Monday, April 13, 2009

Cisco CCNA Certification Exam Case Study: Frame Relay, Pings, And Routing Protocols

Cisco CCNA certification training includes troubleshooting your own work and that of others. The best CCNA certification training you can do is indeed troubleshooting your own Cisco router and switch configurations - as I'm always telling my students, "I can guarantee that any error you make has been made before, and you'll probably see it again one day." One such common error involves two very important CCNA certification topics - Frame Relay and routing protocols.

A student was working on his CCNA exam home lab and came up with an interesting problem. He set Frame Relay up in a hub-and-spoke configuration with R1 as the hub and R2 and R3 as the spokes. He wrote the following frame map statements:

frame-relay map ip 172.12.123.2 122

frame-relay map ip 172.12.123.3 123

He was able to ping both spokes from the hub, so he assumed everything was working correctly. Then he configured RIP version 2 on the router and got the following result after running "debug ip rip" and clearing the routing table with "clear ip route *":

03:33:01: IP: s=172.12.123.1 (local), d=224.0.0.9 (Serial0), len 72, sending broad/multicast

03:33:01: IP: s=172.12.123.1 (local), d=224.0.0.9 (Serial0), len 72, encapsulation failed

You may have already spotted the problem, and if you did, your CCNA certification exam studies are going well! The problem is that the "broadcast" option was left off the frame map statements. "broadcast" must be configured on frame map statements in order to send broadcasts and multicasts across the frame link. As you know from your CCNA certification exam studies, RIP version 1 broadcasts updates and RIP version 2 multicasts them, so the "broadcast" option must be present for either version to send updates by using those frame mappings.

He then rewrote the frame map statements as shown below....

R1(config-if)#frame map ip 172.12.123.2 122 broadcast

R1(config-if)#frame map ip 172.12.123.3 123 broadcast

... and the RIP updates went out as expected.

R1#debug ip rip

RIP protocol debugging is on

R1#clear ip route *

06:22:13: RIP: sending general request on Loopback0 to 224.0.0.9

06:22:13: RIP: sending general request on Serial0 to 224.0.0.9

06:22:13: RIP: ignored v2 packet from 1.1.1.1 (sourced from one of our addresses)

06:22:14: RIP: received v2 update from 172.12.123.3 on Serial0

06:22:14: 1.1.1.1/32 -> 0.0.0.0 in 3 hops

06:22:14: 2.2.2.2/32 -> 0.0.0.0 in 2 hops

06:22:14: 3.3.3.3/32 -> 0.0.0.0 in 1 hops

06:22:14: 172.12.23.0/24 -> 0.0.0.0 in 1 hops

06:22:14: 172.12.123.0/24 -> 0.0.0.0 in 1 hops

06:22:14: RIP: sending v2 update to 224.0.0.9 via Loopback0 (1.1.1.1)

06:22:14: 2.2.2.2/32 -> 0.0.0.0, metric 3, tag 0

06:22:14: 3.3.3.3/32 -> 0.0.0.0, metric 2, tag 0

06:22:14: 172.12.23.0/24 -> 0.0.0.0, metric 2, tag 0

06:22:14: 172.12.123.0/24 -> 0.0.0.0, metric 1, tag 0

06:22:14: RIP: sending v2 update to 224.0.0.9 via Serial0 (172.12.123.1)

Cisco CCNA certification depends on noticing details like these, and there's no better way to learn these details than by working on real Cisco routers and switches. Whether you're renting rack time online or buying used Cisco routers and switches, real-time debugs and configurations are the way to CCNA certification exam success!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

 

Labels: , , , , ,

Thursday, April 2, 2009

Cisco CCNP CIT Exam Training: Creating A Network Baseline

 

Creating a network baseline is an important skill for the CCNP exams, and it's even more important in real-world networks.  Learn the basic of creating a baseline from Chris Bryant, CCIE #12933.

The first thing we've got to do in order to document our network is to create a network baseline.  After all, if we don't know our goals, we can't accomplish them.  A baseline is really a "network snapshot", a picture of our network devices and their performance - which also helps us spot issues before they happen.

Every network has its "breaking point", the point at which it can no longer transfer data effectively.  By creating a baseline, you can see what the current network load is now - and by maintaining that baseline, you can spot network issues well before they become critical.  For example, say you baseline all your network routers, and part of that is noting the CPU capability and usage.  By maintaining the network baseline, you can note smaller, gradual increases in CPU usage and do something about it before the situation becomes critical.

Establishing a baseline also gives less-experienced network personnel a starting point for troubleshooting, and it gives new network support personnel a starting point as well.

To begin that task, we've got to define where this baseline will begin and end - in other words, we must define the scope of the baseline.  Some questions to ask:

What is the scope of this baseline?

What goals do we have for our network?

What network devices will be part of this baseline?

What is the objective here?  Why are we creating this baseline?

Baseline construction methods differ from one vendor to another, but I recommend the first thing you do  when creating a baseline is taking inventory.  Why?  First, it's hard to create a full network picture if you don't know everything that's in your network; second, many networks are poorly inventoried.

When you're creating network documentation, consistency is vital.  This goes for abbreviations, symbols, and icons.  There are sets of Cisco icons for use in Microsoft Visio - find and use these icons when documenting and diagramming your network.  Keep your usage of these icons consistent as well.

Decide upon your scope and your goals, and stick with that decision.  Don't start documenting one part of the network and then jump to another part. 

Also, don't hide the documentation!  If I have to substitute for you at a client site, I should be able to find the documentation without asking anyone.

Most importantly, maintain the documentation.  Nothing is worse than seeing a date at the top of a network baseline doc that's from last year. (Or the last century.)  Don't fall into the trap of "I'll catch the documentation up next week", because I can practically guarantee that no matter how great your work ethic is, something's going to happen that will distract you from getting the documentation done.  Do it now.

In short, when creating network documentation, follow these rules:

Define the scope of the documentation and stick to it.

Define your objective and the values to be documented.

Consistency is key.  Keep abbreviations and terminology consistent from document to document.

Make sure the appropriate personnel have access to the documentation.

Keep the documentation current.

Your client will thank youArticle Submission, and those that follow you will thank you as well!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 200 free certification exam tutorials, including CCNA certification training articles. His exclusive CCNA study guide is also available!Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online Cisco CCNA training boot camp with The Bryant Advantage!

Labels: , , , ,

Monday, March 16, 2009

Cisco CCNA Certification: The Proper Use Of Default Static Routes

Earning your Cisco CCNA certification means knowing the details of Cisco routing, and that includes knowing when Cisco routing terms don't quite mean what they sound like they mean. For example, the general meaning of "default" is a setting that is used unless you or I change it. On the other hand, a default route is a route taken by packets that have no other route they can take. Let's take a look at how a default static route is configured and used on a Cisco router.

Here's our current routing table:

Gateway of last resort is not set

1.0.0.0/32 is subnetted, 1 subnets

C 1.1.1.1 is directly connected, Loopback0

172.12.0.0/16 is variably subnetted, 2 subnets, 2 masks

C 172.12.13.0/24 is directly connected, Serial1

C 172.12.21.0/30 is directly connected, BRI0

If we have packets destined for the network 15.1.1.0 /24, the packets will be dropped by this router. There's no match in that routing table for that network and the gateway of last resort is not set.

We could configure a static route to the 15.1.1.0 /24 network, but instead we'll use a default static route. The hardest part of configuring that route type is getting used to the odd syntax! As with any other static route, we can use the IP address of the next-hop router or the local router's exit interface. Here, we'll send any traffic with no more-specific match in the routing table out the local router's Serial1 interface.

R1(config)#ip route 0.0.0.0 0.0.0.0 serial1

Let's take a look at the routing table now.

Gateway of last resort is 0.0.0.0 to network 0.0.0.0

1.0.0.0/32 is subnetted, 1 subnets

C 1.1.1.1 is directly connected, Loopback0

172.12.0.0/16 is variably subnetted, 2 subnets, 2 masks

C 172.12.13.0/24 is directly connected, Serial1

C 172.12.21.0/30 is directly connected, BRI0

S* 0.0.0.0/0 is directly connected, Serial1

A gateway of last resort has now been successfully configured, and the S* means that last route in the table is a static default route. Remember, the default route is not the route that all packets will take - it's the route packets use if there is no other possible match for their destination in the routing table.

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 200 free certification exam tutorials, including CCNA certification training articles. His exclusive CCNA study guide is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online Cisco CCNA training boot camp with The Bryant Advantage!

 

Labels: , , , , ,

Monday, March 9, 2009

CCNA Certification Training: Configuring Static Routes On A Cisco Router

 

Knowing how to quickly configure a static route is a valuable skill for both the CCNA exam and working with real-world networks.  Learn all about static routes from Chris Bryant, CCIE #12933.

The great thing about CCNA certification training is that the skills you learn will truly come in handy when working with Cisco routers and switches in production networks.  That's particularly true of static route configuration.  While most networks use dynamic routing protocols such as RIP, EIGRP, and OSPF to build routing tables, static routes still come in handy sometimes - especially if a routing protocol configuration goes awry. 

Let's say that you just added a new segment to your network and you've successfully added it to your network's routing tables.  Suddenly, on Monday morning, users on that segment can't get to a network resource such as an email server, or they can't get out to the Internet.  We all know what it's like to try to fix something while the phone's ringing like crazy.  That's when we have to do two things.

First, resist the temptation to say ?I would fix it, but I?m too busy talking to you?.

Second, use a quick fix to get the issue resolved temporarily while you resolve the issue.

Static routes are a great quick fix.  You can use a static route to get the users where they need to be, which gives you time to find out what the problem is with the dynamic routing protocol. (You must also resist the temptation to apply a static route and declare the problem fixed!)

Static routes are configured with the ip route command, followed by the destination network and mask.  After that, you must specify either the next-hop IP address or the local exit interface.  Both of the following masks are acceptable:

ip route 172.10.1.0 255.255.255.0 210.1.1.1

ip route 172.10.1.0 255.255.255.0 serial0

Using IOS Help on a Cisco router shows the various options:

R1(config)#ip route ?

  A.B.C.D  Destination prefix

  profile  Enable IP routing table profile

  vrf      Configure static route for a VPN Routing/Forwarding instance

R1(config)#ip route 172.10.1.0 ?

  A.B.C.D  Destination prefix mask

R1(config)#ip route 172.10.1.0 255.255.255.0 ?

  A.B.C.D    Forwarding router's address

  BRI        ISDN Basic Rate Interface

  Dialer     Dialer interface

  Loopback   Loopback interface

  Null       Null interface

  Serial     Serial

  TokenRing  IEEE 802.5

RememberPsychology Articles, you're specifying either the next-hop router's IP address or the local router's exit interface!

Configuring static routes is a great skill to have in the network room and in the CCNA exam room.  Be ready to configure them in either situation!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 200 free certification exam tutorials, including CCNA certification training articles. His exclusive CCNA study guide is also available!Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online Cisco CCNA training boot camp with The Bryant Advantage!

Labels: , , , ,

Thursday, January 29, 2009

Cisco CCNA Certification Exam Training: Telnet, Passwords, and Privilege

Your CCNA certification exam is likely going to contain questions about Telnet, an application-level protocol that allows remote communication between two networking devices. With Telnet use being as common as it is, you had better know the details of how to configure it in order to pass your CCNA exam and to work in real-world networks.

The basic concept is pretty simple - we want to configure R1, but we're at R2. If we telnet successfully to R1, we will be able to configure R1 if we've been given the proper permission levels. In this CCNA case study, R2 has an IP address of 172.12.123.2 and R1 an address of 172.12.123.1. Let's try to telnet from R2 to R1.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

Password required, but none set

[Connection to 172.12.123.1 closed by foreign host]

This seems like a problem, but it's a problem we're happy to have. A Cisco router will not let any user telnet to it by default. That's a good thing, because we don't want just anyone connecting to our router! The "password required" message means that no password has been set on the VTY lines on R1. Let's do so now.

R1(config)#line vty 0 4

R1(config-line)#password baseball

A password of "baseball" has been set on the VTY lines, so we shouldn't have any trouble using Telnet to get from R2 to R1. Let's try that now.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1>

We're in, and placed into user exec mode. Let's say we want to configure a new IP address on the ethernet interface on R1. We'll now go into privileged exec mode....

R1>enable

% No password set

R1>

... or maybe we won't! The default behavior of Telnet on a Cisco router is to place the incoming user into user exec mode, and require an enable password to allow that user into privileged exec mode! Right now, we can't configure anything on this router and even the show commands we would use are limited at best.

If we wanted to allow all telnetting users to be put into privileged exec mode immediately without being prompted for an enable password, the command privilege level 15 placed on the VTY lines will accomplish this.

R1(config)#line vty 0 4

R1(config-line)#privilege level 15

From R2, we'll telnet into R1 again.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1#

We were able to telnet in from R2 with the original password of "baseball", and even better, we were placed into privileged exec mode immediately!

You may or may not want to do this in real-world networks, though. If you want to assign privilege levels on an individual user basis, configure usernames and passwords and use the privilege 15 command in the actual username/password command itself to give this privilege levels to some users but not all.

R1(config)#username heidi password klum

R1(config)#username tim privilege 15 password gunn

Both users can telnet into the router, but the first user will be placed into user exec and challenged for the enable password to enter privileged exec mode. If there is no enable password, the user literally cannot get into privileged exec. The second user will be placed into privileged exec immediately after successfully authenticating.

Passwords on a Cisco router or switch are vitally important, and you're not tied down to granting "all-or-nothing" access. Knowing the details like the ones shown here help you tie down network security while allowing people to do their jobs - and it doesn't hurt to know this stuff for the CCNA exam, either!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , , ,

Monday, January 12, 2009

CCNA Certification Exam Training: Passwords, Cisco Routers, And Network

CCNA certification is important, and so is securing our network's Cisco routers! To reflect the importance of network security, your CCNA certification exam is likely going to contain quite a few questions about the various passwords you can set on a Cisco router. Let's take a look at some of those passwords and when to apply them.

If the previous user has logged out of the router properly, you will see a prompt like this when you sit down at the router console:

R1 con0 is now available

Press RETURN to get started.

R1>

To get into enable mode, by default all I have to do is type "enable".

R1>enable

R1#

See how the prompt changed? By default, I can now run all the show and debug commands I want, not to mention entering global configuration mode and doing pretty much what I want. It just might be a good idea to password protect this mode! We do so with either the enable password command or the enable secret command. Let's use the enable password command first.

R1(config)#enable password dolphins

Now when I log out and then go back to enable mode - or try to - I should be prompted for the password "dolphins". Let's see what happens.

R1>enable

Password:

R1#

I was indeed prompted for a password. Cisco routers will not show asterisks or any other character when you enter a password; in fact, the cursor doesn't even move.

The problem with the enable password command is that the password will show in the configuration in clear text, making it easy for someone to look over your shoulder and note the password for future use, as shown below:

hostname R1

enable password dolphins

We could use the "service password-encryption" command to encrypt the enable password, but that will also encrypt all the other passwords in the Cisco router config. That's not necessarily a bad thing! Here's the effect of this command on the enable password we set earlier.

enable password 7 110D1609071A020217

Pretty effective encryption! However, if we want to have the enable password automatically encrypted, we can use the enable secret command. I'll use that command here to set this password to "saints", and note that I'm not removing the previous enable password.

R1(config)#enable secret saints

After removing the "service password-encryption" command, we're left with two enable mode passwords, and they appear in the Cisco router config like this:

enable password dolphins

enable secret 5 $1$kJB6$fPuVebg7uMnoj5KV4GUKI/

If we have two enable passwords, which one should we use to log into the router? Let's try the first password, "dolphins", first:

R1>enable

Password:

Password:

When you're prompted for the password a second time, you know you got it wrong the first time! Let's try "saints":

R1>enable

Password:

Password:

R1#

When both the enable secret and enable password commands are in use on a Cisco router, the enable secret password always takes precedence. "dolphins" didn't get us in, but "saints" did. That's valuable information for both the CCNA certification exam and real-world networks, because there's no worse feeling than typing a password at a Cisco router prompt and then getting another password prompt!

This is just one way to perform basic Cisco router security with passwords. We'll take a look at other methods in a future CCNA certification exam training tutorial!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , , , ,

Friday, October 31, 2008

Cisco CCNP Certification Training : The New CCNP BCMSN 642-812 Exam

Cisco CCNP certification is about to become more valuable and more difficult! Cisco is making major changes to the CCNP certification program, retiring two exams (BCRAN and CIT) while updating two old friends, the BSCI and BCMSN exam. Today, we'll take a look at the changes in the Building Converged Cisco Multilayer Switched Networks (BCMSN) exam.

According to Cisco's exam blueprint, there are some major additions with the introduction of the 642-812 exam. Wireless access, security, and voice are all rapidly growing features and concerns in today's real-world networks, and Cisco is responding to that by adding all three of these topics to the CCNP BCMSN exam. Cisco CCNP candidates should expect to be questioned on WLANs as well as wireless clients.

There were some security topics on the 642-811 BCMSN exam, port security and 802.1x among them. The successful Cisco CCNP certification candidate will now be expected to know about the different network attacks that can take place at the data link layer of the OSI model, including DHCP Spoofing and VLAN Hopping.

There was also just a bit of voice material on the 642-811 BCMSN exam, but you'll have to know more voice to pass the 642-812 exam. Voice VLANs, voice QoS, and IP Phone configuration are just some of the topics being added to the new BCMSN exam.

Cisco is obviously raising the bar with the new CCNP exams, and this certification is going to be harder to get than ever before. That also makes it more valuable than ever before, and 2007 will be the best year yet in which to earn your CCNP certification. Make your plans to earn this valuable Cisco certification, and then put that plan into action!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , ,

Tuesday, July 22, 2008

Seattle Seahawks at San Francisco 49ers


It's a week 11 NFL match up of division foes. The Seahawks lead the series 8-6 and have plowed through the 49ers in the last 6 meetings. They could very well post another 14+ point victory this week.

The 49ers are coming off another victory--they are 4-5 now--and hope to make it three in a row. Two weeks ago they beat the Minnesota Vikings in San Francisco 9-6. To say this game was boring is an understatement. Last week they went to Detroit and beat a lackluster Lions team 19-13. I think the Detroit Tigers would have gave them a better run for the money.

The Seahawks continue to move forward without MVP running back Shaun Alexander and Pro Bowl QB Matt Hasslebeck. However, there's good new from Seahawks camp. Both will be practicing this week. They might get some limited duty this weekend--depending how the game goes. Last week backup RB Morris and QB Wallace helped the Seahawks beat division foe St. Louis. The play of the game was the 90ish yard return by newly sign WR Nate Burleson.

Wallace is playing pretty well and the 49ers aren't exactly a top team. We might see Hasslebeck play a series or even take another week off. The remaining schedule favors the Seahawks, so they can be a bit cautious here.

I'm looking for the Hawks offense to explode on the soft 49ers secondary. This is a team--49ers--that gave up 40+ points to Chicago, Kansas City and San Diego. They also gave up 34 to Arizona and 38 to Philadelphia. This could be another explosive day for the Seahawks offense. Look for them to open it up early to get a lead and give their returning stars the opportunity to "practice" during the game. This is another great opportunity for the Seahawks defense to tighten up and work on some issues.

The author writes articles on many topics including sports wagering, jeu casino, and paris en ligne.

Labels: , , ,

Monday, January 28, 2008

Cisco CCNP / BCMSN Exam Tutorial: BPDU Skew Detection

You may look at that feature's name and think, "What is a BPDU Skew, and why do I want to detect it?" What we're actually attempting to detect are BPDUs that aren't being relayed as quickly as they should be.

After the root bridge election, the root bridge transmits BPDUs, and the non-root switches relay that BPDU down the STP tree. This should happen quickly all around, since the root bridge will be sending a BPDU every two seconds by default ("hello time"), and the switches should relay the BDPUs fast enough so every switch is seeing a BPDU every two seconds.

That's in a perfect world, though, and there are plenty of imperfect networks out there! You may have a busy switch that can't spare the CPU to relay the BDPU quickly, or a BPDU may just simply be lost in transmission. That two-second hello time value doesn't give the switches much leeway, but we don't want the STP topology recalculated unnecessarily either.

BDPU Skew Detection is strictly a notification feature. Skew Detection will not take action to prevent STP recalculation when BDPUs are not being relayed quickly enough by the switches, but it will send a syslog message informing the network administrator of the problem. The amount of time between when the BDPU should have arrived and when it did arrive is referred to as "skew time" or "BPDU latency".

A busy CPU could quickly find itself overwhelmed if it had to send a syslog message for every BPDU delivery that's skewed. The syslog messages will be limited to one every 60 seconds, unless the "skew time" is at a critical level. In that case, the syslog message will be sent immediately with no one-per-minute limit.

And what is "critical", according to BDPU Skew Detection? Any value greater than 1/2 of the MaxAge value, making the critical skew time level 10 seconds or greater.

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage (http://www.thebryantadvantage.com), home of free CCNP and CCNA tutorials! For my FREE "How To Pass The CCNA" or "CCNP" ebook, visit the website and download your copies. Pass your CCNP exam with The Bryant Advantage

Labels: , , , , , , ,

Thursday, January 10, 2008

Cisco CCNP/BSCI Exam Tutorial: Rip Update Packet Authentication

When you earned your CCNA, you thought you learned everything there is to know about RIP. Close, but not quite! There are some additional details you need to know to pass the BSCI exam and get one step closer to the CCNP exam, and one of those involves RIP update packet authentication.

You're familiar with some advantages of using RIPv2 over RIPv1, support for VLSM chief among them. But one advantage that you're not introduced to in your CCNA studies is the ability to configure routing update packet authentication.

You have two options, clear text and MD5. Clear text is just that - a clear text password that is visible by anyone who can pick a packet off the wire. If you're going to go to the trouble of configuring update authentication, you should use MD5. The MD stands for "Message Digest", and this is the algorithm that produces the hash value for the password that will be contained in the update packets.

Not only must the routers agree on the password, they must agree on the authentication method. If one router sends an MD5-hashed password to another router that is configured for clear-text authentication, the update will not be accepted. debug ip rip is a great command for troubleshooting authenticated updates.

R1, R2, and R3 are running RIP over a frame relay cloud. Here is how RIP authentication would be configured on these three routers.

R1#conf t

R1(config)#key chain RIP

< The key chain can have any name. >

R1(config-keychain)#key 1

< Key chains can have multiple keys. Number them carefully when using multiples. >

R1(config-keychain-key)#key-string CISCO

< This is the text string the key will use for authentication. >

R1(config)#int s0

R1(config-if)#ip rip authentication mode text

< The interface will use clear-text mode. >

R1(config-if)#ip rip authentication key-chain RIP

< The interface is using key chain RIP, configured earlier. >

R2#conf t

R2(config)#key chain RIP

R2(config-keychain)#key 1

R2(config-keychain-key)#key-string CISCO

R2(config)#int s0.123

R2(config-subif)#ip rip authentication mode text

R2(config-subif)#ip rip authentication key-chain RIP

R3#conf t

R3(config)#key chain RIP

R3(config-keychain)#key 1

R3(config-keychain-key)#key-string CISCO

R3(config)#int s0.31

R3(config-subif)#ip rip authentication mode text

R3(config-subif)#ip rip authentication key-chain RIP

To use MD5 authentication rather than clear-text, simply replace the word "text" in the ip rip authentication mode command with md5.

Here's what a successfully authentication RIPv2 packet looks like, courtesy of debug ip rip. Clear-text authentication is in effect and the password is "cisco".

3d04h: RIP: received packet with text authentication cisco

3d04h: RIP: received v2 update from 150.1.1.3 on Ethernet0

3d04h: 100.0.0.0/8 via 0.0.0.0 in 1 hops

3d04h: 150.1.2.0/24 via 0.0.0.0 in 1 hops

Here's what it looks like when the remote device is set for MD5 authentication and the local router is set for clear-text. You'll also see this message if the password itself is incorrect.

3d04h: RIP: ignored v2 packet from 150.1.1.3 (invalid authentication)

"Debug ip rip" may be a simple command as compared to the debugs for other protocols. but it's also a very powerful debug. Start using debugs as early as possible in your Cisco studies to learn how router commands really work!


Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage (http://www.thebryantadvantage.com), home of free CCNA and CCNP tutorials! For my FREE "How To Pass The CCNA" or "CCNP" ebook, visit the website and download your copies. Pass your CCNA exam with The Bryant Advantage!

Labels: , , ,

Sunday, January 6, 2008

Cisco CCNA Exam Tutorial: Password Recovery Procedures

It might happen on your CCNA exam, it might happen on your production network - but sooner or later, you're going to have to perform password recovery on a Cisco router or switch. This involves manipulating the router's configuration register, and that is enough to make some CCNA candidates and network administrators really nervous!

It's true that setting the configuration register to the wrong value can damage the router, but if you do the proper research before starting the password recovery process, you'll be fine.

Despite what some books say, there is no "one size fits all" approach to Cisco password recovery. What works on a 2500 router may not work on other routers and switches. There is a great master Cisco document out on the Web that you should bookmark today. Just put "cisco password recovery" in your favorite search engine and you should find it quickly.

The following procedure describes the process in recovering from a lost password on a Cisco 2500 router. As always, don't practice this at home. It is a good idea to get some practice with this technique in your CCNA / CCNP home lab, though!

The password recovery method examined here is for 2500 routers.

An engineer who finds themselves locked out of a router can view and change the password by changing the configuration register.

The router must first be rebooted and a "break" performed within the first 60 seconds of the boot process. This break sequence can also vary depending on what program is used to access the router, but is the usual key combination.

The router will now be in ROM Monitor mode. From the rom monitor prompt, change the default configuration register of 0x2102 to 0x2142 with the o/r 0x2142 command. Reload the router with the letter i. (As you can see, ROM Monitor mode is a lot different than working with the IOS!)

This particular config register setting will cause the router to ignore the contents of NVRAM. Your startup configuration is still there, but it will be ignored on reload.

When the router reloads, you'll be prompted to enter Setup mode. Answer "N", and type enable at the router> prompt.

Be careful here. Type configure memory or copy start run. Do NOT type write memory or copy run start!

Enter the command show running-config. You'll see the passwords in either their encrypted or unencrypted format.

Type config t, then use the appropriate command to set a new enable secret or enable password.

Don't forget to change the configuration register setting back to the original value! The command config-register 0x2102 will do the job. Save this change with write memory or copy run start, and then run reload one more time to restart the router.

This process sounds hard, but it's really not. You just have to be careful, particularly when you're copying the startup config over the running config. You don't want to get that backwards! So take your time, check the online Cisco documentation before starting, get some practice with this procedure with lab equipment, and you'll be ready for success on the CCNA exam and in your production network!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage (http://www.thebryantadvantage.com), home of free CCNA and CCNP tutorials! For my FREE "How To Pass The CCNA" or "CCNP" ebook, visit the website and download your copies. Pass your CCNA exam with The Bryant Advantage!

Labels: , , , , , , , ,

Tuesday, November 20, 2007

Cisco CCNA Certification and Career Path

Following your computer training toward your career path, you can go for the CCNA certification (Cisco Certified Network Associate), which indicates a foundation in the apprentice knowledge of networking. CCNA training allows you the ability for installations and operation of LAN, WAN, and dialup access services for small networks with 100 nodes or less.

The CCNA course includes, but not limited to use the different networking protocols such as Ethernet, Access Lists, Serial, IP, IGRP, Frame Relay, IP RIP, and VLANs. Cisco's CCNA Prep Center Pilot offers simulations and sample questions, besides the e-learning modules and laboratories.

Computer training includes also valuable tips from CCNA professionals, in addition to expert advice, and encouragement through CCNA certification success stories. CCNA training does not require any prerequisite and makes available many other resources to help students with the preparation of their CCNA certification exams.

CCNA course, exams and recommended training include the Introduction to Cisco Networking Technologies (INTRO), the Interconnecting Cisco Networking Devices (ICND) or both. CCNA training and additional training, probably cover most of your career path expectations.

However, Cisco's CCNA certifications are valid for 3 years, so it is necessary for additional computer training to re-certify. This is achieved by either passing the current CCNA exam at the moment of the original certification's expiration, passing the ICND exam, passing the 642 professional levels.

After CCNA training your can also re-certify by passing the Cisco Qualified Specialist exam, excluding the Sales Specialist exams, or passing a CCIE written exam, which is a re-certify form valid for individual who had a CCNA certification starting from October 1, 2004.

Cisco CCNA online training certification program, offers the same value, knowledge and skill earned on a traditional CCNA course, and it is a nationally recognized certification. With computer training online, you will gain knowledge of switched LAN Emulation networks, which are made up of Cisco original equipment.

CCNA training online focuses the coverage of Cisco router configuration procedures, mapped to exam objectives in order to prepare you for Cisco Exam 640-80, in partnership with major universities and colleges offering as well CCNA certification.

The Computer training program online consists of 2 sections; "Introduction to Network Engineering", allowing the student to understand the world of network engineering, learning fundamental facts of data network theory and current technologies making the Internet tick.

The second section of the online CCNA course, "Practical Network Engineering", is an approach to some of the most powerful networking technologies, involving extensive work on switches, Cisco routers, and firewalls in a simulated network environment, preparing students to earn the CCNA certification.

Natalie Aranda writes about business, training and certifications.

Labels: , ,

Thursday, August 30, 2007

Cisco Certification: The Cisco Three-Layered Hierarchical Model

Cisco Certification: The Cisco Three-Layered Hierarchical Model

 by: www.SemSim.com

Cisco has defined a hierarchical model known as the hierarchical internetworking model. This model simplifies the task of building a reliable, scalable, and less expensive hierarchical internetwork because rather than focusing on packet construction, it focuses on the three functional areas, or layers, of your network:

Core layer: This layer is considered the backbone of the network and includes the high-end switches and high-speed cables such as fiber cables. This layer of the network does not route traffic at the LAN. In addition, no packet manipulation is done by devices in this layer. Rather, this layer is concerned with speed and ensures reliable delivery of packets.

Distribution layer: This layer includes LAN-based routers and layer 3 switches. This layer ensures that packets are properly routed between subnets and VLANs in your enterprise. This layer is also called the Workgroup layer.

Access layer: This layer includes hubs and switches. This layer is also called the desktop layer because it focuses on connecting client nodes, such as workstations to the network. This layer ensures that packets are delivered to end user computers.

Figure INT.2.1 displays the three layers of the Cisco hierarchical model.

When you implement these layers, each layer might comprise more than two devices or a single device might function across multiple layers.The benefits of the Cisco hierarchical model include:

High Performance: You can design high performance networks, where only certain layers are susceptible to congestion.

Efficient management & troubleshooting: Allows you to efficiently organize network management and isolate causes of network trouble.

Policy creation: You can easily create policies and specify filters and rules.

Scalability: You can grow the network easily by dividing your network into functional areas.

Behavior prediction: When planning or managing a network, the model allows you determine what will happen to the network when new stresses are placed on it.

Core Layer

The core layer is responsible for fast and reliable transportation of data across a network. The core layer is often known as the backbone or foundation network because all other layers rely upon it. Its purpose is to reduce the latency time in the delivery of packets. The factors to be considered while designing devices to be used in the core layer are:

High data transfer rate: Speed is important at the core layer. One way that core networks enable high data transfer rates is through load sharing, where traffic can travel through multiple network connections.

Low latency period: The core layer typically uses high-speed low latency circuits which only forward packets and do not enforcing policy.

High reliability: Multiple data paths ensure high network fault tolerance; if one path experiences a problem, then the device can quickly discover a new route.

At the core layer, efficiency is the key term. Fewer and faster systems create a more efficient backbone. There are various equipments available for the core layer. Examples of core layer Cisco equipment include:

Cisco switches such as 7000, 7200, 7500, and 12000 (for WAN use)

Catalyst switches such as 6000, 5000, and 4000 (for LAN use)

T-1 and E-1 lines, Frame relay connections, ATM networks, Switched Multimegabit Data Service (SMDS)

Distribution Layer

The distribution layer is responsible for routing. It also provides policy-based network connectivity, including:

Packet filtering (firewalling): Processes packets and regulates the transmission of packets based on its source and destination information to create network borders.

QoS: The router or layer 3 switches can read packets and prioritize delivery, based on policies you set.

Access Layer Aggregation Point: The layer serves the aggregation point for the desktop layer switches.

Control Broadcast and Multicast: The layer serves as the boundary for broadcast and multicast domains.

Application Gateways: The layer allows you to create protocol gateways to and from different network architectures.

The distribution layer also performs queuing and provides packet manipulation of the network traffic.

It is at this layer where you begin to exert control over network transmissions, including what comes in and what goes out of the network. You will also limit and create broadcast domains, create virtual LANs, if necessary, and conduct various management tasks, including obtaining route summaries. In a route summary, you consolidate traffic from many subnets into a core network connection. In Cisco routers, the command to obtain a routing summary is:

show ip route summary

You can practice viewing routing information using a free CCNA exam router simulator available from SemSim.com. You can also determine how routers update each other's routing tables by choosing specific routing protocols.

Examples of Cisco-specific distribution layer equipment include 2600,4000, 4500 series routers

Access Layer

The access layer contains devices that allow workgroups and users to use the services provided by the distribution and core layers. In the access layer, you have the ability to expand or contract collision domains using a repeater, hub, or standard switch. In regards to the access layer, a switch is not a high-powered device, such as those found at the core layer.

Rather, a switch is an advanced version of a hub.

A collision domain describes a portion of an Ethernet network at layer 1 of the OSI model where any communication sent by a node can be sensed by any other node on the network. This is different from a broadcast domain which describes any part of a network at layer 2 or 3 of the OSI model where a node can broadcast to any node on the network.

At the access layer, you can:

Enable MAC address filtering: It is possible to program a switch to allow only certain systems to access the connected LANs.

Create separate collision domains: A switch can create separate collision domains for each connected node to improve performance.

Share bandwidth: You can allow the same network connection to handle all data.

Handle switch bandwidth: You can move data from one network to another to perform load balancing

SemSim.com provides training resources for Cisco certification exams: CCIE, CCNP, CCNA, CCDP, CCDA. It offers FREE learning resources to students such as study guides and router simulation labs. For more information visit: http://www.SemSim.com : Making Cisco cetification easy!
support@semsim.co

Labels: , , , , ,