[OSL | CCIE_Security] Pass CCIE Security - My Experience

2014-01-05 Thread Dan Gericke
Hey All, I finally passed my CCIE Security exam on Dec 13 on my second try. I wanted to share some of my experiences and answers to the major questions I had about the lab exam. I passed the written in early July 2013, so it took me about 5 months of studying to get ready for the CCIE

Re: [OSL | CCIE_Security] Questions about the exam

2013-12-13 Thread Dan Gericke
Hi Kent, I just took my lab (2nd attempt) today. 1. For icmp, you can do any any. For anything else, I’d keep it as specific as possible. For example, you almost always need to do NTP. I guess you could do permit udp any host ntpserverip eq 123, but I always do the more specific hosts just in

Re: [OSL | CCIE_Security] Proctorlabs Rack VPN

2013-12-09 Thread Dan Gericke
issue - if not answered in FAQ, select Remote Support (bottom of page). On Sat, Dec 7, 2013 at 1:06 AM, Dan Gericke d...@syssec.biz wrote: All, Anyone else having issues with the lab vpn disconnecting instead of asking you to reauthenticate periodically? Usually I just reauth while

[OSL | CCIE_Security] Proctorlabs Rack VPN

2013-12-06 Thread Dan Gericke
All, Anyone else having issues with the lab vpn disconnecting instead of asking you to reauthenticate periodically? Usually I just reauth while the connection is still live, but now it disconnects me, and I have to reconnect, clear my lines, then reconnect my RDP sessions. -Dan

Re: [OSL | CCIE_Security] CCIE SEC

2013-11-23 Thread Dan Gericke
On my attempt last month I was able to ctrl f inside the doc-cd we pages and the books. I wasn't restricted on that No searching the doc-cd as a whole though. On Nov 24, 2013, at 1:13 AM, Bastien Migette bastien.mige...@gmail.com wrote: One quick tip from my last failed attempt.

Re: [OSL | CCIE_Security] Canidate PC Usable For Testing?

2013-11-21 Thread Dan Gericke
Actually the one thing that really confused me is that the candidate pc had 2 NICs on it, and I thought it was like our practice labs where one couldn’t be changed and was only for our local access, and the other one was for connecting and testing. Actually, you can use your main interface and

Re: [OSL | CCIE_Security] Online rack

2013-09-09 Thread Dan Gericke
Speed is ok especially for IPS lab. It's the VMs you have to worry about, but they have gotten better since everyone(including myself) reported problems. They aren't perfect yet, but they should be replacing some hardware soon, if they didn't already. -Dan On Sep 9, 2013, at 9:04 PM, Daljeet

Re: [OSL | CCIE_Security] Transparent firewall issue

2013-08-20 Thread Dan Gericke
Did you configure the NAT translation rules that allow the traffic to pass through your ASA? How is your nat control configured? http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_control.html -Dan On Aug 20, 2013, at 5:41 PM, MERAJ Khalid merajkha...@hotmail.com wrote:

Re: [OSL | CCIE_Security] Transparent firewall issue

2013-08-20 Thread Dan Gericke
You are right, I missed that you are doing transparent firewalls. Are you running on GNS3 or on a rack session? I've had issues with protocol flapping in GNS3 before, like you described. If the neighborship establishes then goes down, then it seems like your ACLs and configurations are

Re: [OSL | CCIE_Security] Transparent firewall issue

2013-08-20 Thread Dan Gericke
Yes, I've encountered this when the vlans weren't all available on the connected switches. Your configurations may all look correct, but if the vlan isn't in all the catalyst vlan databases that you connect to, then the traffic won't pass. I've learned to always double/triple check my vlans,

Re: [OSL | CCIE_Security] LAb schedule

2013-08-10 Thread Dan Gericke
Keep checking daily. HK was fully booked and I snagged an open seat in October last week. Must be people canceling. On Aug 10, 2013, at 2:24 PM, Daljeet SinGH dalsbeh...@gmail.com wrote: Hi Guys, I have a questions, I dont find any free data to book LAB exam, only found Brussels and

Re: [OSL | CCIE_Security] question on Workbook Volume 1 section 3 WSA

2013-08-03 Thread Dan Gericke
Are you sure you are typing the username and password in correctly? On Aug 4, 2013, at 1:11 PM, coton168 coton...@yahoo.com wrote: Hello, I am working on the proctorlab pod 121. and the WSA can not join the AD. I have two error message preventing WSA join the AD. Anybody has the same

Re: [OSL | CCIE_Security] question on Workbook Volume 1 section 3 WSA

2013-08-03 Thread Dan Gericke
That pod is notorious for having issues lately. Glad a reboot fixed it. Hope you didn't waste too much time. On Aug 4, 2013, at 2:11 PM, coton168 coton...@yahoo.com wrote: Dan, Thanks for the quick response. After trying many times, rebooting the AD fixed the problem From: Dan

Re: [OSL | CCIE_Security] ISE, Unable to see security groups

2013-08-01 Thread Dan Gericke
I had a similar problem yesterday, that I'm guessing was because of the VMs being slow. I got hung on joining the DC, but afterward it said it was joined but disconnected, and I couldn't see any security groups. I had to leave the domain, then rejoin. Once you get a successful rejoin you

Re: [OSL | CCIE_Security] EUN Directory on Ironport WSA

2013-08-01 Thread Dan Gericke
Do you mean using ftp://wsaip in the browser itself or actually browsing directories through the WSA web gui? I don't remember seeing any ability to do that in the gui itself, so I'm guessing you meant ftp in the browser. I'll try it, but I also used filezilla to access it and I couldn't see

[OSL | CCIE_Security] Another pod another issue - ISE and VM overall slowness

2013-07-31 Thread Dan Gericke
Hi everyone, I'm not sure if I'm the only one that constantly has issues with the pods or if I'm the only one complaining about it, but once again I had issues today. Yesterday it took me almost 1.5 hours to get pod 120 to a point where I could log into the PC, and AD servers. Sometime before

[OSL | CCIE_Security] EUN Directory on Ironport WSA

2013-07-30 Thread Dan Gericke
Hi all, I'm wondering if I'm missing something in reference to the custom EUN pages in the WSA. The DSG and Ironport user guides say to change a custom EUN you need to ftp to the box and go to the configuration/eun directory. I tried on the WSA in my pod last night, and I couldn't find the

[OSL | CCIE_Security] IPExpert bootcamp GI Bill

2013-07-22 Thread Dan Gericke
Hi All, Have any of you that attended one of the IPExpert boot camps been able to use the post 9/11 GI Bill to fund it? Also, Have any of you attended the boot camp via Online-HD-ITL? I'm curious what the hours are? Like 9am to 9pm EST? Thanks for any info. -Dan

Re: [OSL | CCIE_Security] IPExpert bootcamp GI Bill

2013-07-22 Thread Dan Gericke
- eBenefits, if you need certificate of eligibility or to apply for post-9/11 - https://www.ebenefits.va.gov/ebenefits-portal/ On 7/22/13 11:19 PM, Dan Gericke d...@syssec.biz wrote: Hi All, Have any of you that attended one of the IPExpert boot camps been able to use the post 9/11 GI Bill

[OSL | CCIE_Security] No lab time until July 29?

2013-07-18 Thread Dan Gericke
Is there no free lab time because you guys have a boot camp going on July 15-26? Does the boot camp really go 24 hours a day? I can't even book lab time from 0400 to 0745? I wish there would have been some kind of advanced notice on this list. -Dan

Re: [OSL | CCIE_Security] No lab time until July 29?

2013-07-18 Thread Dan Gericke
the bootcamp own their assigned rack for the duration so they can complete independent study outside of classroom hours. On 7/18/13 4:06 AM, Dan Gericke d...@syssec.biz wrote: Is there no free lab time because you guys have a boot camp going on July 15-26? Does the boot camp really go 24

Re: [OSL | CCIE_Security] Proctorlabs rack problem

2013-07-14 Thread Dan Gericke
I can't remember exactly where on the website I read this, but I remember that they mentioned back-to-back sessions should be booked at least an hour before your session ends(if you are trying to extend). I'd imagine you'd have the best luck if you schedule the back-to-back session before you

[OSL | CCIE_Security] Able to access any pod

2013-07-14 Thread Dan Gericke
to get into other pods like that should we? Luckily someone else wasn't using pod118 at the same time as I was, or I'd have seriously messed up their session.-Dan Dan Gericke (MBA, PMP, CISSP, CEH, CCNP-S, CCNP, CCDP, BCNP, ACMP, ITIL 2011 FN)Principal Datacenter and Security Architectdgeri

Re: [OSL | CCIE_Security] After Hours Support?

2013-07-09 Thread Dan Gericke
(Garrett Skjelstad) -- Message: 1 Date: Tue, 9 Jul 2013 12:13:32 + From: Manny Fernandez mfernan...@modcomp.com To: Dan Gericke d...@syssec.biz, ccie_security@onlinestudylist.com ccie_security

[OSL | CCIE_Security] CCIE Sec Vol 1 WB Sec 1 Lab 2 Task 6 Question

2013-07-06 Thread Dan Gericke
Hi All, I actually have 2 questions… The first, how do I contact after hours support when I'm working on the labs? I read to contact them through the technical support link, but I can't find anywhere on that page where I can submit a ticket, or call a number…. Second, In Vol 1 Sec 1 Lab 2

Re: [OSL | CCIE_Security] CCIE Sec Vol 1 WB Sec 1 Lab 2 Task 6 Question

2013-07-06 Thread Dan Gericke
, -- Piotr Kaluzny CCIE #25665 (Security), CCSP, CCNP Sr. Technical Instructor - IPexpert, Inc. URL: http://www.IPexpert.com On Sat, Jul 6, 2013 at 10:58 AM, Dan Gericke d...@syssec.biz wrote: Hi All, I actually have 2 questions… The first, how do I contact after hours support when I'm working

[OSL | CCIE_Security] After Hours Support?

2013-07-06 Thread Dan Gericke
I'm in a session right now, most of my reverts have been stuck at 50%, I waited the first time for 30 min, then I've been trying each device individually, and they are still getting stuck. I essentially can't do anything, and the after hours support link at the bottom of the page only takes me