In this blog post, we're going to walk through NAT Traversal and the different considerations to think about when a firewall is in the path of the VPN peers.
CCIE Security: Troubleshooting Site-to-Site IPSec VPN with Crypto Maps
In this post, we are going to go over troubleshooting our VPN using debug commands. This is particularly useful for the folks out there reading this that only have access to only one side of the VPN or have a VPN to a 3rd party. I wanted this to remain a separate post from my ASA and IOS site-to-site VPN configuration posts because troubleshooting this is almost entirely identity on both a router or an ASA so I wanted to combine the troubleshooting to a single post.
CCIE Security: Site-to-Site IOS VPN with Crypto Maps
In this post, I'm going to go through configuring site-to-site VPN on IOS. We're going to take what we learned in the last blog post and apply it here. I think the best way this was explained to me was by Khawar Butt where you should think about your VPN configuration by break it down by the phases and then create your base VPN configuration on that. For the folks who don't know who Khawar Butt is, I'll be writing a review of his class shortly but you can see a sample of his work here.
CCIE Security: IPSec VPN Overview (IKEv1)
In this post, I'm going to go over a high level explanation of VPNs and specifically IPSec. This is going to be the first in a series of VPN posts focusing on the various types of VPNs one might see on the CCIE Security lab or on the job. I think it's important to have this overview because as you configure IPSec VPN or troubleshoot it, it'll help you to know what's going on under the covers of that configuration.
Test Driving DNA Center
Cisco Networks Splunk App
In this post, I'm going to veer away from the network security side of Splunk and more on the network operations side of things by introducing the Cisco Networks Splunk app. This app will gather syslog and Call Home data from various network devices in the network and visualize it in some rather interesting ways.
Cisco Security Suite in Splunk
Integrating WSA with Splunk
Integrating Splunk and Firepower's eStreamer
Integrating ISE with Splunk for Reporting
This post is going to be a bit different. I'm configuring Splunk in my lab currently for reporting and as I go through it, I'm going to detail my configurations here. I am going to use Splunk to aggregate my ISE logs to it. In order to do so, we're going to have to install the Spunk for Identity Services (ISE) app onto Splunk. Before starting, please download the app
Installing Splunk
I'm currently adding Splunk to my lab so as I'm going through the configuraitons, I'm going to list out what I do here as a series of blog posts. Splunk is a pretty power SIEM that works to aggregate and correlate data across your network and security tools. If you ever wanted to try it out for free, go to splunk.com and you should be able to download it for free for use up to a certain point. The nice thing about Splunk is that there are tons of free pre-built apps and dashboards for multiple vendors which you can download
The Cost of my CCIE Data Center - Time & Money in Review
CCIE Security Notes: ISE 2.1 Notes
CCIE Security Notes: ASA Clustering (9.6.1)
CCIE Security Notes: ASA HA Notes (9.6.1)
CCIE Security Notes: ASA Context Notes (9.6.1)
List of Free or Low-Cost IT Training
State of the IT field: Demand is high for SKILLED engineers
I've been thinking about writing this post all week and decided to wait until I processed my thoughts a little more before I wrote it out. There's a lot of fear, uncertainty and doubt that's been going on in the field for years and here are some of repetitive questions I tend to hear on Linkedin, Techexams and other social media:
- Is it worth going into networking/getting a CCIE/etc if SDN is going to take over?
- There's so many engineers out there, why do companies choose to hire H1Bs?
- Do I have to worry about my job getting outsourced to another country?
- Do I have to worry about H1Bs taking my job?
CCIE Security Notes: NAT Notes & Labbing
CCIE Security: Material List Update and Thoughts on the Blueprint
It was about a year ago that I posted this post where I went through the CCIE Security materials I intended to study with. In that time, the CCIE Security v5 blueprint was released and I thought I would update the list to reflect the current blueprint and the study materials I am using.