday, July 06, 2003 5:17 PM To: Michael Jia; [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject: Re: GRE with