<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1540073174900542234</id><updated>2012-02-12T15:55:53.782-08:00</updated><title type='text'>Farhan Anwar's Online Presence</title><subtitle type='html'>Network Implementations, Solutions and Certifications</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-3824710773124517918</id><published>2010-12-14T13:00:00.001-08:00</published><updated>2010-12-14T13:00:13.218-08:00</updated><title type='text'>CCIE SP Experiences</title><content type='html'>I have taken CCIE SP Lab for two times until now. Searching and requesting friends and connections for another date before the track changes. Being in the same shoes two times, I have found the lab quite amazing and enjoying. Also expensive.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- Posted using BlogPress from my iPad&lt;br /&gt;&lt;p class='blogpress_location'&gt;Location:&lt;a href='http://maps.google.com/maps?q=Jebel%20Ali%20Race%20Course%20Rd,Dubai,United%20Arab%20Emirates%4025.096541%2C55.171864&amp;z=10'&gt;Jebel Ali Race Course Rd,Dubai,United Arab Emirates&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-3824710773124517918?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/3824710773124517918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=3824710773124517918' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/3824710773124517918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/3824710773124517918'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2010/12/ccie-sp-experiences.html' title='CCIE SP Experiences'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-7657753496957225640</id><published>2009-04-23T00:54:00.001-07:00</published><updated>2009-04-23T00:54:59.924-07:00</updated><title type='text'>CCIE Security Written Pre-Qualification Exam</title><content type='html'>&lt;p&gt;   &lt;p&gt;&lt;/p&gt;    &lt;p&gt;I have passed my CCIE Security Written Exam recently. It requires extensive preparation and advanced level hands on experience on Cisco Security Appliances, Modules and Security Applications. &lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;Furthermore, it requires deep understanding of Security and IP Protocols is also required. Good Handon experience and understanding on Cisco CS-MARS, NAC Appliances, AAA Servers, CSA etc is also essential.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt; This exam is a little different because, as because, several routing and switching topics are also included, so you must have good understanding of popular routing protocols and their security features.    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;     &lt;p&gt;I have used for following books for preparing for this exam:&lt;/p&gt;   &lt;/p&gt;    &lt;p style="width: 436px; height: 0.93%"&gt;     &lt;h5&gt;1. Cisco Press - Cisco ASA All-In-One Firewall, IPS And VPN Adaptive Security Appliance&lt;/h5&gt;      &lt;h5&gt;2. Cisco Press – CCIE Security Exam Certification Study Guide – 2nd Edition&lt;/h5&gt;   &lt;/p&gt;    &lt;h5&gt;3. Cisco Press – CCIE Security Quick Reference Sheet&lt;/h5&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-7657753496957225640?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/7657753496957225640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=7657753496957225640' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/7657753496957225640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/7657753496957225640'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2009/04/ccie-security-written-pre-qualification.html' title='CCIE Security Written Pre-Qualification Exam'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-5000828694887542940</id><published>2009-04-23T00:38:00.001-07:00</published><updated>2009-04-23T00:38:21.794-07:00</updated><title type='text'>CCIE Bootcamps and Training</title><content type='html'>&lt;p&gt;   &lt;p&gt;&lt;/p&gt;    &lt;p&gt;For getting your CCIE Certification, it is essential that you get proper training, guidance, support and hands-on equipment. There are several world-wide training companies who are giving CCIE Training using several different delivery methods such as online, on-demand, on-site and off-site.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;Below are some of the most popular Training Companies giving world class training:&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;1. Internetwork Expert – internetworkexpert.com, is the leader in CCIE Training with experienced dual, triple, quad and penta ccie instructors.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;2. IP Expert – ipexpert.com, is the most popular CCIE Training and preparation company to date.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;3. ccBootCamp – ccbootcamp.com, is also the leader in training and preparing candidates for multiple CCIE Tracks.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;Besides, these what i can remember, there are several other persons who are very much popular in CCIE BootCamps such as Brian Dennis, Scott Morris, Brian Mcgaghan, Roman, Narbik and Khawar Butt. Try googling for them and you can find their upcoming bootcamps, locations and costs.&lt;/p&gt;    &lt;p&gt;&lt;/p&gt;    &lt;p&gt;     &lt;p&gt;For passing the CCIE Lab, you needs hours and hours of handson, there are three options for it:&lt;/p&gt;      &lt;p&gt;&lt;/p&gt;      &lt;p&gt;1. Purchase your own rack.&lt;/p&gt;      &lt;p&gt;2. Take Equipment on Rent (many companies do it).&lt;/p&gt;      &lt;p&gt;3. Buy online rack rental hours.&lt;/p&gt;      &lt;p&gt;&lt;/p&gt;      &lt;p&gt;Any option can be taken, depending on your financial condition and comfortability. The most expensive option is the first one. The least expensive is the last one.&lt;/p&gt;      &lt;p&gt;&lt;/p&gt;      &lt;p&gt;Some popular rack rental sites are:&lt;/p&gt;      &lt;p&gt;&lt;/p&gt;      &lt;p&gt;1. &lt;a href="http://www.internetworkexpert.com"&gt;www.internetworkexpert.com&lt;/a&gt;&lt;/p&gt;      &lt;p&gt;2. &lt;a href="http://www.proctorlabs.com"&gt;www.proctorlabs.com&lt;/a&gt;&lt;/p&gt;      &lt;p&gt;3. &lt;a href="http://www.ccie2b.com"&gt;www.ccie2b.com&lt;/a&gt;&lt;/p&gt;      &lt;p&gt;4. &lt;a href="http://www.ccie4u.com"&gt;www.ccie4u.com&lt;/a&gt; &lt;/p&gt;      &lt;p&gt;5. &lt;a href="http://www.cconlinelabs.com"&gt;www.cconlinelabs.com&lt;/a&gt;&lt;/p&gt; 6. &lt;a href="http://www.ipexpert.com"&gt;www.ipexpert.com&lt;/a&gt;       &lt;p&gt;&lt;/p&gt; I hope this information might have been useful, if it is to you, do leave a comment or drop me an email.&lt;/p&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-5000828694887542940?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/5000828694887542940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=5000828694887542940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5000828694887542940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5000828694887542940'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2009/04/ccie-bootcamps-and-training.html' title='CCIE Bootcamps and Training'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-1561902833142559774</id><published>2009-04-15T13:44:00.000-07:00</published><updated>2009-04-16T05:53:12.128-07:00</updated><title type='text'>Starter's Guidelines for Persuing Expert Network Certifications</title><content type='html'>After many emails from youngsters and juniors asking how I started my career and pursued a successful career in Information and Communications Technology. Finally i was able to devote some time to write something as a guideline to pursue a successful career in networks engineering.&lt;br /&gt;&lt;br /&gt;First things first, there are a lot of misconceptions getting into the Systems / Networks Engineering, most of the fresh graduates are asking me repeatedly the same question that "&lt;span style="font-style: italic;"&gt;is it worthy enough to pursue a career in it after graduation and do certifications, will it be a good  career with growth and progression&lt;/span&gt;?"&lt;br /&gt;&lt;br /&gt;The simple answer is, &lt;span style="font-style: italic;"&gt;it depends&lt;/span&gt;. There are several specialization paths that could be followed such as "Systems Engineering" , "Network Engineering" , "Security Administration" , "Storage Area Networks Engineering" , "Voice over IP Administration" and "Wireless Networks".&lt;br /&gt;&lt;br /&gt;Lets take each one, once you enter you could go into "Systems Engineering / Administration" that is mainly dominated by Operating Systems and Server Administration like Windows Server System, Linux, Unix and Solaris. Almost all of them offer several enterprise services such as Directory, Naming, Email, Security, Data Transfer, Communication, Voice, Video etc.&lt;br /&gt;&lt;br /&gt;Certifications involving Systems Engineering are available from several different vendors such as Microsoft, RedHat, IBM, HP, Sun, Comptia, EC-Council etc.&lt;br /&gt;&lt;br /&gt;The next path is "Networks Engineering / Administration" which is a very promising and growing field, it sub-divides into several different categories such as Routing &amp;amp; Switching, Network Security, Service Provider Networks, Wireless Networks and Voice over IP. These are very wide, vast fields which can be a WORLD in themselves.&lt;br /&gt;&lt;br /&gt;Major Certifications are offered from Cisco and Juniper.&lt;br /&gt;&lt;br /&gt;The other path belonging to Systems and Network Design and Architecture, this is the next career progression for an engineer after working in the implementation for a considerable number of years. This is a critical job role involving Enterprisewide Systems and Networks design.&lt;br /&gt;&lt;br /&gt;Cisco Offers a seperate track for its design professionals including associate, professional and expert level certifications. Several other vendor neutral and vendor specific certifications are also available, but designing and architecting the enterprise requires implementation experience.&lt;br /&gt;&lt;br /&gt;So far I have highlighted the sub-divisions of the Networks and Systems Engineering including:&lt;br /&gt; - Systems Engineering&lt;br /&gt; - Network Engineering including Routing, Switching, Service Provider and Wireless&lt;br /&gt; - Network and Systems Security Administration&lt;br /&gt; - Network, Systems and Security Design&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-1561902833142559774?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/1561902833142559774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=1561902833142559774' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/1561902833142559774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/1561902833142559774'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2009/04/starters-guidelines-for-persuing-expert.html' title='Starter&apos;s Guidelines for Persuing Expert Network Certifications'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-5423144520200483440</id><published>2008-02-19T01:59:00.000-08:00</published><updated>2008-02-19T02:09:39.156-08:00</updated><title type='text'>Dynamips for CCIE R/S</title><content type='html'>The IdlePC Values and IOS Versions that i used to build the CCIE R/S Lab are:&lt;br /&gt;&lt;br /&gt;[[3725]]&lt;br /&gt;        image = /ccie/base/c3725-adventerprisek9-mz.124-17.bin&lt;br /&gt;        ram = 128&lt;br /&gt;        disk0 = 0&lt;br /&gt;        disk1 = 0&lt;br /&gt;        mmap = True&lt;br /&gt;        ghostios = True&lt;br /&gt;        idlepc = 0x60a6d020&lt;br /&gt;&lt;br /&gt;[[3640]]&lt;br /&gt;        image = /ccie/base/c3640-js-mz.124-17.bin&lt;br /&gt;        ram = 128&lt;br /&gt;        disk0 = 0&lt;br /&gt;        disk1 = 0&lt;br /&gt;        mmap = True&lt;br /&gt;        ghostios = True&lt;br /&gt;        idlepc = 0x604c37fc&lt;br /&gt;&lt;br /&gt;For Instance 1: The 3725's were used for Routers R1 - R6.&lt;br /&gt;For Instance 2: All 3640's were used for SW1 - SW4 and BB1 - BB3.&lt;br /&gt;&lt;br /&gt;In Linux, i have noticed that 3725 performs much better as compared to 3640.  On full load, means IGP, BGP, Redistribution, Multicasting and Security the CPU Load was 40%.&lt;br /&gt;&lt;br /&gt;The Dynamips Server Configuration was:&lt;br /&gt;AMD Athlon X2 64Bit 4400+&lt;br /&gt;2 GB Corsair DDR2&lt;br /&gt;80 Gb HDD&lt;br /&gt;Fedora Core 6, 32Bit&lt;br /&gt;&lt;br /&gt;The Dynagen Client runs on my laptop in Windows XP.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-5423144520200483440?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/5423144520200483440/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=5423144520200483440' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5423144520200483440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5423144520200483440'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2008/02/dynamips-for-ccie-rs.html' title='Dynamips for CCIE R/S'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-8256553598940582191</id><published>2008-01-28T23:36:00.000-08:00</published><updated>2008-01-28T23:41:21.144-08:00</updated><title type='text'></title><content type='html'>&lt;p class="MsoNormal"&gt;Hi All,&lt;br /&gt;&lt;br /&gt;Since my last post regarding my CCIE# i have received countless unicasts from different professionals asking for advice on how to start their studies and how i did it in the first attempt. Finally since I am still resting and evaluating Job Offers in my mailbox :) , I have decided to write my journey towards becoming a ccie. I couldn't find any better place than the GS itself so pardon me if you don't like the size of it. Here it goes, pardon me for any typos and NO I don't work for any workbook vendor ;), telling ya straight.&lt;br /&gt;&lt;br /&gt;I started preparing for the CCIE roughly 4 years ago when i did the CCIE Routing &amp;amp; Switching Training from a local institute during my studies.  But then I entered in the professional field, got married ;) and things slowed down to a halt due to my OTHER activities.&lt;br /&gt;&lt;br /&gt;I started my personal goal again over 1.5 years ago but things were going very slow, until i finally decided to take CCIE Certification Seriously and devote time and resources to it, i started studying in nights and on whole weekends. For Practicing I was in search of low-cost lab equipment when a friend told me about dynamips as a Cisco 7200 Router Simulator; i was impressed with the performance and its ease of use. I immediately started searching for its features, configuration settings and found a detailed article from Brian Mcghan of internetworkexpert explaining dynamips, furthermore the HACKI's forum was very much helpful in the initial stages of dynamips / dynagen experiences.&lt;br /&gt;&lt;br /&gt;I tuned, tweaked and optimized dynamips configuration files and idlepc values for one month while practicing my Routing Techniques on it, and it was in JANUARY 2007. A CCIE Friend told me about &lt;a href="http://internetworkexpert.com/" target="_blank"&gt;internetworkexpert.com&lt;/a&gt;. And also about the &lt;a href="http://groupstudy.com/" target="_blank"&gt;groupstudy.com&lt;/a&gt;, At that time I didn't have a clear view of what to study how to do it and what to practice for the CCIE due to a number of topics being covered in the R&amp;amp;S Program.  Brian's detailed CCIE R&amp;amp;S Topics list in their Free Resources section helped me enormously till the last day for tracking my performance and topics to cover.&lt;br /&gt;&lt;br /&gt;I already had a strong base in IGP and BGP but i was weak in Advanced Switching, QoS, Security and Multicasting. For getting an edge in non-core topics i reviewed KnowledgeNet QoS and Multicast. I polished my security and Switching skills using the Cisco DocCD.&lt;br /&gt;&lt;br /&gt;Afterwards, i started viewing Class on Demand Videos of Internetwork Expert. After digesting that video of several hours in one month by seeing it again and again. I started doing Advanced Technology Labs on Dynamips. It took me another one and a half month to finish them off&lt;br /&gt;completely and tuning Dynamips Topological File for Advanced Technology Labs, i changed the interfaces, switch connections and frame-relay topology to suit my needs. Some Tasks were not supported in Dynamips such as Dot1x Tunneling, VLAN ACLs, RSPAN, Dynamic Trunking etc. so i skipped them and lateron rented a rack several times for practicing those specific topics. During this time, i reviewed the CoD countless times to gain a deeper understanding of&lt;br /&gt;technologies.&lt;br /&gt;&lt;br /&gt;My next move was to purchase a dedicated dynamips server to support my topology as my laptop was not enough for it, i purchased an AMD Athlon 64 4400+ with 2 GiG RAM as a dynamips server machine. Here Scott Vermillion came to the rescue as I was using Windows as my primary OS but I failed miserably in running the full topology, Scott insisted and encouraged me to use linux as at that time he was using MacOSX.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt; You can find my huge post in the GS Archives.&lt;br /&gt;&lt;br /&gt;I started doing the Core-Labs as my next move to improve my IGP, BGP and Redistribution skills, additional one month just for the 10 Labs, they surely were hard as i think now :). Core Labs were done easily done on the Dynamips Server that i had purchased because they focused&lt;br /&gt;on IGP, Redistribution and BGP the most. Switching was mostly simple and when i was stuck with an unsupported task, i always skipped it and did them later on a rented rack if I had the chance.&lt;br /&gt;&lt;br /&gt;Finally i started R&amp;amp;S Workbook Labs, the first five labs were just warm up labs as the authors said but they looked really hard to me at the first glance, they can be done using Dynamips but some tasks were skipped in Switching. Initially it took me 3 days to finish only one lab with research on every topic. When i reached Lab5 i gained speed, accuracy and got familiar with most of the problems. Lab5 was done in 13 Hours in first attempt on my dynamips.&lt;br /&gt;&lt;br /&gt;I continued doing the workbook labs 6,7,8,9 and 10. The hardest of all was Lab 7 which again took me two days to figure out. After finishing Lab10 i almost knew all of the problems and i could solve most of the tasks at the back of my head. Labs 11 - 13 i did with a pencil just to&lt;br /&gt;save some time. Then I did all the remaining 14 – 20 Labs.  Next, I rented rack equipment and did several labs on them again. Again My CCIE friend came to rescue and generously gave access to his own rack with 9 Routers and 2 3550's I used it to do Labs again and gained some speed and accuracy. Thanks Ghias for that.&lt;br /&gt;&lt;br /&gt;In total I did the IE Labs 3 times on different equipment, 1st time on Dynamips, 2nd time on rented rack and third time on Physical Rack. Finally, in the last month, I reviewed most of the content again, reviewed the Class on Demand Videos to refresh some of the topics such as Catalyst QoS (freely available on internetworkexpert free resources section), IP/IOS Services, Multicasting, Security and BGP. I took references from the DocCD to memorize where to find stuff like Router Menus, WCCP, Nat, Reflexive ACLs, CBAC, IGMP Filtering, Multicast Stub&lt;br /&gt;Routing, IPv6 etc.&lt;br /&gt;&lt;br /&gt;I sat for lab in dubai on 22nd Jan 2008 and fortunately attained the number in the first attempt. For the last 2 nights i couldn't sleep and i just kept on praying and building strategies like should i do frame-relay first restart the routers then go on switching  or the otherway around etc etc..&lt;br /&gt;&lt;br /&gt;Well, I hope this LONG LONG Post will help most of the people who emailed me for guidance on how to start and where to search the material. I specifically used IE Material but I have also seen other vendor's workbooks such as IPEXPERT, IEMENTOR, Soup-to-Nuts etc. and I&lt;br /&gt;have found them equally good for practicing the labs. It's a personal preference and what your company/budget allows you to purchase. Lastly, i would say, this was my technique, i cannot guarantee that following this one could lead you to success but it worked for me. I did the core-labs first, authors dont recommend this way, but i did it.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;span style="color: rgb(136, 136, 136);"&gt;--&lt;br /&gt;Farhan Anwar&lt;br /&gt;CCIE #19871&lt;br /&gt;&lt;a href="http://www.farhananwar.com/" target="_blank"&gt;www.farhananwar.com&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-8256553598940582191?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/8256553598940582191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=8256553598940582191' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/8256553598940582191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/8256553598940582191'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2008/01/hi-all-since-my-last-post-regarding-my.html' title=''/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-6292603998822349607</id><published>2008-01-23T23:41:00.000-08:00</published><updated>2008-01-28T23:43:56.463-08:00</updated><title type='text'>Finally CCIE!</title><content type='html'>CCIE#19871 achieved in Routing and Switching on 22nd JANUARY 2008 in Dubai.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Farhan Anwar&lt;br /&gt;Now CCIE#19871&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-6292603998822349607?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/6292603998822349607/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=6292603998822349607' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/6292603998822349607'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/6292603998822349607'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2008/01/finally-ccie.html' title='Finally CCIE!'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-1252762000201491113</id><published>2008-01-22T23:44:00.000-08:00</published><updated>2008-01-31T00:07:32.059-08:00</updated><title type='text'>Just got my CCIE</title><content type='html'>Sitting on dubai international airport .... i have just checked the result with shaking hands. And there i found the CCIE#19871. I can't believe that i am in the &lt;5% style="color: rgb(136, 136, 136);"&gt;--&lt;br /&gt;Farhan Anwar&lt;br /&gt;Now CCIE#19871&lt;br /&gt;&lt;a href="http://www.farhananwar.com/" target="_blank"&gt;www.farhananwar.com&lt;/a&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-1252762000201491113?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/1252762000201491113/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=1252762000201491113' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/1252762000201491113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/1252762000201491113'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2008/01/sitting-on-dubai-international-airport.html' title='Just got my CCIE'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-144753883012606617</id><published>2007-10-19T03:44:00.000-07:00</published><updated>2007-10-19T03:45:11.075-07:00</updated><title type='text'>Dynamips IdlePC Values</title><content type='html'>&lt;blockquote&gt;&lt;/blockquote&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;OS: Windows XP ( any Windows Platform)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Although, these IdlePC Values are hardware independent, but i generated them on:&lt;br /&gt;Intel Core Duo 1.66 GHz Centrino Processor with 2 GB Ram.&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;c3725-adventerprisek9-mz.124-7.ext.BIN&lt;/span&gt;&lt;br /&gt;0x612f1a04 [52]&lt;br /&gt;0x60af25c8 [77]&lt;br /&gt;&lt;br /&gt;&lt;span&gt;c3620-is-mz.123-18.ext.BIN&lt;/span&gt;&lt;br /&gt;0x604ca9ac [67]&lt;br /&gt;&lt;br /&gt;&lt;span&gt;c3640-is-mz.124-8T.bin&lt;/span&gt;&lt;br /&gt;0x605b8dbc [57]&lt;br /&gt;0x6062e728 [69]&lt;br /&gt;0x6062e8f0 [76]&lt;br /&gt;0x606e70ec [66]&lt;br /&gt;0x606e716c [55]&lt;br /&gt;0x6062fb40 [60]&lt;br /&gt;&lt;br /&gt;&lt;span&gt;c3640-jk9o3s-mz.124-5a.ext.BIN&lt;/span&gt;&lt;br /&gt;**0x60610428 [58]&lt;br /&gt;*0x604e0630 [54]&lt;br /&gt;0x6055a938 [69]&lt;br /&gt;0x60555c98 [72]&lt;br /&gt;0x60555cc0 [66]&lt;br /&gt;0x60555e8c [76]&lt;br /&gt;&lt;br /&gt;&lt;span&gt;c3640-ik9o3s-mz.124-7.bin&lt;/span&gt;&lt;br /&gt;**0x60638cd8 [46]&lt;br /&gt;*0x605119f0 [56]&lt;br /&gt;&lt;br /&gt;&lt;span&gt;c7200-adventerprisek9-mz.124-4.T1.ext.BIN&lt;/span&gt;&lt;br /&gt;*0x6070c270 [56]&lt;br /&gt;*0x6034d4bc [57]&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Farhan Anwar.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;MCSE:Security,&lt;/span&gt;&lt;span style="font-style: italic;"&gt;CCNP,JNCIA,CCIE (R&amp;amp;S --Ongoing)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-144753883012606617?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/144753883012606617/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=144753883012606617' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/144753883012606617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/144753883012606617'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/10/dynamips-idlepc-values_19.html' title='Dynamips IdlePC Values'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-5287669336242626622</id><published>2007-09-18T04:17:00.000-07:00</published><updated>2007-09-18T04:17:29.838-07:00</updated><title type='text'>BGP - CCIE Notes</title><content type='html'>&lt;ol style="margin-left: 0.3125in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Within an AS, bgp peers do not need to be directly      connected.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;For routers that      run ebgp, neighbors are usually directly connected.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;ALL bgp speakers      within an AS MUST establish a peer relationship unless you use Route&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;reflectors or      confederations.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;When a bgp      speaker receives an update from other bgp speakers in its own AS, (via      ibgp) the&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;receiving bgp      speaker uses ebgp to forward the update to ebgp speakers only.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The BGP      synchronization rule states that if an AS provides transit service to      another AS, BGP&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;should not      advertise a route until all of the routers within the AS have learned the      route via an&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;IGP.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;You can disable      synchronization if one of the following is true:&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="circle"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;1. Your AS does not pass       traffic from one AS to another.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;2. ALL the transit routers       in your AS run BGP&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The only      difference between advertising a static and a default route, is that when      you redistribute a&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;static, BGP sets      the origin attribute of updates to incomplete.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Redistributing a      static route is the best way to advertise a supernet because it stops the      route from&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;flapping.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;To ensure a loop      free inter-domain topology, BGP does not accept updates that originated      from its own AS.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Origin attribute-      will be “i” when injected with network command in router configuration      mode, “e” when learned through EGP, “?” incomplete when a route is      redistributed into bgp.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;BGP specifies      that the next hop of EBGP learned routes remain unchanged into and through      IBGP.&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;BGP Attributes&lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;The &lt;span style="font-weight: bold;"&gt;weight&lt;/span&gt; attribute is a special CISCO attribute  that is used in the path selection when there is more than one route to the  destination. The weight attribute is local to the router on which it is  assigned and is NOT propagated in routing updates. (higher more preferred),  there are 3 ways to set weight:&lt;/p&gt;&lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="circle"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Access-list&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Route-map&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Neighbor weight command&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;The &lt;span style="font-weight: bold;"&gt;local preference&lt;/span&gt; attribute indicates the  preferred path when there is multiple paths. (higher=better). Unlike the  weight attribute, the local preference is carried with route updates and  exchanged with routers in the same AS. 2 ways to set local preference:&lt;/p&gt;&lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="circle"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;use the bgp default       local-preference command&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;route-maps&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;The&lt;span style="font-weight: bold;"&gt; MED&lt;/span&gt; attribute is a hint to EBGP peers about  the preferred path into an AS when there are multiple. (lower=better). Unlike  local preference, the MED is exchanged between AS’s, but a MED that comes into&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;an AS does not  leave the AS.&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;The&lt;span style="font-weight: bold;"&gt; community&lt;/span&gt; attribute provides a way of  grouping destinations to which routing decisions can be&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;applied. To send  the attribute you MUST use the &lt;span style="font-weight: bold;"&gt;neighbor  send-community&lt;/span&gt; router config command.&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Other  topics:&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style="font-weight: bold;"&gt;BGP Route Reflectors&lt;/span&gt;- eliminates full mesh  requirement.&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style="font-weight: bold;"&gt;BGP Confederations&lt;/span&gt;- makes “mini- AS’s” inside  of an AS.&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style="font-weight: bold;"&gt;BGP Peer groups&lt;/span&gt; – a group of neighbors that  share the same update policies.&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 13pt;"&gt;Brief, BGP Path Selection Process:&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;li value="1" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Is the Next-Hop present for      the Route.&lt;/span&gt;&lt;/li&gt;&lt;li value="2" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer Largest Weight, if      Cisco.&lt;/span&gt;&lt;/li&gt;&lt;li value="3" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer largest local      preference, after Weight.&lt;/span&gt;&lt;/li&gt;&lt;li value="4" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Internally Generated Routes      have high preference.&lt;/span&gt;&lt;/li&gt;&lt;li value="5" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer Shortest AS Path&lt;/span&gt;&lt;/li&gt;&lt;li value="6" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer Incomplete Origin over      IGP and IGP over EGP.&lt;/span&gt;&lt;/li&gt;&lt;li value="7" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer the lowest MED (      Metric )&lt;/span&gt;&lt;/li&gt;&lt;li value="8" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Prefer closest route learned      through an IGP&lt;/span&gt;&lt;/li&gt;&lt;li value="9" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;If still all stuff is same,      make decisions on BGP Router IDs, lowest is always preferred.&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Important BGP Commands:&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;div style="direction: ltr;"&gt;  &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;   &lt;tbody&gt;&lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Aggregate-address&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Configure bgp    aggregate entries&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Auto-summary&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Default-metric&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Set metric of    redistributed routes&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Distance&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Define admin    distance&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Distribute-list&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Filter Networks    in routing updates&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Maximum-paths&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Forward Packets    on multiple paths&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Synchronization&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Perform IGP    Synchronization (IBGP)&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Timers&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Adjust BGP Update    Timers&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Traffic-share&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Algorithm for    computing traffic share over alternate routes&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; advertise-map&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Specific    route-map for conditional adverstisements&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; advertisement-interval&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Min. Interval b/w    EBGP Routing Updates&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; distribute-list&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Filter Routes    specific to neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; Ebgp-multihop&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Allow EBGP    Neighbors not on directly connected networks&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; Filter-list&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Enable BGP    Filters&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; maximum-prefix&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Max. Limit of    Routes the neighbor could learn.&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; next-hop-self&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Disable Next-Hop    Calculation for neighbor and advertise itself as&lt;span style=""&gt;  &lt;/span&gt;the neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; peer-group&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Assign a Peer    Group to the neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; prefix-list&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Filter updates    from this neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; remote-as&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Define the AS&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; remove-private-as&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;No Private AS #s    in outbound updates&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; route-map&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Apply a route-map&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; route-reflector-client&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Enable    Route-Reflection on this Router&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; send-community&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Send the    Community Attribute to this neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; shutdown&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Administratively    disable peering with the neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; timers&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;BGP Neighbor    specific timers&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; unsuppress-map&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Route-Map to    selectively allow suppressed routes to that specific neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; update-source&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Define Source    interface for the neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Neighbor    &lt;ip&gt; weight&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.4645in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Specify neighbor    specific weight (Cisco Only)&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-5287669336242626622?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://downloadcenter.intel.com/Detail_Desc.aspx?agr=N&amp;ProductID=2753&amp;DwnldID=13000&amp;iid=homepage+dc_wireless_xp' title='BGP - CCIE Notes'/><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/5287669336242626622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=5287669336242626622' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5287669336242626622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5287669336242626622'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/09/bgp-ccie-notes.html' title='BGP - CCIE Notes'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-5753064412580946846</id><published>2007-09-18T04:07:00.000-07:00</published><updated>2007-09-18T04:07:13.148-07:00</updated><title type='text'>Switching - CCIE Notes</title><content type='html'>&lt;a href="http://www.intel.com/"&gt;  &lt;/a&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A Switch Port can be dynamic,      static or automatic. Switch Port can be a Trunk or an Access Port.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The Default Encapsulation      Protocol for DTP is ISL.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Native VLAN is supposed to be      an Untagged VLAN which doesn’t has any VLAN information attached.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;To disable Dynamic Trunking      Protocol use no negotiate&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;To create an Ether channel      without negotiation we use channel-group 1 mode on. This creates an ether      channel without any Ether Channeling protocol (PAGP / LACP).&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Making Channel Group Mode to      DESIREABLE or AUTO makes it negotiable over PAGP.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Making Channel Group Mode to      ACTIVE or PASSIVE makes it negotiable over LACP.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling DTP and issuing      conflicting VTP Domain names causes the Switches to warn before enabling      VLAN Trunking Protocols over the Trunk Links.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;VLAN Load Balancing can be      achieved in the following ways:&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-left: 0.75in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;VLAN ALLOW       LIST: &lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;This       allows different VLANs to travel over different Trunks for better trunk       efficiency and load balanced environment. Certain VLANs are allowed over       one trunk and other set of VLANs can be allowed to travel over another       trunk.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;MSTP VLAN       Load Balancing: &lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;This       allows VLAN Instance Load Balancing over different Trunks.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;STP Port       Priority: &lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;By       assigning different VLANs to different TRUNKs and changing the STP Port       Priority.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;STP Port       Cost: &lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;By       assigning different VLANs to different TRUNKs and changing the STP Port       COST.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The Minimum &lt;/span&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Forward      Delay&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt; time for      Spanning Tree is 4 Seconds.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling &lt;/span&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Spanning      Tree PortFast&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt; on      interfaces causes it to bypass Listening and Learning State and directly      transit into FORWARD State.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling UplinkFast Globally      causes the Switch to quickly transit its root port to another port in an      event of an uplink failure.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling BackboneFast      Globally causes the Switch to know immediately if its path to ROOT has      been broken somewhere on another switch (indirectly) and switch its path      to alternate one.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling BPDU-Guard Allows an      ACCESS-PORT to quickly go into PORT-INCONSISTENT (Block) State if a BPDU      is received on it. This is done on all PortFast Enabled Access Ports.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enabling Root Guard on the      Root Switch Designated Ports allows the switch to reject any Superior      BPDUs received on those ports and protect itself from loosing the ROOT      Role.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;BPDU Filter is an extension      of BPDU-Guard in which we can define what to do if a BPDU has been      received on an ACCESS-Port.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;BPDU Loop Guard allows the      switch to protect itself from a sudden loss of BPDUs and go into infinite      Spanning Tree Loop.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A Multiple STP contains      INSTANCES where each instance could contain a single or a group of VLANs      in it.&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-left: 0.75in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Configuration: spanning-tree       mst configuration&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Instance 1 vlan 1-3&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Instance 2 vlan 4-6&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Instance 4 vlan 7-9&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Layer 3 Switching:&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Switch Security:&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;Port Security&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;Max. Mac Address Learn Limits&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;Port Authentication&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;VLAN Hopping:&lt;/p&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Hacker can negotiate a TRUNK      with the Switch and can move b/w VLANs easily.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;This happens because the      default state of every port is Dynamic Desirable.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Private VLANs:&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;The common concept is VLANs within VLANs.&lt;/p&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Private VLANs has sub-vlans,      it contains a Main VLAN called "PRIMARY-VLAN".&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Private VLANs can only be      configured in a TRANSPARENT Mode.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;There can only be 1 ISOLATED      or COMMUNITY VLAN per Primary VLAN.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Private VLANs provide      ISOLATION and GROUPING within a VLAN.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;There are three types of sub-vlans:&lt;/p&gt;  &lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="disc"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; font-size: 11pt;"&gt;      &lt;div style="direction: ltr;"&gt;      &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;       &lt;tbody&gt;&lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.0368in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Promiscuous&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 5.7034in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;It’s a port        in Primary VLAN which can be reached by all Isolated and Community Ports&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;       &lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.0368in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Isolated&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 5.7034in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;It’s a port        in Primary VLAN but can't connect to any other port&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;       &lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.0368in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Community&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 5.7034in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;It’s a group        of ports in Primary VLANs which can connect to each other and they can        also reach Promiscuous Port but they can't reach any ISOLATED Ports.&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;      &lt;/tbody&gt;&lt;/table&gt;      &lt;/div&gt;  &lt;/li&gt;&lt;/ul&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Configuration:&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Vlan 100 &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Private-vlan primary&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Vlan 110&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Private-vlan isolated&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Vlan 120&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Private-vlan community&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Vlan 100&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Private-vlan association 110,120&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Interface fast1/1&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Description Private Isolated VLAN 100&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport mode private-vlan host&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport private-vlan host-association 100 110&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Interface fast1/2&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Description Private Community VLAN 100&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport mode private-vlan host&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport private-vlan host-association 100 120&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Interface fast1/3&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Description Private Community VLAN 100&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport mode private-vlan promiscuous&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: &amp;quot;Courier New&amp;quot;; font-size: 9pt;"&gt;Switchport private-vlan mapping 100 110,120&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style="font-weight: bold;"&gt;Verification:&lt;/span&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt;Show vlan private-vlan&lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Spoofing Attacks:&lt;/p&gt;  &lt;div style="direction: ltr;"&gt;  &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse; margin-left: 0.3333in;" border="1" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.9263in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Ip dhcp snooping   trust&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 3.8138in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Listens to ARP /   DHCP Requests, makes IP to Mac Bindings Table&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.9263in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Ip verify source   vlan dhcp-snooping port-security&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 3.8138in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Ip source guard   enablement.&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Spanning Tree Attacks:&lt;/p&gt;  &lt;div style="direction: ltr;"&gt;  &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse; margin-left: 0.3333in;" border="1" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.5347in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Spanning-tree   bpduguard enable&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 5.2055in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Blocks (shutsdown   - errdisable)a Port which is not destined to receive any BPDUs&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.5347in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Spanning-tree   guard root&lt;/p&gt;   &lt;/td&gt;   &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 5.2055in;"&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Root Guard,   protects a port to receive superior BPDUs on a root-guard enabled port. This   is enabled only on Root and Backup-Root Switches&lt;/p&gt;   &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style=""&gt; &lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;  &lt;p style="margin: 0in 0in 0in 0.375in; font-weight: bold; text-decoration: underline; font-family: Calibri; font-size: 14pt;"&gt;Best Practices:&lt;/p&gt;  &lt;ol style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11pt;" type="1"&gt;&lt;li value="1" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Disable CDP Whenever Possible.&lt;/span&gt;&lt;/li&gt;&lt;li value="2" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Lock down the spanning tree.&lt;/span&gt;&lt;/li&gt;&lt;li value="3" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Disable Trunk Negotiation and      use manual negotiation.&lt;/span&gt;&lt;/li&gt;&lt;li value="4" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Place unused ports in a      blackhole vlan or blocked vlan.&lt;/span&gt;&lt;/li&gt;&lt;li value="5" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Enable SwitchPort host      (enables access mode, enables portfast, disables channelgroup)&lt;/span&gt;&lt;/li&gt;&lt;li value="6" style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Use SSH whenever possible for      doing Switched Configuration.&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-5753064412580946846?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.intel.com/' title='Switching - CCIE Notes'/><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/5753064412580946846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=5753064412580946846' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5753064412580946846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/5753064412580946846'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/09/switching-ccie-notes.html' title='Switching - CCIE Notes'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-2320408278178970268</id><published>2007-09-15T04:03:00.000-07:00</published><updated>2007-09-15T04:03:08.105-07:00</updated><title type='text'>Frame Relay Notes - CCIE</title><content type='html'>&lt;a href="http://www.ccie4u.com/scenarios/r3ie.shtml"&gt;  &lt;/a&gt;&lt;ol style="margin-left: 0.2729in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A point-to-point      sub interface can only accommodate a single DLCI at any given time.      Point-to-point sub-interfaces are treated by the IOS like a physical      point-to-point interface and do not need either inverse-arp or frame-relay      map statements.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Multipoint DLCI’s      rely on either inverse-arp or frame-relay map statements for proper      operation.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;You must manually      clear inverse-arp with a clear frame-inarp command to remove any undesired      inverse-arp entries.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The broadcast      parameter is required for protocols such as OSPF &lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;If the router is      reloaded inverse-arp will be disabled for any DLCI that is used with a      frame-relay map statement.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;As a rule when      configuring frame-relay map statements make note of the protocol and the      DLCI specified if there are any inverse mappings for that same protocol      referencing the same DLCI replace the inverse-arp entries with frame-relay      map statements.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Rules to remember      when configuring point-to-point sub-interfaces are:&lt;/span&gt;&lt;/li&gt;&lt;ul style="margin-left: 0.375in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in;" type="circle"&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;No frame-relay map       statements can be used with point-to-point sub-interfaces&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;One and only once DLCI can       be associated with a single point-to-point interfaces&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Without the      frame-relay interface DLCI command, all DLCI’s are assigned to the      physical Interface Split horizon only blocks routing updates in a hub and      spoke topology&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A Cisco IOS      remedy to this split horizon problem is to disable split horizon on the      hub router in a frame-relay network this can be performed at the interface      configuration mode.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Split horizon is      disabled on frame-relay physical IP interfaces split horizon is enabled on      framerelay point-to-point and multi-point IP sub-interfaces.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;OSPF is not      affected by the rule of split horizon since it does not apply it.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A remedy to the      problem of “hello mismatches” is using the Cisco IOS interface      configuration command “IP OSPF network”:&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;A popular      selection for OSPF networks is the point-to-multipoint option.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;When using only      physical interfaces in a hub and spoke topology you need to add a      frame-relay map statement on the spoke routers to assure spoke to spoke      reachability nothing needs to be done to the hub router.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;If using      point-to-point sub-interfaces each sub-interface must be configured as a      separate sub net. If a physical or multipoint sub interface is being used      at the hub remember to disable split horizon at the hub&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-2320408278178970268?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.ccie4u.com/scenarios/r3ie.shtml' title='Frame Relay Notes - CCIE'/><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/2320408278178970268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=2320408278178970268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/2320408278178970268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/2320408278178970268'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/09/frame-relay-notes-ccie.html' title='Frame Relay Notes - CCIE'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-4372749935903815352</id><published>2007-09-14T15:45:00.000-07:00</published><updated>2007-09-14T15:45:58.765-07:00</updated><title type='text'>Notes on IPv6</title><content type='html'>&lt;a href="http://www.google.com.pk/firefox?client=firefox-a&amp;amp;rls=org.mozilla:en-US:official"&gt;  &lt;/a&gt;&lt;ol style="margin-left: 0.1979in; direction: ltr; unicode-bidi: embed; margin-top: 0in; margin-bottom: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;div style="direction: ltr;"&gt;  &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;   &lt;tbody&gt;&lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.9638in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Aggregatable Global Unitcast    Address&lt;/span&gt;&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.7763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;2000 - 3FFF:    Original Routable Addresses&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.9638in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Link-Local    Unicast Addresses&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.7763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;FE80: 1/1024th of    all available for Link only, used to get Global Unicast Address via a Router    or a DHCP.&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.9638in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Site-Local    Unicast Addresses&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.7763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;FEC0: 1/1024th of    all available IPv6 Space, its sort of Private IP Addressing Scheme.    Deprecated.&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.9638in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Multicast    Addresses&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.7763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;FFxx: Starts with    FF, used for Multicasting.&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.9638in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Multicast to all    hosts&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 4.7763in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;FF02::1    essentially the same as 255.255.255.255&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;The Broadcast has      been removed, multicasting has taken its place.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;FrameRelay      Inverse-Arp is not yet implemented, so Static Mapping should be used.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;ICMPv6 Neighbor      Discovery will ultimately replace IPv4 ARP.&lt;/span&gt;&lt;/li&gt;&lt;div style="direction: ltr;"&gt;  &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;   &lt;tbody&gt;&lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2402in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ICMPv6 Neighbor    Solicitation&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.6854in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Ask for    Information about the neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2402in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ICMPv6 Neighbor    Advertisement&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.6854in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Advertise    yourself to neighbor&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2402in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ICMPv6 Router    Solicitation&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.6854in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Ask for info    about the Local Routers&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;   &lt;tr&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.2402in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ICMPv6 Router    Advertisement&lt;/p&gt;    &lt;/td&gt;    &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.6854in;"&gt;    &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Advertise    yourself as Local Router&lt;/p&gt;    &lt;/td&gt;   &lt;/tr&gt;  &lt;/tbody&gt;&lt;/table&gt;  &lt;/div&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Ipv6      unicast-routing enables IPv6 on a Router. It enables ICMPv6 ND and Dynamic      Routing Support.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Debug ipv6 packet      detail&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Debug ipv6 nd&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 13pt;"&gt;RIPng&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;RFC 2080 Defines  Ripng for IPv6&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;UDP Port 521 is  used instead of 520 with a Multicast Address of FF02::9&lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Configuration:&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Interface Level :  Ipv6 rip [process] enable&lt;/p&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 13pt;"&gt;OSPFv3&lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Similar to OSPFv2&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Router-id is an      IPv4 Address&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Configuration:&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Interface      Level:&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt; ipv6 ospf      [process id] area [area-id]&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-weight: bold; font-family: Calibri; font-size: 11pt;"&gt;Global      Level:&lt;/span&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;      Automatically Enabled.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Multicast Address      is: FF02::5&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 13pt;"&gt;BGPv6&lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Same process for      IPv6 as of IPv4.&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc;"&gt;&lt;span style="font-family: Calibri; font-size: 11pt;"&gt;Address-family      configuration is used.&lt;/span&gt;&lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 13pt;"&gt;Static  Tunneling:&lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc; font-size: 11pt;"&gt;      &lt;div style="direction: ltr;"&gt;      &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;       &lt;tbody&gt;&lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 0.6673in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;GRE&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.184in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;The Default        Tunnel Mode&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;       &lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 0.6673in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;IPv6 IP&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 2.184in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Running IPv4        to IPv6 Tunneling&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;      &lt;/tbody&gt;&lt;/table&gt;      &lt;/div&gt;  &lt;/li&gt;&lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt; &lt;/p&gt;&lt;p style="margin: 0in; font-weight: bold; font-family: Calibri; font-size: 13pt;"&gt;Automatic  Tunnels:&lt;/p&gt;&lt;li style="margin-top: 0pt; margin-bottom: 0pt; vertical-align: middle; list-style-type: disc; font-size: 11pt;"&gt;      &lt;div style="direction: ltr;"&gt;      &lt;table valign="top" style="border: 1pt solid rgb(163, 163, 163); direction: ltr; border-collapse: collapse;" border="1" cellpadding="0" cellspacing="0"&gt;       &lt;tbody&gt;&lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.0284in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;6to4 Tunnels&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 3.468in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;IPv6 Address        to IPv4 Tunneling&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;       &lt;tr&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 1.0284in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;ISATAP&lt;/p&gt;        &lt;/td&gt;        &lt;td style="border: 1pt solid rgb(163, 163, 163); padding: 4pt; vertical-align: top; width: 3.468in;"&gt;        &lt;p style="margin: 0in; font-family: Calibri; font-size: 11pt;"&gt;Automatic        Host to Host or Host to Router Tunneling&lt;/p&gt;        &lt;/td&gt;       &lt;/tr&gt;      &lt;/tbody&gt;&lt;/table&gt;      &lt;/div&gt;  &lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-4372749935903815352?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.google.com.pk/firefox?client=firefox-a&amp;rls=org.mozilla:en-US:official' title='Notes on IPv6'/><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/4372749935903815352/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=4372749935903815352' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/4372749935903815352'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/4372749935903815352'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/09/notes-on-ipv6.html' title='Notes on IPv6'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1540073174900542234.post-2286617371491825060</id><published>2007-08-25T12:29:00.000-07:00</published><updated>2007-08-25T12:31:12.955-07:00</updated><title type='text'>Firewall Filters in Juniper JunOS</title><content type='html'>Introduction to Firewall Filters in JunOS&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;·         Firewall Filters are same as Access Control Lists in Cisco.&lt;br /&gt;·         Firewall Filters are stateless firewall filters just like ACLs in Cisco.&lt;br /&gt;&lt;br /&gt;·         Firewall Filter has:&lt;br /&gt;o    Discard:&lt;br /&gt;o    Reject:&lt;br /&gt;&lt;br /&gt;·         All ACLs are configured in Firewall Hierarchy&lt;br /&gt;·         All Firewall Filters have Names&lt;br /&gt;Every Term has:&lt;br /&gt;From Clauses ( Matches )&lt;br /&gt;Then Clauses ( Actions )&lt;br /&gt;Every Term can have a Number or a Name&lt;br /&gt;The ANNOTATE Command can be used to write Comments against the filter terms&lt;br /&gt;&lt;br /&gt;Show firewall policy-options&lt;br /&gt;&lt;br /&gt;·         JunOS always compiles Firewall Filters.&lt;br /&gt;·         JunOS Firewall Filters are performed always in Hardware using the Internet 2 Processor from IBM which gives Line Rate Packet Filtering Speed.&lt;br /&gt;·         For APPLYING a firewall filter list over an interface:&lt;br /&gt;o    Set interface fe-3/0/0 unit 0 family inet filter input-list block-bad-addresses&lt;br /&gt;o    Set interface fe-3/0/1 unit 0 family inet filter output-list block-bad-addresses&lt;br /&gt;·         Firewall Filters are applied with the perspective of a Router, if a Packet comes in through FE-3/0/0 and after re-routing it goes out from FE-3/0/1 then the input ACL will be at FE-3/0/0 and the output ACL will be at FE-3/0/1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1540073174900542234-2286617371491825060?l=sfarhananwar.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sfarhananwar.blogspot.com/feeds/2286617371491825060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1540073174900542234&amp;postID=2286617371491825060' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/2286617371491825060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1540073174900542234/posts/default/2286617371491825060'/><link rel='alternate' type='text/html' href='http://sfarhananwar.blogspot.com/2007/08/firewall-filters-in-juniper-junos.html' title='Firewall Filters in Juniper JunOS'/><author><name>-</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
