Re: [OSL | CCIE_Security] class-map type portfilter - match-all or match-any

2011-06-29 Thread Kingsley Charles
It's match-all. I sent the mail for this subject :-) With regards Kings On Wed, Jun 29, 2011 at 9:20 AM, Mark Senteza msent...@googlemail.comwrote: Hi, I know this was discussed previously, but I cant find the thread to it. When matching ports in a portfilter type class-map, is it

Re: [OSL | CCIE_Security] CBAC: Audit Trail vs Alerts

2011-06-29 Thread Piotr Matusiak
Yes, you're right. 2011/6/29 Mark Senteza msent...@googlemail.com Hello All, whats the difference between the CBAC feature's Audit Trail and the Alerts ? Cisco docs states: Enhanced audit trail features use SYSLOG to track all network transactions; recording time stamps, source host,

Re: [OSL | CCIE_Security] Crypto identity hostname for GETVPN with CA

2011-06-29 Thread Kingsley Charles
Hi Tyson Even, if the crypto isakmp identity address is configured which is the default, the IOS uses hostname as the identity when the authentication method used by the IPSec VPN is rsa-sig. If we configure crypto isakmp identity hostname and have both types of VPN connections using pre-shared

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Kingsley Charles
Congrats Robert... With regards Kings On Wed, Jun 29, 2011 at 1:13 PM, Robert Gridley bo...@gridley.de wrote: ** Hi, just passed the CCIE Security yesterday in Bruexelles. Im now CCIE #29452 . Thanks for your support during my journey! Maybe CCIE RS next year ... but maybe ... not for

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Farzad Cheema
Congratulation ! On 29 June 2011 08:43, Robert Gridley bo...@gridley.de wrote: ** Hi, just passed the CCIE Security yesterday in Bruexelles. Im now CCIE #29452 . Thanks for your support during my journey! Maybe CCIE RS next year ... but maybe ... not for sure Have a nice day!

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Piotr Matusiak
Congrats Robert! Was it hard? I bet not :) Regards, Piotr 2011/6/29 Robert Gridley bo...@gridley.de ** Hi, just passed the CCIE Security yesterday in Bruexelles. Im now CCIE #29452 . Thanks for your support during my journey! Maybe CCIE RS next year ... but maybe ... not for sure

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Mulholland, Michael
well done robert Michael Mulholland From: ccie_security-boun...@onlinestudylist.com [mailto:ccie_security-boun...@onlinestudylist.com] On Behalf Of Robert Gridley Sent: 29 June 2011 08:43 To: ccie_security@onlinestudylist.com Subject: [OSL | CCIE_Security]

[OSL | CCIE_Security] About CCIE Lab default route for ACS and Test PC

2011-06-29 Thread Richard Chan
Hi, Can someone verify (if it is not an NDA thingy) that in the CCIE Lab does the default route for ACS and Test PC point to the pod or do we have to take care of the RDP/VNC routing? As you know in some rack rentals the default route must not point to the pod or we will lose RDP/VNC. to the

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread -Hammer-
Congrats! -Hammer- On 06/29/2011 02:43 AM, Robert Gridley wrote: Hi, just passed the CCIE Security yesterday in Bruexelles. Im now CCIE #29452 . Thanks for your support during my journey! Maybe CCIE RS next year ... but maybe ... not for sure Have a nice day! regards, robert

[OSL | CCIE_Security] IPSEC security

2011-06-29 Thread Kash iqbal
Hi Experts , A quick question in IPSec Crypto map where you put ACL to allow trarfic to go inside the tunnel , Is there any other place where we can put security on Traffic that is coming thrugh VPN Let me explain. Match acl says Permit IP 1.1.1.0 to 2.2.20 However i want to

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Pieter-Jan Nefkens
Hi Robert, Congrats! PJ On 29 jun 2011, at 15:39, -Hammer- wrote: Congrats! -Hammer- On 06/29/2011 02:43 AM, Robert Gridley wrote: Hi, just passed the CCIE Security yesterday in Bruexelles. Im now CCIE #29452 . Thanks for your support during my journey! Maybe CCIE RS next

[OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Adil Pasha
Could someone please let me know what is the following error about? This is YB Lab 1: I launched the browser on 443 and was able to download and install the client on XP desktop. I am connected to ASA using webvpn and the client is downloaded to the XP desktop, but when I tried to connect

Re: [OSL | CCIE_Security] CBAC: Audit Trail vs Alerts

2011-06-29 Thread Mark Senteza
Thanks Piotr. Good to know that my thinking was on the right track!! On Wed, Jun 29, 2011 at 12:19 AM, Piotr Matusiak pi...@howto.pl wrote: Yes, you're right. 2011/6/29 Mark Senteza msent...@googlemail.com Hello All, whats the difference between the CBAC feature's Audit Trail and the

Re: [OSL | CCIE_Security] IPSEC security

2011-06-29 Thread Piotr Kaluzny
Kashif, You can use the set ip access-group statement under a crypto map or a VPN-filter on the ASA. Regards, -- Piotr Kaluzny CCIE #25665 (Security), CCSP, CCNP Sr. Support Engineer - IPexpert, Inc. URL: http://www.IPexpert.com On Wed, Jun 29, 2011 at 5:43 PM, Kash iqbal sama_1...@hotmail.com

Re: [OSL | CCIE_Security] IPSEC security

2011-06-29 Thread Mark Senteza
You can create an access-list to specify the traffic you want filtered, then apply that ACL to the crypto map. For instance: ip access-list ext VPN-FILTER deny tcp any any eq 23 deny tcp any any eq 80 permit ip any any crypto map VPN 10 ipsec-isakmp set ip access-group VPN-FILTER in Mark

[OSL | CCIE_Security] VNC for MAC.

2011-06-29 Thread Adil Pasha
Does anyone know which is the best VNC client to access IPEXPERT racks using MAC? Best Regards. __ Adil ___ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com Are you a CCNP or CCIE

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Johan Bornman
Well done! From: ccie_security-boun...@onlinestudylist.com [mailto:ccie_security-boun...@onlinestudylist.com] On Behalf Of Robert Gridley Sent: 29 June 2011 09:43 AM To: ccie_security@onlinestudylist.com Subject: [OSL | CCIE_Security] Finally Passed Hi, just passed the CCIE Security

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Dennis DeFoort
You need to create an anyconnect profile upload it to flash , make sure you allow remote desktop connections in the profile. You can edit/crate a profile from the standalone profile editor or asdm 6.3 and up On 2011-06-29, at 2:26 PM, Adil Pasha wrote: %ASA-6-725003: SSL client

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Adil Pasha
Thanks Dennis, This will be a challenge during the actual lab. Have you done YB Lab 1? Best Regards. __ Adil S Pasha iNET SYSTEMS, INC. IT Consulting Services - (Client: Morgan Stanley) New York, USA. Off: 516.742.7532 Cell: 516.524.9361 aspa...@gmail.com On Jun 29, 2011,

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Adil Pasha
Thanks Diego, I used VNC for MAC called Chicken of the VNC, really that is the name:) But it did not work for some reason. I will try to download Real VNC and use it next time. Plus the rack chocked out on me for some reason so I lost interest after 7 hours of working on the rack.

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Dennis DeFoort
no i teach cisco authorized material On 2011-06-29, at 4:25 PM, Adil Pasha wrote: Thanks Dennis, This will be a challenge during the actual lab. Have you done YB Lab 1? Best Regards. __ Adil S Pasha iNET SYSTEMS, INC. IT Consulting Services - (Client: Morgan

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Adil Pasha
I believe Yusuf's Practice Labs are authorized material. Best Regards. __ Adil On Jun 29, 2011, at 4:39 PM, Dennis DeFoort wrote: no i teach cisco authorized material On 2011-06-29, at 4:25 PM, Adil Pasha wrote: Thanks Dennis, This will be a challenge during the

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Piotr Matusiak
Connect to WinXP using VNC instead of RDP. 2011/6/29 Adil Pasha aspa...@gmail.com Could someone please let me know what is the following error about? This is YB Lab 1: I launched the browser on 443 and was able to download and install the client on XP desktop. I am connected to ASA using

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Anthony Sequeira
This is so exciting! Congrats From: ccie_security-boun...@onlinestudylist.com [mailto:ccie_security-boun...@onlinestudylist.com] On Behalf Of Johan Bornman Sent: Wednesday, June 29, 2011 2:40 PM To: 'Robert Gridley'; ccie_security@onlinestudylist.com Subject: Re: [OSL | CCIE_Security] Finally

Re: [OSL | CCIE_Security] Cisco Anyconnect Error.

2011-06-29 Thread Adil Pasha
Thanks Piotr. I tried using a VNC on Mac but it did not work. I got Real VNC for MAC now and will try it in next labs session. Best Regards. __ Adil On Jun 29, 2011, at 4:58 PM, Piotr Matusiak wrote: Connect to WinXP using VNC instead of RDP. 2011/6/29 Adil Pasha

Re: [OSL | CCIE_Security] Finally Passed

2011-06-29 Thread Tiago Lousada Soares
Congratulations! Regards, Tiago De: ccie_security-boun...@onlinestudylist.com [mailto:ccie_security-boun...@onlinestudylist.com] Em nome de Robert Gridley Enviada: quarta-feira, 29 de Junho de 2011 08:43 Para: ccie_security@onlinestudylist.com Assunto: [OSL | CCIE_Security] Finally

Re: [OSL | CCIE_Security] [OT] Has any one tried Cisco ISE 1.0?

2011-06-29 Thread Richard Chan
Tks for the insight Tyson: slight correction: there is an ISE physical appliance that supports inline posture mode (the VM/ESX version works as you described, and is not inline). Possibly the VM version is too slow/not designed to support inline work. It's interesting that Cisco has embraced