Posts

Showing posts with the label SP CCIE Lab

Cisco Announces New Service Provider Operations Track

Cisco Announces New Service Provider Operations Track Built on the growing demand for dedicated professionals who can manage, maintain and troubleshoot complex service provider IP NGN core network infrastructures, Cisco is introducing a new Service Provider (SP) Operations track. This new track is focused on developing associate, professional and expert-level capabilities to operate large, complex SP networks. These new, first of their kind certifications are designed specifically for Cisco Service Provider Customers, Partners and Cisco Networking Engineers. Over the coming months Cisco will release new CCIE, CCNP, and CCNA SP Operations courses and exams. In addition, the written exam topics for the CCIE SP Operations certification are now available on the Cisco Learning Network. The CCIE SP Operations written exam is scheduled for release in the second quarter of 2010. CCIE SP Operations Certification The  Cisco CCIE SP Operations  certification assesses and validates...

Remotely-Triggered Black Hole (RTBH) Routing

Image
Remotely-Triggered Black Hole (RTBH) routing is an interesting application of BGP as a security tool within service provider networks. One common use is mitigation of distributed denial of service (DDoS) attacks, as this article will explore. Pictured below is a (very) simplified service provider architecture. Routers 1 through 4 compose the network core, and router 9 functions as a standalone "management" router for route injection. OSPF is running across the core to exchange internal routes. Each router in this core square also maintains an iBGP adjacency with the other core routers, and with router 9. The server at 172.16.10.100 represents the target of a DDoS attack. Assume a DDoS attack is launched from the public Internet toward the customer server at 172.16.10.100. The throughput consumed is so excessive that the attack is impacting the entire internal infrastructure and must be blocked at the edge. Due to the distributed nature of the attack, we must bl...

我的第二張New Type CCIE獎牌(Service Provider)

Image
其實上個月就已經收到了,不過一直沒有空去把它拍照起來,今天趁著空檔時間把它拍了一張照片,現在擺放在TP的大廳裏,跟舊版的CCIE獎牌比起來大小尺寸差了一大截(我想成本應該可以節省不少),不過相較舊版的CCIE獎牌感覺上比較有質感,背面也預留了可以掛到牆上的掛孔(之前舊版的CCIE獎牌只預留給你裝裱的幾條凹槽)。 不過今年2009年Cisco準備全面更換新Logo,所以我想CCIE獎牌也會跟著再次改版吧!

我的Cisco Service Provider CCIE 證書和"信用卡" ?

Image
今天早上一進辦公室就看到我桌上多了一份國外寄來的包裹,拆開時沒注意我還以為是我的CCXP的證書,不過仔細看一下多了一個logo,原來是CCIE的證書…我記得我2003年拿到的證書logo還是鍍金的,現在什麼都不鍍了,只剩墨汁,嗯,我只能說Cisco推動環保不遺餘力… 為什麼我一開始會以為是CCXP的證書呢? 因為從包裹中掉了一張信用卡下來,呃,不是,是一張很像信用卡的塑料卡片,背後翻過來看還有真的是可以刷卡讀資料的區域。今年年中我剛考完CCIP,那時Cisco也寄了一張一模一樣的卡片給我,不過到現在還是不了解那張卡片是要幹嘛的…。 不過目前還沒收到新的CCIE塑膠獎牌,聽說是比以前剛開始的CCIE"墓碑"好看一些…自從CCIE銅牌獎牌被換成塑膠獎牌之後很多人都在抱怨,花了這麼一大筆的考試費用(Written + Lab + Travel expense),結果只得到這些廉價的東西有時覺得很沒價值,Cisco這麼多年來仍然沒有針對大家的意見進行調整,看來Cisco跟一些政府機構也是差不多,聽不到人民的聲音,只是自顧自的往前走向"錢"看!

IMPROVE THE CONVERGENCE OF MISSION-CRITICAL NETWORKS WITH BIDIRECTIONAL FORWARDING DETECTION (BFD)

Image
BFD在我之前準備SP CCIE LAB時就曾經提及過,目前sp ccie lAB中ios vERSION暫時尚未支援此功能,但是這個新功能在未來的r&s OR sp CCIE中應該會是一個很好的題材,因為它可以達到比縮減HELLO TIMER的方式更快速的收歛。 以下的文章摘錄自nli( http://www.nil.com/ipcorner/bfd/ ),內容相當詳實比Cisco官網更容易了解,在此推薦給各位參考。 IMPROVE THE CONVERGENCE OF MISSION-CRITICAL NETWORKS WITH BIDIRECTIONAL FORWARDING DETECTION (BFD) by  Ivan Pepelnjak A few years ago, we measured network convergence times in seconds, and aimed to establish an alternate path across the network following a link or node failure within a few seconds. Ten seconds was a sensible number that wouldn’t upset users (assuming that the failures weren’t too common) and definitely wouldn’t break TCP sessions. (The DLSw local termination would take care of the leftovers of the SNA networks.) The only environments aiming at sub-second convergence times were real-time mission-critical applications, from industrial control to battlefield communications. The introduction of Voice over IP (VoIP) into the data networks changed the rules compl...

CCIE#11440's SP CCIE Lab Exam Experience Sharing

我其實沒有想過我還會有第二次機會報告個人的CCIE Lab考試經驗,不過還是很高興地跟大家說,我終於辦到了! 在這個過程中最需要感謝的還是 brook 兄,沒有他跟我一起co-work共同討論,互相挑戰彼此對同一個題目不同看法不同的solution真的讓我們彼此的功力在短時間內快速增長,我是無法這麼順利完成這個目標的! 當然還有我辛苦的老婆一個人24 hrs帶著兩個小朋友,讓我幾乎完全沒有後顧之憂(過去一年以來,除了假日之外,我每天回到家的時間平均是PM 11:00~11:30左右...,還好我兒子們還認得我是他們老爸...),希望這段話可以稍稍安撫我老婆的辛苦及她對我及這個家庭無私的奉獻。 以下的內容我還是按照我五年前準備的考試經驗為大綱來update,希望對各位有幫助! (我更希望這次其他簡體中文論壇的轉載行為可以有所長進,請尊重原作者保留原始出處,謝謝!) 準備Service Provider CCIE Lab最重要的當然是以Routing & Switching為基礎,所以我在此不會強調Routing & Switching的部份,我會把重心放在MPLS/BGP/Multicast上。我會建議所有要準備考SP CCIE的candidates都應該至少要把CCIP - BGP/MPLS/QoS這幾科熟讀,因為它們是SP最基本的功夫,不用我多說,很多人會想直接進入主軸去看WB or 考古題,我個人的建議是不要急躁,因為你會因此而常常回頭看基礎理論反而更沒效率… ◎參考書目: 1. Cisco Press - MPLS Configuration on Cisco IOS Software * 2. Cisco Press - MPLS and VPN Architectures Vol.I & II 3. Cisco Press - MPLS Fundamentals * 4. Cisco Press - Routing TCP/IP Volume I & II * 5. Cisco Press - Advanced MPLS Design and Implementation 6. Cisco Press - Traffic Engineering with MPLS 7. Cisco Press - BGP Design a...

How to memorize RFC3330 all prefix ?

You know in some cases you have no any tool to search for RFC specification(if someone know how to search RFC in Cisco Document Website, please leave your comment), but you still need to apply some network security policy, then you have to hard dump to your brain. For example, in SP CCIE Lab, the questions may ask you to apply an access-list to match all prefix documented in RFC 3330. After my hard work, I have find out some hints for this RFC related reserved prefix listing: Part I : RFC 1918 In RFC 3330 including well-known private IP network defined in RFC1918, so I think it is no a problem for most network engineer. - 10.0.0.0/8 - 172.16.0.0/12 - 192.168.0.0/16 Part II : All classful network the First and the Last network (1)The First & Last network in Class A network - 0.0.0.0/8 - 127.0.0.0/8 (2)The First & Last network in Class B network - 128.0.0.0/16 - 191.255.0.0/16 (3)The First & Last network in Class C network - 192.0.0.0/24 - 223.255.255.0/24 Part III : Class D ...

Cisco IOS Embedded Event Manager (EEM)

Image
在Cisco SP CCIE Lab中最近有人在討論出現了一個新的topic,那就是所謂的EEM,跟平常我們所熟知的RMON, SNMP Trap不太一樣,所以我特別在這邊把相關的資料列出,其實資料並不多,大部份都是在Cisco官網上。 Cisco IOS Embedded Event Manager (EEM) http://www.cisco.com/en/US/products/ps6815/products_ios_protocol_group_home.html Cisco IOS Embedded Event Manager (EEM) is a powerful ally for device and system management. EEM enables customers to harness the network intelligence intrinsic to Cisco IOS and customize the behavior based on real network events as they happen. EEM consists of Event Detectors, the Event Manager, and an Event Manager Policy Engine. The policy engine drives two types of policies that users can configure, Applet policies and Tcl policies. Customers can define policies to take specific actions when the Cisco IOS software recognizes certain events through the Event Detectors. The result is an extremely powerful and flexible set of tools to automate many network management tasks and direct the operation of Cisco IOS to increase availability, collect informa...