<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5977838822789730906</id><updated>2011-10-18T22:11:08.264+02:00</updated><category term='etherchannel'/><category term='router'/><category term='tools'/><category term='vrf'/><category term='gns3'/><category term='basic'/><category term='news'/><category term='pemu'/><category term='on-a-stick'/><category term='security'/><category term='smalltalk'/><category term='asdm'/><category term='ospf'/><category term='tricky'/><category term='procurve'/><category term='advanced'/><category term='ccie sec'/><category term='rommon'/><category term='HyperV'/><category term='switch'/><category term='static route'/><category term='stp'/><category term='ios'/><category term='IINS'/><category term='ccie'/><category term='routing'/><category term='catalyst'/><category term='vpn'/><category term='pix'/><category term='lab'/><category term='sdm'/><category term='iou'/><category term='asa'/><category term='ipv6'/><title type='text'>Playing  with Networks</title><subtitle type='html'>mostly cisco CCNA / CCNP / CCSP / CCIE related networking stuff here.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default?start-index=101&amp;max-results=100'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>103</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4874805190187875198</id><published>2011-10-18T21:32:00.003+02:00</published><updated>2011-10-18T21:32:28.747+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><title type='text'>DE – Blog Empfehlung</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OfficeDocumentSettings&gt;  &lt;o:AllowPNG/&gt; &lt;/o:OfficeDocumentSettings&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;w:WordDocument&gt;  &lt;w:View&gt;Normal&lt;/w:View&gt;  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;  &lt;w:TrackMoves/&gt;  &lt;w:TrackFormatting/&gt;  &lt;w:HyphenationZone&gt;21&lt;/w:HyphenationZone&gt;  &lt;w:PunctuationKerning/&gt;  &lt;w:ValidateAgainstSchemas/&gt;  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;  &lt;w:DoNotPromoteQF/&gt;  &lt;w:LidThemeOther&gt;DE&lt;/w:LidThemeOther&gt;  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;  &lt;w:Compatibility&gt;   &lt;w:BreakWrappedTables/&gt;   &lt;w:SnapToGridInCell/&gt;   &lt;w:WrapTextWithPunct/&gt;   &lt;w:UseAsianBreakRules/&gt;   &lt;w:DontGrowAutofit/&gt;   &lt;w:SplitPgBreakAndParaMark/&gt;   &lt;w:EnableOpenTypeKerning/&gt;   &lt;w:DontFlipMirrorIndents/&gt;   &lt;w:OverrideTableStyleHps/&gt;  &lt;/w:Compatibility&gt;  &lt;m:mathPr&gt;   &lt;m:mathFont m:val="Cambria Math"/&gt;   &lt;m:brkBin m:val="before"/&gt;   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;   &lt;m:smallFrac m:val="off"/&gt;   &lt;m:dispDef/&gt;   &lt;m:lMargin m:val="0"/&gt;   &lt;m:rMargin m:val="0"/&gt;   &lt;m:defJc m:val="centerGroup"/&gt;   &lt;m:wrapIndent m:val="1440"/&gt;   &lt;m:intLim m:val="subSup"/&gt;   &lt;m:naryLim m:val="undOvr"/&gt;  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt; &lt;/w:LatentStyles&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;&lt;style&gt; /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Normale Tabelle"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin-top:0cm; mso-para-margin-right:0cm; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0cm; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:EN-US;}&lt;/style&gt;&lt;![endif]--&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;Da ich immer noch an meinem neuen Blog Post sitze und keinewirkliche Zeit hab ihn fertig zu schreiben gibt es heute eine kleine Empfehlungzum Lesen zwischendurch. Paul Stewart hat ein interessantes Thema aufgegriffenwas man auf jeden Fall im Hinterkopf haben sollte, beim Arbeiten mit einer ASA.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Sollte irgendjemand den Text auch in Deutsch braucheneinfach in die Comments posten ich kümmere mich dann darum.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://packetu.com/content/view/80/1/"&gt;The Woes of Using an ASA as a Default Gateway&lt;/a&gt; @ Packet U&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4874805190187875198?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4874805190187875198/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-blog-empfehlung.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4874805190187875198'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4874805190187875198'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-blog-empfehlung.html' title='DE – Blog Empfehlung'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-495213911514834410</id><published>2011-10-18T21:26:00.000+02:00</published><updated>2011-10-18T21:26:25.256+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><title type='text'>EN – Blog post recommendation</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OfficeDocumentSettings&gt;  &lt;o:AllowPNG/&gt; &lt;/o:OfficeDocumentSettings&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;w:WordDocument&gt;  &lt;w:View&gt;Normal&lt;/w:View&gt;  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;  &lt;w:TrackMoves/&gt;  &lt;w:TrackFormatting/&gt;  &lt;w:HyphenationZone&gt;21&lt;/w:HyphenationZone&gt;  &lt;w:PunctuationKerning/&gt;  &lt;w:ValidateAgainstSchemas/&gt;  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;  &lt;w:DoNotPromoteQF/&gt;  &lt;w:LidThemeOther&gt;DE&lt;/w:LidThemeOther&gt;  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;  &lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;  &lt;w:Compatibility&gt;   &lt;w:BreakWrappedTables/&gt;   &lt;w:SnapToGridInCell/&gt;   &lt;w:WrapTextWithPunct/&gt;   &lt;w:UseAsianBreakRules/&gt;   &lt;w:DontGrowAutofit/&gt;   &lt;w:SplitPgBreakAndParaMark/&gt;   &lt;w:EnableOpenTypeKerning/&gt;   &lt;w:DontFlipMirrorIndents/&gt;   &lt;w:OverrideTableStyleHps/&gt;  &lt;/w:Compatibility&gt;  &lt;m:mathPr&gt;   &lt;m:mathFont m:val="Cambria Math"/&gt;   &lt;m:brkBin m:val="before"/&gt;   &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;   &lt;m:smallFrac m:val="off"/&gt;   &lt;m:dispDef/&gt;   &lt;m:lMargin m:val="0"/&gt;   &lt;m:rMargin m:val="0"/&gt;   &lt;m:defJc m:val="centerGroup"/&gt;   &lt;m:wrapIndent m:val="1440"/&gt;   &lt;m:intLim m:val="subSup"/&gt;   &lt;m:naryLim m:val="undOvr"/&gt;  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"  DefSemiHidden="true" DefQFormat="false" DefPriority="99"  LatentStyleCount="267"&gt;  &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;  &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;  &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;  &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;  &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;  &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;  &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;  &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;  &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;  &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"   UnhideWhenUsed="false" Name="Table Grid"/&gt;  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;  &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;  &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;  &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;  &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;  &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;  &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;  &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;  &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;  &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;  &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;  &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt; &lt;/w:LatentStyles&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;&lt;style&gt; /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Normale Tabelle"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin-top:0cm; mso-para-margin-right:0cm; mso-para-margin-bottom:10.0pt; mso-para-margin-left:0cm; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:EN-US;}&lt;/style&gt;&lt;![endif]--&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="mso-ansi-language: EN-US;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="mso-ansi-language: EN-US;"&gt;Since I´mstill working on my next blog post and lacking the time to finish it, I wouldlike you to have a few at this cool ASA related post at Packet University. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;I´ve not encountered the problem in real lifebut well you never know.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US" style="mso-ansi-language: EN-US;"&gt;&lt;a href="http://packetu.com/content/view/80/1/"&gt;The Woes ofUsing an ASA as a Default Gateway&lt;/a&gt; @ Packet U&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-495213911514834410?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/495213911514834410/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-blog-post-recommendation.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/495213911514834410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/495213911514834410'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-blog-post-recommendation.html' title='EN – Blog post recommendation'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2750021780868772200</id><published>2011-10-11T00:00:00.001+02:00</published><updated>2011-10-12T23:46:35.767+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>DE - Wie kommt das "?" auf den Router</title><content type='html'>&lt;br /&gt;Da ich es ja ausgiebig in den letzten Posts zu IPv6 verwendet habe und ich auchschon einige Male gefragt wurde, Hier die Lösung zum Problem, wie kommt dasFragezeichen in die Konfig / die URL / das Passwort / den Pre-shared-key:&lt;br /&gt;&amp;nbsp;&lt;i&gt;&lt;span style="font-size: 10pt;"&gt;STRG + V und dann ?&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;Das war‘s, weiter gehen, hier gibt es nichts zu sehen ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2750021780868772200?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2750021780868772200/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-wie-kommt-das-auf-den-router.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2750021780868772200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2750021780868772200'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-wie-kommt-das-auf-den-router.html' title='DE - Wie kommt das &quot;?&quot; auf den Router'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6814861323610131247</id><published>2011-10-11T00:00:00.000+02:00</published><updated>2011-10-11T00:00:00.100+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>EN - How to get a ? in your config</title><content type='html'>Well since I´ve used it in my last posts about IPv6 on Cisco routers and I was asked a few times how to get a question mark into the config / url / password / pre-shared-key on your cisco device here the solution:&lt;br /&gt;&lt;blockquote&gt;&amp;nbsp;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;CRTL + V + ?&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;Thats it folks!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6814861323610131247?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6814861323610131247/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-how-to-get-in-your-config.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6814861323610131247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6814861323610131247'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-how-to-get-in-your-config.html' title='EN - How to get a ? in your config'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4626578559124802045</id><published>2011-10-10T22:35:00.002+02:00</published><updated>2011-10-10T22:35:40.926+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>EN - HEv6 Tunnel improvements</title><content type='html'>After surfing the HE forum and a few other blogs I noticed some nice improvements that i would like to share with you.&lt;br /&gt;&lt;br /&gt;DDNS URL&lt;br /&gt;Currently I´m using the inital URL from HE but it is possible to use another URL that does not leave youre password in plaintext in your config &lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;https://ipv4.tunnelbroker.net/ipv4_end.php?ip=AUTO&amp;amp;pass=MD5PASS&amp;amp;apikey=USERID&amp;amp;tid=TUNNELID&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Keep in mind that USERID is not your accountname but the ID you can find on the HE webpage. MD5PASS is your account password as MD5 hash and TUNNELID stays your asigned tunnel id.&lt;br /&gt;For the ip parameter you can either choose your static IPv4 IP or AUTO for dynamic IP updates.&lt;br /&gt;&lt;br /&gt;Another interessting option is the following command&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;ipv6 general-prefix HEv6 2001:470:XXXX::/48&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;This enables you to use the reference your prefix by calling the “name” of the prefix. The configuration of the loop 2 interface changes accordingly to:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;Interface loopback 2&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;ipv6 address HEv6 ::1/58&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&amp;nbsp;ipv6 enable&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;Thanks to Karsten for the prefix hint on his blog. (&lt;a href="http://security-planet.de/2009/06/22/per-tunnel-ins-ipv6-internet/"&gt;Link&lt;/a&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4626578559124802045?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4626578559124802045/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-hev6-tunnel-improvements.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4626578559124802045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4626578559124802045'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-hev6-tunnel-improvements.html' title='EN - HEv6 Tunnel improvements'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5453251030650280030</id><published>2011-10-10T22:30:00.000+02:00</published><updated>2011-10-11T21:53:16.595+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>DE - HEv6 Tunnel Verbesserungen</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;Nachdem ich noch etwas Zeit in den Foren von HE verbrachthab und auch bei anderen Quellen mich umgesehen habe, will ich hier noch einpaar Verbesserungen einpflegen.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;DDNS URL&lt;/div&gt;&lt;div class="MsoNormal"&gt;Derzeit verwende ich die URL wie sie Initial vorgeschlagenwird, aus dem HE Forum habe ich eine neue Form der URL, die verhindert dass dasPasswort im Klartext in der Router Konfig steht.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&amp;nbsp;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;https://ipv4.tunnelbroker.net/ipv4_end.php?ip=AUTO&amp;amp;pass=MD5PASS&amp;amp;apikey=USERID&amp;amp;tid=TUNNELID&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;pre&gt;&amp;nbsp;&lt;/pre&gt;&lt;span style="font-size: small;"&gt;Dabei ist zu beachten, das im Gegensatz zur original Form, ist der paramter IP mit der statischen IP oder mit AUTO für dynamische IPs zu belegen, sowie die USERID die ID und nicht der Accountname, MD5PASS das Accountpasswort als MD5 Hash und die TUNNELID wie gehabt die Tunnelid des IPv6 Tunnels ist&lt;/span&gt;.&lt;br /&gt;&lt;code&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Auch interessant ist die Option&lt;br /&gt;&lt;br /&gt;Das ermöglicht das Referenzieren in der weiteren Routerkonfiguration auf diesen Präfix. Lässt sich einfacher merken und spricht sich im Zweifelsfall auch einfacher.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ipv6 general-prefix HEv6 2001:470:XXXX::/48&lt;/span&gt;&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;Daraus ergibt sich für das Loop 2 Interface folgende Config&lt;br /&gt;&lt;blockquote&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;nterface loopback 2&lt;/span&gt;&lt;/i&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0.0001pt;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;ipv6 address HEv6 ::1/58&lt;/span&gt;&lt;/i&gt;&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;"&gt;&amp;nbsp;ipv6 enable&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&amp;nbsp;Danke an Karsten bei dem ich mir das Präfix Command geliehen hab. (&lt;a href="http://security-planet.de/2009/06/22/per-tunnel-ins-ipv6-internet/"&gt;Link&lt;/a&gt;) &lt;br /&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;code&gt;&lt;/code&gt;&lt;/span&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5453251030650280030?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5453251030650280030/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-hev6-tunnel-verbesserungen.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5453251030650280030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5453251030650280030'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-hev6-tunnel-verbesserungen.html' title='DE - HEv6 Tunnel Verbesserungen'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3697111497646222203</id><published>2011-10-09T23:15:00.000+02:00</published><updated>2011-10-10T22:39:48.801+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>EN - Hurricane Electric IPv6 Tunnel with Cisco 887</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Asmentioned earlier I was playing with the Hurricane Electric IPv6 Tunnel setup.Now that the Tunnel is up and running I would like to share some knowledge I gainedand provide a few config sniplets.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Startingwith the registration at &lt;a href="http://www.tunnelbroker.net/"&gt;www.tunnelbroker.net&lt;/a&gt;you can request an IPv6 Tunnel. As soon as you´ve registered you can set upyour tunnel and register for a complete network with a/48 mask. Obviously to say– I did register for the network.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;You can divideconfiguring your router into 4 steps (more or less)&lt;/span&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;Tunnelcreation&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;ConfigureHE Tunnel update&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;Addthe HE Certificate&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;Configureand use your /48 network&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;testing &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The defaultconfiguration of HE expects you to have a static IPv4 configured at yourrouter. Well since I’m using a home DSL connection my IP address changes every24 hours. That´s why I change the tunnel source from IP to dialer 1.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;interfaceTunnel0&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;description Hurricane Electric IPv6 TunnelBroker&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;no ip address&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;ipv6 enable&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;ipv6 address 2001:470:xxxx:xxxx::2/64&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;tunnel source Dialer 1 &lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;tunnel destination 216.66.84.42&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;tunnel mode ipv6ip&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;ipv6 route::/0 Tunnel0&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Additionalto the configuration I added this interface into the appropriate zone of theZone-Based firewall.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The nextstep for locations with changing IP addresses is to convince your router to tellHE the changing IPv4 address. Hurricane offers a default URL that you can usefor the updating process. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;https://ACCOUNTNAME:ACCOUNTPASSWORT@ipv4.tunnelbroker.net/ipv4_end.php?tid=TUNNELID&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;To updateyour IP at HE, you can use the DDNS feature of the Cisco router.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;ip ddnsupdate method HEv6&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;HTTP&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;&amp;nbsp; add https://ACCOUNTNAME:ACCOUNTPASSWORT@ipv4.tunnelbroker.net/ipv4_end.php?tid=TUNNELID&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;a href="http://playingwithnetworks.blogspot.com/2011/10/en-hev6-tunnel-improvements.html"&gt;!update in next blog post&lt;/a&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;interval maximum 0 6 0 0&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;interval minimum 0 1 0 0&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Every hourbut your router will update the IP at HE.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;You have toupdate the configuration of your dialer interface (or the interface that isproviding your internet connection) to update HE. &lt;/span&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;Interface Dialer1&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;ip ddns update hostname WS-Router&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;ip ddns update HEv6&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Next stepis to import the certificate HE is using for the tunnel broker website. Sincethis page is using a self-signed certificate the update with ddns could causeproblems if you don´t import it.&lt;/span&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;crypto pkitrustpoint HEv6&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;enrollment terminal pem&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;revocation-check none&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;You need toauthenticate the trustpoint using the following dialog:&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;#crypto pkiauthenticate HEv6&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;Enter thebase 64 encoded CA certificate.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;End with ablank line or the word "quit" on a line by itself&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;MIID8DCCAtigAwIBAgIJAPF6IlDmmdRhMA0GCSqGSIb3DQEBBQUAMIGcMQswCQYD&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEQMA4GA1UEBxMHRnJlbW9udDEg&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;MB4GA1UEChMXSHVycmljYW5lIEVsZWN0cmljLCBMTEMxDTALBgNVBAsTBElQdjYx&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;GTAXBgNVBAMTEHR1bm5lbGJyb2tlci5uZXQxGjAYBgkqhkiG9w0BCQEWC2lwdjZA&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;aGUubmV0MB4XDTExMDQyMjE3NDIyMFoXDTIxMDQxOTE3NDIyMFowgZwxCzAJBgNV&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRAwDgYDVQQHEwdGcmVtb250MSAw&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;HgYDVQQKExdIdXJyaWNhbmUgRWxlY3RyaWMsIExMQzENMAsGA1UECxMESVB2NjEZ&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;MBcGA1UEAxMQdHVubmVsYnJva2VyLm5ldDEaMBgGCSqGSIb3DQEJARYLaXB2NkBo&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;ZS5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDe5nza8zQ/AiT+&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;ySc4mZYmLMcIrcU3q6ZEwIY5vHg2chzCJGCPQIwtBiexSZ7CWL8/GjdPWs6DoCut&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;DS6VlGGaRhJd0ppUOB3uZLcqnfY0/d40WpRFm49yAV3fmhQg744BKUz2+V23E3tP&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;n4UXq507dQ3RmNiZoS/T+DUbt1URXFZDIJmc4vjnYfGQhUzhbWZbC7J5fMFnTFSL&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;NWNou4drWwcApm4FjPfVr+tdanjGEs8bMGSbXo6BjtStiEy1yJ3QGyZLwuURcMMv&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;DV06/hc2Nv9MZPUaIPvXmNcSuVvY3MJiD1CiCWVmfiO3h7b5EmIWC+ZpO9L3Mk6/&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;j/MgWR6jAgMBAAGjMzAxMC8GA1UdEQQoMCaCEHR1bm5lbGJyb2tlci5uZXSCEiou&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;dHVubmVsYnJva2VyLm5ldDANBgkqhkiG9w0BAQUFAAOCAQEAXMG5ZOeyRCzIEPYP&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;tZKbr1N0CkiBHf+7bVqUqfifEte6S/edpUdzIzB9Wtt484Dt88cAeg4BH2z+Kx2C&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;lE9PxtTSMCInZIniuoLhaBP0BiRXEurTYdreFmen/S5cCkffVr+eJGk92lQQAdMr&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;kyz2kD1NCwCaEp1w9DYltDbfC2v8BSIiEKVvD72VW6E2r7AvW73s3+E3WcWbt6pV&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;qrKfFH4mKH0BR7nLzm5zduojCvIdH3GjelyLd7lUVR3N8Dz626tOzni/bzHpbH3T&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;dMlBIl3f7c41wcoFG5zSZf1mvgyOnSlOnNmlxMbnfnrIyIyfYz1L8UWqWZGbxJYH&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;EXcOrA==&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;Certificatehas the following attributes:&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fingerprint MD5: 1128B641 08E7E271B2FFB7FF 91411952&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Fingerprint SHA1: 9EB44F27 6BCE5EF65D9D38CC A9252276 4318075C&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;% Do youaccept this certificate? [yes/no]: yes&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;TrustpointCA certificate accepted.&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;%Certificate successfully imported&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I exported theapplied certificate from my browser after opening the tunnelbroker page with Firefox.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The /48network HE assigned to me was subnetted and applied to my loop 2 interface tocheck if everything works fine.&lt;/span&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;Interfaceloopback 2&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;ipv6address 2001:470:XXXX::1/58&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;ipv6 enable&lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Last butnot least you should activate domain lookups on your router to resolve thetunnelbroker URL for ddns.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Finaltesting:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;ping ipv6ipv6.google.com source loop 2&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;Sending 5,100-byte ICMP Echos to 2A00:1450:8004::6A, timeout is 2 seconds:&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;Packet sentwith a source address of 2001:470:XXX::1&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;!!!!!&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&lt;span lang="EN-US"&gt;Successrate is 100 percent (5/5), round-trip min/avg/max = 76/76/76 ms&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;YEAH! Everythingworked as expected great &lt;/span&gt;!&lt;span lang="EN-US"&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;More to come &lt;a href="http://playingwithnetworks.blogspot.com/2011/10/en-hev6-tunnel-improvements.html"&gt;here&lt;/a&gt;!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3697111497646222203?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3697111497646222203/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-hurricane-electric-ipv6-tunnel-with.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3697111497646222203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3697111497646222203'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-hurricane-electric-ipv6-tunnel-with.html' title='EN - Hurricane Electric IPv6 Tunnel with Cisco 887'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4301930121414657491</id><published>2011-10-09T11:30:00.000+02:00</published><updated>2011-10-10T22:38:59.089+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>DE - Hurricane Electric IPv6 Tunnel mit Cisco 887</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Wie schon geschrieben hab ich mich das vergangene Wochenendemit dem IPv6 Tunnel von HE rumgeschlagen. Jetzt da er Up und Running ist willich meine Erfahrungen mal zusammenfassen und Konfigsniplets preisgeben.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Fangen wir am Anfang an, die Website ist unter &lt;a href="http://www.tunnelbroker.net/"&gt;www.tunnelbroker.net&lt;/a&gt; &amp;nbsp;zu finden, die Registrierung ist quasiselbsterklärend und sollte keine Hürde darstellen. Sobald man seinen Tunnelangelegt hat kann man sich auch noch ein Netz /48 reservieren lassen, was ichnatürlich gleich gemacht hab.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;Die Konfiguration erfolgt in mehreren Schritten,&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;Tunnel aufsetzen&lt;/li&gt;&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;HE Tunnel update&lt;/li&gt;&lt;li&gt;HE Zertifikat einspielen&lt;/li&gt;&lt;li&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&lt;/span&gt;/48 Netz verwenden&lt;/li&gt;&lt;li&gt;Test &lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;Die Konfig des Tunnels geht davon aus, dass man einestatische IP hat und verwendet die IP des Browser in der initialen Konfiguration.Da wir nur einen Standard DSL am Standort haben hab ich die Statische IP durchdas Dialer Interface ersetzt, das bei uns die DSL Einwahl macht. &amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;interface Tunnel0&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; description HurricaneElectric IPv6 Tunnel Broker&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; no ip address&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; ipv6 enable&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; ipv6 address2001:470:xxxx:xxxx::2/64&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; tunnel source Dialer1 &lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; tunnel destination216.66.84.42&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp; tunnel mode ipv6ip&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ipv6 route ::/0 Tunnel0&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Zusätzlich hab ich das Interface noch in die entsprechendeZone der Zone-Base Firewall gehängt.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Als nächstes sollte man, bei dynamische angebundenenStandorten, den Router dazu überreden, bei Zwangstrennung oder IP wechseln dieTunneldaten bei HE zu aktualisieren.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Hurricane gibt dafür eine URL vor, die man vom Router ausaufrufen &amp;nbsp;kann, die URL hat folgendenSyntax: &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;https://ACCOUNTNAME:ACCOUNTPASSWORT@ipv4.tunnelbroker.net/ipv4_end.php?tid=TUNNELID&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Um Hurricane zu aktualisieren sollte das DDNS feature desRouters verwendet werden:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ip ddns update method HEv6&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;HTTP&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp; add https://ACCOUNTNAME:ACCOUNTPASSWORT@ipv4.tunnelbroker.net/ipv4_end.php?tid=TUNNELID &lt;a href="http://playingwithnetworks.blogspot.com/2011/10/de-hev6-tunnel-verbesserungen.html"&gt;!Update im nächsten Blogpost&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;interval maximum 0 60 0&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;interval minimum 0 10 0&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;Hier wird die dynamische IP meines Routers HE jede Stunde,spätestens nach 6 Stunden mitgeteilt.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&amp;nbsp;Dem Dialer Interface müssen noch die DDNS Infos mitgegebenwerden, damit dieses HE aktualisiert.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Interface Dialer 1&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;ip ddns updatehostname WS-Router&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;ip ddns update HEv6&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Als letztes muss noch das Zertifikat von HE hinterlegtwerden, da die Tunnelbroker Seite ein selbst signiertes Zertifikat verwendetund das zu Probleme mit dem DDNS Feature führen kann.&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;crypto pki trustpoint HEv6&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;enrollment terminalpem&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;revocation-check none&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;Danach muss der Trustpoint noch authentifiziert werden, derganze Prozess stellt sich so dar:&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;crypto pki authenticate HEv6&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Enter the base 64 encoded CA certificate.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;End with a blank line or the word "quit" on a lineby itself&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;MIID8DCCAtigAwIBAgIJAPF6IlDmmdRhMA0GCSqGSIb3DQEBBQUAMIGcMQswCQYD&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEQMA4GA1UEBxMHRnJlbW9udDEg&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;MB4GA1UEChMXSHVycmljYW5lIEVsZWN0cmljLCBMTEMxDTALBgNVBAsTBElQdjYx&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;GTAXBgNVBAMTEHR1bm5lbGJyb2tlci5uZXQxGjAYBgkqhkiG9w0BCQEWC2lwdjZA&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;aGUubmV0MB4XDTExMDQyMjE3NDIyMFoXDTIxMDQxOTE3NDIyMFowgZwxCzAJBgNV&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;BAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRAwDgYDVQQHEwdGcmVtb250MSAw&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;HgYDVQQKExdIdXJyaWNhbmUgRWxlY3RyaWMsIExMQzENMAsGA1UECxMESVB2NjEZ&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;MBcGA1UEAxMQdHVubmVsYnJva2VyLm5ldDEaMBgGCSqGSIb3DQEJARYLaXB2NkBo&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ZS5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDe5nza8zQ/AiT+&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ySc4mZYmLMcIrcU3q6ZEwIY5vHg2chzCJGCPQIwtBiexSZ7CWL8/GjdPWs6DoCut&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;DS6VlGGaRhJd0ppUOB3uZLcqnfY0/d40WpRFm49yAV3fmhQg744BKUz2+V23E3tP&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;n4UXq507dQ3RmNiZoS/T+DUbt1URXFZDIJmc4vjnYfGQhUzhbWZbC7J5fMFnTFSL&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;NWNou4drWwcApm4FjPfVr+tdanjGEs8bMGSbXo6BjtStiEy1yJ3QGyZLwuURcMMv&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;DV06/hc2Nv9MZPUaIPvXmNcSuVvY3MJiD1CiCWVmfiO3h7b5EmIWC+ZpO9L3Mk6/&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;j/MgWR6jAgMBAAGjMzAxMC8GA1UdEQQoMCaCEHR1bm5lbGJyb2tlci5uZXSCEiou&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;dHVubmVsYnJva2VyLm5ldDANBgkqhkiG9w0BAQUFAAOCAQEAXMG5ZOeyRCzIEPYP&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;tZKbr1N0CkiBHf+7bVqUqfifEte6S/edpUdzIzB9Wtt484Dt88cAeg4BH2z+Kx2C&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;lE9PxtTSMCInZIniuoLhaBP0BiRXEurTYdreFmen/S5cCkffVr+eJGk92lQQAdMr&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;kyz2kD1NCwCaEp1w9DYltDbfC2v8BSIiEKVvD72VW6E2r7AvW73s3+E3WcWbt6pV&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;qrKfFH4mKH0BR7nLzm5zduojCvIdH3GjelyLd7lUVR3N8Dz626tOzni/bzHpbH3T&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;dMlBIl3f7c41wcoFG5zSZf1mvgyOnSlOnNmlxMbnfnrIyIyfYz1L8UWqWZGbxJYH&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;EXcOrA==&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Certificate has the following attributes:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FingerprintMD5: 1128B641 08E7E271 B2FFB7FF 91411952&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FingerprintSHA1: 9EB44F27 6BCE5EF6 5D9D38CC A9252276 4318075C&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;% Do you accept this certificate? [yes/no]: yes&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Trustpoint CA certificate accepted.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;% Certificate successfully imported&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Das eingefügte Zertifikat kann man aus den Browserexportieren, wenn man die DDNS URL manuell aufruft.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Ich habe das /48 Netz etwas gesubnettet und verwende für denTest das Loop 2 Interface um von einfach zu schauen ob wir Konnektivität haben.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;Interface loopback 2&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;ipv6 address 2001:470:XXXX::1/58&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span style="font-size: x-small;"&gt;&lt;i&gt;&amp;nbsp;ipv6 enable&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Ach ja zu guter Letzt sofern noch nicht vorhanden, sollteDNS aktiviert sein, schon allein damit die DDNS URL von HE aufgelöst wird.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Abschließender Test:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;ping ipv6 ipv6.google.com source loop 2&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Sending 5, 100-byte ICMP Echos to 2A00:1450:8004::6A,timeout is 2 seconds:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Packet sent with a source address of 2001:470:XXX::1&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;!!!!!&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-size: x-small;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max =76/76/76 ms&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;YEAH! Alles schick, mehr kommt &lt;a href="http://playingwithnetworks.blogspot.com/2011/10/de-hev6-tunnel-verbesserungen.html"&gt;hier&lt;/a&gt;!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4301930121414657491?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4301930121414657491/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-hurricane-electric-ipv6-tunnel-mit.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4301930121414657491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4301930121414657491'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-hurricane-electric-ipv6-tunnel-mit.html' title='DE - Hurricane Electric IPv6 Tunnel mit Cisco 887'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2032150950487695586</id><published>2011-10-08T23:30:00.001+02:00</published><updated>2011-10-09T23:16:52.932+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>EN - Cisco 887w default open ports! WTF!</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The lasttwo nights I was playing with the &lt;a href="http://tunnelbroker.net/"&gt;Hurricane Electric&lt;/a&gt; Tunnel setup for one ofour routers to get IPv6 to my lab. For some strange reason the tunnel showedthat it was up but I was unable to ping the IPv6 IP of Google.com. To trackdown the issue I used the port scan feature of HE on my public v6 and besidesthe expected port 22 for tcp the following ports showed up on my 887w: Port tcp2002, tcp 4002, tcp 6002 and tcp 9002. I tried a telnet and I was really scaredwhen my router replied with a nice telnet prompt.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I goggledfor the open ports plus cisco 887w and found the &lt;a href="http://www.dataprotectioncenter.com/security/the-matryoshka-router/"&gt;article&lt;/a&gt; over at &lt;a href="http://www.dataprotectioncenter.com/"&gt;www.dataprotectioncenter.com&lt;/a&gt;. Itlooked like the Line 2 is used to communicate between the router and thewireless controller. This controller was working like a service module in therouter.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The article provided a simple solution that I instantly applied. Whatwas the solution – put an access list on the Line 2 for IPv4 and IPv6.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I dug alittle to the bug database at cisco.com but I couldn´t find anything.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&amp;nbsp;When I’m back at the office I´ll have a closerlook on this particular problem and keep you updated.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Thanks to “DidierStevens“ &amp;nbsp;for figuring and sharing this issue.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2032150950487695586?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2032150950487695586/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-cisco-887w-default-open-ports-wtf.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2032150950487695586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2032150950487695586'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-cisco-887w-default-open-ports-wtf.html' title='EN - Cisco 887w default open ports! WTF!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-877707621156556999</id><published>2011-10-08T23:30:00.000+02:00</published><updated>2011-10-09T23:16:33.612+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>DE - Cisco 887w offene Ports! WTF!</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;Die letzten zwei Nächte haben meinem 887w Router und&lt;a href="http://tunnelbroker.net/"&gt;Hurricane Electrics&lt;/a&gt; IPv6 Tunnel gehört. Ich wollte für mein Lab ein echtes IPv6Netz haben und habe mir daher einen HE Tunnel auf den Router konfiguriert. Alsdie Konfig durch war konnte ich leider meine Test Host ipv6.google.com nichterreichen. Da ich einen Fehler auf meiner Seite ausschließen wollte probierteich mit dem HE Tool einen Port Scan auf meine Maschine der ziemlich erfolgreichwar.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Leider erfolgreicher als erwünscht da er neben demerwarteten Port TCP 22 auch die Ports TCP 2002, TCP 4002, TCP 6002 und TCP 9002als offen anzeigte. Einen kurzen versuch via Telnet später zeigte mir, dass aufden Ports auch wirklich eine hübsche Cisco Telnet Login Aufforderung kam. WTF,wo kommt das den her, ging mir durch den Kopf.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Wie so oft wusste Google Rat und ich fand bei der Suche nach“open ports cisco 887w” eine &lt;a href="http://www.dataprotectioncenter.com/security/the-matryoshka-router/"&gt;Artikel&lt;/a&gt; bei &lt;a href="http://www.dataprotectioncenter.com/"&gt;www.dataprotectioncenter.com&lt;/a&gt;. Derlieferte eine grobe Erklärung was dort antwortet, es ist dem Artikel zufolge “Line2” die dafür genutzt wird, dass man vom Router mit dem Service Module des WirelessController kommunizieren kann. Die Lösung die der Artikel anbot ist rechteinfach – einfach eine entsprechende access-list auf die “Line 2” binden undschon ist ruhe.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Sobald ich wieder im Büro bin und etwas mehr Zeit hab schauich mir das Thema noch einmal genauer an. Im Moment mag ich nicht an dem Astsägen, auf dem ich sitze :D&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Wenn ich etwas mehr weiß, melde ich mich.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Ein dickes danke an “Didier Stevens“&amp;nbsp; von dem der Artikel stammt.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Achja die Cisco BUG DB findet dazu nichts (war ja klar)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-877707621156556999?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/877707621156556999/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-cisco-887w-offene-ports-wtf.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/877707621156556999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/877707621156556999'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-cisco-887w-offene-ports-wtf.html' title='DE - Cisco 887w offene Ports! WTF!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1549774567861936492</id><published>2011-10-07T23:30:00.001+02:00</published><updated>2011-10-09T23:18:02.888+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>EN - What a week!</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;First weekwith a new customer is done and it was quite nice. Quite good documented andnice topics I´m working on. Bad luck most stuff is once again CheckPoint butwell I´ve got to face it, they won´t go away, so I got to deal with them.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Anywaysince I was figuring out processes and stuff I wasn´t able to update my postshere but I think next week I´ll have a little more time for blogging.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1549774567861936492?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1549774567861936492/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-what-week.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1549774567861936492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1549774567861936492'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-what-week.html' title='EN - What a week!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5747919889528339228</id><published>2011-10-07T23:30:00.000+02:00</published><updated>2011-10-09T23:17:42.849+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>DE - Was für eine Woche!</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;Quasi die erste Woche beim Kunden ist um und ich muss sagenich bin positiv überrascht. Die meisten Sachen sind gut dokumentiert und / oderselbsterklärend und auch das Bereitstellen der Arbeitsmittel hat fastreibungslos funktioniert. Leider ist der Fokus auch dieses Mal wieder aufCheckPoint, aber da CheckPoint vermutlich nicht so schnell verschwindet, werdeich mich damit arrangieren (müssen).&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Auf jeden Fall blieb mir nicht so viel Zeit zum bloggen, dadie meiste Zeit zum einlesen und durcharbeiten drauf gegangen ist. NächsteWoche dürfte es besser werden und dann gibt es auch wieder neue Posts.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5747919889528339228?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5747919889528339228/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-was-fur-eine-woche.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5747919889528339228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5747919889528339228'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-was-fur-eine-woche.html' title='DE - Was für eine Woche!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1142597214057487115</id><published>2011-10-04T07:01:00.001+02:00</published><updated>2011-10-04T07:02:01.434+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>DE –  Rack Layout</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;OK ich hab es also wieder nicht wirklich geschafft meinenZeitplan treu zu bleiben. Aber da ich mit meiner Familie meine Eltern besuchenwar hab ich das verlängerte Wochenende für mehr Zeit mit der Familie undweniger Zeit zum Lernen und Bloggen genutzt.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Wie schon im letzten Post erwähnt, hab ich es geschafft meinLab fertig zu stellen.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s1600/IMAG0351.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s320/IMAG0351.jpg" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Anbei eine kleine Auflistung der Sachen die ich jetztverbaut hab und warum sie sich dort befinden &lt;span style="font-family: Wingdings;"&gt;:)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE 1 &amp;amp; 2 - Patch Panels für die Büro Verkabelung – das Rackwird auch im Produktiven Netz benutzt&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE 3 - Cisco 2509 + Oktopus Kabel + AUI Konverter Der Routerarbeitet als Terminal Server für alle Lab Geräte&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE 4 - Cisco 2924 – 24 Port Fast Ethernet Switch, alsBackbone Switch übernimmt er die L2 Topologie Anbindung der ASAs&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE5 -6 Neat Patch – Kabelführungsgedönst (sehr schick)&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE7 HP ProCurve Switch (non Lab)&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE8 Cisco ASA (BLUE) –ASA OS 8.0.2 &lt;/div&gt;&lt;div class="MsoNormal"&gt;HE9 Cisco ASA (GREEN) –ASA OS 8.0.2&lt;/div&gt;&lt;div class="MsoNormal"&gt;HE10 Cisco ASA (RED) –ASA OS 8.0.4 (wird noch angepasst)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Unter den ASAs befindet sich eine etwas ältere VostroWorkstation von Dell, die so umgebaut wurde, das sie nun als VMware Server fürdie anderen Systeme dient, sprich für ACS, IOU, GNS3 und natürlich auch für dieClient Betriebssysteme&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Auf der Rückseite des Racks befindet sich eine achtfachSteckdose, mit IP Anschluss, so dass alle Geräte per Webmanagement hoch undrunter gefahren werden können.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Sobald ich Zeit hab update ich meine L1/ L2 Topologie undposte sie hier&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So long&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1142597214057487115?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1142597214057487115/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-rack-layout.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1142597214057487115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1142597214057487115'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-rack-layout.html' title='DE –  Rack Layout'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s72-c/IMAG0351.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3331818296886586085</id><published>2011-10-04T07:01:00.000+02:00</published><updated>2011-10-04T07:01:44.420+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>EN - Rack layout</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Once againI´ve been a bit lazy, we´ve been to my parents and I decided to spent more timewith my family than blogging (and learning).&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;But asmentioned earlier I was finally able to cable my rack. &lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s1600/IMAG0351.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s320/IMAG0351.jpg" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;As you cansee (hopefully) I´ve got a mixed rack. This means a small part of the stuff isused for productive networking in our office.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I will quicklyline out what I´ve used and why, starting from top.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U 1 &amp;amp; 2- patch panels for the office (non LAB)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U 3 - Cisco2509 + octopus cable + AUI converter – this router is used to provide consoleconnections to all lab devices&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U4 - Cisco 2924– 24 Port Fast Ethernet switch, not really part of the lab the switch justprovides the L2 Structure for the ASAs&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U5 -6 NeatPatch – just to keep the rack clean&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U7 HP ProCurveSwitch (non Lab)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U8 CiscoASA (BLUE) – Running ASA OS 8.0.2 &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U9 CiscoASA (GREEN) – Running ASA OS 8.0.2&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;U10 CiscoASA (RED) – Running ASA OS 8.0.4 (need to fix that)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Below – notrack mounted – Dell Vostro 410 Desktop PC modified to work as VM host systemwith ACS, IOU , GNS3 and some Guest OS to work as clients.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;All Labequipment is attached to an 8 port power outlet that can be managed using a webinterface to remotely reboot the stuff in case it fails.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I´ll updatethe L1 / L2 topology in the next view days and once again post it here.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;So long&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3331818296886586085?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3331818296886586085/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-rack-layout.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3331818296886586085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3331818296886586085'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-rack-layout.html' title='EN - Rack layout'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-WxWY_0dGX6k/TojdfQEcKQI/AAAAAAAAAEc/QAqaHFnjsSA/s72-c/IMAG0351.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4106439699256776386</id><published>2011-10-02T12:04:00.000+02:00</published><updated>2011-10-02T12:07:37.502+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='procurve'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><title type='text'>EN - So many things, so little time</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Actually I hadplanned to post a small update on my CCIE lab the last Thursday, but as usuallife or in this case the customer had another opinion about it.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;As mentionedearlier I was working at a customer location to immediately fix some networkissues with HP system. After the STP problem was solved we talked a while and decidedto move to L3 meaning enabling routing and reducing the spanning tree. Since thecustomer had special demands considering network outages during business hourswe scheduled the redesign and rebuild of the network to Thursday night. Not tomention that it took the whole night after we “crashed” their router (Draytek)so hard that this stupid box didn´t knew that it had interfaces after thereboot&lt;/span&gt;&lt;span lang="EN-US"&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;At 4 in themorning everything was back up and the network was running smooth (and allswitches stayed significant below 20% CPU utilization). Next step will be replacingthe Draytek box with two Cisco routers and shifting from copper uplinks tofiber as well as implement QoS&lt;/span&gt;&lt;span lang="EN-US"&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;So I hadabout 4 hours to go back home, shower, sleep, wake up, get to the office andprepare for the next customer meeting – no time for blog post&lt;/span&gt;&lt;span lang="EN-US"&gt;.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;Anyway I managedto finally cable my CCIE Security lab rack and will post a few updates about ittonight, hopefully.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4106439699256776386?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4106439699256776386/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-so-many-things-so-little-time.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4106439699256776386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4106439699256776386'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/en-so-many-things-so-little-time.html' title='EN - So many things, so little time'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6769979314895644225</id><published>2011-10-02T00:30:00.000+02:00</published><updated>2011-10-02T12:05:35.213+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='procurve'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><title type='text'>DE – viel zu viel zu tun und viel zu wenig Zeit</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;Eigentlich wollte ich euch am vergangenen Donnerstagberichten wie toll mein CCIE Lab voranschreitet aber leider ist, wie so oft, etwas dazwischen gekommen, in diesem Fall ein Kunde.&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Wie schon berichtet, habeich ja letzten wieder einmal etwas mit HP ProCurves zu tun gehabt. Der Kundehatte massive Netzwerkprobleme beklagt und wie sich herausstellte, war es unteranderem ein STP Problem, welches sich recht schnell fixen ließ. Nachdem der Fiximplementiert war haben wir noch etwas zusammen gesessen und uns dann daraufverständigt, das wir von einer flachen L2 Struktur auf eine L3 Strukturwechseln und so den Spanning Tree massive verkleinern – quasi Bonsai Spanning Tree.Da der Kunde aber den kompletten Umbau der Netztopology nicht unbedingt in die Geschäftszeitenlegen wollte, haben wir uns für die vergangene Donnerstagnacht entschieden. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Gesagt getan, die gesamte Nacht haben wir das Netz umgebautund dabei den Edge Router (einen Draytek) so sehr verwirrt, das er nach einem Rebootnicht mehr seine Interfaces gefunden hatte. Zum Glück konnten wir die Box aufWerkseinstellungen zurücksetzen und ein Backup einspielen. Gegen 4 Uhr war dasNetz dann umgestellt und schnurrte wie ein Kätzchen, Yeah! Als nächstes wirddie Draytek Box durch ein paar Cisco Router ersetzt und die Uplinks auf Fiberumgestellt. Ach ja QoS soll auch noch kommen, unter anderem.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Danach blieben mir noch gute 4 Stunden um nach Hause zukommen, zu duschen, zu schlafen, aufzustehen und ins Büro zu kommen für dennächsten Kundentermin. Sprich es blieb keine Zeit mehr für mein CCIE LAB Postübrig.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Egal, egal, egal, ich hab es am Freitag geschafft mein Racknoch fertig zu verkabeln und darüber gibt es hoffentlich heute Nacht ein Post;)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6769979314895644225?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6769979314895644225/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-viel-zu-viel-zu-tun-und-viel-zu.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6769979314895644225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6769979314895644225'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/10/de-viel-zu-viel-zu-tun-und-viel-zu.html' title='DE – viel zu viel zu tun und viel zu wenig Zeit'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4964129904753283586</id><published>2011-09-28T00:10:00.004+02:00</published><updated>2011-09-27T23:51:51.671+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='catalyst'/><category scheme='http://www.blogger.com/atom/ns#' term='procurve'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><title type='text'>EN – HP ProCurve / Cisco Catalyst Interoperability</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Today I was working at a customer location playing around with some HP ProCurve switches. Usually I do configure Cisco switches, so I was happy to find this little guide about HP ProCurve and Cisco Catalyst interoperability. Quite nice if you are sure what you want to do on Cisco but are unsure what the command should look like on ProCurve. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://www.tecnocael.it/ftp/docs/ProCurve_Cisco.pdf"&gt;ProCurve /Catalyst Interoperability Guide&lt;/a&gt; (found at www.tecnocael.it)&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4964129904753283586?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4964129904753283586/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-hp-procurve-cisco-catalyst.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4964129904753283586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4964129904753283586'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-hp-procurve-cisco-catalyst.html' title='EN – HP ProCurve / Cisco Catalyst Interoperability'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7427076777544357374</id><published>2011-09-28T00:10:00.003+02:00</published><updated>2011-09-28T00:10:00.374+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='catalyst'/><category scheme='http://www.blogger.com/atom/ns#' term='procurve'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><title type='text'>DE – Zusammenspiel von HP ProCurve und Cisco Catalyst</title><content type='html'>&lt;div class="MsoNormal"&gt;Heute hatte ich das Glück bei einem Kunden mit einigen HP ProCurve Switches zu arbeiten. Da ich schon eine Weile nicht mehr mit den ProCurves zu tun hatte, ist mein Know How über den speziellen Syntax etwas eingerostet. Umso mehr hab ich mich gefreut im Netz einen kleinen Guide zu finden der im Prinzip darstellt, wie Cisco Catalyst und HP ProCurves zusammenarbeiten. Der Vorteil daran ist, dass man sehen kann wie eine Konfiguration unter Cisco als ProCurve Config aussieht. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://www.tecnocael.it/ftp/docs/ProCurve_Cisco.pdf"&gt;ProCurve / Catalyst Interoperability Guide&lt;/a&gt; (gefunden bei &amp;nbsp;www.tecnocael.it)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7427076777544357374?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7427076777544357374/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-zusammenspiel-von-hp-procurve-und.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7427076777544357374'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7427076777544357374'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-zusammenspiel-von-hp-procurve-und.html' title='DE – Zusammenspiel von HP ProCurve und Cisco Catalyst'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4531722849632542809</id><published>2011-09-27T07:30:00.009+02:00</published><updated>2011-09-27T23:32:30.202+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>DE - Grundlagen schaffen</title><content type='html'>Yeah, ich hab ein neues Projekt – ASA / Checkpoint in Hamburg, sprich leider weit weg von meiner Familie. Der einzige Vorteil den ich da habe, ist das ich die Abende zum Lernen nutzen kann.  &lt;br /&gt;&lt;div class="MsoNormal"&gt;Um richtig loszulegen habe ich begonnen Grundlagen zu schaffen.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Was bedeutet das genau. Ich habe einige von meinen alten MSDN CDs rausgekramt und in VMware ein paar Systeme hochgezogen.&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;System 1: Windows Server 2003 Inkl. AD, CA und Tardis (NTP Server/Client)&lt;/li&gt;&lt;li&gt;System 2: Windows Server 2003 ACS 4.2 Server, 3CDaemon&lt;/li&gt;&lt;li&gt;System 3+4: Windows XP, Client System für VPN usw.&lt;/li&gt;&lt;/ul&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;Morgen werden die Systeme auf den VM Server geschoben und dann bin ich fast fertig mit der Lab Vorbereitung. &lt;/div&gt;&lt;div class="MsoNormal"&gt;Achja kleine Anekdote am Rande, ich habe mir ja einen 2509 gekauft der als TS Server dienen soll, leider hab ich übersehen, dass das gute Stück nur 2 Serial + 1 AUI Interface hat, so dass ich jetzt noch einmal ein paar Euro für einen AUI – Ethernet Adapter nachschießen darf.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Hoffentlich mehr am Donnerstag&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4531722849632542809?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4531722849632542809/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-grundlagen-schaffen.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4531722849632542809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4531722849632542809'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-grundlagen-schaffen.html' title='DE - Grundlagen schaffen'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6133873776507291885</id><published>2011-09-27T07:30:00.008+02:00</published><updated>2011-09-27T23:32:03.230+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>EN – Setting up the basics</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;First of all yeah I´ve got a new project, mostly ASA/Checkpoint. Sadly it is in Hamburg so quite a good deal away from my family. The only thing positive about being in Hamburg is that I will have the time for some serious learning.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;To do so, I´ve started today to build up some basics for the lab.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I had to dig out my old MSDN CDs and deployed a few systems in VMware.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;System 1: Windows Server 2003 with Active Directory, Certificate Authority and Tardis (for NTP)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;System 2: Windows Server 2003 with ACS 4.2 and 3CDaemon for Syslog&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;System 3 and 4: Windows XP, Client System for VPN and so on…&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;span lang="EN-US"&gt;Hopefully I will be able to move them from my laptop to the VM Server. When this is completed, my lab is nearly ready.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I noticed today when my Terminal Server Router (2509) arrived that this box was missing an Ethernet interface. Default configuration is just 2x serial and 1x AUI interface, so I had to order an AUI to Ethernet adaptor. Bad luck!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6133873776507291885?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6133873776507291885/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-setting-up-basics.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6133873776507291885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6133873776507291885'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-setting-up-basics.html' title='EN – Setting up the basics'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2770016365287672427</id><published>2011-09-26T00:44:00.001+02:00</published><updated>2011-09-26T23:32:03.754+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>EN – Books!</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Depending on your time zone Sunday has already passed and my post intentioned for Sunday is published on Monday, but well at least it is published.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;As I mentioned two days ago, I really want to get into this CCIE thing and started with one important question „ what should I read?“ Cisco got a quite good answer, a book list recommended for your CCIE security studies. This list is quite scary because it would take years to read all these books.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://www.cisco.com/web/learning/le3/ccie/security/book_list.html"&gt;&lt;span lang="EN-US"&gt;Cisco CCIE security book list&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I already own the following books.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587140268"&gt;CCIE Security v3.0 Configuration Practice Labs (eBook), 2nd Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/bookstore/product.asp?isbn=1587058197"&gt;Cisco ASA: All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance, 2nd Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587052040"&gt;The Complete Cisco VPN Configuration Guide&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span lang="EN-US" style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587052024"&gt;Routing TCP/IP, Volume I, Second Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://www.amazon.com/exec/obidos/ASIN/0201633469/qid=1101962272/sr=2-1/ref=pd_ka_b_2_1/002-8670228-6404004"&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; text-decoration: none;"&gt;The Protocols (TCP/IP Illustrated : Volume 1)&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The first is he only book I bought specially for my CCIE training, the rest I own because from time to time it is nice to look something up during the job.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;As soon as I add a new book I´ll publish it here and of course give some comments about the existing once.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Hopefully my next post will be up on Tuesday.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2770016365287672427?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2770016365287672427/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-books.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2770016365287672427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2770016365287672427'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-books.html' title='EN – Books!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7561197204988623213</id><published>2011-09-26T00:34:00.003+02:00</published><updated>2011-09-26T23:32:24.401+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>DE – Bücher!</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Je nachdem in welcher Zeitzone ihr wohnt ist der Sonntag schon vorbei, leider bei mir auch, so das aus dem Sonntagsposting ein Montagmorgenposting geworden ist.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Jetzt da ich das Thema CCIE ernsthaft angehen will, ist natürlich eine der wichtigsten Fragen, was sollte man alles Lesen um Fit auf dem Bereich zu werden und auch eine ernsthafte Chance zu haben.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Es gibt bei Cisco eine schicke Liste mit empfohlenen Büchern, wenn man die durchgeht bekommt man es mit der Angst zu tun, da um das alles zu lesen man vermutlich Jahre braucht.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://www.cisco.com/web/learning/le3/ccie/security/book_list.html"&gt;Cisco CCIE Security Liste&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Ich nenne davon Folgende bereits mein eigen:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587140268"&gt;CCIE Security v3.0 Configuration Practice Labs (eBook), 2nd Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/bookstore/product.asp?isbn=1587058197"&gt;Cisco ASA: All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance, 2nd Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587052040"&gt;The Complete Cisco VPN Configuration Guide&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;"&gt;&lt;a href="http://www.ciscopress.com/title/1587052024"&gt;Routing TCP/IP, Volume I, Second Edition&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/exec/obidos/ASIN/0201633469/qid=1101962272/sr=2-1/ref=pd_ka_b_2_1/002-8670228-6404004"&gt;&lt;i&gt;&lt;span style="font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; text-decoration: none;"&gt;The Protocols (TCP/IP Illustrated : Volume 1)&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;Bis auf das erste hab ich diese schon einige Zeit da ich sie fürs Arbeitsleben hin und wieder auch gebrauchen kann. Das erste Buch hab ich nur zum CCIE Training mir an Land gezogen.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Sobald ich neue Bücher mir hinzu hole wird ich das hier irgendwo updaten. Fürs erste hab ich genug mit den die ich habe zu tun.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Mehr gibt es voraussichtlich am Dienstag&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7561197204988623213?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7561197204988623213/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-bucher.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7561197204988623213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7561197204988623213'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-bucher.html' title='DE – Bücher!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5700769303114456176</id><published>2011-09-24T00:39:00.001+02:00</published><updated>2011-09-26T23:31:30.528+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='iou'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>EN - Go Go Go!</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Well that’s life,&amp;nbsp;traveling around and doing various projects you end up doing more Checkpoint than Cisco stuff. Actually I´m fine with both but I like Cisco a little more. So what can I do to get back on the Cisco track? Yes aim for the CCIE security. (You have to have big goals).&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;I was hoping that I would have finished my CCIE before I hit the age of 31 but well I really had no time (insert other lame excuse here!) .&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Anyway to really start with the CCIE preparations you need what (except from time and books) yes equipment! Here we go!&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s1600/IMAG0346.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s320/IMAG0346.jpg" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;That’s 3x ASA 5510 Sec bun + 3x 2940 + 1x 1841. In theory I just need the ASAs and the switch the rest will be done using VMware, GNS3 and IOU. &lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;When the lab is finished wiring it will hopefully look somewhat like this:&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0LKM9EA8fro/Tn0GzYhFgbI/AAAAAAAAAEQ/OIbuCiBDK8c/s1600/L2Lab_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-0LKM9EA8fro/Tn0GzYhFgbI/AAAAAAAAAEQ/OIbuCiBDK8c/s320/L2Lab_1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;The top left router is a 2509 for TS that I bought today but that is not jet shipped.&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;That’s all for now more on Sunday (hopefully)&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5700769303114456176?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5700769303114456176/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-go-go-go.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5700769303114456176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5700769303114456176'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/en-go-go-go.html' title='EN - Go Go Go!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s72-c/IMAG0346.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8645187570296520609</id><published>2011-09-24T00:25:00.002+02:00</published><updated>2011-09-26T23:33:06.622+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='iou'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie sec'/><title type='text'>DE – Go Go Go!</title><content type='html'>&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So schön kann die Welt sein. Da treibt man sich eine Weile in den unterschiedlichsten Projekten herum und plötzlich hat man mehr mit Checkpoint zu tun als mit Cisco. Grundsätzlich kann ich mit beiden Systemen leben aber mir liegt eigentlich eher die Cisco Variante. &amp;nbsp;Daher heißt es für mich in nächster Zeit Cisco wieder stärker forcieren. &lt;/div&gt;&lt;div class="MsoNormal"&gt;Und wie lässt sich Cisco stärker forcieren genau mit einem CCIE. JAHA! Genau CCIE! Eigentlich wollte ich das Thema noch vor meinem 31 erledigt haben aber irgendwie war der Rest der Welt gegen mich. (Bitte hier beliebige andere Ausrede einsetzen)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Sei es wie es sei, ich mach nun ernst. Was braucht man wenn man es ernst meint? Richtig Equipment!&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s1600/IMAG0346.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s320/IMAG0346.jpg" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Das hab ich ja nun wie man hier hübsch sieht (3x ASA 5510 Sec bun + 3x 2940 + 1x 1841)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Brauchen tu ich eigentlich nur die drei ASAs und den 2940 24 Port Switch eventuell fällt mir noch etwas Sinnvolles für den 1841 ein aber eigentlich wollte ich alles was Router und Switch heißt ins IOU bzw. Dynamips verbannen.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Das ganze sieht dann nach aktuellem Netzwerkplan auf Layer 2 etwa so au:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-0LKM9EA8fro/Tn0GzYhFgbI/AAAAAAAAAEQ/OIbuCiBDK8c/s1600/L2Lab_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="180" src="http://1.bp.blogspot.com/-0LKM9EA8fro/Tn0GzYhFgbI/AAAAAAAAAEQ/OIbuCiBDK8c/s320/L2Lab_1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;Ach ja der Router oben links ist ein 2509 als TermServer der heute günstig für mich abfiel, aber sich noch ein paar Tage auf Reisen befindet.&lt;/div&gt;&lt;div class="MsoNormal"&gt;So, am Sonntag gibt es mehr!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8645187570296520609?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8645187570296520609/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-go-go-go.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8645187570296520609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8645187570296520609'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/09/de-go-go-go.html' title='DE – Go Go Go!'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-mgYeBymtc9A/Tn0GlMHAUSI/AAAAAAAAAEM/1_LECIIwDNc/s72-c/IMAG0346.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8731683353820980861</id><published>2011-01-03T22:18:00.002+01:00</published><updated>2011-01-03T22:20:49.526+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='etherchannel'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>DE - Port Channel</title><content type='html'>Wie schon heute Vormittag erwähnt, werde ich mich z.Z. etwas mehr dem CCNP Themen widmen und Überraschung hier ist das erste aus dem SWITCH Bereich: EtherChannel. Da es mir im Moment an echten Switchen fehlt hab ich das ganze soweit wie möglich in GNS3 / Dynamips nachgebaut.&lt;br /&gt;&lt;br /&gt;Das Setup ist denkbar einfach 2x 3725 als Hosts und 2x 3725 mit NM-16ESW als Switches die den EtherChannel bilden, wobei die Switches mit 4 Kabeln direkt an den Interfaces FastEthernet 1/12 - 15 verbunden werden.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s1600/EtherChannel.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="77" src="http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s320/EtherChannel.png" width="320" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Die Konfiguration ist nur um den Domainnamen, eine IP und den Speed sowie Duplex Einstellungen erweitert worden.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;ip domain name EtherChannel.playingwithnetworks.com&lt;br /&gt;int fast 0/0&lt;br /&gt;speed 100&lt;br /&gt;du fu&lt;br /&gt;ip address 10.0.1.1 255.255.255.0&lt;br /&gt;no shut&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Auf den Switches muss an sich nur der EtherChannel konfiguriert werden. Sobald beide Switches an sind konnte man im Spanning Tree das erwartete verhalten bei redundanten Verbindungen sehen. Das geringwertigste Interface, in diesem Fall FastEthernet 1/12 geht in den forwarding modus die restlichen Interfaces sind im Blocking auf dem Switch der nicht Root Bridge geworden ist. &lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Switch_A#sh spanning-tree brief&lt;br /&gt;VLAN1&lt;br /&gt;Spanning tree enabled protocol ieee&lt;br /&gt;Root ID Priority 32768&lt;br /&gt;Address c20a.1ed0.0000&lt;br /&gt;Cost 19&lt;br /&gt;Port 53 (FastEthernet1/12)&lt;br /&gt;Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec&lt;br /&gt;&lt;br /&gt;Bridge ID Priority 32768&lt;br /&gt;Address c20b.1ed0.0000&lt;br /&gt;Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec&lt;br /&gt;Aging Time 300&lt;br /&gt;&lt;br /&gt;Interface Designated&lt;br /&gt;Name Port ID Prio Cost Sts Cost Bridge ID Port ID&lt;br /&gt;-------------------- ------- ---- ----- --- ----- -------------------- -------&lt;br /&gt;FastEthernet1/0 128.41 128 19 FWD 19 32768 c20b.1ed0.0000 128.41&lt;br /&gt;&lt;span style="background-color: yellow;"&gt;FastEthernet1/12 128.53 128 19 FWD 0 32768 c20a.1ed0.0000 128.53&lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: orange;"&gt;FastEthernet1/13 128.54 128 19 BLK 0 32768 c20a.1ed0.0000 128.54&lt;/span&gt;&lt;br style="background-color: orange;" /&gt;&lt;span style="background-color: orange;"&gt; FastEthernet1/14 128.55 128 19 BLK 0 32768 c20a.1ed0.0000 128.55&lt;/span&gt;&lt;br style="background-color: orange;" /&gt;&lt;span style="background-color: orange;"&gt; FastEthernet1/15 128.56 128 19 BLK 0 32768 c20a.1ed0.0000 128.56&lt;/span&gt;&lt;/span&gt;  &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Der EtherChannel kann dann wie folgt konfiguriert werden:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;Interface range fast 1/12 – 15&lt;br /&gt;Switchport trunk encryption dot1q&lt;br /&gt;Switchport mode trunk&lt;br /&gt;Channel-group 1 mode on&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Wobei die Trunk Settings optional sind wichtig ist nur das die Interfaces dieselben Settings haben.&lt;br /&gt;Sobald beide Switches durchkonfiguriert sind und die PortChannel Interfacesauf beiden Up sind verschwinden Interfaces Fast 1/12 – 15 aus der Spanning Tree Ansicht. Es bleibt nur noch das PortChannel 1 Interface im Forwarding Modus.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Switch_A#sh spanning-tree brief&lt;br /&gt;&lt;br /&gt;VLAN1&lt;br /&gt;Spanning tree enabled protocol ieee&lt;br /&gt;Root ID Priority 32768&lt;br /&gt;Address c20a.1ed0.0000&lt;br /&gt;Cost 8&lt;br /&gt;Port 321 (Port-channel1)&lt;br /&gt;Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec&lt;br /&gt;&lt;br /&gt;Bridge ID Priority 32768&lt;br /&gt;Address c20b.1ed0.0000&lt;br /&gt;Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec&lt;br /&gt;Aging Time 300&lt;br /&gt;&lt;br /&gt;Interface Designated&lt;br /&gt;Name Port ID Prio Cost Sts Cost Bridge ID Port ID&lt;br /&gt;-------------------- ------- ---- ----- --- ----- -------------------- -------&lt;br /&gt;FastEthernet1/0 128.41 128 19 FWD 8 32768 c20b.1ed0.0000 128.41&lt;br /&gt;FastEthernet1/1 128.42 128 19 FWD 8 32768 c20b.1ed0.0000 128.42&lt;br /&gt;&lt;span style="background-color: orange;"&gt;Port-channel1 129.65 128 8 FWD 0 32768 c20a.1ed0.0000 129.65&lt;/span&gt;&lt;/span&gt;   &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Das war´s ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8731683353820980861?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8731683353820980861/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-port-channel.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8731683353820980861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8731683353820980861'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-port-channel.html' title='DE - Port Channel'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s72-c/EtherChannel.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6371103603725837825</id><published>2011-01-03T17:21:00.001+01:00</published><updated>2011-01-03T17:23:50.992+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='etherchannel'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>EN – Ether Channel</title><content type='html'>As I mentioned I will put up some CCNP stuff so here we go Ether Channel. Since I´m lacking real Switch hardware I sat it up on GNS3 / Dynamips.&lt;br /&gt;First of all I added 2 x 3725 as Hosts than 2 x 3725 with NM-16ESW  as “Switches”and connected both switches with 4 cables via interfaces fast ethernet 1/12 - 15.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s1600/EtherChannel.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="77" src="http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s320/EtherChannel.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;The configuration of the Hosts is straight forward&amp;nbsp; &lt;br /&gt;domain name, interface IP address 10.0.1.1 or 2 /24 speed and duplex&lt;br /&gt;&lt;code&gt;&lt;br /&gt;ip domain name EtherChannel.playingwithnetworks.com&lt;br /&gt;int fast 0/0&lt;br /&gt;speed 100&lt;br /&gt;du fu&lt;br /&gt;ip address 10.0.1.1 255.255.255.0&lt;br /&gt;no shut&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;On the „switches“  you have to configure the Ether Channels. If you have a look on your spanning tree you´ll see that only the interface with the lowest interface number is in forwarding state all other interfaces connecting to your root bridge are in blocking state.  &lt;br /&gt;&lt;code&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Switch_A#sh spanning-tree brief&lt;br /&gt;VLAN1&lt;br /&gt;Spanning tree enabled protocol ieee&lt;br /&gt;Root ID    Priority    32768&lt;br /&gt;Address     c20a.1ed0.0000&lt;br /&gt;Cost        19&lt;br /&gt;Port        53 (FastEthernet1/12)&lt;br /&gt;Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec&lt;br /&gt;&lt;br /&gt;Bridge ID  Priority    32768&lt;br /&gt;Address     c20b.1ed0.0000&lt;br /&gt;Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec&lt;br /&gt;Aging Time 300&lt;br /&gt;&lt;br /&gt;Interface                                   Designated&lt;br /&gt;Name                 Port ID Prio Cost  Sts Cost  Bridge ID            Port ID&lt;br /&gt;-------------------- ------- ---- ----- --- ----- -------------------- -------&lt;br /&gt;FastEthernet1/0      128.41   128    19 FWD    19 32768 c20b.1ed0.0000 128.41&lt;br /&gt;&lt;span style="background-color: yellow;"&gt;FastEthernet1/12     128.53   128    19 FWD     0 32768 c20a.1ed0.0000 128.53&lt;/span&gt;&lt;br /&gt;&lt;span style="background-color: orange;"&gt;FastEthernet1/13     128.54   128    19 BLK     0 32768 c20a.1ed0.0000 128.54&lt;/span&gt;&lt;br style="background-color: orange;" /&gt;&lt;span style="background-color: orange;"&gt; FastEthernet1/14     128.55   128    19 BLK     0 32768 c20a.1ed0.0000 128.55&lt;/span&gt;&lt;br style="background-color: orange;" /&gt;&lt;span style="background-color: orange;"&gt; FastEthernet1/15     128.56   128    19 BLK     0 32768 c20a.1ed0.0000 128.56&lt;/span&gt;&lt;/span&gt;  &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The Ether Channel is configured by adding all physical interfaces to a channel group.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;Interface range fast 1/12 – 15&lt;br /&gt;Switchport trunk encryption dot1q&lt;br /&gt;Switchport mode trunk&lt;br /&gt;Channel-group  1 mode on&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;As soon as on both switches this configuration has been applied you can have another look into the spanning tree and you´ll see that the interfaces fastethernet 1/12 – 15 have vanished and only interface Port-channel 1 is in forwarding state. &lt;br /&gt;&lt;code&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;Switch_A#sh spanning-tree brief&lt;br /&gt;&lt;br /&gt;VLAN1&lt;br /&gt;Spanning tree enabled protocol ieee&lt;br /&gt;Root ID    Priority    32768&lt;br /&gt;Address     c20a.1ed0.0000&lt;br /&gt;Cost        8&lt;br /&gt;Port        321 (Port-channel1)&lt;br /&gt;Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec&lt;br /&gt;&lt;br /&gt;Bridge ID  Priority    32768&lt;br /&gt;Address     c20b.1ed0.0000&lt;br /&gt;Hello Time   2 sec  Max Age 20 sec  Forward Delay 15 sec&lt;br /&gt;Aging Time 300&lt;br /&gt;&lt;br /&gt;Interface                                   Designated&lt;br /&gt;Name                 Port ID Prio Cost  Sts Cost  Bridge ID            Port ID&lt;br /&gt;-------------------- ------- ---- ----- --- ----- -------------------- -------&lt;br /&gt;FastEthernet1/0      128.41   128    19 FWD     8 32768 c20b.1ed0.0000 128.41&lt;br /&gt;FastEthernet1/1      128.42   128    19 FWD     8 32768 c20b.1ed0.0000 128.42&lt;br /&gt;&lt;span style="background-color: yellow;"&gt;Port-channel1        129.65   128     8 FWD     0 32768 c20a.1ed0.0000 129.65&lt;/span&gt;&lt;/span&gt;    &lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Done ;)&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6371103603725837825?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6371103603725837825/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-ether-channel.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6371103603725837825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6371103603725837825'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-ether-channel.html' title='EN – Ether Channel'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qoVkk4XAzPw/TSH2lccZOXI/AAAAAAAAAD8/iiURA0XTwAw/s72-c/EtherChannel.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8557862481783612738</id><published>2011-01-03T12:13:00.000+01:00</published><updated>2011-01-03T12:14:36.457+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>DE - Change Blog Roll</title><content type='html'>Zum neuen Jahr hab ich mal die Blogroll etwas ausgemistet und Blogs rausgeworfen die seit mehr als einem Jahr kein Update mehr gemacht haben – Asche auf mein Haupt. Ich habe dafür die Blogs von &lt;a href="http://gns3vault.com/The-Vault-Blog.html"&gt;GNSVaul&lt;/a&gt;t und &lt;a href="http://www.darbyslogs.blogspot.com/"&gt;Darby Weaver&lt;/a&gt; neu reingenommen, beide sind sehr lesenswert. Wer noch andere lesenswerte Blogs empfehlen kann nur her damit.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8557862481783612738?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8557862481783612738/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-change-blog-roll.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8557862481783612738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8557862481783612738'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-change-blog-roll.html' title='DE - Change Blog Roll'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1185813892535423593</id><published>2011-01-03T11:39:00.002+01:00</published><updated>2011-01-03T11:43:23.053+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>EN - Change Blog Roll</title><content type='html'>I just cleaned our blog roll since we had some blogs in it that were dead for more than one year  (BTW: does someone know what happened to Joe Harris 6200networks.com). I ´ve added the blogs of &lt;a href="http://gns3vault.com/The-Vault-Blog.html"&gt;GNSvault&lt;/a&gt; and &lt;a href="http://www.darbyslogs.blogspot.com/"&gt;Darby Weaver&lt;/a&gt; to the blog roll they are both worth reading a lot. Any other recommendations please post into the comments.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1185813892535423593?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1185813892535423593/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-change-blog-roll.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1185813892535423593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1185813892535423593'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-change-blog-roll.html' title='EN - Change Blog Roll'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-9075540740730032097</id><published>2011-01-03T11:28:00.001+01:00</published><updated>2011-01-03T11:28:54.045+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>DE - Frohes Neues ...</title><content type='html'>Ein frohes neues Jahr&lt;br /&gt;Ich hoffe ihr seid alle mindestens genauso gut in 2011 angekommen wie ich und habt ordentlich gefeiert. Wie der ein oder andere vielleicht via Twitter oder Facebook mitbekommen hat lerne ich z.Z. die Basics des CCNP Tracks um dort etwas sicherer zu werden. Also werde ich hier in der nächsten Zeit etwas mehr CCN Stuff posten.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-9075540740730032097?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/9075540740730032097/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-frohes-neues.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9075540740730032097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9075540740730032097'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/de-frohes-neues.html' title='DE - Frohes Neues ...'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1274784641266406585</id><published>2011-01-03T11:23:00.000+01:00</published><updated>2011-01-03T11:24:20.304+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>EN- Happy New Year</title><content type='html'>Happy New Year ;)&lt;br /&gt;Hey networking people – hope you got well into 2011. Speaking for myself I can acknowledge this. As some of you may have noticed I started learning some basic stuff for CCNP. I want to make sure to now the basic stuff before moving on. So expect some CCNP material here soon.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1274784641266406585?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1274784641266406585/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-happy-new-year.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1274784641266406585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1274784641266406585'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2011/01/en-happy-new-year.html' title='EN- Happy New Year'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2260802436660198686</id><published>2010-12-14T14:29:00.001+01:00</published><updated>2010-12-14T14:29:52.827+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><title type='text'>DE - GNS3Vault</title><content type='html'>Vor ein paar Tagen ist mir ein Tweet oder Retweet über gns3vault aufgefallen und da ich gerade etwas Zeit hatte, habe ich mir die Seite angesehen. Es sind eine Menge guter und vor allem interessanter Labs zu finden und die Seite ist auf jeden Fall einen Blick wert. Wer sich für den CCNA oder NP vorbereitet sollte dir vorbeischauen.&lt;br /&gt;&lt;br /&gt;http://gns3vault.com&lt;br /&gt;&lt;br /&gt;Viel Spaß beim Lab nachbauen&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2260802436660198686?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2260802436660198686/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/12/de-gns3vault.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2260802436660198686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2260802436660198686'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/12/de-gns3vault.html' title='DE - GNS3Vault'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3572675575572578228</id><published>2010-12-14T14:26:00.001+01:00</published><updated>2010-12-14T14:27:19.399+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><title type='text'>EN - GNS3Vault</title><content type='html'>So a few days ago I noticed a tweet or retweet about gns3vault and I decided to have a look at this page. I was really surprised about the amounts of labs they had already in place. If you are learning Cisco (CCNA / NP) it is definitely worth having a look. &lt;br /&gt;&lt;br /&gt;http://gns3vault.com&lt;br /&gt;&lt;br /&gt;have fun / good luck :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3572675575572578228?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3572675575572578228/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/12/en-gns3vault.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3572675575572578228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3572675575572578228'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/12/en-gns3vault.html' title='EN - GNS3Vault'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4168881292120739211</id><published>2010-11-08T10:47:00.000+01:00</published><updated>2010-11-08T10:48:00.219+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE - Neues aus der Gruft</title><content type='html'>OK wir waren im Großen und Ganzen ziemlich faul was unseren Blog angeht. Ich kann nur ´tschuldigung sagen und Besserung geloben. Aber wie schon erwähnt hab ich das Jahr über eine neue Firma mitaufgebaut und froh sagen zu können das diese nun ganz passabel läuft. Zif hingegen hatte genug mit dem Familienleben zu tun so, dass auch bei Ihm nicht wirklich viel Zeit zum bloggen übrig blieb.&lt;br /&gt;Wie auch immer, ich hatte das Glück in den letzten Wochen und Monaten ein paar interessante Projekte zu haben und vor allem extrem coole Netzwerke zu sehen von denen ich hin und wieder mal ein paar Informationen durchblicken lassen will.  &lt;br /&gt;Ich versuche auch immer noch meinen CCIE Sec zu schaffen, aber da hab ich leider auch etliches an Nachholbedarf, was das Training angeht.  Auf jeden Fall werde ich jetzt wieder mehr hier von meinem Weg zum CCIE usw. posten. Hoffe ich zumindest.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4168881292120739211?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4168881292120739211/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/11/de-neues-aus-der-gruft.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4168881292120739211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4168881292120739211'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/11/de-neues-aus-der-gruft.html' title='DE - Neues aus der Gruft'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2008493985566153662</id><published>2010-11-08T10:41:00.002+01:00</published><updated>2010-11-08T10:42:06.138+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>EN - Back from the grave ;)</title><content type='html'>So we´ve been more than lazy concerning this blog, hope we still have people coming here from time to time. Sorry for that but as I already mentioned I had to build up a new company, that actually is now quite good and Zif has been busy with family life etc. &lt;br /&gt;Anyway I had some nice projects going on the last months and have seen some impressive networks. Since I still try to get my CCIE I will reactivate this blog and drop some more post within the next months. I hope I can do it at least.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2008493985566153662?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2008493985566153662/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/11/back-from-grave.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2008493985566153662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2008493985566153662'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/11/back-from-grave.html' title='EN - Back from the grave ;)'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2575256368661104704</id><published>2010-01-03T00:10:00.000+01:00</published><updated>2010-01-03T00:16:23.845+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie'/><title type='text'>EN - Happy new year ...</title><content type='html'>Happy new year to all our readers.&lt;br /&gt;&lt;br /&gt;I hope that everyone had a good start into 2010 and that everyone had the chance to achieve the aims they set for 2009. I'm proud to say that I did :D, I managed short before X-mas to pass the last CCSP exams and I'm now officially a CCSP.  The exams where quite hard and I took a boot camp in India just for the CCSP preparation, that helped me a lot in the IPS topics.&lt;br /&gt;&lt;br /&gt;Now we have 2010 and the next big aim is CCIE Security by the end of the year. I'll keep you updated on my progress.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2575256368661104704?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2575256368661104704/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/01/en-happy-new-year.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2575256368661104704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2575256368661104704'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/01/en-happy-new-year.html' title='EN - Happy new year ...'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3124562393299975688</id><published>2010-01-03T00:09:00.002+01:00</published><updated>2010-01-03T00:17:36.181+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='ccie'/><title type='text'>DE - Frohes neues ...</title><content type='html'>Frohes neues Jahr und so, sei allen Lesern hier vorab gewünscht. &lt;br /&gt;Ich hoffe ein jeder ist gut in das neue Jahr rein gekommen und konnte am Ende von 2009 sagen er hat alle selbst gesteckten Ziele für sich erfüllt. Ich zumindest konnte das behaupten. Kurz vor Weihnachten hab ich die letzten Tests abgelegt und darf mich nun ganz offiziell CCSP nennen. Ich hab dafür extra noch ein Bootcamp in Indien mitgemacht, was mir gerade im Bereich IPS sehr geholfen hat.&lt;br /&gt;&lt;br /&gt;Jetzt kommt das nächste große Ziel bis zum Ende 2010 CCIE Security. Ich werde euch auf dem laufenden halten. &lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3124562393299975688?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3124562393299975688/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/01/de-frohes-neues.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3124562393299975688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3124562393299975688'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2010/01/de-frohes-neues.html' title='DE - Frohes neues ...'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3030454613069045388</id><published>2009-12-14T11:47:00.003+01:00</published><updated>2010-01-03T00:18:21.100+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='vrf'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>DE - dynamisches Routeleanking oder "Inter VRF routing"</title><content type='html'>Dynamisches Route Leaking oder Routing Protokolle fürs Routing zwischen der globales Routingtabelle (GRT) und VRFs&lt;br /&gt;&lt;br /&gt;Hallo zusammen,&lt;br /&gt;&lt;br /&gt;das letzte mal gab es ein Beispiel, wie man statisch das Routing zwischen 2 VRFs einrichtet und dachte, daß es doch garnicht so schwer sein kann, dies auch dynamisch zu realisieren ... das war reichlich naiv ;)&lt;br /&gt;Nach massig herumprobieren und mit dem Rat von ein paar anderen habe ich ein kleines Lab zusammengebaut, wo Routen zwischen der GRT und einem VRF dynamisch ausgetauscht werden.&lt;br /&gt;Soweit ich es sagen kann, gibt es keine Möglichkeit Routen auf normalem Wege zu redistributen, wenn ein Routingprozess der globale ist. Wenn man es dennoch versucht, bekommt man eine kryptische Fehlermeldung wie diese:&lt;br /&gt;VRF -&gt; GRT [code]%OSPF process 1 is attached to Default-IP-Routing-Table[/code]&lt;br /&gt;GRT -&gt; VRF [code]OSPF process 22 already exists and is attached to Default-IP-Routing-Table[/code]&lt;br /&gt;&lt;br /&gt;Dies müssen wir einfach "austricksen" und dafür brauchen wir einige Tunnelinterfaces und ein paar Loopbacks&lt;br /&gt;&lt;br /&gt;So sieht mein Netzplan aus:&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 280px; height: 236px;" src="http://2.bp.blogspot.com/_Xv6C9sn9zDM/SrD2lsnh2jI/AAAAAAAAABE/GI9XdY-b8lU/s320/Clipboard01.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5382072682200291890" /&gt;&lt;br /&gt;&lt;br /&gt;Der globale Client und der VRF_Client werden wieder durch missbrauchte Router dargestellt, die lediglich eine IP haben und eine Default Router auf das ausgehende Interface+Next Hop IP.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;grt_host&lt;/b&gt;&lt;br /&gt;[code]interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.10 255.255.255.0&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 10.10.10.1 FastEthernet0/0[/code]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;vrf_host&lt;/b&gt;&lt;br /&gt;[code]interface FastEthernet0/1&lt;br /&gt; ip address 20.20.20.20 255.255.255.0&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 20.20.20.1 FastEthernet0/1[/code]&lt;br /&gt;&lt;br /&gt;Nun brauchen wir ein paar Grundkonfigurationen für den VRF Router:&lt;br /&gt;&lt;br /&gt;ein vrf erstellen:&lt;br /&gt;&lt;code&gt;ip vrf zif&lt;br /&gt; rd 1:1&lt;br /&gt; route-target both 1:1&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Interface config zum grt_host:&lt;br /&gt;&lt;code&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;/code&gt;&lt;br /&gt; &lt;br /&gt;Interface config zum vrf_host:&lt;br /&gt;&lt;code&gt;interface FastEthernet0/1&lt;br /&gt; ip vrf forwarding zif&lt;br /&gt; ip address 20.20.20.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Das alles ist kein Hexenwerk ... bis jetzt ;)&lt;br /&gt;&lt;br /&gt;Das erste was wir uns überlegen müssen: wie tricksen wir die Grenzen des Designs aus?&lt;br /&gt;&lt;br /&gt;Die erste Zutat sind &lt;b&gt;"Tunnel-Interfaces"&lt;/b&gt;, die andere sind &lt;span style="font-weight:bold;"&gt;"Loopbacks"&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Unterm Strich brauchen wir:&lt;br /&gt;ein Tunnel-Interface pro VRF, &lt;br /&gt;ein Tunnel-Interface für die GRT&lt;br /&gt;ein Loopback pro VRF und&lt;br /&gt;ein Loopback für die GRT.&lt;br /&gt;&lt;br /&gt;Wenn wir mehrere VRFs mit der GRT verknüpfen wollen, brauchen wir entsprechend der obigen Liste das gleiche nochmal pro zusätlichem VRF.&lt;br /&gt;&lt;br /&gt;Beide Loopbacks werden in der GRT gelassen:&lt;br /&gt;&lt;b&gt;VRF Router&lt;/b&gt;&lt;br /&gt;&lt;code&gt;interface Loopback111&lt;br /&gt; ip address 111.111.111.111 255.255.255.255&lt;br /&gt;&lt;br /&gt;interface Loopback222&lt;br /&gt; ip address 222.222.222.222 255.255.255.255&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Jetzt brauchen wir die dazugehörigen Tunnel-Interfaces.&lt;br /&gt;Das für die GRT:&lt;br /&gt;&lt;code&gt;interface Tunnel102&lt;br /&gt; ip address 100.100.100.1 255.255.255.0&lt;br /&gt; tunnel source 111.111.111.111&lt;br /&gt; tunnel destination 222.222.222.222&lt;/code&gt;&lt;br /&gt;Und das für das VRF:&lt;br /&gt;&lt;code&gt;interface Tunnel201&lt;br /&gt; ip vrf forwarding RED&lt;br /&gt; ip address 100.100.100.2 255.255.255.0&lt;br /&gt; tunnel source 222.222.222.222&lt;br /&gt; tunnel destination 111.111.111.111&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Was macht dieses Konstrukt? Wir zeigen mit dem dem Tunnel 201 auf die Loopback in der GRT, mit der Quelle in der GRT und packen das ganze dann ins VRF. Hört sich nicht nur komisch an, es ist komisch (und &lt;span style="font-style:italic;"&gt;"fühlt&lt;/span&gt; sich komisch an), ABER es funktioniert ;)&lt;br /&gt;&lt;br /&gt;Jetzt haben wir schicke Netzwerke, zwischen denen wir ein Routingprozess wie zB OSPF laufen lassen können.&lt;br /&gt;&lt;br /&gt;Der globale Routingprozess:&lt;br /&gt;&lt;code&gt;router ospf 1&lt;br /&gt; router-id 10.10.10.10&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 100.100.100.1 0.0.0.0 area 0&lt;br /&gt; network 10.10.10.0 0.0.0.255 area 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Der VRF Routingprozess:&lt;br /&gt;&lt;code&gt;router ospf 2 vrf zif&lt;br /&gt; router-id 20.20.20.20&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 20.20.20.0 0.0.0.255 area 0&lt;br /&gt; network 102.102.102.2 0.0.0.0 area 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Die Routing Tabelle schaut danach wiefolgt aus::&lt;br /&gt;global&lt;br /&gt;&lt;code&gt;&lt;br /&gt;VRF_Router#sh ip route&lt;br /&gt;[...snip...]&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;     102.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       102.102.102.0 is directly connected, Tunnel102&lt;br /&gt;     200.200.200.0/32 is subnetted, 1 subnets&lt;br /&gt;C       200.200.200.200 is directly connected, Loopback200&lt;br /&gt;     100.0.0.0/32 is subnetted, 1 subnets&lt;br /&gt;C       100.100.100.100 is directly connected, Loopback100&lt;br /&gt;     20.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;O       20.20.20.0 [110/11112] via 102.102.102.2, 00:24:29, Tunnel102&lt;br /&gt;     10.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       10.10.10.0 is directly connected, FastEthernet0/0&lt;/code&gt;&lt;br /&gt;vrf&lt;br /&gt;&lt;code&gt;&lt;br /&gt;Router#sh ip route vrf zif&lt;br /&gt;&lt;br /&gt;Routing Table: zif&lt;br /&gt;[...snip...]&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;     102.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       102.102.102.0 is directly connected, Tunnel201&lt;br /&gt;     20.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       20.20.20.0 is directly connected, FastEthernet0/1&lt;br /&gt;     10.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;O       10.10.10.0 [110/11112] via 102.102.102.1, 00:26:19, Tunnel201&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Und das wars auch schon!&lt;br /&gt;Nun ist es möglich vom grt_host direkt den vrf_host zu pingen und umgekehrt.&lt;br /&gt;&lt;br /&gt;Bei Fragen nutzt einfach die Kommentarfunktion&lt;br /&gt;&lt;br /&gt;Bis dann,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3030454613069045388?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3030454613069045388/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/12/de-dynamisches-routeleanking-oder-inter.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3030454613069045388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3030454613069045388'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/12/de-dynamisches-routeleanking-oder-inter.html' title='DE - dynamisches Routeleanking oder &quot;Inter VRF routing&quot;'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Xv6C9sn9zDM/SrD2lsnh2jI/AAAAAAAAABE/GI9XdY-b8lU/s72-c/Clipboard01.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6724117059041969585</id><published>2009-11-26T15:16:00.004+01:00</published><updated>2009-11-26T15:21:52.110+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='sdm'/><title type='text'>DE - IOS HTTP Server "hacking" Vorsorge</title><content type='html'>So nachdem ich heute 4 Firmen angerufen hab und denen mitgeteilt hab das die Konfiguration Murks ist, poste ich die ganze Geschichte auch noch in deutsch.&lt;br /&gt;&lt;br /&gt;Vor kurzem bin ich über eine Suchmaschine gestolpert mit der man auch was finden kann. Dabei ging es aber nicht um den Inhalt der Webseite sondern mehr das drum herum. So war es möglich nach dem Webserver  und deren Version zu suchen. &lt;br /&gt;&lt;br /&gt;Gesagt getan auf meine suche nach Cisco IOS Webservern erhielt ich über 67.000 Treffer. Ouch,. mal ehrlich 67k wieso müssen die Webinterfaces haben und vor allem warum müssen die via Publik IP Verfügbar sein. &lt;br /&gt;&lt;br /&gt;Als ich so durch die liste surfte stellt ich fest das einige nicht mit der 401 sondern mit einer 200 als HTTP Statuscode antworteten. Einen von den Routern angeklickt und schon hat sich gezeigt. Prima die Systeme arbeiten ganz ohne Authentifizierung.&lt;br /&gt;&lt;br /&gt;Ich hab die Suchkriterien angepasst und von 67.000 Routern brauchen mehr als 1200 Kein Passwort sind also ungeschützt. &lt;br /&gt;&lt;br /&gt;Da es über die Weboberfläche möglich ist ein show cdp neigbor abzusetzen zeigte sich das hinter den Routern noch andere Cisco Komponenten hängen. Ich hoffe das die nicht so lausig konfiguriert sind wie der Router.&lt;br /&gt;&lt;br /&gt;Um sicher zu sein, gilt daher entweder eine Access Liste auf den Webserver binden:&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;access-list 1 permit X.X.X.X ! x.x.x.x= your management network&lt;br /&gt;ip http access-class 1&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;oder noch besser:&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;no ip http server &lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6724117059041969585?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6724117059041969585/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-ios-http-server-via-suchmaschine.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6724117059041969585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6724117059041969585'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-ios-http-server-via-suchmaschine.html' title='DE - IOS HTTP Server &quot;hacking&quot; Vorsorge'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7151886677736447190</id><published>2009-11-26T14:03:00.004+01:00</published><updated>2009-11-26T15:20:32.757+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='sdm'/><title type='text'>EN - IOS HTTP Server hacking prevention</title><content type='html'>OK I need to post this since this is really scary to me.&lt;br /&gt;&lt;br /&gt;A few days ago I stumbled upon a quite cool search engine (no I will not post the URL) what was really interesting is that it did not search for the content of the website it was more interested in the server replies like Server Version HTTP status code.&lt;br /&gt;&lt;br /&gt;Since Cisco routers and switches offer a web server for configuration I searched for Cisco IOS servers. The result was scary (it gets worse a bit later) more than 67.000 routers and switches operating the HTTP server are public available. Their may be reasons why routers should be available via HTTP from the Internet but 67000 router people you are kidding me.&lt;br /&gt;I checked some of them and most look like real routers/ switches.&lt;br /&gt;&lt;br /&gt;But while browsing the list I found a few routers responding with Cisco IOS Server AND HTTP 200 code. (most of the routers respond with 401 authorization required). I tried one of these and great  I could log in and have a look at the configuration passwords etc. &lt;br /&gt;&lt;br /&gt;I decided to redefine my search and the result was: from those 67.000 routers 1200 are not requiring authorization of any kind, great.&lt;br /&gt;&lt;br /&gt;A quick show cdp neigh showed that most of them I've checked are connected to other Cisco devices. I hope that these devices aren't configured that poorly.&lt;br /&gt;&lt;br /&gt;To get out of this list just bind an access list to you HTTP Server, &lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;access-list 1 permit X.X.X.X ! x.x.x.x= your management network&lt;br /&gt;ip http access-class 1&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;or even better do a&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;no ip http server &lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;hope some of those guys owning these routers fix them (fast)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7151886677736447190?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7151886677736447190/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-publick-ios-http-server-search.html#comment-form' title='2 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7151886677736447190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7151886677736447190'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-publick-ios-http-server-search.html' title='EN - IOS HTTP Server hacking prevention'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8473922357629733744</id><published>2009-11-21T02:01:00.006+01:00</published><updated>2009-11-21T02:08:50.298+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='on-a-stick'/><title type='text'>DE - "Router on a Stick" oder "Inter VLAN routing" mit ASA 5505</title><content type='html'>Da ich eben beim durchschauen der Google Auswertung unserer Seite festgestellt hab das mehrere Abfragen bzgl. ASA 5505 und Router on-a-stick kamen will ich hier ein kurze Antwort posten.&lt;br /&gt;&lt;br /&gt;Die Frage ob es überhaupt geht, ist mit einem klaren &lt;span style="font-weight:bold;"&gt;Ja&lt;/span&gt; und &lt;span style="font-weight:bold;"&gt;Nein&lt;/span&gt; zu beantworten. Die ASA 5505 bietet in der Basis Lizenz 3 Vlans an und enthält keine Trunk Option. Das bedeutet in der Basis Lizenz geht ein Router on-a-stick nicht, da ja on-a-stick bedeutet, rein und raus am selben physikalischen Interface. &lt;br /&gt;Hat man die erweiterte (Plus) Lizenz gekauft, hat man mehr Vlans und kann auch Trunks bauen. Dies erfolgt dann ähnlich der Konfiguration von Trunk Ports auf einem Switch:&lt;br /&gt;&lt;br /&gt;Anlegen der entsprechenden Vlan Interfaces &lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;interface vlan 10&lt;br /&gt;nameif IF_outside&lt;br /&gt;security-level 0&lt;br /&gt;ip address 172.20.2.1 255.255.255.0&lt;br /&gt;no shutdown&lt;br /&gt;&lt;br /&gt;interface vlan 20&lt;br /&gt;nameif IF_Core&lt;br /&gt;security-level 100&lt;br /&gt;ip address 172.20.3.1 255.255.255.0&lt;br /&gt;no shutdown&lt;br /&gt;&lt;br /&gt;interface vlan 30&lt;br /&gt;nameif IF_MGMT&lt;br /&gt;security-level 99&lt;br /&gt;ip address 172.20.4.1 255.255.255.0&lt;br /&gt;no shutdown&lt;br /&gt;&lt;br /&gt;interface vlan 30&lt;br /&gt;nameif IF_Marketing&lt;br /&gt;security-level 20&lt;br /&gt;ip address 172.20.5.1 255.255.255.0&lt;br /&gt;no shutdown&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Aufbauen des „Sticks" Interfaces&lt;br /&gt;&lt;code&gt;&lt;br /&gt;interface ethernet 0/0&lt;br /&gt;description ### Stick Interfaces ###&lt;br /&gt;switchport mode trunk&lt;br /&gt;switchport trunk allowed vlan 10,20,30&lt;br /&gt;no shutdown&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Access-listen können wie gewohnt eingebunden werden und auch der Rest arbeitet genau wie erwartet. Am anderen Ende der Verbindung von Ethernet 0/0 sollte ein Switch dann den Trunk wieder aufteilen. Routing erfolg gemaess den richtlinien der ASA bzgl der Security-Level der einzelnen Vlans (vom hohen Level zum niedrigen ist default erlaubt, andersherum muss freigeschalten werden)&lt;br /&gt;&lt;br /&gt;Vielleicht eine Anmerkung, die 5505 hat 8 Ports, daher ist eigentlich eine on-a-stick Konfiguration nur bedingt sinnvoll. Ich persönlich würde zumindest die WAN Seite von den Internen Ports trennen. Aber das ist nur meine Meinung. &lt;br /&gt;Anmerkung 2, auf den anderen ASA 55x0 funktioniert das bauen von Router on-a-stick Konfigurationen fast genau wie bei einem Cisco Router.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8473922357629733744?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8473922357629733744/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-router-on-stick-oder-inter-vlan.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8473922357629733744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8473922357629733744'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-router-on-stick-oder-inter-vlan.html' title='DE - &quot;Router on a Stick&quot; oder &quot;Inter VLAN routing&quot; mit ASA 5505'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-123052382778942743</id><published>2009-11-21T00:47:00.008+01:00</published><updated>2009-11-21T02:07:48.003+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='stp'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><title type='text'>EN - Layer 2 redundancy with routers</title><content type='html'>Yesterday I was playing around with dynamips and found a really cool solution to a problem that well not exists.  But after thinking a while I found a situation at a customer location that could make use of my idea.&lt;br /&gt;&lt;br /&gt;I'll describe the situation.&lt;br /&gt;The customer has one core switch located in his main building and across his (large) campus a few distribution switches. All switches are layer 2 only so no routing stuff.  Since the network small (a view servers and some hand full of workstations) the customer uses one class C subnet (eg 172.20.3.0 /24) &lt;br /&gt;The problem is, the internet access is located near 2 edge switches but far from the main building. So the Edge Router is placed with one WAN interfaces and 2 LAN interfaces one connecting to each edge switch&lt;br /&gt;This looks like this diagram:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_qoVkk4XAzPw/SwcqyRrfeVI/AAAAAAAAADI/veYWCj8yczk/s1600/Layer2.png"&gt;&lt;img style="display:block; margin:0 10px 10px 0;text-align:center;cursor:pointerr; cursor:hand;width: 200px; height: 122px;" src="http://2.bp.blogspot.com/_qoVkk4XAzPw/SwcqyRrfeVI/AAAAAAAAADI/veYWCj8yczk/s200/Layer2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406336920909216082" /&gt;&lt;/a&gt;&lt;br /&gt;So this leads to one obvious question, how do you provide on those LAN interfaces ONE gateway IP (remember no dynamic routing plain default gateway)&lt;br /&gt;The solution is easy: build a bridge group and add a Bridged Virtual Interface (BVI) &lt;br /&gt;&lt;br /&gt;How this is done? Just a second I'll show you.&lt;br /&gt;Start with the usual fluff: name, domain, ntp whatever you need and want.&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;enable&lt;br /&gt;configure terminal&lt;br /&gt;&lt;br /&gt;hostname EdgeRouter&lt;br /&gt;ip domain-name playingwithnetworks.com&lt;br /&gt;no ip domain-lookup&lt;br /&gt;&lt;br /&gt;line console 0&lt;br /&gt; logging synchronous&lt;br /&gt; password #sicher01&lt;br /&gt; login&lt;br /&gt;&lt;br /&gt;line vty 0 4&lt;br /&gt; logging synchronous&lt;br /&gt; password #sicher01&lt;br /&gt; login&lt;br /&gt; transport input telnet&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;OK you should add of course logging, ntp, ssh security and so on but this would be to much.&lt;br /&gt;&lt;br /&gt;Now the next step becomes interesting.&lt;br /&gt;Apply the bridging settings&lt;br /&gt;&lt;br /&gt;&lt;quote&gt;&lt;code&gt;&lt;br /&gt;bridge irb&lt;br /&gt;! enables bridging with routing&lt;br /&gt;&lt;br /&gt;bridge 1 protocol ieee&lt;br /&gt;! tells the router what protocol to bridge on bridge group 1&lt;br /&gt;&lt;br /&gt;bridge 1 route ip&lt;br /&gt;! tells the router what protocol to route (not what routing protocol )&lt;br /&gt;&lt;br /&gt;! configure your LAN interfaces&lt;br /&gt;interface fastEthernet 0/0&lt;br /&gt;description ### LAN Link to EdgeSwitch01 ###&lt;br /&gt;bridge-group 1&lt;br /&gt;! add interface to bridging group 1&lt;br /&gt;&lt;br /&gt;! configure your LAN interfaces&lt;br /&gt;interface fastEthernet 0/1&lt;br /&gt;description ### LAN Link to EdgeSwitch02 ###&lt;br /&gt;bridge-group 1&lt;br /&gt;! add interface to bridging group 1&lt;br /&gt;&lt;br /&gt;interface BVI 1&lt;br /&gt;description ### routing interface of bridge group 1 ###&lt;br /&gt;ip address 172.20.3.1 255.255.255.0&lt;br /&gt;no shutdown&lt;br /&gt;&lt;/code&gt;&lt;/quote&gt;&lt;br /&gt;&lt;br /&gt;Next thing you need is to configure the interface to the ISP, this is usual stuff done about a hundred of times and set your default route.&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface Serial0/0&lt;br /&gt; description ### ISP Uplink ###&lt;br /&gt; ip address 172.20.4.2 255.255.255.252&lt;br /&gt; no shutdown&lt;br /&gt;&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 Serial0/0 172.20.4.1&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;Well that's it !!&lt;br /&gt;&lt;br /&gt;To verify that all is working, issue a show spanning-tree on your EdgeRouter&lt;br /&gt;&lt;br /&gt; &lt;span style="font-weight:bold;"&gt;Bridge group 1 is executing the ieee compatible Spanning Tree protoco&lt;/span&gt;l&lt;br /&gt; (…)&lt;br /&gt; &lt;span style="font-weight:bold;"&gt;Port 3 (FastEthernet0/0) of Bridge group 1 is forwarding&lt;/span&gt;&lt;br /&gt;(...)&lt;br /&gt;&lt;span style="font-weight:bold;"&gt; Port 4 (FastEthernet0/1) of Bridge group 1 is blocking&lt;/span&gt;&lt;br /&gt;(…)&lt;br /&gt;&lt;br /&gt;By now you know that what we've done is, we've turned the LAN side of our Router into a switch and let spanning tree do the path selection. We could have bought a switching module for our router or created a third single point of failure (1st is only one CoreSwitch, 2nd is only one Edge Router) and set up a physical switch between the edge switches and our router.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-123052382778942743?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/123052382778942743/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/layer-2-redundancy-with-routers.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/123052382778942743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/123052382778942743'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/layer-2-redundancy-with-routers.html' title='EN - Layer 2 redundancy with routers'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qoVkk4XAzPw/SwcqyRrfeVI/AAAAAAAAADI/veYWCj8yczk/s72-c/Layer2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6933249682453004741</id><published>2009-11-16T12:39:00.005+01:00</published><updated>2009-11-16T12:44:17.848+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='IINS'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='sdm'/><title type='text'>DE – SDM mit Dynamips Routern (IINS Vorbereitung)</title><content type='html'>Das wird ein kurzes Zwischenpost da das Thema an sich recht einfach ist. &lt;br /&gt;Jeder der sich auf den IINS Test von Cisco vorbereitet weiß das der SDM zu den Dingen gehört die zwingend notwendig sind, um bei dem Test was zu erreichen. Wer aber (wie ich) nicht unbedingt so viel Geld in die Hand nehmen will für echte Routerhardware, der nutzt vermutlich Dyanmips, Dynagen bzw GNS3. Doch dann stellt sich die Frage, wie bekommt man den SDM auf einem virtuellen Router zu laufen , dem gehen wir hier nach.&lt;br /&gt;&lt;br /&gt;Vorbereitung: In meinem Aufbau, musste ich eine VM meines dynaBuntu anlegen und diese mit dem Router LAB_R001 verbinden (das werden die meisten von euch nicht machen)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Schritt 1:&lt;/span&gt; Vorbereitung des Virtuellen Routers mit den üblichen Einstellungen wie Hostnamen Interface IPs etc.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Schritt 2:&lt;/span&gt; Einschalten des HTTP Servers des Routers mittels des Befehls&lt;br /&gt;&lt;code&gt;&lt;qoute&gt;&lt;br /&gt;ip http server &lt;br /&gt;&lt;/qoute&gt;&lt;/code&gt;&lt;br /&gt;Jetzt sollte die Konfiguration des Routers in etwa so aussehen (defaults und unwichtige Informationen wurden raus gelassen)&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;qoute&gt;&lt;br /&gt;service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_LAB_SDM_01&lt;br /&gt;!&lt;br /&gt;enable secret 5 $1$51xU$t3K/gEBYlwwTYeTEdCqTy/&lt;br /&gt;!&lt;br /&gt;ip domain name playingwithnetworks.com&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt;description ### Link to LAB_R001 and HyperV ###&lt;br /&gt;ip address 172.20.1.3 255.255.255.0&lt;br /&gt;speed 100&lt;br /&gt;full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt;no ip address&lt;br /&gt;shutdown&lt;br /&gt;duplex auto&lt;br /&gt;speed auto&lt;br /&gt;!&lt;br /&gt;ip http server&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;password 7 XYZXYZ&lt;br /&gt;logging synchronous&lt;br /&gt;login&lt;br /&gt;line vty 0 4&lt;br /&gt;password 7 YZXZY&lt;br /&gt;logging synchronous&lt;br /&gt;login&lt;br /&gt;transport input telnet &lt;br /&gt;&lt;/code&gt;&lt;/qoute&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Schritt 3:&lt;/span&gt; Eine Kopie des SDM besorgen – das macht sich am besten von der Cisco Seite, wofür aber ein CCO Account gebraucht wird&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Zwischenschritt 4:&lt;/span&gt; Es ist sicherzustellen das der Router die VM oder den PC erreichen kann und umgekehrt, das funktioniert am besten mit einem Ping zwischen den Geräten..&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Schritt 4:&lt;/span&gt; Installation des SDM&lt;br /&gt; &lt;br /&gt;Welcome Window – klick next &lt;br /&gt;License Agreement – anklicken “I accept the terms of agreement” &amp; klick next &lt;br /&gt;Install Options: - auswählen der Option : “This Computer” &amp; klick next &lt;br /&gt;Choose Destination Location – klick next (oder einen anderen Pfad wählen) &lt;br /&gt;Ready to Install the Program – klick install&lt;br /&gt;&lt;br /&gt;Sobald die Installation beendet ist findet sich auf dem Desktop der Workstation ein Icon mit dem Namen: “Cisco SDM” das bitte durch doppelklick starten. Nach Eingabe der guiltigen IP (bei mir 172.20.1.3) sollte folgendes Bild erscheinen (oder so ähnlich)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s1600-h/IINS-SDM.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 144px;" src="http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s200/IINS-SDM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5404502407366072402" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Das war es erst mal, danke für die Aufmerksamkeit :D&lt;br /&gt;&lt;br /&gt;cheers NWG&lt;br /&gt;&lt;a href="http://www.blindhog.net/how-to-integrate-a-microsoft-loopback-interface-with-gns3/"&gt;PS Ein etwas ausführlichers Video zum Thema SDM auf GNS3 von Blindhog.net&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6933249682453004741?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6933249682453004741/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-sdm-mit-dynamips-routern-iins.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6933249682453004741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6933249682453004741'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-sdm-mit-dynamips-routern-iins.html' title='DE – SDM mit Dynamips Routern (IINS Vorbereitung)'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s72-c/IINS-SDM.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8187835414664979963</id><published>2009-11-16T01:56:00.013+01:00</published><updated>2009-11-16T12:19:56.505+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='IINS'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='sdm'/><title type='text'>EN - SDM on Dynamips Routers (IINS preparation)</title><content type='html'>This post will be quite short because the topic is pretty easy.&lt;br /&gt;To prepare for the IINS exam you need to have a router with SDM support. If you (like me) don't want to spend the money on real hardware you'll use dynamips/dynagen/gns3.&lt;br /&gt;&lt;br /&gt;So how can you run a dynamips router with SDM support. Well this is pretty straight forward&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;pre-step 1&lt;/span&gt;:&lt;br /&gt; In my setup I've had to set up a new dynaBuntu VM and connect this VM to LAB_R001 (you'll probably not have to do this)&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 1:&lt;/span&gt; prepare your router with the usually fluff: set up interfaces, users hostname etc ..&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 2:&lt;/span&gt; add http and if desired https server capability to the router setup&lt;br /&gt;&lt;code&gt;&lt;qoute&gt;&lt;br /&gt;       ip http server&lt;br /&gt;&lt;/qoute&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The configuration of your dynamips router could look like this (defaults have been skipped) one by now:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_LAB_SDM_01&lt;br /&gt;!&lt;br /&gt;enable secret 5 $1$51xU$t3K/gEBYlwwTYeTEdCqTy/&lt;br /&gt;!&lt;br /&gt;ip domain name playingwithnetworks.com&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt;description ### Link to LAB_R001 and HyperV ###&lt;br /&gt;ip address 172.20.1.3 255.255.255.0&lt;br /&gt;speed 100&lt;br /&gt;full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt;no ip address&lt;br /&gt;shutdown&lt;br /&gt;duplex auto&lt;br /&gt;speed auto&lt;br /&gt;!&lt;br /&gt;ip http server&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;password 7 XYZXYZ&lt;br /&gt;logging synchronous&lt;br /&gt;login&lt;br /&gt;line vty 0 4&lt;br /&gt;password 7 YZXZY&lt;br /&gt;logging synchronous&lt;br /&gt;login&lt;br /&gt;transport input telnet&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 3:&lt;/span&gt; get you copy of the SDM from Cisco (CCO required)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;pre-step 4:&lt;/span&gt; make sure your dynamips Router can ping your SDM host and vice versa&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Step 4:&lt;/span&gt;: install the SDM on a PC (or VM)&lt;br /&gt;&lt;br /&gt;Welcome Window – click next&lt;br /&gt;License Agreement – select “I accept the terms of agreement” &amp;amp; click next&lt;br /&gt;Install Options: - choose the option: “This Computer” &amp;amp; click next&lt;br /&gt;Choose Destination Location – click next (or select an other location)&lt;br /&gt;Ready to Install the Program – click Install&lt;br /&gt;&lt;br /&gt;After the installation has finished you've got a new icon on your desktop called: “Cisco SDM”, double click the icon and enter the IP of your dynamips router. If you've followed this guide you should be able to login to your router via SDM and get something like this screenshot.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s1600-h/IINS-SDM.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 144px;" src="http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s200/IINS-SDM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5404502407366072402" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers and Thanks for your attention.&lt;br /&gt;NWG&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blindhog.net/how-to-integrate-a-microsoft-loopback-interface-with-gns3/"&gt;PS a little more detailed movie about the SDM on GNS3 topic, just click to get to the blindhog Video&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8187835414664979963?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8187835414664979963/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-sdm-on-dynamips-routers-iins.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8187835414664979963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8187835414664979963'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-sdm-on-dynamips-routers-iins.html' title='EN - SDM on Dynamips Routers (IINS preparation)'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_qoVkk4XAzPw/SwCmTiLMWFI/AAAAAAAAADA/X9srf4FSTTM/s72-c/IINS-SDM.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4375604212158959273</id><published>2009-11-16T00:07:00.002+01:00</published><updated>2009-11-16T00:11:30.484+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HyperV'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>DE - HyperV  dynamips Problem</title><content type='html'>So jetzt auch in Deutsch, hat etwas gedauert aber das Wochenende war anstrengend.&lt;br /&gt;&lt;br /&gt;Was ist also passiert? Ich hab ein wenig an meinem LAB Setup herum gebastelt und DynaSlax gegen ein selbst gebautes Ubuntu Relase getauscht. Ich hab das Image auf dynaBuntu getauft, das Image ist ausschließlich ein Text &lt;a href="http://www.ubuntu.com/"&gt;Ubuntu&lt;/a&gt; mit Dynamips/ Dynagen sowie tcpdump und ssh ausgestattet, der Rest wurde raus geschmissen.&lt;br /&gt;&lt;br /&gt;Das ganze läuft, wie in meinem letzten &lt;a href="http://playingwithnetworks.blogspot.com/2009/11/de-lab-update.html"&gt;Blog&lt;/a&gt; Eintrag beschrieben, auf HyperV unter Windows Server 2k8. Vorgestern habe ich dann ein Szenario erstellt, bei dem die Router in dynaBuntu mit der echten Hardware meines Netzes kommunizieren können müsse. &lt;br /&gt;Schon während des installieren des BGP Router Setups zeigte sich, dass ich von meiner ASA zwar alle Systeme entlang des Netzwerkpfades, inklusive der dynaBuntu Maschine erreichen kann (Home-SW002, Core01, LAB-R001), nur die BGP-Router nicht. Interessanterweise zeigte ein &lt;span style="font-weight:bold;"&gt;show cdp neighbors&lt;/span&gt; das der BGP Router LAB-R001 sah, aber umgekehrt nicht. &lt;br /&gt;TCPdump auf der dynaBuntu Maschine zeigte das ARP Requests an den BGP-Router per Broadcast angenommen und beantwortet wurden, aber auf der LAB-R001 Seite des HyperV vSwitches  nichts mehr ankam. Es sah so aus, als wäre eine Art Port-Security auf dem HyperV vSwitch aktiv.&lt;br /&gt;&lt;br /&gt;Es dauerte noch eine Weile bis ich in den Einstellungen der VM die Option “ Enable spoofing of MAC addresses” fand. &lt;br /&gt;&lt;br /&gt;Nachdem die VM ausgeschalteten war und die Einstellungen angepasst waren, sahen sich meine Systeme wie gewollt und die Routen verteilten sich wie erwartet im Netz.&lt;br /&gt;&lt;br /&gt;Beste Grüße&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4375604212158959273?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4375604212158959273/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-hyperv-dynamips-problem.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4375604212158959273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4375604212158959273'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-hyperv-dynamips-problem.html' title='DE - HyperV  dynamips Problem'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8834512402261398505</id><published>2009-11-14T01:11:00.003+01:00</published><updated>2009-11-14T01:16:28.357+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='HyperV'/><category scheme='http://www.blogger.com/atom/ns#' term='switch'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>EN - HyperV  dynamips problem</title><content type='html'>Well well well, I've posted some days ago my new lab setup. Today I ran into a strange problem. I replaced today dynaslax with my dynaBuntu a self build Ubuntu release. DynaBuntu focuses on dynamips / dynagen and only ssh is running else, no fluff stuff :D&lt;br /&gt;&lt;br /&gt;Anyway I deployed a BGP router scenario that should interact with my real hardware firewall. &lt;br /&gt;Strangely I could ping from my ASA all important Ips: Core01, LAB-R001 and the dynaBuntu instance but I could not ping the router in dynaBuntu (BGPRouter). I was even more surprised when my BGPRouter showed that he could build a CDP connection with LAB-R001.&lt;br /&gt;&lt;br /&gt;Some times later I noticed that LAB-R001 could not resolve the IP of my BGPRouter. ARP requests were send and tcpdump showed that BGPRouter responded as expected. The next step showed the ARP response disappeared somewhere in the HyperV vSwitch.  So I needed to find a way to allow this setup.&lt;br /&gt;&lt;br /&gt;After a while I found the check box in the VM network settings that specified &lt;br /&gt;“Enable spoofing of MAC addresses”, it looks like the HyperV vSwitch is running some kind of port-security settings.&lt;br /&gt;&lt;br /&gt;Shutting down the VM, changing this setting and hurray I could ping my router and my routes where redistributed as desired.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8834512402261398505?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8834512402261398505/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-hyperv-dynamips-problem.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8834512402261398505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8834512402261398505'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-hyperv-dynamips-problem.html' title='EN - HyperV  dynamips problem'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-939092349826476040</id><published>2009-11-09T12:06:00.004+01:00</published><updated>2009-11-09T12:39:18.804+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>DE - LAB Update</title><content type='html'>Ok es ist wieder eine Weile her, dass ich gepostet habe (passiert mir anscheinend öfter). Es gibt mehrere Grunde warum ich nicht gepostet hab. Zum einen habe ich mich seit August mit mehreren Trainings zum Thema CCNA und CCNA Security befasst. Mittlerweile habe ich den CCNA Test bestanden und bald kommt der CCNA Security dran. Danach geht es zum CCSP Training das ich hoffentlich auch irgendwann im Januar 2010 hinter mich gebracht hab. &lt;br /&gt;&lt;br /&gt;Der zweite Grund ist, das ich mein Lab überarbeiten musste und zwar von Grund auf. Grund dafür ist das mein Lab bei weitem nicht den Anforderung entsprochen hat, die ich für meine Kunden brauchte und das ich damit keine CCNA Security Labs durchführen konnte.&lt;br /&gt;&lt;br /&gt;Deshalb hier ein kurzer Überblick über mein jetziges LAB Setup:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s1600-h/LAB-Net.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 124px;" src="http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s200/LAB-Net.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5402042577516517986" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Anbei eine Erklärung der wichtigsten Maschinen und Systeme:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Elysium: &lt;/span&gt;&lt;br /&gt; - eine XP64 Arbeitsstation mit GNS3 und VMware Server 1.8&lt;br /&gt; - die meisten kleinen Labs erarbeite ich hier (quick und dirty)&lt;br /&gt; - bei großen Labs dient die Maschine auch als zusätzlicher Hypervisor&lt;br /&gt; - beide Netzwerkkarten sind am Main und Lab Switch angebunden&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Core01&lt;/span&gt;&lt;br /&gt; - Win2k8 x64 (64 GB RAM 2x4 Core CPUs) – merkt man das ich stolz auf die Box bin&lt;br /&gt; - alle VMs laufen via Hyper V&lt;br /&gt; - beide Netzwerkkarten sind am Main und Lab Switch angebunden&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;VM Server:&lt;/span&gt;&lt;br /&gt; Active Directory Server und AD Child Server&lt;br /&gt;  - um sich gegen AD Szenario zu authentifizieren&lt;br /&gt; CA Server &lt;br /&gt;  - MS CA Server für PKI Szenarios zwischen den Routern&lt;br /&gt; Nagios&lt;br /&gt;  - Nagios überwacht meine Labs und ein paar echte Maschinen&lt;br /&gt; Radius&lt;br /&gt;  - Free Radius um Radius auth. zu simulieren &lt;br /&gt; Tacacs&lt;br /&gt;  - TACACS+ um  Tacacs auth. zu simulieren (noch nicht fertig eingerichtet)&lt;br /&gt; SDM&lt;br /&gt;  - Die XP Maschine stellt den SMD für das CCNA Security Labs zur Verfügung&lt;br /&gt; Workstation&lt;br /&gt;  - nur eine Testmaschine für VPN Clients et&lt;br /&gt; MAIL&lt;br /&gt;  - Sendet Mails von Nagios  &lt;br /&gt; Cisco MARS&lt;br /&gt;  - eine virtuelle MARS Appliance (auch noch nicht ganz fertig)&lt;br /&gt; Nicht aufgeführte Systeme:&lt;br /&gt;  Cisco ACS 4/5 (trial), CUCM 7/ 5&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;LAB-R001&lt;/span&gt;&lt;br /&gt;- virtueller 7200 Router mit IOS 15.0.1.M&lt;br /&gt;- komplett mit FE Anschlüssen ausgerüstet&lt;br /&gt;- jeder FE Anschluss ist an ein LAB angebunden&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;LAB-SW01/SW02/SW03&lt;/span&gt;&lt;br /&gt;- Cisco Lab Switches von Ebay&lt;br /&gt;- Catalyst 2950 12.1.22-EA13&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Home-SW02&lt;/span&gt;&lt;br /&gt;- Netgear 8 Port Gigabit Switch&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Router Labs&lt;/span&gt;&lt;br /&gt;Jedes Router Lab läuft in einer eigenen &lt;a href="http://www.gns3-labs.com/2008/06/23/dynaslax-dynaslaxgns3-and-dynaslaxusb-livecds/"&gt;Dynaslax VM&lt;/a&gt; die so viele Ressourcen wie nötig zugewiesen bekommen.&lt;br /&gt;&lt;br /&gt;Ich würde mich über Anregungen Kommentare und Ideen zu meinem Labaufbau freuen.&lt;br /&gt;Das war's fürs erste.&lt;br /&gt;&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-939092349826476040?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/939092349826476040/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-lab-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/939092349826476040'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/939092349826476040'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-lab-update.html' title='DE - LAB Update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s72-c/LAB-Net.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8186986119737783648</id><published>2009-11-09T11:24:00.001+01:00</published><updated>2009-11-09T11:24:37.105+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>DE- NEWS: Neue Bloggerin bei Playingwithnetworks</title><content type='html'>Hallo liebe Leser,&lt;br /&gt;&lt;br /&gt;ich hab eine gute Freundin von Zif und mir dazu überreden können, bei uns hier mitzuposten und ihre Erfahrung im Netzwerkbereich allen mitzuteilen. Sie hat vor kurzen ihr CCNA Training absolviert und übt sich jetzt langsam in die Ciscowelt ein.&lt;br /&gt;&lt;br /&gt;Ich bin wirklich gespannt was sie hier als erstes postet.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8186986119737783648?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8186986119737783648/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-news-neue-bloggerin-bei.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8186986119737783648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8186986119737783648'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/de-news-neue-bloggerin-bei.html' title='DE- NEWS: Neue Bloggerin bei Playingwithnetworks'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-9077721752079086672</id><published>2009-11-09T11:20:00.000+01:00</published><updated>2009-11-09T11:21:02.797+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>EN - NEWS: New Author</title><content type='html'>Hi guys,&lt;br /&gt;&lt;br /&gt;I was able to convince a good friend of us (Zif and me) to post here her experience on network stuff. She is pretty new and had her first CCNA trainings some weeks ago. &lt;br /&gt;&lt;br /&gt;I'm quite excited what her first post will be.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-9077721752079086672?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/9077721752079086672/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-news-new-author.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9077721752079086672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9077721752079086672'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-news-new-author.html' title='EN - NEWS: New Author'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8545860283321764665</id><published>2009-11-09T11:02:00.003+01:00</published><updated>2009-11-09T11:09:45.539+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>EN - Lab update</title><content type='html'>It has been a while since I made my last post. This was due to several reasons. &lt;br /&gt;First of all I was doing some training for my CCNA and CCNA Sec certification. I've already passed the CCNA stuff and now I'm up to do the CCNA Sec test. &lt;br /&gt;Later on I've planed to do the CCSP tests, hopefully I'll have them finished in January 2010.&lt;br /&gt; &lt;br /&gt;The second reason was that I've restructured my lab  from the scratch. This was necessary since the old setup did not reflect the environments I've had to face at my customers location and it was not possible to train for the CCNA Sec stuff. :D&lt;br /&gt;&lt;br /&gt;So here is a quick overview of my current lab setup&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s1600-h/LAB-Net.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 200px; height: 124px;" src="http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s200/LAB-Net.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5402042577516517986" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'll go through the picture and explain the most important machines:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Elysium: &lt;/span&gt;&lt;br /&gt; - Is a XP64 workstation running GNS3 and VMWare Server 1.8&lt;br /&gt; - most small labs and tests are done here&lt;br /&gt; - for larger labs this box is used as additional hypervisor&lt;br /&gt; - 2xNICs connected to my main and my lab switch&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Core01&lt;/span&gt;&lt;br /&gt; - Win2k8 x64 (64 GB RAM 2x4 Core CPUs) – I'm happy with this box :D&lt;br /&gt; - Hyper V is running all VMS&lt;br /&gt; - 2xNICs connected to my main and my lab switch&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;VM Servers:&lt;/span&gt;&lt;br /&gt; Active Directory Server and AD Child Server&lt;br /&gt;  - for authentication tests with Active Directory &lt;br /&gt; CA Server &lt;br /&gt;  - MS CA Server to do the PKI stuff for router to router authentication&lt;br /&gt; Nagios&lt;br /&gt;  - Nagios is monitoring my lab networks and some of my real workstations&lt;br /&gt; Radius&lt;br /&gt;  - Free Radius implementation for authentication testing&lt;br /&gt; Tacacs&lt;br /&gt;  - TACACS+ for Tacacs testing (still in deployment)&lt;br /&gt; SDM&lt;br /&gt;  - Well this XP Machine provides the SDM that is required for CCNA Sec&lt;br /&gt; Workstation&lt;br /&gt;  - This is just a testing machine (VPN client and so on)&lt;br /&gt; MAIL&lt;br /&gt;  - Reporting from Nagios &lt;br /&gt; Cisco MARS&lt;br /&gt;  - a virtual MARS appliance (not really deployed yet)&lt;br /&gt; Machines not listed:&lt;br /&gt;  Cisco ACS 4/5 (trial), CUCM 7/ 5&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;LAB-R001&lt;/span&gt;&lt;br /&gt;- virtual 7200 running IOS 15.0.1.M&lt;br /&gt;- stuffed with lots of FE interfaces&lt;br /&gt;- each FE connects to a router lab&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;LAB-SW01/SW02/SW03&lt;/span&gt;&lt;br /&gt;- Cisco lab switches from Ebay&lt;br /&gt;- Catalyst 2950 12.1.22-EA13&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Home-SW02&lt;/span&gt;&lt;br /&gt;- Netgear 8 Port Gigabit Switch&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Router Labs&lt;/span&gt;&lt;br /&gt;Each router lab is a own VM running &lt;a href="http://www.gns3-labs.com/2008/06/23/dynaslax-dynaslaxgns3-and-dynaslaxusb-livecds/"&gt;Dynaslax&lt;/a&gt; with as much resources allocated as needed&lt;br /&gt;&lt;br /&gt;I would be thank full for any comments and other ideas about the lab setup. Even for questions :D&lt;br /&gt;&lt;br /&gt;Thats it for now :D&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8545860283321764665?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8545860283321764665/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-lab-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8545860283321764665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8545860283321764665'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/11/en-lab-update.html' title='EN - Lab update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qoVkk4XAzPw/SvfpGl5oWmI/AAAAAAAAAC4/11DVit7ASt4/s72-c/LAB-Net.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3634293100560204275</id><published>2009-10-23T23:22:00.002+02:00</published><updated>2009-10-23T23:28:18.812+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='asdm'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>DE - "ASDM" Befehlseinschränkung</title><content type='html'>Ich hab eine ganze Weile nichts mehr gepostet und komme auch im Moment nicht wirklich dazu, daher mach ich mich mal ans übersetzen von älteren Artikeln, Es ist ja nicht so das wir hier nicht eigentlich Deutsch und Englisch anbieten wollten.&lt;br /&gt;&lt;br /&gt;Die Anfrage um die es geht kam damals via Twitter und es war einfach grundlegend nur die Frage, Kann man Nutzern im ASDM rechte beschneiden, so das sie nur Teile der Konfiguration sehen können.. Kurz um: “Ja es geht”&lt;br /&gt;&lt;br /&gt;Anbei hab ich eine Quick und Dirty Konfiguration zusammengeschustert die zeigt wie es geht. Ich hab das ganze auf realer Hardware getestet (ASA 5505 8.0.3 ASDM 6.2.1) mit echten VPN settings. Wie gesagt es geht und die Nutzer können nur die Settings im ASDM betrachten und nicht ändern.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;PIX Version 8.0(3)&lt;br /&gt;!&lt;br /&gt;hostname PIX&lt;br /&gt;domain-name playingwithnetworks.com&lt;br /&gt;enable password 123 encrypted&lt;br /&gt;!&lt;br /&gt;interface Ethernet0&lt;br /&gt; shutdown&lt;br /&gt; no nameif&lt;br /&gt; no security-level&lt;br /&gt; no ip address&lt;br /&gt;!&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.188.2 255.255.255.0&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;dns server-group DefaultDNS&lt;br /&gt; domain-name playingwithnetworks.com&lt;br /&gt;pager lines 24&lt;br /&gt;logging enable&lt;br /&gt;logging buffered debugging&lt;br /&gt;logging asdm errors&lt;br /&gt;mtu inside 1500&lt;br /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;br /&gt;asdm image flash:/asdm-621.bin&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;br /&gt;&lt;b&gt;&lt;br /&gt;aaa authentication http console LOCAL&lt;br /&gt;aaa authorization command LOCAL&lt;br /&gt;! THIS IS IMPORTANT IF YOU MISS THIS COMMANDS THE THING WILL NOT WORK&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;http server enable&lt;br /&gt;http 192.168.188.0 255.255.255.0 inside&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;username VPNSUPPORT password 123 encrypted priv 2&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;privilege show level 2 mode exec command running-config&lt;br /&gt;privilege show level 2 mode exec command version&lt;br /&gt;privilege show level 2 mode exec command interface&lt;br /&gt;privilege show level 2 mode exec command logging&lt;br /&gt;privilege show level 2 mode exec command aaa&lt;br /&gt;privilege show level 2 mode exec command crypto&lt;br /&gt;privilege show level 2 mode exec command vpn-sessiondb&lt;br /&gt;privilege show level 2 mode exec command vpnclient&lt;br /&gt;privilege show level 2 mode exec command vpn&lt;br /&gt;privilege show level 2 mode exec command blocks&lt;br /&gt;privilege show level 2 mode exec command webvpn&lt;br /&gt;privilege show level 2 mode exec command compression&lt;br /&gt;!&lt;br /&gt;prompt hostname context&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;In der vorangegangene Konfiguration wird dem User VPNSUPPORT das Recht eingeräumt, VPN Informationen abzurufen, ohne sie ändern zu können. &lt;br /&gt;Um andere Bereich freizugeben oder zu Sperren kann man einen Trick anwenden.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;debug http  enabled at level 250&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Dann clickt man mit einem User auf die Bereiche die man sehen will und im Debug sieht man die URL die aufgerufen wird. Anhand dieser Information kann die CFG oben angepasst werden.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;HTTP: processing GET URL '/admin/exec/show+ipv6+neighbor'&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Im Beispiel kann Ipv6 für Level 2 User freigegeben werden.&lt;br /&gt;&lt;br /&gt;HTH&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3634293100560204275?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3634293100560204275/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/10/de-asdm-befehlseinschrankung.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3634293100560204275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3634293100560204275'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/10/de-asdm-befehlseinschrankung.html' title='DE - &quot;ASDM&quot; Befehlseinschränkung'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1697763364860193140</id><published>2009-07-01T16:16:00.012+02:00</published><updated>2009-11-09T11:10:38.582+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='vrf'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>EN - dynamic routleaking or Inter VRF routing</title><content type='html'>dynamic route leaking or routing protcols between global routing table (GRT) and VRFs &lt;br /&gt;&lt;br /&gt;Hey Everybody,&lt;br /&gt;&lt;br /&gt;last time I showed some exampel config for static roue leaking and thought that dynamic routing between GRT and VRF can't be that hard ... how green.&lt;br /&gt;After some hard trys and help from other people I will now show you, how to exchange routes between GRT and VRF-RT dynamicly.&lt;br /&gt;There is no chance to do a normal redistrubution between routing processes if one is the global one.&lt;br /&gt;If you try so, you'll get some cryptic message like &lt;br /&gt;VRF -&gt; GRT [code]%OSPF process 1 is attached to Default-IP-Routing-Table[/code]&lt;br /&gt;GRT -&gt; VRF [code]OSPF process 22 already exists and is attached to Default-IP-Routing-Table[/code]&lt;br /&gt;&lt;br /&gt;How ever, now we need to get this tricked. Therefor we use tunnel interfaces and some loopbacks.&lt;br /&gt;&lt;br /&gt;This is my tiny topology:&lt;br /&gt;&lt;img style="cursor:pointer; cursor:hand;width: 280px; height: 236px;" src="http://2.bp.blogspot.com/_Xv6C9sn9zDM/SrD2lsnh2jI/AAAAAAAAABE/GI9XdY-b8lU/s320/Clipboard01.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5382072682200291890" /&gt;&lt;br /&gt;&lt;br /&gt;The global Client and the VRF_Client are again just some as host missused routers with one IP address and a default route pointing on the outgoing IF.&lt;br /&gt;&lt;b&gt;grt_host&lt;/b&gt;&lt;br /&gt;[code]interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.10 255.255.255.0&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 10.10.10.1 FastEthernet0/0[/code]&lt;br /&gt;&lt;br /&gt;&lt;b&gt;vrf_host&lt;/b&gt;&lt;br /&gt;[code]interface FastEthernet0/1&lt;br /&gt; ip address 20.20.20.20 255.255.255.0&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 20.20.20.1 FastEthernet0/1[/code]&lt;br /&gt;&lt;br /&gt;Now are some basic config for the vrf_router needed:&lt;br /&gt;&lt;br /&gt;Create a vrf:&lt;br /&gt;&lt;code&gt;ip vrf zif&lt;br /&gt; rd 1:1&lt;br /&gt; route-target both 1:1&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Link to grt_host:&lt;br /&gt;&lt;code&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;/code&gt;&lt;br /&gt; &lt;br /&gt;Link to vrf_host:&lt;br /&gt;&lt;code&gt;interface FastEthernet0/1&lt;br /&gt; ip vrf forwarding zif&lt;br /&gt; ip address 20.20.20.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;This all was no rocket science yet, until now ;)&lt;br /&gt;&lt;br /&gt;First thing to figure out: how to outsmart the limitations of design?&lt;br /&gt;&lt;br /&gt;One credential are &lt;b&gt;"Tunnel-Interfaces"&lt;/b&gt;, an other one &lt;b&gt;"loopbacks"&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;In sum we need one tunnel-IF per VRF and GRT plus one loopback for each.&lt;br /&gt;&lt;br /&gt;Both loopbacks are left in GRT:&lt;br /&gt;&lt;b&gt;VRF Router&lt;/b&gt;&lt;br /&gt;&lt;code&gt;interface Loopback111&lt;br /&gt; ip address 111.111.111.111 255.255.255.255&lt;br /&gt;&lt;br /&gt;interface Loopback222&lt;br /&gt; ip address 222.222.222.222 255.255.255.255&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Now we need the correspondent tunnel IFs.&lt;br /&gt;The global one:&lt;br /&gt;&lt;code&gt;interface Tunnel102&lt;br /&gt; ip address 100.100.100.1 255.255.255.0&lt;br /&gt; tunnel source 111.111.111.111&lt;br /&gt; tunnel destination 222.222.222.222&lt;/code&gt;&lt;br /&gt;And the VRF one:&lt;br /&gt;&lt;code&gt;interface Tunnel201&lt;br /&gt; ip vrf forwarding RED&lt;br /&gt; ip address 100.100.100.2 255.255.255.0&lt;br /&gt; tunnel source 222.222.222.222&lt;br /&gt; tunnel destination 111.111.111.111&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;What this is doing: pointing with the tunnel 201 to a GRT loopback with a source in GRT putting itself in a VRF. It sounds, strange, it looks strange, it feels strange, BUT it works ;)&lt;br /&gt;&lt;br /&gt;Now you have sweet networks which you can add to routing processes like OSPF.&lt;br /&gt;&lt;br /&gt;The global routing process:&lt;br /&gt;&lt;code&gt;router ospf 1&lt;br /&gt; router-id 10.10.10.10&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 100.100.100.1 0.0.0.0 area 0&lt;br /&gt; network 10.10.10.0 0.0.0.255 area 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The VRF routing process:&lt;br /&gt;&lt;code&gt;router ospf 2 vrf zif&lt;br /&gt; router-id 20.20.20.20&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 20.20.20.0 0.0.0.255 area 0&lt;br /&gt; network 102.102.102.2 0.0.0.0 area 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The routintg tables looks like this:&lt;br /&gt;global&lt;br /&gt;&lt;code&gt;&lt;br /&gt;VRF_Router#sh ip route&lt;br /&gt;[...snip...]&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;     102.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       102.102.102.0 is directly connected, Tunnel102&lt;br /&gt;     200.200.200.0/32 is subnetted, 1 subnets&lt;br /&gt;C       200.200.200.200 is directly connected, Loopback200&lt;br /&gt;     100.0.0.0/32 is subnetted, 1 subnets&lt;br /&gt;C       100.100.100.100 is directly connected, Loopback100&lt;br /&gt;     20.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;O       20.20.20.0 [110/11112] via 102.102.102.2, 00:24:29, Tunnel102&lt;br /&gt;     10.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       10.10.10.0 is directly connected, FastEthernet0/0&lt;/code&gt;&lt;br /&gt;vrf&lt;br /&gt;&lt;code&gt;&lt;br /&gt;Router#sh ip route vrf zif&lt;br /&gt;&lt;br /&gt;Routing Table: zif&lt;br /&gt;[...snip...]&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;     102.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       102.102.102.0 is directly connected, Tunnel201&lt;br /&gt;     20.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       20.20.20.0 is directly connected, FastEthernet0/1&lt;br /&gt;     10.0.0.0/24 is subnetted, 1 subnets&lt;br /&gt;O       10.10.10.0 [110/11112] via 102.102.102.1, 00:26:19, Tunnel201&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And thats it! Now you are able to ping from you grt_host straight through the vrf_host.&lt;br /&gt;&lt;br /&gt;For questions just use the comments.&lt;br /&gt;&lt;br /&gt;so long,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1697763364860193140?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1697763364860193140/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/07/dynamic-routleaking-or-inter-vrf.html#comment-form' title='2 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1697763364860193140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1697763364860193140'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/07/dynamic-routleaking-or-inter-vrf.html' title='EN - dynamic routleaking or Inter VRF routing'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Xv6C9sn9zDM/SrD2lsnh2jI/AAAAAAAAABE/GI9XdY-b8lU/s72-c/Clipboard01.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5272090192171846997</id><published>2009-07-01T16:08:00.004+02:00</published><updated>2009-11-09T11:11:10.458+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><title type='text'>EN - Upcomming: dynamic route leaking or routing protcols between global routing table (GRT) and VRFs</title><content type='html'>Hey everyone,&lt;br /&gt;&lt;br /&gt;due to NWG asked me for this I started investigation about a way to do some dynamic redistribution between a VRF and the GRT. Everyone trying to solve this by a simple "redistribute" command in the routing process knows, thats that is not the way ;)&lt;br /&gt;&lt;br /&gt;At the moment I am preparing the entry for this blog. At this point big thanks to "conspathas" from the dynamip forum for his time explaining this way.&lt;br /&gt;&lt;br /&gt;See ya soon,&lt;br /&gt;Zif&lt;br /&gt;&lt;br /&gt;Update 09-07-10: due to heavy load @work there is a delay in publication, please stand by :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5272090192171846997?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5272090192171846997/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/07/upcomming-dynamic-route-leaking-or.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5272090192171846997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5272090192171846997'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/07/upcomming-dynamic-route-leaking-or.html' title='EN - Upcomming: dynamic route leaking or routing protcols between global routing table (GRT) and VRFs'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7727778644034166789</id><published>2009-06-22T21:28:00.006+02:00</published><updated>2009-06-22T23:29:19.600+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='asdm'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>EN - "ASDM" command restrictions</title><content type='html'>This one I just received via Twitter (Well i grabbed it from my search stream)&lt;br /&gt;Can you restrict ASDM so that users can only view parts of the configuration.&lt;br /&gt;&lt;br /&gt;Well "Yes you can"&lt;br /&gt;I´ve created a quick and dirty configuration that should reflect this settings. &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Update&lt;/span&gt; tested on real hardware with real VPN connections (ASA 5505 8.0.3 ASDM 6.2.1) Works quite well, users can´t reset or disconnect only view. Some commands added to view all VPN settings on ASDM.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;PIX Version 8.0(3)&lt;br /&gt;!&lt;br /&gt;hostname PIX&lt;br /&gt;domain-name playingwithnetworks.com&lt;br /&gt;enable password 123 encrypted&lt;br /&gt;!&lt;br /&gt;interface Ethernet0&lt;br /&gt; shutdown&lt;br /&gt; no nameif&lt;br /&gt; no security-level&lt;br /&gt; no ip address&lt;br /&gt;!&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.188.2 255.255.255.0&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;dns server-group DefaultDNS&lt;br /&gt; domain-name playingwithnetworks.com&lt;br /&gt;pager lines 24&lt;br /&gt;logging enable&lt;br /&gt;logging buffered debugging&lt;br /&gt;logging asdm errors&lt;br /&gt;mtu inside 1500&lt;br /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;br /&gt;asdm image flash:/asdm-621.bin&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;br /&gt;&lt;b&gt;&lt;br /&gt;aaa authentication http console LOCAL&lt;br /&gt;aaa authorization command LOCAL&lt;br /&gt;! THIS IS IMPORTANT IF YOU MISS THIS COMMANDS THE THING WILL NOT WORK&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;http server enable&lt;br /&gt;http 192.168.188.0 255.255.255.0 inside&lt;br /&gt;!&lt;br /&gt;! &lt;snip&gt;&lt;br /&gt;!&lt;br /&gt;username VPNSUPPORT password 123 encrypted priv 2&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;privilege show level 2 mode exec command running-config&lt;br /&gt;privilege show level 2 mode exec command version&lt;br /&gt;privilege show level 2 mode exec command interface&lt;br /&gt;privilege show level 2 mode exec command logging&lt;br /&gt;privilege show level 2 mode exec command aaa&lt;br /&gt;privilege show level 2 mode exec command crypto&lt;br /&gt;privilege show level 2 mode exec command vpn-sessiondb&lt;br /&gt;privilege show level 2 mode exec command vpnclient&lt;br /&gt;privilege show level 2 mode exec command vpn&lt;br /&gt;privilege show level 2 mode exec command blocks&lt;br /&gt;privilege show level 2 mode exec command webvpn&lt;br /&gt;privilege show level 2 mode exec command compression&lt;br /&gt;!&lt;br /&gt;prompt hostname context&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;So this should be enough to show your user VPNSUPPORT information about the status of your VPN connection. If you need further information you could use the following trick: switch on debug:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;debug http  enabled at level 250&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;and then click with you low priv user to the location of the ASDM you need. You will get the output of what URL was requested and from this you can see what commands you need to enable&lt;br /&gt;for example if you click on monitor interfaces you will get along with others the debug output:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;HTTP: processing GET URL '/admin/exec/show+ipv6+neighbor'&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;With this information you can now enable show ip6 for level 2 if you need.&lt;br /&gt;&lt;br /&gt;Hope that helps&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7727778644034166789?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7727778644034166789/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/06/this-one-i-just-received-via-twitter.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7727778644034166789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7727778644034166789'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/06/this-one-i-just-received-via-twitter.html' title='EN - &quot;ASDM&quot; command restrictions'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7895709212895475108</id><published>2009-05-18T19:55:00.003+02:00</published><updated>2009-05-18T20:01:46.123+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><title type='text'>EN/DE - Configuration Registers on Routers</title><content type='html'>Hey out there,&lt;br /&gt;&lt;br /&gt;due to I stubled over some wrong set config registered in last time and had not all settings in mind, I found a nice cisco document revealing the secrets about the crytic hex values:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a008022493f.shtml"&gt;Use of the Configuration Register on All Cisco Routers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Have fun with it,&lt;br /&gt;Zif&lt;hr&gt;&lt;br /&gt;Hallo zusammen,&lt;br /&gt;&lt;br /&gt;letztens bin ich bei einem Kunden über falsch gesetzte config registers gestolpert und da ich mir nicht sämtliche Werte merken kann, habe ich ein schickes Cisco-Dokument gefunden, welches die Bedeutung hinter den kryptischen Hex-Zahlen verrät:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/products/hw/routers/ps133/products_tech_note09186a008022493f.shtml"&gt;Use of the Configuration Register on All Cisco Routers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Habt Spaß damit,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7895709212895475108?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7895709212895475108/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/ende-configuration-registers-on-routers.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7895709212895475108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7895709212895475108'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/ende-configuration-registers-on-routers.html' title='EN/DE - Configuration Registers on Routers'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6593550536365997327</id><published>2009-05-07T09:49:00.001+02:00</published><updated>2009-05-07T09:49:59.380+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>DE - ASA 8.2 Release endlich herunterladbar</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Ich lade im Moment das ASA 8.2(1) Image herunter um es auf einer meiner Testboxen zu deployen. Der Download ist wie immer unter http://www.cisco.com/cgi-bin/tablebuild.pl/asa zu finden (CCO Account wird benötigt)&lt;br /&gt;Ich halt euch auf dem laufenden wie das Upgrade lief.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6593550536365997327?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6593550536365997327/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/de-asa-82-release-endlich.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6593550536365997327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6593550536365997327'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/de-asa-82-release-endlich.html' title='DE - ASA 8.2 Release endlich herunterladbar'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4441267699586511939</id><published>2009-05-07T09:48:00.000+02:00</published><updated>2009-05-07T09:49:18.020+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><title type='text'>EN - ASA 8.2 Release ready for download</title><content type='html'>Hi all,&lt;br /&gt;I’m currently downloading ASA 8.2(1) Release to deploy it on one of my testing boxes. You can find the download from http://www.cisco.com/cgi-bin/tablebuild.pl/asa (CCO with Contract required)&lt;br /&gt;I'll tell you how the upgrade went.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4441267699586511939?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4441267699586511939/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/en-asa-82-release-ready-for-download.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4441267699586511939'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4441267699586511939'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/05/en-asa-82-release-ready-for-download.html' title='EN - ASA 8.2 Release ready for download'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4561574948438490330</id><published>2009-04-29T11:49:00.015+02:00</published><updated>2009-04-30T11:55:09.619+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='vrf'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>EN - "Route Leaking" or Inter VRF routing</title><content type='html'>Heyho,&lt;br /&gt;&lt;br /&gt;today I want to give a small guide, how to configure inter-VRF (VRF = VPN Routung and Forwarding) routing.&lt;br /&gt;The Cisco documentation I found for this is more likely rocket science than a working guide.&lt;br /&gt;&lt;br /&gt;The task was to implement static routes on one device routing between different VRFs.&lt;br /&gt;I used following network map:&lt;br /&gt;&lt;img src="http://666kb.com/i/b8i4qeej1mwblogk6.jpg" title="hosted by 666kb.com"/&gt;&lt;br /&gt;Both routers "VRF_1" and "VRF_2" are only hosts with only an IP and a default route pointing at the outgoin interface:&lt;br /&gt;VRF1&lt;blockquote&gt;&lt;code&gt;interface FastEthernet0/1&lt;br /&gt; description Link to VRF_Router&lt;br /&gt; ip address 10.0.100.2 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/0&lt;/code&gt;&lt;/blockquote&gt;&lt;br /&gt;VRF2&lt;blockquote&gt;&lt;pre&gt;&lt;code&gt;interface FastEthernet0/1&lt;br /&gt; description Link to VRF_Router&lt;br /&gt; ip address 10.0.200.2 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/1&lt;/code&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Now to the routing part:&lt;br /&gt;At first you need an basic VRF lite config:&lt;br /&gt;&lt;blockquote&gt;ip vrf vrf1&lt;br /&gt; rd 1:1&lt;br /&gt; route-target export 1:1&lt;br /&gt; route-target import 1:1&lt;br /&gt;!&lt;br /&gt;ip vrf vrf2&lt;br /&gt; rd 2:2&lt;br /&gt; route-target export 2:2&lt;br /&gt; route-target import 2:2&lt;/blockquote&gt;&lt;br /&gt;The two commands  &lt;span style="font-weight:bold;"&gt;&lt;code&gt;route-target export 2:2&lt;/code&gt;&lt;/span&gt; and &lt;span style="font-weight:bold;"&gt;&lt;code&gt;route-target import 2:2&lt;/code&gt;&lt;/span&gt; can be summed up with the command "&lt;span style="font-weight:bold;"&gt;&lt;code&gt;route-target both&lt;/code&gt;&lt;/span&gt;. In your config this will be automaticaly replaced with to commands shown.&lt;br /&gt;&lt;br /&gt;In addition to this there is some IF configuration:&lt;br /&gt;&lt;blockquote&gt;interface FastEthernet0/0&lt;br /&gt; ip vrf forwarding vrf1&lt;br /&gt; ip address 10.0.100.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; ip vrf forwarding vrf2&lt;br /&gt; ip address 10.0.200.1 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;The command &lt;span style="font-weight:bold;"&gt;&lt;code&gt;ip vrf forwarding [vrf_name]&lt;/code&gt;&lt;/span&gt; associates the IF into a VRF so the traffic is marked up.&lt;br /&gt;&lt;br /&gt;Now you need to set up the routing. There for you only need a route for each VRF pointing on the IF &lt;span style="font-weight:bold;"&gt;and&lt;/span&gt; Next-Hop-IP of the targeted VRF.&lt;br /&gt;&lt;blockquote&gt;ip route vrf vrf1 10.0.200.0 255.255.255.0 FastEthernet0/1 10.0.200.2&lt;br /&gt;&lt;br /&gt;ip route vrf vrf2 10.0.100.0 255.255.255.0 FastEthernet0/0 10.0.100.2&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;And thats all. If you issue the command &lt;span style="font-weight:bold;"&gt;&lt;code&gt;show ip route&lt;/code&gt;&lt;/span&gt;. &lt;blockquote&gt;VRF_Router#show ip route&lt;br /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;br /&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;br /&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;br /&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;br /&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;br /&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;br /&gt;       o - ODR, P - periodic downloaded static route&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;VRF_Router#&lt;/blockquote&gt;&lt;br /&gt;You'll see an empty global routing table. If you add &lt;span style="font-weight:bold;"&gt;&lt;code&gt;show ip route vrf [vrf_name]&lt;/code&gt;&lt;/span&gt;. As example only the output of one vrf:&lt;blockquote&gt;VRF_Router#show ip route vrf vrf1&lt;br /&gt;&lt;br /&gt;Routing Table: vrf1&lt;br /&gt;&lt;br /&gt;[... snip ...]&lt;br /&gt;&lt;br /&gt;Gateway of last resort is not set&lt;br /&gt;&lt;br /&gt;     10.0.0.0/24 is subnetted, 2 subnets&lt;br /&gt;C       10.0.100.0 is directly connected, FastEthernet0/0&lt;br /&gt;S       10.0.200.0 [1/0] via 10.0.200.2, FastEthernet0/1&lt;br /&gt;VRF_Router#&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Note that it says explictly which routing table it's showing you and you have one extra routing table for each VRF.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If there are any open questions left, just use the commenting funtion&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regrads,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4561574948438490330?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4561574948438490330/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-route-leaking-or-inter-vrf-routing.html#comment-form' title='5 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4561574948438490330'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4561574948438490330'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-route-leaking-or-inter-vrf-routing.html' title='EN - &quot;Route Leaking&quot; or Inter VRF routing'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-471613163887768542</id><published>2009-04-24T10:56:00.005+02:00</published><updated>2009-04-24T11:12:02.243+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>DE - Task 2.2.1 hinzufügen der VPN Edge Geräte</title><content type='html'>Entschuldigung, dass das letzte Post zum Thema so lang her ist, ich hoffe es stört nicht allzu sehr. Prinzipiell sind die Konfigs fertig nur das dokumentieren nervt furchtbar :)&lt;br /&gt;Wir fangen mit unserem Netzwerk aus dem letzten Task an, das heißt wir haben 3 Router und eine PIX die untereinander OSPF sprechen (&lt;a href="http://playingwithnetworks.blogspot.com/2009/04/task-21-grundlegendes-ospf-zwischen.html"&gt;LINK&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Zuerst werden wir die VPN Endgeräte hinzufügen, so das wir später unser Sicherheitskonzept auf das ganze Netzwerk ausrollen können.&lt;br /&gt; &lt;br /&gt;Die Router sind an sich sehr einfach konfiguriert und ich werde nicht tiefer darauf eingehen. Wir konfigurieren wie übliche, die Interfaces für externe und interne Kommunikation, OSPF und zum Schluss sollten wir einen blick auf die anderen Router werfen ob die Routen alle sauber übertragen werden.&lt;br /&gt;Näheres zum Konfigurieren der Router lässt sich unter &lt;a href="http://playingwithnetworks.blogspot.com/2009/04/task-21-grundlegendes-ospf-zwischen.html"&gt;Task 2.1&lt;/a&gt; finden.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;VPN Edge Router 1 - R_VPN_1&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;version 12.4&lt;br /&gt;service timestamps debug datetime msec&lt;br /&gt;service timestamps log datetime msec&lt;br /&gt;no service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_VPN_1&lt;br /&gt;!&lt;br /&gt;boot-start-marker&lt;br /&gt;boot-end-marker&lt;br /&gt;!&lt;br /&gt;no aaa new-model&lt;br /&gt;no logging console&lt;br /&gt;no logging monitor&lt;br /&gt;!&lt;br /&gt;memory-size iomem 5&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;no ip domain lookup&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;multilink bundle-name authenticated&lt;br /&gt;!&lt;br /&gt;archive&lt;br /&gt; log config&lt;br /&gt;  hidekeys&lt;br /&gt;!&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.4 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink ISP 1 ###&lt;br /&gt; ip address 192.168.11.2 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP 2 ###&lt;br /&gt; ip address 192.168.22.2 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.1.0.2 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Uplink to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.1.0.10 255.255.255.252&lt;br /&gt; speed auto&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; network 10.1.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.1.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.4 0.0.0.0 area 0&lt;br /&gt;!&lt;br /&gt;ip forward-protocol nd&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.11.1&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.22.1 10&lt;br /&gt;!&lt;br /&gt;ip http server&lt;br /&gt;no ip http secure-server&lt;br /&gt;!&lt;br /&gt;control-plane&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;line aux 0&lt;br /&gt;line vty 0 4&lt;br /&gt;!&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;VPN Edge Router 2 - R_VPN_2&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;version 12.4&lt;br /&gt;service timestamps debug datetime msec&lt;br /&gt;service timestamps log datetime msec&lt;br /&gt;no service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_VPN_2&lt;br /&gt;!&lt;br /&gt;no logging console&lt;br /&gt;no logging monitor&lt;br /&gt;!&lt;br /&gt;no aaa new-model&lt;br /&gt;memory-size iomem 5&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;no ip domain lookup&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;multilink bundle-name authenticated&lt;br /&gt;!&lt;br /&gt;archive&lt;br /&gt; log config&lt;br /&gt;  hidekeys&lt;br /&gt;! &lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.5 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink ISP 1 ###&lt;br /&gt; ip address 192.168.11.3 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink to ISP 2 ###&lt;br /&gt; ip address 192.168.22.3 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.1.0.6 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Uplink to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.1.0.14 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; network 10.1.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.1.0.12 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.5 0.0.0.0 area 0&lt;br /&gt;!&lt;br /&gt;ip forward-protocol nd&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.11.1&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.22.1 10&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;no ip http server&lt;br /&gt;no ip http secure-server&lt;br /&gt;!&lt;br /&gt;control-plane&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;line aux 0&lt;br /&gt;line vty 0 4&lt;br /&gt;!&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Das war es im großen und ganzen, wir haben nun 5 Router und eine PIX, auf diesem Netzwerk Sicherheit zu implementieren ist etwas aufwändiger und bekommt daher einen eigenen Blogeintrag.&lt;br /&gt;&lt;br /&gt;cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-471613163887768542?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/471613163887768542/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-task-221-hinzufugen-der-vpn-edge.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/471613163887768542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/471613163887768542'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-task-221-hinzufugen-der-vpn-edge.html' title='DE - Task 2.2.1 hinzufügen der VPN Edge Geräte'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6349633382189646401</id><published>2009-04-24T10:34:00.005+02:00</published><updated>2009-04-24T11:12:48.682+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>EN - Task 2.2.1 adding VPN Edge devices</title><content type='html'>Well it has been a while since the last task update and I hope you don´t mind to much. &lt;br /&gt;So we start with our network from last time, this means 3 routers and a pix running OSPF. (&lt;a href="http://playingwithnetworks.blogspot.com/2009/04/task-21-basic-ospf-routing-between.html"&gt;LINK&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;First of all we will add the two VPN Edge devices, so that we can build security concept for the complete network.&lt;br /&gt;The Routers are set up quit easily and i won´t explain in detail what to do on those machines. We will do the usual stuff like setting up network interfaces for internal and external communication, add OSPF and have a look on the other routers to see if the routes are propagated as expected. Fore more information about see the &lt;a href="http://playingwithnetworks.blogspot.com/2009/04/task-21-basic-ospf-routing-between.html"&gt;Task 2.1 Post&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;VPN Edge Router 1 - R_VPN_1&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;service timestamps debug datetime msec&lt;br /&gt;service timestamps log datetime msec&lt;br /&gt;no service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_VPN_1&lt;br /&gt;!&lt;br /&gt;boot-start-marker&lt;br /&gt;boot-end-marker&lt;br /&gt;!&lt;br /&gt;no aaa new-model&lt;br /&gt;no logging console&lt;br /&gt;no logging monitor&lt;br /&gt;!&lt;br /&gt;memory-size iomem 5&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;no ip domain lookup&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;multilink bundle-name authenticated&lt;br /&gt;!&lt;br /&gt;archive&lt;br /&gt; log config&lt;br /&gt;  hidekeys&lt;br /&gt;!&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.4 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink ISP 1 ###&lt;br /&gt; ip address 192.168.11.2 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP 2 ###&lt;br /&gt; ip address 192.168.22.2 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.1.0.2 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Uplink to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.1.0.10 255.255.255.252&lt;br /&gt; speed auto&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; network 10.1.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.1.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.4 0.0.0.0 area 0&lt;br /&gt;!&lt;br /&gt;ip forward-protocol nd&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.11.1&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.22.1 10&lt;br /&gt;!&lt;br /&gt;ip http server&lt;br /&gt;no ip http secure-server&lt;br /&gt;!&lt;br /&gt;control-plane&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;line aux 0&lt;br /&gt;line vty 0 4&lt;br /&gt;!&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;VPN Edge Router 2 - R_VPN_2&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;service timestamps debug datetime msec&lt;br /&gt;service timestamps log datetime msec&lt;br /&gt;no service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname R_VPN_2&lt;br /&gt;!&lt;br /&gt;no logging console&lt;br /&gt;no logging monitor&lt;br /&gt;!&lt;br /&gt;no aaa new-model&lt;br /&gt;memory-size iomem 5&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;no ip domain lookup&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;multilink bundle-name authenticated&lt;br /&gt;!&lt;br /&gt;archive&lt;br /&gt; log config&lt;br /&gt;  hidekeys&lt;br /&gt;! &lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.5 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink ISP 1 ###&lt;br /&gt; ip address 192.168.11.3 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink to ISP 2 ###&lt;br /&gt; ip address 192.168.22.3 255.255.255.128&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.1.0.6 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Uplink to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.1.0.14 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; network 10.1.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.1.0.12 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.5 0.0.0.0 area 0&lt;br /&gt;!&lt;br /&gt;ip forward-protocol nd&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.11.1&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.22.1 10&lt;br /&gt;!&lt;br /&gt;!&lt;br /&gt;no ip http server&lt;br /&gt;no ip http secure-server&lt;br /&gt;!&lt;br /&gt;control-plane&lt;br /&gt;!&lt;br /&gt;line con 0&lt;br /&gt;line aux 0&lt;br /&gt;line vty 0 4&lt;br /&gt;!&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Well thats it for now. Since adding security to those devices is a larger task I´ll create a new blog post about this topic.&lt;br /&gt;&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6349633382189646401?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6349633382189646401/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-221-adding-vpn-edge-devices.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6349633382189646401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6349633382189646401'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-221-adding-vpn-edge-devices.html' title='EN - Task 2.2.1 adding VPN Edge devices'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4032993363876171628</id><published>2009-04-24T00:24:00.000+02:00</published><updated>2009-04-24T00:31:49.973+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>EN/DE - Twitter</title><content type='html'>You may notice that I´ve added a new blogroll entry. I´ve started to twitter, lets see if I have enough time to do this. Have a look, If you like Link&lt;br /&gt;&lt;br /&gt;Es mag vielleicht aufgefallen sein , Ich habe einen neuen Eintrag in die Blogroll aufgenommen. Es ist ein direkter Link zu meinem Tweet. Mal sehen ob ich noch ein bisschen Zeit finde um das ernst zu betreiben.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4032993363876171628?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4032993363876171628/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/ende-twitter.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4032993363876171628'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4032993363876171628'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/ende-twitter.html' title='EN/DE - Twitter'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-9186246764069327862</id><published>2009-04-23T00:20:00.002+02:00</published><updated>2009-04-23T00:25:19.545+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>DE - NEUES aus dem Netz- ASA 8.2 und das neue IPS für die ASA 5505</title><content type='html'>In den meisten englischen Blogs ist es seit 2 Tage ein großes Thema, die aktuellen Ankündigungen von Cisco zum Security Bereich. Zwei der wichtigsten Themen (aus meiner Sicht) sind &lt;br /&gt;&lt;br /&gt;Die neuen Features des ASA 8.2 Releases&lt;br /&gt;Eigentlich sollte die Version 8.2 bereits zum Download angeboten sein aber mein CCO Account weis noch nichts davon. Na mal sehen wann das Release kommt und ich ein wenig damit rumspielen kann. Leider ist das ASA only so das man es nicht in Pemu verwenden kann. Egal!&lt;br /&gt;Das wichtigste Feature ist wohl der Botnet Filter, der die Kommunikation von bereits infizierten Geräten zu den Botnetzen unterbinden soll. &lt;br /&gt;Außerdem klingt der TCP State Bypass ganz interessant, aber das muss ich dann in der echten Welt zeigen.&lt;br /&gt;&lt;br /&gt;Das zweites Highlight ist das IPS für die ASA 5505&lt;br /&gt;Vor einer weile hab ich schon einmal Gerüchte über ein IPS für die ASA 5505 gehört und nun ist offiziell für den Mai angekündigt. Persönlich finde ich die Idee großartig und hoffe das sie vom Markt angenommen wird (und das sie nicht zu teuer wird).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-525310.html"&gt;Cisco Q&amp;A about the new features and the ASA 5505 IPS +  more&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_bulletin_c25-526545.html"&gt;ASA 8.2 Image Features&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks for the information to &lt;a href="http://www.networkworld.com/community/node/41189"&gt;Jamey Heary  at Networkworld &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-9186246764069327862?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/9186246764069327862/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-neues-aus-dem-netz-asa-82-und-das.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9186246764069327862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/9186246764069327862'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-neues-aus-dem-netz-asa-82-und-das.html' title='DE - NEUES aus dem Netz- ASA 8.2 und das neue IPS für die ASA 5505'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5715269071955692956</id><published>2009-04-22T23:11:00.006+02:00</published><updated>2009-04-23T00:22:26.676+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='news'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>EN - NEWS from the Web - ASA 8.2 and IPS for ASA 5505</title><content type='html'>Well you may have heard from several other blogs and news sites that Cisco announced some new interesting features for the ASA Firewalls. Among some other the key things that are interesting for me (personal) are&lt;br /&gt;&lt;br /&gt;ASA 8.2 main feature  &lt;br /&gt;Basing on the ASA Q+A this ASA Image should be available already but my CCO account shows nothing for the ASA to download. Hope that this image will be available soon for test deployment.&lt;br /&gt;Some features that really are worth a second look. &lt;br /&gt;First to mention is Botnet Filtering that by design should prevent traffic from a already infected machine to the Botnets. &lt;br /&gt;Interesting sounds the TCP State bypass but this will need some hands on to check :)&lt;br /&gt;Some drawback, ASA 8.2 is an ASA only image so no support in PEMU&lt;br /&gt;&lt;br /&gt;ASA 5505 IPS&lt;br /&gt;I´ve heard rumors about it and the empty slot was obvious for some add on. Well now you can have a look at the brand new Cisco ASA 5505 IPS module. I think this is a great feature for the ASA 5505, I know some customers that  are looking for this feature and I hope that the market accepts the IPS. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-525310.html"&gt;Cisco Q&amp;A about the new features and the ASA 5505 IPS +  more&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/product_bulletin_c25-526545.html"&gt;ASA 8.2 Image Features&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks for the information to &lt;a href="http://www.networkworld.com/community/node/41189"&gt;Jamey Heary  at Networkworld &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5715269071955692956?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5715269071955692956/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-news-from-web-asa-82-and-ips-for-asa.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5715269071955692956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5715269071955692956'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-news-from-web-asa-82-and-ips-for-asa.html' title='EN - NEWS from the Web - ASA 8.2 and IPS for ASA 5505'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-63273938786470397</id><published>2009-04-22T16:35:00.006+02:00</published><updated>2009-04-22T23:10:28.498+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rommon'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='tricky'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>EN - cast away in ROMMON</title><content type='html'>Hey,&lt;br /&gt;&lt;br /&gt;today I was cought up in rommon in a router configuration.&lt;br /&gt;I had to config 3 2651 routers. One of them had a corrupt IOS file and booted to ROMMON only.&lt;br /&gt;&lt;br /&gt;I feares I had to use a xmodem connection to get an new IOS loaded to the flash, but luckily there is a posibility to use TFTP in ROMMON. To get the following commands working, the IP connectivity must be working, eg Routing from/to the TFTP server.&lt;br /&gt;&lt;br /&gt;Your prompt should look like: &lt;span style="font-weight:bold;"&gt;rommon 1 &gt;&lt;/span&gt;&lt;br /&gt;Now you have to assign all essential informations to it:&lt;br /&gt;&lt;code&gt;IP_ADDRESS=192.168.100.1&lt;br /&gt;IP_SUBNET_MASK=255.255.255.0&lt;br /&gt;DEFAULT_GATEWAY=192.168.100.2&lt;br /&gt;TFTP_SERVER=192.168.100.2&lt;br /&gt;TFTP_FILE=c2600-i-mz.123-26.bin&lt;br /&gt;tftpdnld&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The last command starts the transfer and if its finished enter &lt;span style="font-weight:bold;"&gt;&lt;code&gt;reset&lt;/code&gt;&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Now the router is booting with its brand new IOS.&lt;br /&gt;&lt;br /&gt;have fun,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-63273938786470397?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/63273938786470397/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-cast-away-in-rommon.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/63273938786470397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/63273938786470397'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-cast-away-in-rommon.html' title='EN - cast away in ROMMON'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8487473647270193758</id><published>2009-04-21T23:55:00.001+02:00</published><updated>2009-04-22T00:00:34.356+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><title type='text'>DE – "Wiederherstellen" des Pre Shared Keys auf der ASA</title><content type='html'>Es soll ja vorkommen das man nach zu viel Arbeit noch etwas an der Konfig ändern will und dann einem Flüchtigkeitsfehler unterlaufen. Besonders gern passiert so was bei Copy+Paste Aktionen. Vor einiger ist es mir auch schon passiert, bei der Erstellung einer Tunnelgruppe bei der ich alle Parameter aus einer alten Tunnelgruppe kopierte habe ich den Pre Shared Key der alten Gruppe aus versehen überschrieben. Wie kann man diesen Key wieder herstellen, ein &lt;b&gt;show run&lt;/b&gt;&lt;br /&gt;zeigt nur ein &lt;b&gt;*&lt;/b&gt; als pre shared key. &lt;br /&gt;Aber so lässt sich der Key auch anzeigen:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;copy startup flash:/startup_bck.cfg&lt;br /&gt;more flash:/startup_bck.cfg&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Nun einfach nur noch runter scrollen bis zu den Tunnel Gruppen und dann den Key wieder an die richtige Stelle kopieren. &lt;br /&gt;Das ganze Funktioniert natürlich nur solange kein copy run start oder wr mem ausgeführt wurde.&lt;br /&gt;&lt;br /&gt;Immer daran denken die Datei nach Verwendung wieder von Flash zu löschen&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8487473647270193758?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8487473647270193758/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-wiederherstellen-des-pre-shared-keys.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8487473647270193758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8487473647270193758'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-wiederherstellen-des-pre-shared-keys.html' title='DE – &quot;Wiederherstellen&quot; des Pre Shared Keys auf der ASA'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5237404662339829304</id><published>2009-04-21T23:29:00.004+02:00</published><updated>2009-04-21T23:59:10.204+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><title type='text'>EN - How to "recover" ASA Pre Shared Key</title><content type='html'>If you´ve ever done a configuration to late at night and did some copy+paste you might had the same problem I´ve had some days ago. &lt;br /&gt;I was creating a new VPN tunnel and generally was copy and pasting the settings from an old tunnel. Accidentally I kicked out the pre shared key from the original tunnel (learned lesson: always check twice what you paste). &lt;br /&gt;So how to fix this problem. This is not that simple since a &lt;b&gt;show run&lt;/b&gt; will just give you a &lt;b&gt;*&lt;/b&gt; as pre shared key.&lt;br /&gt;Anyway do the following:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;copy startup flash:/startup_bck.cfg&lt;br /&gt;more flash:/startup_bck.cfg&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;scroll down to your tunnel groups and you will get the plain password. If you copy and past this password into your running tunnel group configuration your tunnel should be working in no time.&lt;br /&gt;It is only possible to do this if you did not issue a &lt;b&gt;copy run start&lt;/b&gt; or &lt;b&gt;wr mem&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Remember to delete that file if you don´t need it anymore.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5237404662339829304?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5237404662339829304/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-how-to-recover-asa-pre-shared-key.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5237404662339829304'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5237404662339829304'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-how-to-recover-asa-pre-shared-key.html' title='EN - How to &quot;recover&quot; ASA Pre Shared Key'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2792798532728501941</id><published>2009-04-15T00:45:00.001+02:00</published><updated>2009-04-20T07:39:05.758+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='on-a-stick'/><title type='text'>DE - VPN on a stick mit Cisco PIX und ASA</title><content type='html'>Vor einer Weile hat Zif ja die "Router on a stick" Konfiguration gepostet. Ich will die Gelegenheit nutzen, um etwas wesentlich Interessanteres darzustellen, die "VPN on a Stick" Konfiguration auf der Cisco ASA bzw. PIX.&lt;br /&gt;&lt;br /&gt;Was bedeutet VPN on a Stick genau, nun es handelt sich dabei um die Konfiguration des VPN so das der VPN Nutzer sich durch das VPN Gateway auf das Internet zugreifen kann. Besonders ist daran, das der VPN Nutzer die Appliance nicht wirklich verlässt sonder direkt über das eingehende Interface wieder hinaus geht. In anderen fällen wird das ganze auch Hairpinning genannt.&lt;br /&gt;&lt;br /&gt;Konfiguration.&lt;br /&gt;Zuerst muss das erledigt werden was auf jeder ASA/PIX notwendig ist, also so etwas wie Interface Konfiguration usw.&lt;br /&gt;Grundlegend ist das überall gleich aber unterscheidet sich doch zwischen ASA, PIX und ASA 5505, die Unterschiede werde ich hier posten, aber für genauere Unterschiede werft doch einen Blick auf &lt;a href="http://www.cisco.com"&gt;CISCO.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;ASA 5510 oder höher&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface ethernet 0/0&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;interface ethernet 0/1&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;ASA 5505 &lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface vlan 10&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;interface vlan 20&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;  &lt;br /&gt;PIX&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface ethernet 0&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;  no shutdown&lt;br /&gt;interface ethernet 1&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;  no shutdown&lt;br /&gt;&lt;br /&gt;global (outside) 1 interface&lt;br /&gt;nat (inside) 1 192.168.0.0 255.255.255.0&lt;br /&gt;route outside 0.0.0.0 0.0.0.0 10.255.255.254 &lt;br /&gt;! 10.255.255.254 ist der nächste Hop, der Router des Providers&lt;br /&gt;&lt;br /&gt;crypto ipsec transform-set ESP-AES256-MD5 esp-aes-256 esp-md5-hmac&lt;br /&gt;&lt;br /&gt;crypto dynamic-map DynOutsideMap 100 set transform-set ESP-AES256-MD5&lt;br /&gt;! Konfiguration für den dynamischen VPN Client&lt;br /&gt;!&lt;br /&gt;crypto map OutsideMap 65535 ipsec-isakmp dynamic DynOutsideMap&lt;br /&gt;crypto map OutsideMap interface outside&lt;br /&gt;! Konfiguration der Crypto Map die auf dem Outside Interface gebunden wird&lt;br /&gt;&lt;br /&gt;crypto isakmp enable outside&lt;br /&gt;crypto isakmp policy 100&lt;br /&gt; authentication pre-share&lt;br /&gt; encryption aes-256&lt;br /&gt; hash sha&lt;br /&gt; group 2&lt;br /&gt; lifetime 86400&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Das ist die Grundlage die fast überall benötigt wird. Als nächstes müssen die spezifischen VPN Parameter konfiguriert werden.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;ip local pool POOL_VPN_Client 192.168.1.1-192.168.1.254 mask 255.255.255.0&lt;br /&gt;&lt;br /&gt;group-policy GPOL_VPN_Client internal&lt;br /&gt;group-policy GPOL_VPN_Client attributes&lt;br /&gt; split-tunnel-policy tunnelall&lt;br /&gt;&lt;br /&gt;tunnel-group GRP_VPN_Client type remote-access&lt;br /&gt;tunnel-group GRP_VPN_Client general-attributes&lt;br /&gt;  default-group-policy GPOL_VPN_Client&lt;br /&gt;  address-pool POOL_VPN_Client&lt;br /&gt;tunnel-group GRP_VPN_Client ipsec-attributes&lt;br /&gt;  pre-shared-key DoNotUseMe&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;So weit so gut, der Client sollte nun in der Lage sein eine Verbindung zur ASA oder PIX aufzubauen (noch keine wirkliche VPN Verbindung). Es bedarf natürlich noch einen User für die Verbindung. AAA wäre eine Lösung, aber für dieses Beispiel bleiben wir bei der LOCAL Lösung.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;username VPNUser password none priv 1&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Jetzt etwas interessantes, NAT.&lt;br /&gt;Wir vermuten einfach mal das auf der ASA/ PIX NAT gemacht wird (wird es ja meistens), so muss nun eine NAT Ausnahme konfiguriert werden, damit der VPN Client die internen Hosts erreichen kann.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;Object-group network OBJ_VPN_Client&lt;br /&gt; network 192.168.1.0 255.255.255.0&lt;br /&gt;Object-group network OBJ_LAN&lt;br /&gt; network 192.168.0.0 255.255.255.0&lt;br /&gt;&lt;br /&gt;access-list NO_nat_inside remark ### NAT exceptions ###&lt;br /&gt;access-list NO_nat_inside permit ip object-group OBJ_LAN object-group OBJ_VPN_Client&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;So nun sind wir fast durch, noch das NAT Statement hinzufügen.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;nat (outside) 1 192.168.1.0 255.255.255.0&lt;br /&gt;! NAT auf dem Outside interface damit der VPN Nutzer eine öffentliche IP &lt;br /&gt;! erhält&lt;br /&gt;nat (inside) 0 access-list NO_nat_inside&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Jetzt noch die Standard Regel "Kein Traffic zwischen Interfaces mit dem gleichen Sicherheitslevel" aufheben.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;same-security-traffic permit intra-interface&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Das war es also!&lt;br /&gt;&lt;br /&gt;Ich hoffe es hat gefallen und danke für die Aufmerksamkeit :D&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/PIX_VPNonAStick.txt"&gt;Vollständige PIX Konfiguration&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2792798532728501941?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2792798532728501941/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-vpn-on-stick-mit-cisco-pix-und-asa.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2792798532728501941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2792798532728501941'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-vpn-on-stick-mit-cisco-pix-und-asa.html' title='DE - VPN on a stick mit Cisco PIX und ASA'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8942544697803579976</id><published>2009-04-14T00:39:00.005+02:00</published><updated>2009-04-20T07:40:11.960+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='advanced'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='on-a-stick'/><title type='text'>EN - VPN on a stick with Cisco PIX and ASA</title><content type='html'>Well since Zif was doing the &lt;a href="http://playingwithnetworks.blogspot.com/2009/03/en-router-on-stick-or-inter-vlan.html"&gt;"Router on a stick"&lt;/a&gt; configuration, I'd like to share with you the much cooler "VPN on a Stick" configuration on the ASA/ PIX. &lt;br /&gt;&lt;br /&gt;What does VPN on a stick mean. Well it means that if you connect to a VPN gateway your traffic will run across this gateway and will be forwarded into the Internet (if you try to connect to the Internet). Why is it named "on a stick" this is because you enter the VPN gateway (ASA/Pix) on the &lt;br /&gt;outside interface an you leave it the same way without accessing the private LAN Sometimes it called hair pinning (if you enter an other VPN connection)&lt;br /&gt;&lt;br /&gt;So what do we need? First of all an ASA/ PIX and second a VPN Client.&lt;br /&gt;&lt;br /&gt;Configuration.&lt;br /&gt;First we´ll have to do some fluff stuff like creating interfaces etc. This is depending on your hardware slightly different. I´ll post the differences here but for later configs please have a look at &lt;a href="http://www.cisco.com"&gt;CISCO.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ASA 5510 or higher&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface ethernet 0/0&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;interface ethernet 0/1&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;ASA 5505 &lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface vlan 10&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;interface vlan 20&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;  &lt;br /&gt;PIX&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;interface ethernet 0&lt;br /&gt;  description ### Outside Interface ###&lt;br /&gt;  nameif outside&lt;br /&gt;  ip address 10.255.255.2 255.255.255.0&lt;br /&gt;  no shutdown&lt;br /&gt;interface ethernet 1&lt;br /&gt;  description ### Inside Interface ###&lt;br /&gt;  nameif inside&lt;br /&gt;  ip address 192.168.0.1 255.255.255.0&lt;br /&gt;  no shutdown&lt;br /&gt;&lt;br /&gt;global (outside) 1 interface&lt;br /&gt;nat (inside) 1 192.168.0.0 255.255.255.0&lt;br /&gt;route outside 0.0.0.0 0.0.0.0 10.255.255.254 &lt;br /&gt;! 10.255.255.254 is the next hop router from the ISP&lt;br /&gt;&lt;br /&gt;crypto ipsec transform-set ESP-AES256-MD5 esp-aes-256 esp-md5-hmac&lt;br /&gt;&lt;br /&gt;crypto dynamic-map DynOutsideMap 100 set transform-set ESP-AES256-MD5&lt;br /&gt;! configuration for dynamic Clients like the Cisco VPN Client&lt;br /&gt;!&lt;br /&gt;crypto map OutsideMap 65535 ipsec-isakmp dynamic DynOutsideMap&lt;br /&gt;crypto map OutsideMap interface outside&lt;br /&gt;! configuration of the over all Crypto Map that is applied on the outside Interface&lt;br /&gt;&lt;br /&gt;crypto isakmp enable outside&lt;br /&gt;crypto isakmp policy 100&lt;br /&gt; authentication pre-share&lt;br /&gt; encryption aes-256&lt;br /&gt; hash sha&lt;br /&gt; group 2&lt;br /&gt; lifetime 86400&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Thats the basic part that you need nearly everywhere. Next step would be to configure the specific parameters for your VPN client.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;ip local pool POOL_VPN_Client 192.168.1.1-192.168.1.254 mask 255.255.255.0&lt;br /&gt;&lt;br /&gt;group-policy GPOL_VPN_Client internal&lt;br /&gt;group-policy GPOL_VPN_Client attributes&lt;br /&gt; split-tunnel-policy tunnelall&lt;br /&gt;&lt;br /&gt;tunnel-group GRP_VPN_Client type remote-access&lt;br /&gt;tunnel-group GRP_VPN_Client general-attributes&lt;br /&gt;  default-group-policy GPOL_VPN_Client&lt;br /&gt;  address-pool POOL_VPN_Client&lt;br /&gt;tunnel-group GRP_VPN_Client ipsec-attributes&lt;br /&gt;  pre-shared-key DoNotUseMe&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;So far, so good, your client should now be able to connect to your ASA or Pix but well, nothing more.&lt;br /&gt;You still need to add a User that is allowed to log in. You could use AAA but for this scenario we stick to LOCAL users.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;username VPNUser password none priv 1&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Now lets start with the interesting parts&lt;br /&gt;Assuming that you do NAT on your ASA/ Pix you need to configure a NAT exception so that you can access your hosts on the inside interface from your VPN Client.&lt;br /&gt;&lt;br /&gt;I tend to use objects groups quite a lot since they enable you to quick change a lot of ACLs. For this reason I´ll set up some object groups and use them later.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;Object-group network OBJ_VPN_Client&lt;br /&gt; network 192.168.1.0 255.255.255.0&lt;br /&gt;Object-group network OBJ_LAN&lt;br /&gt; network 192.168.0.0 255.255.255.0&lt;br /&gt;&lt;br /&gt;access-list NO_nat_inside remark ### NAT exceptions ###&lt;br /&gt;access-list NO_nat_inside permit ip object-group OBJ_LAN object-group OBJ_VPN_Client&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;So we are nearly through add a new NAT statement&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;&lt;br /&gt;nat (outside) 1 192.168.1.0 255.255.255.0&lt;br /&gt;! NAT on interface outside so that your VPN User get your public IP&lt;br /&gt;nat (inside) 0 access-list NO_nat_inside&lt;br /&gt;&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Finlay disable the default rule "No traffic between interfaces with the same security level".&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;quote&gt;same-security-traffic permit intra-interface&lt;/quote&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thats it!&lt;br /&gt;&lt;br /&gt;Hope you enjoyed and thanks for your attention.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/PIX_VPNonAStick.txt"&gt;Full PIX configuration&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8942544697803579976?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8942544697803579976/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/vpn-on-stick-with-cisco-pix-and-asa.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8942544697803579976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8942544697803579976'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/vpn-on-stick-with-cisco-pix-and-asa.html' title='EN - VPN on a stick with Cisco PIX and ASA'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1816853700572132557</id><published>2009-04-11T01:26:00.006+02:00</published><updated>2009-04-24T11:10:44.151+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>DE - Task 2.1 - Grundlegendes OSPF zwischen Routern und ASA</title><content type='html'>In diesem Kapitel erarbeiten wir die Startkonfiguration wie sie beim Kunden existiert, mit kleinen Abänderungen um dem Blogthema gerecht zu werden. &lt;br /&gt;Das Startnetzwerk besteht aus 3 Routern und 1 PIX die den Internetzugriff realisiert.&lt;br /&gt;&lt;br /&gt;Wie bereits erwähnt stimmt das Netzwerk nicht zu 100 % mit dem des Kunden überein. Wir verwenden für die Bereiche Inner Core Routing und Outer Core Routing Cisco 3660 Router mit einem 12.3.26 IOS. Beim Kunden befinden sich in beiden Bereiche nicht nur Cisco Router sondern auch Geräte anderer Hersteller und natürlich sind es nicht nur 3 Geräte. Alle 3660 Router haben in den vorhanden Slots je 2 zusätzliche Fastethernet Interfaces installiert. &lt;br /&gt;&lt;br /&gt;Das zentrale Internet Gateway wird wie bereits erwähnt von einer PIX 525 gestellt, diese läuft mit der Version 7.2.4 der PIX Software.&lt;br /&gt;&lt;br /&gt;Zwischen allen Geräten wurden Transfernetze angelegt die genau groß genug sind um 2 IPs zu enthalten, sprich es wird mit einer Netzmaske von 255.255.255.252 (/30) gearbeitet. Alle Verbindungen zwischen Inner Core und Outer Core liegen im Netzwerkbereich 10.0.0.0 255.255.0.0. Alle Verbindungen die den Core Bereich verlassen liegen im Netzbereich 10.1.0.0 255.255.0.0. Dies sind Verbindungen zu den später einzufügenden VPN-Edge Routern und der PIX.&lt;br /&gt;&lt;br /&gt;Am Inner Core Router hängt außerdem noch das Netzwerk 172.16.0.0 /24, dieses Netzwerk beinhaltet die Management Server des Kunden, unter anderem den CISCO ACS (Version 4.2), einen MS Active Directory Server mit einer bereits installierten CA und einen weiteren Radius Server. Alle Server sind relevant für die spätere Anbindung der VPN Nutzer. Aber mehr davon in den nächsten Kapiteln.&lt;br /&gt;&lt;br /&gt;Wir haben als 3 Cisco Router und eine PIX, wo fängt man am besten an? Natürlich mit den Standard Aufgaben die man bei jedem Gerät einpflegt. Nur als Info, ich werde in den folgenden Konfigs nur Änderungen von den Vorgaben von Cisco einpflegen.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.1 Grundlagen Konfiguration für Hostname, Domainname NTP Settings und IP Interfaces auf Cisco Routern und PIX/ ASA Firewall&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Router für den Inner Core Bereich - R_Inner_Core&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname und Domain Konfiguration&lt;br /&gt;! =================================&lt;br /&gt;hostname R_Inner_Core&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! Kein DNS Lookup fuer Router&lt;br /&gt;! ===========================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface Konfiguration&lt;br /&gt;! =======================&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.1 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink R_Outer_Core_1 ###&lt;br /&gt; ip address 10.0.0.1 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink R_Outer_Core_2 ###&lt;br /&gt; ip address 10.0.0.5 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to internet gateway PIX ###&lt;br /&gt; ip address 10.0.0.13 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Connection to Server Network ###&lt;br /&gt; ip address 172.16.0.5 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! Konfiguration der NTP Einstellungen&lt;br /&gt;! ===================================&lt;br /&gt;ntp server 192.53.103.108 prefer&lt;br /&gt;ntp server 192.53.103.104&lt;br /&gt;! external NTP Server &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Router für den Netzwerkbereich Outer Core Routing - R_Outer_Core_1 und R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname und Domain Konfiguration&lt;br /&gt;! =================================&lt;br /&gt;hostname R_Outer_Core_1&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! Kein DNS Lookup fuer Router&lt;br /&gt;! ===========================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface Konfiguration&lt;br /&gt;! =======================&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.2 255.255.255.255&lt;br /&gt;&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Link to R_Inner_Core ###&lt;br /&gt; ip address 10.0.0.2 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### inter Link to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.0.0.9 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown &lt;br /&gt;!&lt;br /&gt;! Konfiguration der NTP Einstellungen&lt;br /&gt;! ===================================&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;! Hier fällt gleich auf das als NTP Quelle der Router R_Inner_Core verwendet&lt;br /&gt;! wird. Damit werden die Zugriffe der Router auf das Internet minimiert&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Als letztes kommt Router R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname und Domain Konfiguration&lt;br /&gt;! =================================&lt;br /&gt;hostname R_Outer_Core_2&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! Kein DNS Lookup fuer Router&lt;br /&gt;! ===========================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface Konfiguration&lt;br /&gt;! =======================&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.3 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Link to R_Inner_Core ###&lt;br /&gt; ip address 10.0.0.6 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### inter Link to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.0.0.10 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! Konfiguration der NTP Einstellungen&lt;br /&gt;! ===================================&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Als letztes wird die PIX das Internet Gateway konfiguriert - FW-GW-1&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname und Domain Konfiguration&lt;br /&gt;! =================================&lt;br /&gt;hostname FW-GW-1&lt;br /&gt;domain-name Task2.local&lt;br /&gt;!&lt;br /&gt;! Interface Konfiguration&lt;br /&gt;! =======================&lt;br /&gt;interface Ethernet0&lt;br /&gt; description ### Central Breakout Point ###&lt;br /&gt; speed 100&lt;br /&gt; duplex full&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 192.168.33.2 255.255.255.240&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface Ethernet1&lt;br /&gt; description ### Link to Core Router ###&lt;br /&gt; speed 100&lt;br /&gt; duplex full&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 10.0.0.14 255.255.255.252&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! Default Route für unbekannten Traffic&lt;br /&gt;! =====================================&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 192.168.33.1 1&lt;br /&gt;! 192.168.33.1 ist der Nächste Hop, der Router des ISP&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Ab jetzt sollte es möglich sein von jedem gerät die direkt verbundenen Geräte anzupingen.&lt;br /&gt;&lt;br /&gt;Es fällt auf das auf der PIX noch kein NAT konfiguriert ist. Das werden wir später nachholen.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.2 OSPF zwischen Cisco Routern und PIX/ ASA&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Nachdem wir die grundlegende Konfiguration der Router und der PIX /ASA hinter uns haben, geht es nun weiter mit OSPF. Mehr Informationen über &lt;a href="http://playingwithnetworks.blogspot.com/2009/03/configuration-basics.html"&gt;Grundlagen Konfiguration&lt;/a&gt;von Routern werft einen Blick in ZIFs Blog Eintrag von vor einigen Tagen.&lt;br /&gt;&lt;br /&gt;OSPF ist recht einfach zu konfigurieren! &lt;br /&gt;Als erstes muss ein Routing Prozess definiert werden, in diesem wird festgelegt welche Routen der Router mitteilen soll und wenn alle richtig gemacht wurde, war es das schon.&lt;br /&gt;&lt;br /&gt;R_Inner_Core&lt;br /&gt;&lt;Code&gt;&lt;br /&gt;! Erzeugen des Routing Prozesses&lt;br /&gt;router ospf 100&lt;br /&gt;! definieren der Router ID&lt;br /&gt; router-id 10.99.99.1&lt;br /&gt;! Konfigurieren des Loggings&lt;br /&gt; log-adjacency-changes&lt;br /&gt;! Bestimmen was der Router bekannt geben soll&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt;! keine Routing Updates für Interface Loopback 0&lt;br /&gt; passive-interface Loopback0&lt;br /&gt;!&lt;br /&gt;! Bestimmen welche Netzwerk an dem Router hängen. Wird ein Netzwerk hier nicht&lt;br /&gt;! eingepflegt wird dort kein Routing ausgeführt.&lt;br /&gt;!&lt;br /&gt; network 10.0.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.13 0.0.0.3 area 0&lt;br /&gt;! Auch das Loopback Interface (Netzwerk mit 32er Maske) wird bekannt gegeben&lt;br /&gt; network 10.99.99.1 0.0.0.0 area 0&lt;br /&gt; network 172.16.0.0 0.0.0.255 area 0&lt;br /&gt; &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Fast das gleiche wird auf den anderen Routern R_Outer_Core_1 und R_Outer_Core_2 konfiguriert.&lt;br /&gt;&lt;br /&gt;R_Outer_Core_1&lt;br /&gt;&lt;code&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.2&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; passive-interface Loopback0&lt;br /&gt; network 10.0.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.2 0.0.0.0 area 0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; passive-interface Loopback0&lt;br /&gt; network 10.0.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.3 0.0.0.0 area 0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Als letztes wird die PIX/ ASA dem OSPF Netzwerk hinzugefügt.&lt;br /&gt;FW-GW-1&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! erzeugen des Routing Prozesses&lt;br /&gt;router ospf 100&lt;br /&gt;! Definieren der Router ID &lt;br /&gt;! Hinweis: da auf der ASA / PIX keine Loopback Interfaces angelegt werden &lt;br /&gt;!          können, kann man hier den Hostnamen oder ein anderes Interface nehmen&lt;br /&gt; router-id 10.0.0.14&lt;br /&gt; network 10.0.0.12 255.255.255.252 area 0&lt;br /&gt; log-adj-changes&lt;br /&gt; redistribute static subnets&lt;br /&gt;! hier wird eine Defaultroute in das OSPF Netzwerk eingepflegt so das das&lt;br /&gt;! Internet über DIESE PIX / ASA erreicht werden kann.&lt;br /&gt; default-information originate&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Das war es auch schon mit der grundlegenden OSPF Konfiguration. Es sollte nun möglich sein von jedem Gerät jedes andere Gerät anzupingen.&lt;br /&gt;&lt;br /&gt;Nach dem Aufruf des Befehls &lt;i&gt; show ip route&lt;/i&gt; auf R_Inner_Core sollte die Ausgabe etwa dieses Format haben.&lt;br /&gt;&lt;code&gt;&lt;br /&gt;R_Inner_Core#sh ip route&lt;br /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;br /&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;br /&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;br /&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;br /&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;br /&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;br /&gt;       o - ODR, P - periodic downloaded static route&lt;br /&gt;&lt;br /&gt;Gateway of last resort is 10.0.0.14 to network 0.0.0.0&lt;br /&gt;&lt;br /&gt;     172.16.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       172.16.0.0 is directly connected, FastEthernet2/0&lt;br /&gt;     10.0.0.0/8 is variably subnetted, 7 subnets, 2 masks&lt;br /&gt;O       10.0.0.8/30 [110/2] via 10.0.0.6, 00:01:18, FastEthernet0/1&lt;br /&gt;                    [110/2] via 10.0.0.2, 00:01:18, FastEthernet0/0&lt;br /&gt;C       10.0.0.12/30 is directly connected, FastEthernet1/0&lt;br /&gt;O       10.99.99.2/32 [110/2] via 10.0.0.2, 00:01:18, FastEthernet0/0&lt;br /&gt;O       10.99.99.3/32 [110/2] via 10.0.0.6, 00:01:18, FastEthernet0/1&lt;br /&gt;C       10.0.0.0/30 is directly connected, FastEthernet0/0&lt;br /&gt;C       10.99.99.1/32 is directly connected, Loopback0&lt;br /&gt;C       10.0.0.4/30 is directly connected, FastEthernet0/1&lt;br /&gt;O*E2 0.0.0.0/0 [110/1] via 10.0.0.14, 00:01:18, FastEthernet1/0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt; &lt;br /&gt;&lt;i&gt;O*E2 0.0.0.0/0 [110/1] via 10.0.0.14, 00:01:18, FastEthernet1/0&lt;/i&gt; ist die Interessanteste Route von allen. Sie besagt das jede unbekannte IP über die PIX erreicht werden kann. Es handelt sich hierbei um die vorhin angesprochende Default Route.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.3 Anschliesen der Internetverbindung&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Wenn OSPF läuft und alle Router die Route zum Internet kennen muss eigentlich nur noch NAT auf der ASA / PIX konfiguriert werden um den Router auch Internetzugriff zu ermöglichen.&lt;br /&gt;NAT ist notwendig da unser Netzwerk mit privaten Adressen gestaltet ist und diese bekanntermassen nicht ins Internet geroutet werden. Wir benutzen an dieser Stelle eine Unterart des NAT nämlich PAT (Port Address Translation).&lt;br /&gt;&lt;br /&gt;Nehmen wir an das unser Provider uns das Netzwerk 192.168.33.0 255.255.255.240 zur Verfügung gestellt hat und sein Router in dem Netz die 192.168.33.1 benutzt. Das bedeutet das unserem Netzwerk noch die IPs von 192.168.33.2- 192.168.33.14 zur Verfügung stehen.&lt;br /&gt;&lt;br /&gt;Für das PAT werden wir die 192.168.33.3 benutzen, das sollte eigentlich reichen. Als zweiten Schritt müssen wir bestimmen welche Netze umgesetzt werden sollen. Natürlich alle Netzwerk die intern sind.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;global (IF_Outside) 1 192.168.33.3&lt;br /&gt;nat (IF_Inside) 1 0.0.0.0 0.0.0.0&lt;br /&gt;! übersetze jede IP die über das Interface IF_Inside kommt &lt;br /&gt;! in die Öffentliche Adresse + Port&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Da wir noch keinen ISP Router konfiguriert haben, können wir NAT nur mit den Befehl  &lt;i&gt; show nat &lt;/i&gt; überprüfen.&lt;br /&gt;Der Befehl sollte folgenden Output zurück geben:&lt;br /&gt;&lt;code&gt;&lt;br /&gt;show nat&lt;br /&gt;&lt;br /&gt;NAT policies on Interface IF_Inside:&lt;br /&gt;  match ip IF_Inside any IF_Outside any&lt;br /&gt;    dynamic translation to pool 1 (192.168.33.3)&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Gut das war´s. Mit dem nun funktionierenden Netzwerk, können wir später weiterarbeiten.&lt;br /&gt;&lt;br /&gt;Netzwerk Diagramm:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s1600-h/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 114px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s200/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5322477929648703890" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hier könnt ihr noch einmal die gesamte Konfiguration der Router herunterladen: &lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Inner_Core.txt"&gt;R_Inner_Core&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Outer_Core_1.txt"&gt;R_Outer_Core_1&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Outer_Core_2.txt"&gt;R_Outer_Core_2&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/FW-GW-1.txt"&gt;FW-GW-1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Bald gibt es mehr. Wie immer sind Kommentare, Hinweise und natürlich Fragen sehr willkommen&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1816853700572132557?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1816853700572132557/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-21-grundlegendes-ospf-zwischen.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1816853700572132557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1816853700572132557'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-21-grundlegendes-ospf-zwischen.html' title='DE - Task 2.1 - Grundlegendes OSPF zwischen Routern und ASA'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s72-c/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1415132691740385295</id><published>2009-04-08T01:54:00.016+02:00</published><updated>2009-04-15T00:47:55.406+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>EN - Task 2.1 - Basic OSPF routing between router and ASA</title><content type='html'>This is the initial configuration from where we will start to deploy our scenario. We´ve got 3 router and one PIX, this pix is doing the uplink to the Internet.&lt;br /&gt;&lt;br /&gt;As mentioned earlier this is a scheme that has been slightly changed to fit into this blog. Both inner and outer core routers are not only Cisco routers, as well as the used firewall is in the real world no ASA or PIX. Since we are focusing on Cisco this facts have been ignored and we stick to Cisco routers, PIXs and ASAs. &lt;br /&gt;In this example the inner core routing network is represented by one 3660 router running IOS 12.3.26 The outer core routing network consist of 2x 3660 routers also running IOS 12.3.26. All 3660 got 2 additional Fast Ethernet Interfaces installed. Finally the firewall is a Cisco PIX 252 running 7.2.4.&lt;br /&gt;&lt;br /&gt;Between the routers their are transfer networks, just big enough to hold 2 IP addresses, this means we use a 255.255.255.252 (/30)mask for those networks. All connections between inner and outer core as well as within the outer core are located in the network 10.0.0.0 255.255.0.0. Connections leaving the core network are usually 10.1.0.0 255.255.0.0 most times this is used for links to the edge devices like the PIX and later on to connect the VPN edge routers. &lt;br /&gt;&lt;br /&gt;Attached to the inner core router is the network 172.16.0.0 /24 this network holds the customers servers like the Cisco ACS (version 4.2) an MS Active Directory Server (Server 2003)with a certification authority configured as well as a free radius server. All Servers will be used later for the VPN User configuration. But this will be important later.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So we´ve got 3 routers and a PIX. Where to start? Well we start with common tasks configuration of hostnames, domain names and interfaces. I´ll just post the changes I´ve made, no defaults included. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.1 Basic Configuration including Hostname, Domainname, NTP Settings and IP Interfaces on Routers and PIX /ASA Firewalls&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Router for the inner core area - R_Inner_Core&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname and Domain configuration&lt;br /&gt;! =================================&lt;br /&gt;hostname R_Inner_Core&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! No hostname lookup for routers&lt;br /&gt;! ==============================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface configuration&lt;br /&gt;! =======================&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.1 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### Uplink R_Outer_Core_1 ###&lt;br /&gt; ip address 10.0.0.1 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink R_Outer_Core_2 ###&lt;br /&gt; ip address 10.0.0.5 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to internet gateway PIX ###&lt;br /&gt; ip address 10.0.0.13 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### Connection to Server Network ###&lt;br /&gt; ip address 172.16.0.5 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! configuration for NTP settings&lt;br /&gt;! ==============================&lt;br /&gt;ntp server 192.53.103.108 prefer&lt;br /&gt;ntp server 192.53.103.104&lt;br /&gt;! external NTP Server &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;So first router done, to more to go.&lt;br /&gt;&lt;br /&gt;Routers for the outer routing Network R_Outer_Core_1 and R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostename and domain configuration&lt;br /&gt;! ==================================&lt;br /&gt;hostname R_Outer_Core_1&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! No hostname lookup for routers&lt;br /&gt;! ==============================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface configuration&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.2 255.255.255.255&lt;br /&gt;&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Link to R_Inner_Core ###&lt;br /&gt; ip address 10.0.0.2 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### inter Link to R_Outer_Core_2 ###&lt;br /&gt; ip address 10.0.0.9 255.255.255.252&lt;br /&gt; full-duplex&lt;br /&gt; speed 100&lt;br /&gt; no shutdown &lt;br /&gt;!&lt;br /&gt;! NTP Settings&lt;br /&gt;! ============&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;! You may note that the NTP server is the inner core router R_Inner_Core. &lt;br /&gt;! This is to limit access to public resources.&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Last router to be configured R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname and domain name configuration&lt;br /&gt;! ======================================&lt;br /&gt;hostname R_Outer_Core_2&lt;br /&gt;ip domain name Task2.local&lt;br /&gt;!&lt;br /&gt;! No hostname lookup for routers&lt;br /&gt;! ==============================&lt;br /&gt;no ip domain lookup&lt;br /&gt;!&lt;br /&gt;! Interface configuration&lt;br /&gt;! =======================&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### Loop 0 for MGMT ###&lt;br /&gt; ip address 10.99.99.3 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Link to R_Inner_Core ###&lt;br /&gt; ip address 10.0.0.6 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface FastEthernet2/0&lt;br /&gt; description ### inter Link to R_Outer_Core_1 ###&lt;br /&gt; ip address 10.0.0.10 255.255.255.252&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! NTP Settings&lt;br /&gt;! ============&lt;br /&gt;ntp server 10.99.99.1 prefer&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Last configured is the Internet Gateway in this scenario the PIX FW-GW-1&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! Hostname and domain configuration&lt;br /&gt;! =================================&lt;br /&gt;hostname FW-GW-1&lt;br /&gt;domain-name Task2.local&lt;br /&gt;!&lt;br /&gt;! Interface Configuration&lt;br /&gt;! =======================&lt;br /&gt;interface Ethernet0&lt;br /&gt; description ### Central Breakout Point ###&lt;br /&gt; speed 100&lt;br /&gt; duplex full&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 192.168.33.2 255.255.255.240&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;interface Ethernet1&lt;br /&gt; description ### Link to Core Router ###&lt;br /&gt; speed 100&lt;br /&gt; duplex full&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 10.0.0.14 255.255.255.252&lt;br /&gt; no shutdown&lt;br /&gt;!&lt;br /&gt;! Default route for any unknown traffic&lt;br /&gt;! =====================================&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 192.168.33.1 1&lt;br /&gt;! 192.168.33.1 is the next hop to the ISP&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;By now you should be able to ping any directly connected device from each machine.&lt;br /&gt;&lt;br /&gt;As you may notice the PIX is not doing NAT, this will be configured in a separate step later on in this section.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.2 OSPF between Cisco Routers and PIX/ ASA&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;After we´ve finished the basic steps of configuring routers and PIX/ ASA Firewalls we will move to OSPF. For more information on setting up a &lt;a href="http://playingwithnetworks.blogspot.com/2009/03/configuration-basics.html"&gt;basic router configuration&lt;/a&gt; have a look at ZIFs post some days ago.&lt;br /&gt;&lt;br /&gt;OSPF is quite easy to configure. &lt;br /&gt;First of you need to define a routing process, the routes you like to redistribute and if everything is fine you should have OSPF running in no time.&lt;br /&gt;As earlier mentioned in this configs I´ll just post changes from the default configuration.&lt;br /&gt;&lt;br /&gt;R_Inner_Core&lt;br /&gt;&lt;Code&gt;&lt;br /&gt;! define your routing process&lt;br /&gt;router ospf 100&lt;br /&gt;! set your router ID &lt;br /&gt; router-id 10.99.99.1&lt;br /&gt;! configure logging&lt;br /&gt; log-adjacency-changes&lt;br /&gt;! define what you want to announce from this router&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt;! no routing updates on interface Loopback0&lt;br /&gt; passive-interface Loopback0&lt;br /&gt;!&lt;br /&gt;! define networks attached to your router, if you do not add a network &lt;br /&gt;! that is configured on one of your interfaces this interface will not be &lt;br /&gt;! part of your OSPF (obvious!)&lt;br /&gt;!&lt;br /&gt; network 10.0.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.13 0.0.0.3 area 0&lt;br /&gt;! announce even your loopback interface&lt;br /&gt; network 10.99.99.1 0.0.0.0 area 0&lt;br /&gt; network 172.16.0.0 0.0.0.255 area 0&lt;br /&gt; &lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The same is configured on router R_Outer_Core_1 and R_Outer_Core_2&lt;br /&gt;R_Outer_Core_1&lt;br /&gt;&lt;code&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.2&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; passive-interface Loopback0&lt;br /&gt; network 10.0.0.0 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.2 0.0.0.0 area 0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;R_Outer_Core_2&lt;br /&gt;&lt;code&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute connected subnets&lt;br /&gt; redistribute static subnets&lt;br /&gt; passive-interface Loopback0&lt;br /&gt; network 10.0.0.4 0.0.0.3 area 0&lt;br /&gt; network 10.0.0.8 0.0.0.3 area 0&lt;br /&gt; network 10.99.99.3 0.0.0.0 area 0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Finally add your PIX /ASA to the OSPF network.&lt;br /&gt;FW-GW-1&lt;br /&gt;&lt;code&gt;&lt;br /&gt;! create your routing process&lt;br /&gt;router ospf 100&lt;br /&gt;! define your router ID | &lt;br /&gt;! NOTE: no loopback interfaces can be created on ASA and PIX &lt;br /&gt;!       you could use a hostname instead&lt;br /&gt; router-id 10.0.0.14&lt;br /&gt; network 10.0.0.12 255.255.255.252 area 0&lt;br /&gt; log-adj-changes&lt;br /&gt; redistribute static subnets&lt;br /&gt;! Propagate a default route into the OSPF process so that every unknown IP &lt;br /&gt;! can be reached via THIS pix /ASA&lt;br /&gt; default-information originate&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Well so much for basic OSPF. You should be able to ping every device in your network from every location.&lt;br /&gt;&lt;br /&gt;If you issue a &lt;i&gt; show ip route&lt;/i&gt; on R_Inner_Core the output should look like:&lt;br /&gt;&lt;code&gt;&lt;br /&gt;R_Inner_Core#sh ip route&lt;br /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;br /&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;br /&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;br /&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;br /&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;br /&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;br /&gt;       o - ODR, P - periodic downloaded static route&lt;br /&gt;&lt;br /&gt;Gateway of last resort is 10.0.0.14 to network 0.0.0.0&lt;br /&gt;&lt;br /&gt;     172.16.0.0/24 is subnetted, 1 subnets&lt;br /&gt;C       172.16.0.0 is directly connected, FastEthernet2/0&lt;br /&gt;     10.0.0.0/8 is variably subnetted, 7 subnets, 2 masks&lt;br /&gt;O       10.0.0.8/30 [110/2] via 10.0.0.6, 00:01:18, FastEthernet0/1&lt;br /&gt;                    [110/2] via 10.0.0.2, 00:01:18, FastEthernet0/0&lt;br /&gt;C       10.0.0.12/30 is directly connected, FastEthernet1/0&lt;br /&gt;O       10.99.99.2/32 [110/2] via 10.0.0.2, 00:01:18, FastEthernet0/0&lt;br /&gt;O       10.99.99.3/32 [110/2] via 10.0.0.6, 00:01:18, FastEthernet0/1&lt;br /&gt;C       10.0.0.0/30 is directly connected, FastEthernet0/0&lt;br /&gt;C       10.99.99.1/32 is directly connected, Loopback0&lt;br /&gt;C       10.0.0.4/30 is directly connected, FastEthernet0/1&lt;br /&gt;O*E2 0.0.0.0/0 [110/1] via 10.0.0.14, 00:01:18, FastEthernet1/0&lt;br /&gt;&lt;/code&gt;&lt;br /&gt; &lt;br /&gt;&lt;i&gt;O*E2 0.0.0.0/0 [110/1] via 10.0.0.14, 00:01:18, FastEthernet1/0&lt;/i&gt; is one of the more interesting routes. This is the default route announced into the OSPF area by our PIX/ASA. As a consequence all traffic to unknown IPs will be send to the PIX/ASA.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;2.1.3 Bringing up the Internet gateway&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;With OSPF running and a default route pointing to the Internet propagated we just need some few adjustments on our PIX/ASA to allow Internet access.&lt;br /&gt;First of all, since our network is running with private IPs, we need NAT to be configured. In this case PAT (port address translation) is the better term.&lt;br /&gt;&lt;br /&gt;Assuming that our ISP offered us the network 192.168.33.0 255.255.255.240 and his router got the IP 192.168.33.1 we have left the IP range 192.168.33.2-192.168.33.14 for our use.&lt;br /&gt;&lt;br /&gt;We will use the IP address 192.168.33.3 for the PAT configuration that should be enough for a while. Second step is to configure what source IP addresses will be NATed. Since this is the central breakout point the answer is obvious every IP!&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;global (IF_Outside) 1 192.168.33.3&lt;br /&gt;nat (IF_Inside) 1 0.0.0.0 0.0.0.0&lt;br /&gt;! translate every IP on the inside Interface into &lt;br /&gt;! the public IP + specific port&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Since we've not configured the ISP router we check if NAT is correct configured by using &lt;i&gt; show nat &lt;/i&gt;&lt;br /&gt;This should return something like:&lt;br /&gt;&lt;code&gt;&lt;br /&gt;show nat&lt;br /&gt;&lt;br /&gt;NAT policies on Interface IF_Inside:&lt;br /&gt;  match ip IF_Inside any IF_Outside any&lt;br /&gt;    dynamic translation to pool 1 (192.168.33.3)&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;All done now! You should have a running network from where we can go ahead. &lt;br /&gt;&lt;br /&gt;Network Diagramm:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s1600-h/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 114px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s200/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5322477929648703890" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Attached you can find the configuration of our Routers and PIX &lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Inner_Core.txt"&gt;R_Inner_Core&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Outer_Core_1.txt"&gt;R_Outer_Core_1&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/R_Outer_Core_2.txt"&gt;R_Outer_Core_2&lt;/a&gt;&lt;br /&gt;LINK: &lt;a href="http://www.unimatrix01.de/Tasks/Task2/2/FW-GW-1.txt"&gt;FW-GW-1&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;More to come in a few days, feel free to post corrections, suggestions and of course questions.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1415132691740385295?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1415132691740385295/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-21-basic-ospf-routing-between.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1415132691740385295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1415132691740385295'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/task-21-basic-ospf-routing-between.html' title='EN - Task 2.1 - Basic OSPF routing between router and ASA'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qoVkk4XAzPw/Sd09ejGRSZI/AAAAAAAAACw/mhV4VGhdERc/s72-c/Task2.1_Basic_OSPF_with_PIX_ASA_Router.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7020053848069184576</id><published>2009-04-06T02:21:00.003+02:00</published><updated>2009-04-06T22:31:03.229+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>DE - Kron zum automatischen Sichern von Konfigurationen</title><content type='html'>Vor einigen Tagen habe ich die Frage gesehen ob man automatisch Konfigurationen wegsichern kann. Da ich schon einmal gelesen hatte das es geht hab ich die Infos hier einmal zusammengetragen. Der Schlüssel dafür heißt Kron &lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;configure terminal&lt;br /&gt; kron policy-list SaveCFG &lt;br /&gt;  show run | redirect tftp://"yourTFTPServerIP"/backup.cfg&lt;br /&gt;!&lt;br /&gt;! An der Stelle muss show run + | eingesetzt werden &lt;br /&gt;! da der Kron Befehl keine interaktiven Befehle unterstützt&lt;br /&gt;!&lt;br /&gt; kron occurrence SaveCFG at 00:00 mon recurring&lt;br /&gt; !&lt;br /&gt; ! dadurch wird der Kron Job jeden morgen ausgeführt&lt;br /&gt; !&lt;br /&gt;  policy SaveCFG&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Durch Aufrufen des Befehls&lt;br /&gt;&lt;code&gt;show kron schedule &lt;/code&gt;&lt;br /&gt;&lt;br /&gt;kann man sich anzeigen lassen ob der Kron Job bereit ist.&lt;br /&gt;&lt;code&gt;SaveCFG inactive, will run again in 4 days 12:59:58 at 0 :00 on Mon&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Debugs gehen wie so oft natürlich auch&lt;br /&gt;&lt;code&gt;debug kron all&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;hier sieht man, was gerade ausgeführt wird bzw. was geändert wird.&lt;br /&gt;&lt;br /&gt;Kron oder einen ähnlichen Befehl gibt es leider soweit mir bekannt ist nicht für die ASA/ PIX Software.&lt;br /&gt;&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7020053848069184576?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7020053848069184576/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-kron-zum-automatischen-sichern-von.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7020053848069184576'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7020053848069184576'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-kron-zum-automatischen-sichern-von.html' title='DE - Kron zum automatischen Sichern von Konfigurationen'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4499294196016724737</id><published>2009-04-06T02:12:00.003+02:00</published><updated>2009-04-06T02:24:42.339+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>EN - kron to backup configuration automatically</title><content type='html'>A few days ago a came across a nice little question. "Can We do an automatic backup from a config of a router to a tftp server"&lt;br /&gt;Well "Yes we can" (sorry i couldn´t resist)&lt;br /&gt;The key is the kron command&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;configure terminal&lt;br /&gt; kron policy-list SaveCFG &lt;br /&gt;  show run | redirect tftp://"yourTFTPServerIP"/backup.cfg&lt;br /&gt;!&lt;br /&gt;! We´ve got to use Show run + | &lt;br /&gt;! because Kron does not support interactive commands like copy&lt;br /&gt;!&lt;br /&gt; kron occurrence SaveCFG atjavascript:void(0) 00:00 mon recurring&lt;br /&gt; !&lt;br /&gt; ! this causes the kron job to run every monday at 0:00&lt;br /&gt; ! &lt;br /&gt;  policy SaveCFG&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;You can verify if your kron job is working with a &lt;br /&gt;&lt;br /&gt;&lt;code&gt;show kron schedule &lt;/code&gt;&lt;br /&gt;&lt;br /&gt;and get the response&lt;br /&gt;&lt;br /&gt;&lt;code&gt;SaveCFG inactive, will run again in 4 days 12:59:58 at 0 :00 on Mon&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;A well you can debug it too with:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;debug kron all&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;an you should see what happens when you create change or try to execute a kron policy.&lt;br /&gt;&lt;br /&gt;Kron is not working on a ASA/ PIX and AFAIK their is no substitute command for the same task.&lt;br /&gt;&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4499294196016724737?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4499294196016724737/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-kron-to-backup-configuration.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4499294196016724737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4499294196016724737'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-kron-to-backup-configuration.html' title='EN - kron to backup configuration automatically'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3367602650595340155</id><published>2009-04-02T12:46:00.004+02:00</published><updated>2009-04-02T12:57:28.198+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>DE - VPN Netzwerk mit OSPF auf  PIX/ ASA und Routern (Task 2)</title><content type='html'>Gut weiter geht´s mit den Aufgaben. Nachdem ich mir Aufgabe 1 noch einmal angesehen habe, habe ich entschieden die mir selbst auferlegten Aufgaben etwas anders zu bearbeiten. Die Aufgabe 1 enthält, so denke ich, viele Informationen die hilfreich sein können, aber Aufgrund der Fülle nicht einfach zu erfassen sind. Daher will ich weitere Aufgaben in kleinere Teilaufgaben untergliedern um das Lesen, Verstehen und ggf. auch wiederfinden einfacher zu machen.&lt;br /&gt;&lt;br /&gt;Wie soll also Aufgabe 2 aufgeteilt werden&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.1 Nachbau des Kundennetzwerk&lt;/span&gt;&lt;br /&gt;        Grundlegende OSPF Konfiguration auf Cisco Routern und PIX /ASA&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Task 2.2 Hinzufügen von Sicherheitsfeatures und Einbau der VPN Router&lt;/span&gt;&lt;br /&gt;        Aktiveren der MD5 Authentifizierung für OSPF auf den Routern und der PIX/ASA&lt;br /&gt; Hinzufügen der neuen VPN Edge Router zum OSPF Netzwerk&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.3 Erstellen der ISP Router &lt;/span&gt;&lt;br /&gt;        Erstellen von 3 ISP Routern mit OSPF als Routing Protokoll &lt;br /&gt;        (nichts besonderes halt)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.4 Konfigurieren von HSRP auf den VPN Routern&lt;/span&gt;&lt;br /&gt; Grundlegende HSRP Konfiguration auf Routern implementieren&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.5 Aktivieren der VPN Verbindung für Clients auf den VPN Routern&lt;/span&gt;&lt;br /&gt;    &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.6 Hinzufügen von Site 2 Site VPN Funktionalität&lt;/span&gt;&lt;br /&gt;        Einrichten von Site 2 Site VPNs zwischen Router und Router sowie Router &lt;br /&gt;        und PIX/ASA&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.7 Hinzufügen von NEM Hardware Clients&lt;/span&gt;&lt;br /&gt;        Hinzufügen von PIX/ASA als NEM Client&lt;br /&gt; Einrichten von Routern als NEM Client&lt;br /&gt;          &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.8 Volle Redundanz&lt;/span&gt;&lt;br /&gt;        Aktivieren von SSO auf den Routern&lt;br /&gt;&lt;br /&gt;Innerhalb der nächsten Tage will ich Stück für Stück die Lösungen der Teilaufgaben posten. Aber jetzt will ich erst mal das Netz etwas näher erklären&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s1600-h/Network+Base.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 136px;" src="http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s200/Network+Base.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5320034704097772114" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Das ist grundlegend das Netzwerk des Kunden (ja es handelt sich um ein Kunden Netzwerk). Das Netzwerk ist unterteilt in Inner Core Routing, Outer Core Routing und Edge Netzwerk. Inner und Outer Core  Routing Netzwerk sind grundlegend identisch und bestehen aus mehreren Routern die OSPF als routing Protokoll verwenden. In Zukunft sollen diese Bereiche stärker getrennt werden aber das ist Zukunftsplanung und hier uninteressant. Der Edge Bereich enthält alle Netzwerk Geräte die Verbindung zum Internet haben.  Im Edge Netzwerk steht Initial nur eine Firewall, ähnlich wie viele der Router handelt es sich nicht um ein Cisco Produkt aber das ignorieren wir im Interesse der Aufgabe einfach mal und setzen eine PIX/ ASA ein.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_qoVkk4XAzPw/SdSPYHf-vRI/AAAAAAAAACo/pIWKR-xYWfo/s1600-h/Second+Phase.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 180px; height: 200px;" src="http://1.bp.blogspot.com/_qoVkk4XAzPw/SdSPYHf-vRI/AAAAAAAAACo/pIWKR-xYWfo/s200/Second+Phase.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5320034704324214034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Im zweiten Diagramm sieht man die zwei neuen VPN Router wie sie ins Netzwerk eingebracht werden sollen. Ebenso die 3 ISP Router an die die VPN Router angeschlossen werden. &lt;br /&gt;&lt;br /&gt;Wie immer gilt, wenn es Fragen gibt einfach in die Kommentare schreiben.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3367602650595340155?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3367602650595340155/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-vpn-netzwerk-mit-ospf-auf-pix-asa.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3367602650595340155'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3367602650595340155'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-vpn-netzwerk-mit-ospf-auf-pix-asa.html' title='DE - VPN Netzwerk mit OSPF auf  PIX/ ASA und Routern (Task 2)'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s72-c/Network+Base.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4856955758189581793</id><published>2009-04-02T11:53:00.010+02:00</published><updated>2009-04-02T12:17:44.961+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>EN - VPN network with OSPF on PIX/ ASA and routers (Task 2)</title><content type='html'>OK I´ve changed the way how I will handle the answering of the tasks. The problem is that Task 1 was (at least I think) informative but it was also quite a lot to read. So I´ll split up the solutions to my self created tasks into smaller chunks, thus will make it easier to read, understand and find (if you search for the problem).&lt;br /&gt;&lt;br /&gt;So how will task 2 be divided?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.1 Recreating the customers network&lt;/span&gt;&lt;br /&gt;         Basic OSPF configuration on routers and PIX/ASA&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.2 Adding security features and VPN endpoint routers&lt;/span&gt;&lt;br /&gt;         Enabling OSPF MD5 Authentication on PIX/ASA and Routers&lt;br /&gt;         Adding new VPN edge routers to the OSPF Network&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.3 Creating ISP Access&lt;/span&gt;&lt;br /&gt;         Basic OSPF Configuration between 3 ISPs (nothing fancy)&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.4 Creating HSRP on the VPN endpoint routers&lt;/span&gt;&lt;br /&gt;         Basic HSRP Configuration on the two VPN routers&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.5 Adding VPN Support for VPN Clients&lt;/span&gt;&lt;br /&gt;         Creating VPN access on VPN Edge routers&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.6 Adding Site 2 Site VPN&lt;/span&gt;&lt;br /&gt;         Creating Site2Site VPN between routers and PIX/ASA&lt;br /&gt;         &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.7 Adding network extension mode Clients (NEM)&lt;/span&gt;&lt;br /&gt;         Creating VPN hardware clients (Routers and PIX/ASA)for NEM access&lt;br /&gt;          &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 2.8 Full Redundancy &lt;/span&gt;&lt;br /&gt;         Enabling SSO on Routers&lt;br /&gt;&lt;br /&gt;The next few days I´ll post solution step by step. But first some pictures to explain the network concept.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s1600-h/Network+Base.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 136px;" src="http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s200/Network+Base.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5320034704097772114" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is the basic network that I´ve found at the customer location. The routers of the inner core routing network are running OSPF with no security features enabled the routers are most times non Cisco products but since we focus on Cisco network devices we ignore this fact. ;)&lt;br /&gt;The outer core routing network is nearly the same like the inner core routing network but in future the customer plans to divide those network parts more. (but this is future planing and not covered here). Last is the edge network, this part contains network devices that connect to the Internet. In this scenario the primary edge is a ASA/ PIX but in the customer scenario there is an other firewall device in place (but this fact is ignored to ;) )&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_qoVkk4XAzPw/SdSPYHf-vRI/AAAAAAAAACo/pIWKR-xYWfo/s1600-h/Second+Phase.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 180px; height: 200px;" src="http://1.bp.blogspot.com/_qoVkk4XAzPw/SdSPYHf-vRI/AAAAAAAAACo/pIWKR-xYWfo/s200/Second+Phase.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5320034704324214034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here you can see the planed next stage, where two VPN routers are placed in the edge network. These routers are connected to two independent ISPs routers for redundancy issues.&lt;br /&gt;&lt;br /&gt;As always if you got questions just drop a not into the comments.&lt;br /&gt;More to come.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4856955758189581793?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4856955758189581793/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-vpn-network-with-ospf-on-pix-asa-and.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4856955758189581793'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4856955758189581793'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-vpn-network-with-ospf-on-pix-asa-and.html' title='EN - VPN network with OSPF on PIX/ ASA and routers (Task 2)'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qoVkk4XAzPw/SdSPYGp_glI/AAAAAAAAACg/YTa9gmy1bx0/s72-c/Network+Base.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1114212245289455393</id><published>2009-04-02T02:53:00.001+02:00</published><updated>2009-04-02T10:23:53.626+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>EN/ DE – Blogchanges</title><content type='html'>Nach dem ich etwas bei &lt;a href="http://technorati.com/"&gt;Technorati&lt;/a&gt; mit dem Tag Cloud widget gespielt habe, habe ich unsere Blogtags überarbeitet. Ich hoffe es gefällt so.&lt;br /&gt;&lt;br /&gt;After playing a bit with the &lt;a href="http://technorati.com/"&gt;Technorati&lt;/a&gt; tag cloud widget I’ve reviewed our tags and changed a lot. Hope you like it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1114212245289455393?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1114212245289455393/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-de-blogchanges-nach-dem-ich-etwas.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1114212245289455393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1114212245289455393'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/en-de-blogchanges-nach-dem-ich-etwas.html' title='EN/ DE – Blogchanges'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7551226345239161657</id><published>2009-04-01T12:10:00.006+02:00</published><updated>2009-04-02T02:56:32.862+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE/ ENG - www.PlayingWithNetworks.com</title><content type='html'>Nun der Titel sagt es ja schon ganz gut. Wir sind jetzt auch unter der Domain &lt;a href="http://www.PlayingWithNetworks.com"&gt;www.PlayingWithNetworks.com&lt;/a&gt; zu erreichen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well the topic says it all. We now can be reached with the domain &lt;a href="http://www.PlayingWithNetworks.com"&gt;www.PlayingWithNetworks.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7551226345239161657?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7551226345239161657/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-eng-wwwplayingwithnetworkscom.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7551226345239161657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7551226345239161657'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/04/de-eng-wwwplayingwithnetworkscom.html' title='DE/ ENG - www.PlayingWithNetworks.com'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8402112362905682625</id><published>2009-03-29T14:01:00.001+02:00</published><updated>2009-04-02T02:05:42.602+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='rommon'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><title type='text'>DE- ASA Passwort Wiederherstellung – Hinweis</title><content type='html'>Wenn man mal in die Verlegenheit kommt und auf einer ASA die Passwortwiederherstellungsprozedur durchführen zu müssen wie auf der Cisco Seite beschrieben, (&lt;a href="http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/trouble.html#wp1058131"&gt;Passwort Recovery Guide&lt;/a&gt;) kann es zu merkwürdigen Symptomen kommen. Ich habe Gestern eine ganze Weile damit zugebracht herauszufinden warum auf einer Kunden ASA das PPPOE plötzlich nicht mehr ging. Nach einiger Zeit und der Tatsache das ein Debug auf PPPOE gar nichts brachte, konnte ich heraus finden das das Register der ASA nicht passte. Es zeigte sich dann, dass das zurücksetzen des Konfigurationsregisters zusammen mit einem Neustart das Problem restlos löste. Ergo hing die ASA die ganze Zeit im Passwortwiederherstellungsprozess. Interessanterweise funktionierte der Rest der aktivierten ASA Features wie gewohnt.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8402112362905682625?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8402112362905682625/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-asa-passwort-wiederherstellung.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8402112362905682625'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8402112362905682625'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-asa-passwort-wiederherstellung.html' title='DE- ASA Passwort Wiederherstellung – Hinweis'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7330228374775879302</id><published>2009-03-29T14:00:00.000+02:00</published><updated>2009-04-02T02:05:42.603+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='rommon'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><title type='text'>EN - ASA Password recovery - something to note</title><content type='html'>If you are doing ASA password recovery like it is discribed on CISCO.com &lt;br /&gt;(&lt;a href="http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/trouble.html#wp1058131"&gt;Recovery procedure link&lt;/a&gt;)&lt;br /&gt;One thing you might notice that some functions are not working as expected. Well the „disable system configuration?“ question has to be answerd with „Yes“ so sure nothing should realy work. &lt;br /&gt;Yesterday I spend quite a lot of time till I recognised that the ASA was nearly working except for the PPPOE part. A debug on pppoe showed ..well nothing. After some time I figured that the customer did not switch the configuration register back to the defaults and did not do a reload, so we were still hanging in the password recovery process. Switching back the configuration register, reloading and hurray the ASA was back up online. Interesstingly the rest of the activated features worked like a charm.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7330228374775879302?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7330228374775879302/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/en-asa-password-recovery-something-to.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7330228374775879302'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7330228374775879302'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/en-asa-password-recovery-something-to.html' title='EN - ASA Password recovery - something to note'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-157692165750205871</id><published>2009-03-27T13:26:00.003+01:00</published><updated>2009-04-15T21:58:11.950+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='on-a-stick'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>DE - 'Router on a Stick' oder "Inter VLAN routing"</title><content type='html'>Hallo zusammen,&lt;br /&gt;&lt;br /&gt;ich versuche heute einmal in einfachen Schritten das Inter-VLAN Routing zu erläuterm.&lt;br /&gt;Weil ich mein Heim noch nicht mit Routern und Switchen tapeziert habe, habe ich Dynamips aus dem GNS3 Paket benutzt.&lt;br /&gt;&lt;br /&gt;Das folgende Setup habe ich mit 3725er Routern gebaut:&lt;br /&gt;R0 ist der &lt;span style="font-style:italic;"&gt;eigentliche&lt;/span&gt; Rrouter.&lt;br /&gt;R2 habe ich als Switch im Einsatz. In Slot1 steckt ein NM-16ESW welches den Switch darstellt.&lt;br /&gt;Host1 und Host2 stellen sind wie der Name schon erahnen lässt, lediglich Hosts.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s1600-h/intervlan.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 216px;" src="http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s320/intervlan.jpg" border="0" alt="inter vlan routing" id="BLOGGER_PHOTO_ID_5317264201892814290" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ich werde nur die Zeilen der Config posten, die nicht standartmäßig drin sind.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;R0&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname R0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; no ip address&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0.100&lt;br /&gt; encapsulation dot1Q 100&lt;br /&gt; ip address 10.0.100.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0.200&lt;br /&gt; encapsulation dot1Q 200&lt;br /&gt; ip address 10.0.200.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; no ip address&lt;br /&gt; shutdown&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;ip route 10.0.100.0 255.255.255.0 FastEthernet0/0.100&lt;br /&gt;ip route 10.0.200.0 255.255.255.0 FastEthernet0/0.200&lt;/code&gt;&lt;/pre&gt;Für jedes VLAN muss ein Subinterface angelegt werden. Ich empfehle die VLAN-Nummern als Sub-IFnummer zu benutzen, aber das ist jedem freigelassen.&lt;br /&gt;Als erstes muß auf dem Subinterface der encapsulation Befehl abgesetzt werden.&lt;br /&gt;&lt;code&gt;encapsulation dot1Q &amp;lt;vlan ID&amp;gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Um das Routing zwischen den VLANs einzuschalten kann man entweder statisches Routing nutzen, oder aber ein belieibiges Routing Protokoll. Ich habe statitische Routen benutzt, die jedes Subnetz über das zugehörige Subinterface erreichbar machen.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;R2&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname R2&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description Link to R0&lt;br /&gt; switchport mode trunk&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/5&lt;br /&gt; description Link to Host1&lt;br /&gt; switchport access vlan 100&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/10&lt;br /&gt; description Link to Host2&lt;br /&gt; switchport access vlan 200&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;Da dieser Router lediglich als L2 Switch dient, sind keinerlei IP Adressen konifguriert. Normalerweise sollte zumindest eine Management IP auf irgend ein VLAN gebunden werden.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Host1&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname Host1&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.0.100.100 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/0&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;Da diese Router lediglich Hosts simulieren sollen, haben sie eine Defaultroute die auf das ausgehende Interface zeigt, und somit das Default Gateway darstellt.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Host2&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname Host2&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.0.200.200 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/0&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Ich empfehle dringend (eigentlich in jeder Config) &lt;code&gt;speed&lt;/code&gt; und &lt;code&gt;duplex&lt;/code&gt; Befehle, um "Missmatch"-Errors zu vermeiden.&lt;br /&gt;&lt;br /&gt;Für Fragen benutzt einfach die Kommentar-Funktion.&lt;br /&gt;Regards,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-157692165750205871?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/157692165750205871/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/ip-cef-ip-vrf-vpn2-rd-2001-route-target.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/157692165750205871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/157692165750205871'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/ip-cef-ip-vrf-vpn2-rd-2001-route-target.html' title='DE - &apos;Router on a Stick&apos; oder &quot;Inter VLAN routing&quot;'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s72-c/intervlan.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-3739718157716079869</id><published>2009-03-25T23:49:00.000+01:00</published><updated>2009-04-15T21:58:11.950+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='on-a-stick'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>EN - 'Router on a Stick' or Inter VLAN routing</title><content type='html'>Hey again,&lt;br /&gt;&lt;br /&gt;I try to explain in simple steps how to do inter vlan routing.&lt;br /&gt;Due to the lack of real equipment @home I used dynamips from the GNS3 package.&lt;br /&gt;&lt;br /&gt;I built the folowing setup using 3725 routers.&lt;br /&gt;R0 is the &lt;span style="font-style:italic;"&gt;real&lt;/span&gt; router.&lt;br /&gt;R2 is used as switch. In Slot1 I inserted a NM-16ESW which simulates the switch.&lt;br /&gt;Host1 and Host2 are used as host only.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s1600-h/intervlan.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 216px;" src="http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s320/intervlan.jpg" border="0" alt="inter vlan routing" id="BLOGGER_PHOTO_ID_5317264201892814290" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will only post non-auto config lines.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;R0&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname R0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; no ip address&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0.100&lt;br /&gt; encapsulation dot1Q 100&lt;br /&gt; ip address 10.0.100.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0.200&lt;br /&gt; encapsulation dot1Q 200&lt;br /&gt; ip address 10.0.200.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; no ip address&lt;br /&gt; shutdown&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;ip route 10.0.100.0 255.255.255.0 FastEthernet0/0.100&lt;br /&gt;ip route 10.0.200.0 255.255.255.0 FastEthernet0/0.200&lt;/code&gt;&lt;/pre&gt;For each VLAN a subinterface has to be created. I recommend using the VLAN number but there are no rule for it.&lt;br /&gt;When configuring the subinterfaces enter first the encapsulation command.&lt;br /&gt;&lt;code&gt;encapsulation dot1Q &amp;lt;vlan ID&amp;gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;To enable routing between VLANs you need either static routes or a routing protocol. I used static routes pointing for each subnet to its related subinterface.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;R2&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname R2&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description Link to R0&lt;br /&gt; switchport mode trunk&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/5&lt;br /&gt; description Link to Host1&lt;br /&gt; switchport access vlan 100&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;!&lt;br /&gt;interface FastEthernet1/10&lt;br /&gt; description Link to Host2&lt;br /&gt; switchport access vlan 200&lt;br /&gt; duplex full&lt;br /&gt; speed 100&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;Due to this router is used as Switch only, there are no IP addresses configured. In a real scenario there would be at least a management IP normaly bound on a VLAN.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Host1&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname Host1&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.0.100.100 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/0&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;Due to these routers are (mis)used as host, the have an default gateway pointing at the outgoing interface. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Host2&lt;/span&gt;&lt;pre&gt;&lt;code&gt;hostname Host2&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.0.200.200 255.255.255.0&lt;br /&gt; speed 100&lt;br /&gt; full-duplex&lt;br /&gt;!&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 FastEthernet0/0&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;I highly recommend (in every environment) to use the &lt;code&gt;speed&lt;/code&gt; and &lt;code&gt;duplex&lt;/code&gt; settings to avoid running in mismatch errors!&lt;br /&gt;&lt;br /&gt;For questions just use the comment section.&lt;br /&gt;Regards,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-3739718157716079869?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/3739718157716079869/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/en-router-on-stick-or-inter-vlan.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3739718157716079869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/3739718157716079869'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/en-router-on-stick-or-inter-vlan.html' title='EN - &apos;Router on a Stick&apos; or Inter VLAN routing'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Xv6C9sn9zDM/Scq3npq43dI/AAAAAAAAAA0/Da7x2mQrFL0/s72-c/intervlan.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1802401169899075362</id><published>2009-03-25T22:31:00.000+01:00</published><updated>2009-04-02T02:08:30.508+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>DE - Configuration Basics</title><content type='html'>Hallo zusammen,&lt;br /&gt;Ich bin der Neue ;)&lt;br /&gt;Ich will hier mit einigen initialen Konfigurationsschritten, die bei jedem jungreulichem Router oder Switch abgesetzt werden sollten.&lt;br /&gt;&lt;br /&gt;Wenn das Gerät startet, steht normalerweise folgender Prompt:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;Would you like to enter the initial configuration dialog? [yes/no]:&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Natürlich antwortet man hier mit "no". Ehrlich gesagt habe ich keine Ahnung was kommt, wenn man "yes" sagt ;)&lt;br /&gt;Damit man mit der CLI ordentlich arbeiten kann, kopiert einfach die folgenden Zeilen und fügt sie in der CLI ein:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;enable&lt;br /&gt;configure terminal&lt;br /&gt;line console 0&lt;br /&gt;logging synchronous&lt;br /&gt;exec-timeout 0 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Diese Kommandos tun folgendes:&lt;br /&gt;&lt;code&gt;enable&lt;/code&gt; - führt euch in den "priveledge mode"&lt;br /&gt;&lt;code&gt;configure terminal&lt;/code&gt; - führt euch in den "config mode"&lt;br /&gt;&lt;code&gt;line console 0&lt;/code&gt; - wählt den Konsolenport zur Konfiguration aus.&lt;br /&gt;&lt;code&gt;logging synchronous&lt;/code&gt; - noch jedem vom Router/Switch generiertem Output wird ein Zeilenumbruch eingefügt&lt;br /&gt;&lt;code&gt;exec-timeout 0 0&lt;/code&gt; - der Session timeout wird abgeschaltet&lt;br /&gt;&lt;br /&gt;Diese wenigen Zeilen werden euch helfen auf der CLI die Übersicht zu behalten.&lt;br /&gt;&lt;br /&gt;Gruß,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1802401169899075362?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1802401169899075362/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/configuration-basics_25.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1802401169899075362'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1802401169899075362'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/configuration-basics_25.html' title='DE - Configuration Basics'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2418229182599974653</id><published>2009-03-25T22:11:00.000+01:00</published><updated>2009-04-02T02:08:30.508+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><title type='text'>EN - Configuration Basics</title><content type='html'>Hey gals'n guys,&lt;br /&gt;I am the new one ;) &lt;br /&gt;Lets start with some basic configuration steps, which should be applied to every maiden-like router or switch.&lt;br /&gt;&lt;br /&gt;Every device startup should end in folowing prompt:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Would you like to enter the initial configuration dialog? [yes/no]: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Of course chose "no" due to I have no idea what happens when chosing "yes" ;)&lt;br /&gt;Now to get the CLI working smoothly you can copy and paste the following lines:&lt;br /&gt;&lt;br /&gt;&lt;code&gt;enable&lt;br /&gt;configure terminal&lt;br /&gt;line console 0&lt;br /&gt;logging synchronous&lt;br /&gt;exec-timeout 0 0&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;The shown commands do:&lt;br /&gt;&lt;code&gt;enable&lt;/code&gt; - priveledge mode&lt;br /&gt;&lt;code&gt;configure terminal&lt;/code&gt; - enter config mode&lt;br /&gt;&lt;code&gt;line console 0&lt;/code&gt; - select console port for configurations&lt;br /&gt;&lt;code&gt;logging synchronous&lt;/code&gt; - after each router/switch generated output a carriage return (CR) is inserted&lt;br /&gt;&lt;code&gt;exec-timeout 0 0&lt;/code&gt; - the session timeout is disabled&lt;br /&gt;&lt;br /&gt;This will help help to keep track of the following configuration.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Zif&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2418229182599974653?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2418229182599974653/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/configuration-basics.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2418229182599974653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2418229182599974653'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/configuration-basics.html' title='EN - Configuration Basics'/><author><name>Zif</name><uri>http://www.blogger.com/profile/08597276547168753974</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://bp2.blogger.com/_Xv6C9sn9zDM/R8ahCS2ZNCI/AAAAAAAAAAM/SvX9SS-3llo/S220/200px-V_mask.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8952413339635516018</id><published>2009-03-25T01:21:00.000+01:00</published><updated>2009-04-02T02:10:40.078+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>ENG – Task 2 VPN Networks</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Task 2&lt;/span&gt;&lt;br /&gt;Add two routers to an existing OSPF Network.&lt;br /&gt;Terminate several VPN types on this routers and try to implement high availibilty.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools&lt;/span&gt;&lt;br /&gt;GNS3&lt;br /&gt;&lt;span style="font-style:italic;"&gt;existing network core:&lt;/span&gt; &lt;br /&gt;- 3x 3660 IOS 12.3.26&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;VPN edge routers:&lt;/span&gt;&lt;br /&gt;- 2x 3725 IOS 12.4.15T8&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;ISP Routers:&lt;/span&gt;&lt;br /&gt;- 3x 2691 IOS 12.4.15T7&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;VPN Devices:&lt;/span&gt;&lt;br /&gt;- 2x PIX 7.2.4&lt;br /&gt;- 2x 2610 12.4.15T7&lt;br /&gt;- 1x Cisco VPN client 5.0.x&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8952413339635516018?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8952413339635516018/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-task-2-vpn-networks.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8952413339635516018'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8952413339635516018'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-task-2-vpn-networks.html' title='ENG – Task 2 VPN Networks'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4369670616722661309</id><published>2009-03-25T01:17:00.000+01:00</published><updated>2009-04-02T02:10:40.078+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>DE - Aufgabe 2 - VPN Netzwerke</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Aufgabe 2&lt;/span&gt;&lt;br /&gt;Anbinden zweier Router an ein bestehendes OSPF - Netz.&lt;br /&gt;Terminierung dieverser VPN Arten auf den Routern moeglichst ausfallsicher.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Tools&lt;/span&gt;&lt;br /&gt;GNS3&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Bestehender Netzwerk Kern:&lt;/span&gt; &lt;br /&gt;- 3x 3660 IOS 12.3.26&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;VPN Perimeterrouter:&lt;/span&gt;&lt;br /&gt;- 2x 3725 IOS 12.4.15T8&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;ISP Router:&lt;/span&gt;&lt;br /&gt;- 3x 2691 IOS 12.4.15T7&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;VPN Endpunkte:&lt;/span&gt;&lt;br /&gt;- 2x PIX 7.2.4&lt;br /&gt;- 2x 2610 12.4.15T7&lt;br /&gt;- 1x Cisco VPN client 5.0.x&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4369670616722661309?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4369670616722661309/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-aufgabe-2-vpn-netzwerke.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4369670616722661309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4369670616722661309'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-aufgabe-2-vpn-netzwerke.html' title='DE - Aufgabe 2 - VPN Netzwerke'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1274618622540071531</id><published>2009-03-25T00:25:00.000+01:00</published><updated>2009-04-02T01:56:53.435+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>ENG- Zif joined</title><content type='html'>From now on &lt;a href="http://zifs.blogspot.com/"&gt;Zif&lt;/a&gt; will, depending on his time. Add some nice configs and tips for the routing topics.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1274618622540071531?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1274618622540071531/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-zif-joined.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1274618622540071531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1274618622540071531'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-zif-joined.html' title='ENG- Zif joined'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-2289024265208485683</id><published>2009-03-25T00:24:00.000+01:00</published><updated>2009-04-02T01:56:53.435+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE - Zif an Bord</title><content type='html'>Seit Heute schreibt &lt;a href="http://zifs.blogspot.com/"&gt;Zif&lt;/a&gt; mit im Blog und wird sich, so er Zeit hat, um das Thema Routing kümmern&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-2289024265208485683?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/2289024265208485683/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-zif-bord.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2289024265208485683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/2289024265208485683'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-zif-bord.html' title='DE - Zif an Bord'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6314311250970024199</id><published>2009-03-24T00:40:00.000+01:00</published><updated>2009-04-02T02:11:56.206+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>DE – Tools update</title><content type='html'>In den letzten Wochen hat sich mein Lab doch etwas verändert, daher hier ein kurzes Update.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;GNS3&lt;/span&gt; Version 0.6&lt;br /&gt;&lt;br /&gt;Ich musste feststellen das die &lt;span style="font-style:italic;"&gt;7200 Router&lt;/span&gt; ab einer bestimmten Anzahl dazu tendieren einfach so zu crashen. Bei meinem Arbeitsnotebook ist das zwischen 3 und 4 Router. Daher habe ich die Wahl dieser Boxen verworfen. Seit kurzem setze ich daher auf 3725, ich wollte zuerst die 3745er nehmen aber die leiden unter einem Dynamips Bug und so kann man die Konfig nicht reimportieren nachdem man sie gespeichert hat. Die &lt;span style="font-weight:bold;"&gt;3725&lt;/span&gt; laufen mit dem IOS &lt;span style="font-weight:bold;"&gt;12.4.15T8&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Ach so ich habe eine der &lt;span style="font-weight:bold;"&gt;5505 ASA&lt;/span&gt;s ausgetauscht gegen eine &lt;span style="font-weight:bold;"&gt;5510&lt;/span&gt; aber leider ist die Box im produktiven Umfeld. Daher wird es auf der keinen großen außergewöhnlichen Configs geben.&lt;br /&gt;&lt;br /&gt;Bei VMWare bleibt alles beim alten.&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6314311250970024199?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6314311250970024199/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-tools-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6314311250970024199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6314311250970024199'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-tools-update.html' title='DE – Tools update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6669544080618140010</id><published>2009-03-24T00:28:00.000+01:00</published><updated>2009-04-02T02:11:56.207+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>ENG – Tools update</title><content type='html'>Well within the last weeks my environment slightly changed.&lt;br /&gt;&lt;br /&gt;Just to give you a quick update&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;GNS3&lt;/span&gt; version 0.6 &lt;br /&gt;&lt;br /&gt;I've noticed that the &lt;span style="font-style:italic;"&gt;7200 routers&lt;/span&gt; tend to crash, if you run more than a certain amount of them. On my notebook it is often between 3 or 4 7200 routers, even if the are doing nothing. I dropped them and only use them if I need features of &lt;span style="font-style:italic;"&gt;12.4.22T1&lt;/span&gt;.&lt;br /&gt;My main routers are now &lt;span style="font-weight:bold;"&gt;3725&lt;/span&gt;, I tried the 3745 but due to some kind of &lt;a href="http://7200emu.hacki.at/viewtopic.php?t=5606&amp;postdays=0&amp;postorder=asc&amp;start=15&amp;sid=77bdb6d2d01cd9cb1c6b58832f9f1a01"&gt;dynamips bug&lt;/a&gt; the do not re import saved configs. So I keep the 3725s running IOS &lt;span style="font-weight:bold;"&gt;12.4.15T8&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;I changed one of the &lt;span style="font-weight:bold;"&gt;ASA 5505&lt;/span&gt; to an &lt;span style="font-weight:bold;"&gt;ASA 5510&lt;/span&gt; but this equipment is now in productive environment so their is no big chance of using them in tricky configs. Both ASAs are still running &lt;span style="font-weight:bold;"&gt;v8.0.3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;VMWare stays the same &lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6669544080618140010?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6669544080618140010/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-tools-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6669544080618140010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6669544080618140010'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-tools-update.html' title='ENG – Tools update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1823444152178910069</id><published>2009-03-19T23:15:00.000+01:00</published><updated>2009-04-02T02:17:00.586+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>ENG - Hub-Spoke Configuration PIX/ASA - Task 1</title><content type='html'>Finlay I've had the time to write this blog entry. As you may have noticed I´ve done the post in German some days ago, no big deal since it is my mother tong.&lt;br /&gt;&lt;br /&gt;But back to the problem: creating a Hub Spoke VPN topology between 3 Cisco PIX. Where the two spoke PIX can send packets to each other&lt;br /&gt;&lt;br /&gt;At first a small break for theory.&lt;br /&gt;&lt;br /&gt;VPN networks are commonly divided into two topology schemes The first is Hub Spoke the other Full Mesh. &lt;br /&gt;Hub Spoke is somehow easier to manage, because all you have to do is make sure that your remote location can connect to the central side. Everything else can be configured at the central location.&lt;br /&gt;&lt;br /&gt;Full Mesh offers more redundancy and you don´t have to fear that your network is completely down if your central side is off-line In comparison to Hub Spoke Full mesh is harder to administrate &lt;br /&gt;&lt;br /&gt;In larger enterprises you often find both schemes together, Full Mesh connecting the country offices and hub spoke for the regional offices connecting to the country headquarters&lt;br /&gt;&lt;br /&gt;Now lets get started with solution to task 1&lt;br /&gt;Setting:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/ScLHF7cjXNI/AAAAAAAAABs/mp-cxDoNLyo/s1600-h/TASK.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 123px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/ScLHF7cjXNI/AAAAAAAAABs/mp-cxDoNLyo/s200/TASK.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5315029414921329874" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Used networks&lt;br /&gt;&lt;b&gt;192.168.1.0 /24&lt;/b&gt; - LAN main site ; routing via default route&lt;br /&gt;&lt;b&gt;192.168.2.0 /24&lt;/b&gt; – LAN at customer 1 location 1 (Cust_1); routing via default route&lt;br /&gt;&lt;b&gt;192.168.3.0 /24&lt;/b&gt; – LAN at customer 2 location (Cust_2); routing via default route&lt;br /&gt;&lt;b&gt;10.10.1.x  /30&lt;/b&gt; transfer network between ISP router and ASA/PIX; routing via default route&lt;br /&gt;&lt;b&gt;10.10.98.x /30&lt;/b&gt; transfer networks between ISP routers, routing via OSPF&lt;br /&gt;&lt;b&gt;10.10.99.x /32&lt;/b&gt; Management IP of the ISP Router; added to OSPF routing &lt;br /&gt;&lt;br /&gt;Used tools, router and software versions&lt;br /&gt;configuration and simulation using GNS3 + dynamips + PEMU&lt;br /&gt;3x router 7200 (IOS 12.4.24T) as ISP router&lt;br /&gt;3x router 1700 (IOS 12.3.26) as LAN hosts&lt;br /&gt;3x PIX 525 (ASA/PIX 8.0.3) as Firewall and VPN endpoints&lt;br /&gt;&lt;br /&gt;Step by step solution:&lt;br /&gt;&lt;b&gt;Configuration of the ISP zone&lt;br /&gt;&lt;i&gt;Interface creation at the routers:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: ISP_Main&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.1 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW_Main-e0 ###&lt;br /&gt; ip address 10.10.1.1 255.255.255.252&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP-Cust-2_f0/1 ###&lt;br /&gt; ip address 10.10.98.5 255.255.255.252&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink ISP-Cust-1_f1/0 ###&lt;br /&gt; ip address 10.10.98.1 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: ISP_Cust_1&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.3 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW_Cust_1-e0 ###&lt;br /&gt; ip address 10.10.1.5 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink to ISP_Cust_2-f1/0 ###&lt;br /&gt; ip address 10.10.98.10 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to ISP_Main-f1/0 ###&lt;br /&gt; ip address 10.10.98.2 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: ISP_Cust_2&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.2 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW-cust-2-e0 ###&lt;br /&gt; ip address 10.10.1.9 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP_Main-f0/1 ###&lt;br /&gt; ip address 10.10.98.6 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink ISP_Cust_1-f0/1 ###&lt;br /&gt; ip address 10.10.98.9 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Configuration of OSPF&lt;/b&gt;&lt;br /&gt;The task is easy but for the 3 internet routers I decided to work with a dynamic routing protocol OSPF&lt;br /&gt;Using the command &lt;i&gt;router ospf [prozess ID]&lt;/i&gt; will enable OSPF in your routers. The &lt;i&gt;network&lt;/i&gt; statements define the networks that will be redistributed into OSPF.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: ISP_Main&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.10.99.1&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.1 0.0.0.0 area 0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: ISP_Cust_1&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.2&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.3 0.0.0.0 area 0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: ISP_Cust_2&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.3&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.2 0.0.0.0 area 0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The main configuration tasks are now done. Just do a quick ping from the router to the other routers&lt;br /&gt;will ensure that the "Internet" works&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Note:&lt;/b&gt;&lt;br /&gt;I just wanted to use 12.4.24T and did get more trouble than necessary I´ve had to reconfigure quite a lot of times the IDLEPC value in Dynamips so that they do not consume all my CPU capacity. 3724 Router would have done the job running 12.4.15T8. This will be a lesson for me.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Configuration of the „Hosts“&lt;/b&gt;&lt;br /&gt;Create an IP on the connected Interface and configure a default route to the Firewall. Nothing more to do here.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: Host_Main&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.1.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: Host_Cust_1&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.2.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.2.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: Host_Cust_2&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.3.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.3.1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The configuration of this Hosts was done quick and after &lt;i&gt;no shutdown&lt;/i&gt; was issued on all Interfaces they could be pinged from the PIX.&lt;br /&gt;&lt;br /&gt;&lt;B&gt;Configuration of the PIX&lt;br /&gt;&lt;I&gt;Basics&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;In the first step  basic configuration on every ASA/PIX have been made. This means Interfaces, default routes to the ISPs and object groups.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW_Main&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.2 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.1.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.1 1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-1&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.6 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.2.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.5 1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-2&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.10 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.3.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.9 1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;All object groups are the same on all firewalls.&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main / FW-Cust-1 /FW-Cust-2&lt;/b&gt; &lt;br /&gt;object-group network OBJ_VPN_Main&lt;br /&gt; network-object 192.168.1.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer_1&lt;br /&gt; network-object 192.168.2.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer_2&lt;br /&gt; network-object 192.168.3.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer&lt;br /&gt; group-object OBJ_VPN_Customer_1&lt;br /&gt; group-object OBJ_VPN_Customer_2&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Site 2 Site VPNs have 3 characteristics that have to be configured&lt;br /&gt;&lt;br /&gt;1. Crypto ACLs that define what traffic has to be encrypted&lt;br /&gt;2. Tunnel groups that characterize the tunnel  &lt;br /&gt;3. ISAKMP and IPSEC parameters to build the tunnel.&lt;br /&gt;&lt;br /&gt;Crypto ACLs are somehow every time the same. Allow traffic from local network A to remote network B.&lt;br /&gt;The only thing to remember is that you have to apply a exact mirror on the other side of your VPN connection.&lt;br /&gt;So this nearly automatically leads to the following crypto ACLs.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Customer 1 ###&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer_1&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;access-list ACL_Cry_map_20 remark ### traffic for VPN to Customer 2 ###&lt;br /&gt;access-list ACL_Cry_map_20 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer_2&lt;br /&gt;access-list ACL_Cry_map_20 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-1&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Main Location ###&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Main&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-2&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Main Location ###&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Main&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;So far the traffic that has to be encrypted is defined. Now the tunnel has to be specified&lt;br /&gt;Together with several parameters the pre shared key is configured using the tunnel group.&lt;br /&gt;If you use PSK you should use of course long and complex keys and change them from time to time.&lt;br /&gt;Certificates may be an alternative for other scenarios but this will be covered in later tasks&lt;br /&gt;&lt;br /&gt;For site 2 site VPNs usually the IP Address of the remote endpoint is the name of the tunnel group.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main&lt;/b&gt;&lt;br /&gt;!   Tunnel Group for FW-Cust-1&lt;br /&gt;tunnel-group 10.10.1.6 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.6 ipsec-attributes&lt;br /&gt; pre-shared-key 1234567890&lt;br /&gt;!   Tunnel Group for FW-Cust-2&lt;br /&gt;tunnel-group 10.10.1.10 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.10 ipsec-attributes&lt;br /&gt; pre-shared-key 0987654321&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-1&lt;/b&gt;&lt;br /&gt;!   Tunnel Group for FW-Main&lt;br /&gt;tunnel-group 10.10.1.2 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.2 ipsec-attributes&lt;br /&gt; pre-shared-key 1234567890&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-2&lt;/b&gt;&lt;br /&gt;!   Tunnel Group for FW-Main&lt;br /&gt;tunnel-group 10.10.1.2 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.2 ipsec-attributes&lt;br /&gt; pre-shared-key 0987654321&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The last and biggest configuration block is for the ISAKMP and IPsec parameters and of course the matching between ISAKMP / IPSec parameters, the tunnel group and the ACLs.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main/ FW-Cust-1 / FW-Cust-2&lt;/b&gt;&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;crypto isakmp policy 100&lt;br /&gt; authentication pre-share&lt;br /&gt; encryption aes-256&lt;br /&gt; hash sha&lt;br /&gt; group 2&lt;br /&gt; lifetime 86400&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Creating the IPSec transform Sets&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main/ FW-Cust-1 / FW-Cust-2&lt;/b&gt;&lt;br /&gt;crypto ipsec transform-set TRANS_1 esp-aes-256 esp-sha-hmac&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Defining the crypto map to match the parameters with each other. It is only possible to match one Crypto map on a logical interface, but every crypto map offers enough space for 65534 static connections&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main&lt;/b&gt;&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.6&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside 20 match address ACL_Cry_map_20&lt;br /&gt;crypto map MAP_Outside 20 set peer 10.10.1.10&lt;br /&gt;crypto map MAP_Outside 20 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-1&lt;/b&gt;&lt;br /&gt;crypto ipsec transform-set TRANS_1 esp-aes-256 esp-sha-hmac&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.2&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-2&lt;/b&gt;&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.2&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Basically the VPN tunnels are now ready to do their job. Often NAT is configured on the firewall and even more often this fact is forgotten, so that the tunnel will not work.&lt;br /&gt;That is why the in this task is NAT zero configured. &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-1&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Main&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;device: FW-Cust-2&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Main&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Last but not least we have to enable that traffic can flow from one VPN tunnel to the other. This is by default not possible. Why VPN tunnel have the same security level and by design traffic within the same level is not allowed. Solution, enable&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;device: FW-Main&lt;/b&gt;&lt;br /&gt;same-security-traffic permit intra-interface &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;If everything works as expected we should now be able to ping from any host to the other hosts&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/ScLGt_K_yoI/AAAAAAAAABk/REiq9PIMcpw/s1600-h/Host_Cust_2.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 106px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/ScLGt_K_yoI/AAAAAAAAABk/REiq9PIMcpw/s200/Host_Cust_2.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5315029003604576898" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_qoVkk4XAzPw/ScLGtpUGMlI/AAAAAAAAABc/8dOFbmlxZng/s1600-h/Host_Main.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 102px;" src="http://1.bp.blogspot.com/_qoVkk4XAzPw/ScLGtpUGMlI/AAAAAAAAABc/8dOFbmlxZng/s200/Host_Main.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5315028997737165394" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_qoVkk4XAzPw/ScLGtfAoiRI/AAAAAAAAABU/tTlwM0KRJ80/s1600-h/Host_Cust_1.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 112px;" src="http://2.bp.blogspot.com/_qoVkk4XAzPw/ScLGtfAoiRI/AAAAAAAAABU/tTlwM0KRJ80/s200/Host_Cust_1.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5315028994971175186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The ASA and PIX will now show a MM_Actif if you run show crypto isakmp sa&lt;br /&gt;&lt;br /&gt;Feel free to comment, ask question or give feedback (corrections).&lt;br /&gt;cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1823444152178910069?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1823444152178910069/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-hub-spoke-configuration-pixasa-task.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1823444152178910069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1823444152178910069'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-hub-spoke-configuration-pixasa-task.html' title='ENG - Hub-Spoke Configuration PIX/ASA - Task 1'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qoVkk4XAzPw/ScLHF7cjXNI/AAAAAAAAABs/mp-cxDoNLyo/s72-c/TASK.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4744147297245967327</id><published>2009-03-16T09:41:00.000+01:00</published><updated>2009-04-02T02:14:57.895+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>DE – Tool für PEMU unter Windows</title><content type='html'>In der letzten Zeit habe ich viel mit Dynamips und PEMU gemacht und habe festgestellt das es oft anstrengend ist mehr als 2 PIX laufen zu lassen. Meistens ist nach 4 PIX Schluss da mein CPU bei 100% ist und selbst schreiben unmöglich wird. Am Freitag hat mir ein Kollege „Battle Encoder Shiraze“ als zusätzliches Tool empfohlen. Damit lassen sich einzelne CPU Prozesse limitieren. Ich war danach in der Lage 9 PIX und einen Router gleichzeitig laufen zu lassen.&lt;br /&gt;Es ist auf jeden Fall einen blick Wert&lt;br /&gt;&lt;br /&gt;&lt;a href="http://mion.faireal.net/BES/"&gt;BES 1.3.8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hoffentlich hilft es noch mehr Leuten als nur mir&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4744147297245967327?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4744147297245967327/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-tool-fur-pemu-unter-windows.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4744147297245967327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4744147297245967327'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-tool-fur-pemu-unter-windows.html' title='DE – Tool für PEMU unter Windows'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-4480521533608060293</id><published>2009-03-16T09:39:00.000+01:00</published><updated>2009-04-02T02:14:57.895+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>ENG - Tool for PEMU under Windows</title><content type='html'>Playing around with dynamips and pemu is sometime quite hard since running two or more PIX Firewalls costs a lot of resources. Usually running 4 PIX is the maximum I can run on my laptop before I hit 100% CPU Load. &lt;br /&gt;But on Friday a co-worker showed me „Battle Encoder Shiraze“ with this tool you are able to limit the CPU load of PEMU. Quite nice!! I was able to run about 9 PIX and 1 Router without problems.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://mion.faireal.net/BES/"&gt;BES 1.3.8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hope that helps&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-4480521533608060293?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/4480521533608060293/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-tool-for-pemu-under-windows.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4480521533608060293'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/4480521533608060293'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-tool-for-pemu-under-windows.html' title='ENG - Tool for PEMU under Windows'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-578767779865005993</id><published>2009-03-14T07:18:00.001+01:00</published><updated>2009-04-20T07:41:31.604+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>DE - Hub-Spoke Konfiguration Pix /ASA - Task 1</title><content type='html'>Endlich ist es geschafft und vor allem beschrieben. Also jetzt zur Frage Task 1 wie konfiguriere ich 2 Pixen so das sie mit der Zentralen Pix kommunizieren können und auch untereinander Daten verschicken können.&lt;br /&gt; &lt;br /&gt;Ein bisschen was zu Theorie aber vorab.&lt;br /&gt;Im VPN Netzwerken (nicht nur dort) kann man grundsätzlich zwischen zwei Topologie unterscheiden. Zum Einen Hub-Spoke und zum Anderen Full-Mesh Netzen.&lt;br /&gt;Hub Spoke Netze sind Zentral ausgerichtet. Alle Remotestandorte verbinden sich zu einer Zentrale und über diese findet auch die Kommunikation zwischen den Remotestandorten statt. Administrativ ist die Konfiguration vermeintlich sehr elegant, da der Administrator sich nur an einer Stelle Gedanken machen muss, wer worauf zugreifen darf. In den Remotestandorten muss nur sicherstellen werden das die Zentrale erreicht wird. Fällt die Zentrale oder die Verbindung dorthin aus, ist das Datentechnisch der Super GAU – der Ausdruck „Nichts geht mehr“ trifft es so ziemlich genau.&lt;br /&gt;&lt;br /&gt;Im Gegensatz dazu sind Full-Mesh Netzwerke ausfallsicher. Es gibt keine klare Zentrale und jeder Teilnehmer ist, an sich, mit jedem anderen vernetzt. Dies ermöglicht eine große Flexibilität falls einmal eine Lokation nicht erreichbar ist, sorgt aber im schlimmsten Fall auch für einen enormen administrativen Zusatzaufwand, da die Verbindungen konfiguriert, gemonitort und auch „gepflegt“ werden müssen.&lt;br /&gt;&lt;br /&gt;Oft findet man in großen Organisationen eine Mischform aus beiden Konzepten. So sind oft bei einer Firma die Landesfilialen untereinander mittels Full-Mesh Konzept verbunden, die Regionalbüros aber dann wiederum mittels Hub-Spoke Topologie an die Landesfiliale angebunden.&lt;br /&gt;&lt;br /&gt;Aber zurück zur Aufgabe&lt;br /&gt;Testaufbau:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_qoVkk4XAzPw/Sb2GxQbT34I/AAAAAAAAABE/HRxd6j7-Jwk/s1600-h/TASK.png"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 123px;" src="http://4.bp.blogspot.com/_qoVkk4XAzPw/Sb2GxQbT34I/AAAAAAAAABE/HRxd6j7-Jwk/s200/TASK.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5313551316148281218" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Verwendete Netzwerke:&lt;br /&gt;&lt;b&gt;192.168.1.0 /24&lt;/b&gt; - LAN in der Zentrale (Main); Routing via Default Route&lt;br /&gt;&lt;b&gt;192.168.2.0 /24&lt;/b&gt; – LAN bei Kunden 1 (Cust_1); Routing via Default Route&lt;br /&gt;&lt;b&gt;192.168.3.0 /24&lt;/b&gt; – LAN bei Kunden 2 (Cust_2); Routing via Default Route&lt;br /&gt;&lt;b&gt;10.10.1.x  /30&lt;/b&gt; Verbindungsnetze zwischen ISP Router und PIX/ASA ; Routing via Default Route&lt;br /&gt;&lt;b&gt;10.10.98.x /30&lt;/b&gt; Verbindungsnetze zwischen den ISP Routern, Routing via OSPF&lt;br /&gt;&lt;b&gt;10.10.99.x /32&lt;/b&gt; Management IP der ISP Router; in OSPF Routing eingebunden&lt;br /&gt;&lt;br /&gt;Verwendete Tools, Router, Software Versionen&lt;br /&gt;Konfiguration und Simulation GNS3 + Dynamips + Pemu&lt;br /&gt;3x Router 7200 (IOS 12.4.24T) als ISP Router&lt;br /&gt;3x Router 1700 (IOS 12.3.26) als LAN Hosts&lt;br /&gt;3x PIX 525 (ASA/PIX 8.0.3) als Firewall und VPN Endpunkt&lt;br /&gt;&lt;br /&gt;Schritt für Schritt Lösung der Aufgabe:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Konfiguration der ISP Zone&lt;br /&gt;&lt;i&gt;Anlegen der Interface auf den Routern:&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: ISP_Main&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.1 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW_Main-e0 ###&lt;br /&gt; ip address 10.10.1.1 255.255.255.252&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP-Cust-2_f0/1 ###&lt;br /&gt; ip address 10.10.98.5 255.255.255.252&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink ISP-Cust-1_f1/0 ###&lt;br /&gt; ip address 10.10.98.1 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: ISP_Cust_1&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.3 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW_Cust_1-e0 ###&lt;br /&gt; ip address 10.10.1.5 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink to ISP_Cust_2-f1/0 ###&lt;br /&gt; ip address 10.10.98.10 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink to ISP_Main-f1/0 ###&lt;br /&gt; ip address 10.10.98.2 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: ISP_Cust_2&lt;/b&gt;&lt;br /&gt;interface Loopback0&lt;br /&gt; description ### MGMT INT ###&lt;br /&gt; ip address 10.10.99.2 255.255.255.255&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; description ### FW-cust-2-e0 ###&lt;br /&gt; ip address 10.10.1.9 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; description ### Uplink ISP_Main-f0/1 ###&lt;br /&gt; ip address 10.10.98.6 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet1/0&lt;br /&gt; description ### Uplink ISP_Cust_1-f0/1 ###&lt;br /&gt; ip address 10.10.98.9 255.255.255.252&lt;br /&gt; duplex full&lt;br /&gt; speed auto&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Konfiguration des OSPF auf den Routern&lt;/b&gt;&lt;br /&gt;Auf wenn die Aufgabe einfach ist, wird für die drei Internet Router ein Routing Protokoll in der einfachsten Form implementiert.&lt;br /&gt;Mit dem Befehl &lt;i&gt;router ospf [Prozess ID]&lt;/i&gt; wird auf dem Router das OSPF Protokoll aktiviert. Die &lt;i&gt;network&lt;/i&gt; Statements definieren die Netze die im Routing verteilt werden sollen. In diesem Fall werden alle Netze nur im Area 0 des OSPF Netzwerks bekannt gegeben.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: ISP_Main&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.10.99.1&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.1 0.0.0.0 area 0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: ISP_Cust_1&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.2&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.0 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.3 0.0.0.0 area 0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: ISP_Cust_2&lt;/b&gt;&lt;br /&gt;router ospf 100&lt;br /&gt; router-id 10.99.99.3&lt;br /&gt; log-adjacency-changes&lt;br /&gt; network 10.10.1.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.4 0.0.0.3 area 0&lt;br /&gt; network 10.10.98.8 0.0.0.3 area 0&lt;br /&gt; network 10.10.99.2 0.0.0.0 area 0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Die Kernaufgaben auf den Routern sind damit abgeschlossen. Ein kurzes pingen der einzelnen Interfaces von jedem Router aus, ergab das das „Internet“ funktioniert.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Anmerkungen:&lt;/b&gt;&lt;br /&gt;Ich wollte unbedingt 12.4.24T einsetzen, und habe mir damit mehr Ärger als nötig eingehandelt, da die 72er Router regelmäßig nachdem sie konfiguriert wurden, mussten ihren IDLEPC Werte im Dynamips angepasst werden. 37er hätten es wohl auch getan und dann 12.4.15T8.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Konfiguration der LAN „Hosts“&lt;/b&gt;&lt;br /&gt;Einrichten einer IP auf dem angeschlossenen Interface und setzen einer statischen Default Router in Richtung der PIX war alles was hier zu konfigurieren war.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: Host_Main&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.1.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.1.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: Host_Cust_1&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.2.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.2.1&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: Host_Cust_2&lt;/b&gt;&lt;br /&gt;interface FastEthernet0&lt;br /&gt; ip address 192.168.3.2 255.255.255.0&lt;br /&gt; speed auto&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 192.168.3.1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Die Hosts waren schnell erledigt und nachdem ein &lt;i&gt;no shutdown&lt;/i&gt; auf allen Interfaces gesetzt war, konnte man sie auch von den PIXen nach deren Konfiguration erreichen.&lt;br /&gt;&lt;br /&gt;&lt;B&gt;Konfiguration der PIX&lt;br /&gt;&lt;I&gt;Grundlagen&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Als erstes wurden die Dinge, die es auf jeder PIX/ ASA gibt konfiguriert. Also in dem Fall die Interfaces, die (default) Routen zu den ISPs und die Optionalen Objekt Gruppen.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW_Main&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.2 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.1.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.1 1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-1&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.6 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.2.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.5 1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-2&lt;/b&gt;&lt;br /&gt;interface Ethernet0&lt;br /&gt; nameif IF_Outside&lt;br /&gt; security-level 0&lt;br /&gt; ip address 10.10.1.10 255.255.255.252&lt;br /&gt;&lt;br /&gt;interface Ethernet1&lt;br /&gt; nameif IF_Inside&lt;br /&gt; security-level 100&lt;br /&gt; ip address 192.168.3.1 255.255.255.0&lt;br /&gt;&lt;br /&gt;route IF_Outside 0.0.0.0 0.0.0.0 10.10.1.9 1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Die Objekt Gruppen sind auf allen drei PIXen identisch.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Geräte: FW-Main / FW-Cust-1 /FW-Cust-2&lt;/b&gt; &lt;br /&gt;object-group network OBJ_VPN_Main&lt;br /&gt; network-object 192.168.1.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer_1&lt;br /&gt; network-object 192.168.2.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer_2&lt;br /&gt; network-object 192.168.3.0 255.255.255.0&lt;br /&gt;object-group network OBJ_VPN_Customer&lt;br /&gt; group-object OBJ_VPN_Customer_1&lt;br /&gt; group-object OBJ_VPN_Customer_2&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Die definierten Objekt Gruppen werden vor allem in ACLs eingesetzt, da man dann die ACLs bereits durch das ändern der Objekt Definition anpassen kann. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Site 2 Site VPNs zeichnen sich durch 3 Punkte aus, die zwingend in der Konfiguration vorhanden sein müssen. &lt;br /&gt;&lt;br /&gt;1. ACLs die den zu verschlüsselnden Traffice definieren&lt;br /&gt;2. Eine Tunnelgruppe die den Tunnel charakterisiert  &lt;br /&gt;3. den ISAKMP und IPSEC Parametern um den Tunnel aufzubauen&lt;br /&gt;&lt;br /&gt;Die ACLs die die Tunnel definieren sind im Grunde genommen immer gleich. Erlaube Traffic von IP oder Netz A nach IP oder Netz B im Remote-Standort. Dabei ist nur zu beachten das die ACL gespiegelt auf dem anderen Teilnehmer zur Anwendung kommt.&lt;br /&gt;So ergibt sich für die Crypto ACLs folgender Inhalt:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW-Main&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Customer 1 ###&lt;br /&gt;!  Folgende Zeile erlaubt: Traffic von der Zentralen Main Seite zum Netz im Standort Cust_1&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer_1&lt;br /&gt;!  Folgende Zeile erlaubt: Traffic vom LAN Cust_2 zum LAN Cust_1 &lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;access-list ACL_Cry_map_20 remark ### traffic for VPN to Customer 2 ###&lt;br /&gt;!   Folgende Zeile erlaubt: Traffic aus dem Main LAN zum Netz Standort Cust_2&lt;br /&gt;access-list ACL_Cry_map_20 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer_2&lt;br /&gt;!   Folgende Zeile erlaubt: Traffic vom LAN Cust_2 zum LAN Cust_1 &lt;br /&gt;access-list ACL_Cry_map_20 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-1&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Main Location ###&lt;br /&gt;!   Folgende Zeile erlaubt:  Traffic vom LAN Cust_1 zum Main_LAN&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Main&lt;br /&gt;!   Folgende Zeile erlaubt:  Traffic vom LAN Cust_1 zum LAN Cust_2&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-2&lt;/b&gt;&lt;br /&gt;access-list ACL_Cry_map_10 remark ### traffic for VPN to Main Location ###&lt;br /&gt;!   Folgende Zeile erlaubt:  Traffic vom LAN Cust_2 zum Main LAN &lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Main&lt;br /&gt;!   Folgende Zeile erlaubt:  Traffic vom LAN Cust_2 zum LAN Cust_1&lt;br /&gt;access-list ACL_Cry_map_10 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Somit wäre definiert, welcher Traffic zu verschlüsseln ist. Jetzt muss Der Tunnel genauer definiert werden. Neben diversen Parametern lässt sich vor allem in der Tunnelgruppe der Pre Shared Key bestimmen. Setzt man PSK ein sollte dieser möglichst Lang und Komplex sein und von Zeit zur Zeit geändert werden. Alternativ lassen sich Zertifikate verwenden. Der Einfachheit der Aufgabe aber ist das hier außen vor.&lt;br /&gt;Für Site 2 Site VPNs werden in der Regel als Tunnelbezeichnung die IP Adresse der entfernten Seite der VPN Verbindung verwendet.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW-Main&lt;/b&gt;&lt;br /&gt;!   Tunnel Gruppe zur FW-Cust-1&lt;br /&gt;tunnel-group 10.10.1.6 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.6 ipsec-attributes&lt;br /&gt; pre-shared-key 1234567890&lt;br /&gt;!   Tunnel Gruppe zur FW-Cust-2&lt;br /&gt;tunnel-group 10.10.1.10 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.10 ipsec-attributes&lt;br /&gt; pre-shared-key 0987654321&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-1&lt;/b&gt;&lt;br /&gt;!   Tunnel Gruppe zur FW-Main&lt;br /&gt;tunnel-group 10.10.1.2 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.2 ipsec-attributes&lt;br /&gt; pre-shared-key 1234567890&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-2&lt;/b&gt;&lt;br /&gt;!   Tunnel Gruppe zur FW-Main&lt;br /&gt;tunnel-group 10.10.1.2 type ipsec-l2l&lt;br /&gt;tunnel-group 10.10.1.2 ipsec-attributes&lt;br /&gt; pre-shared-key 0987654321&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Als letzten und größten Block müssen die ISAKMP und IPSec Parameter der Tunnel festgelegt werden und natürlich ein Zuordnung zwischen ISAKMP/ IPSec Parametern, Tunnel Gruppe und ACLs erfolgen.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Geräte: FW-Main/ FW-Cust-1 / FW-Cust-2&lt;/b&gt;&lt;br /&gt;!   Definieren der ISAKMP Parameter auf allen 3 Firewall Geräten gleich&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;crypto isakmp policy 100&lt;br /&gt; authentication pre-share&lt;br /&gt; encryption aes-256&lt;br /&gt; hash sha&lt;br /&gt; group 2&lt;br /&gt; lifetime 86400&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Bestimmen des IPSec Transform Sets&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Geräte: FW-Main/ FW-Cust-1 / FW-Cust-2&lt;/b&gt;&lt;br /&gt;crypto ipsec transform-set TRANS_1 esp-aes-256 esp-sha-hmac&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Definieren der Crypto Map um die Parameter miteinander zu verknüpfen. Die Auswahl erfolgt beim Verbindungsaufbau über den bereits definierten Traffic durch die ACL.&lt;br /&gt;Es kann pro Logischem Interface nur eine Crypto map gebunden werden, aber jede Crypto map bietet theoretisch Platz für 65534 statische Verbindungen.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW-Main&lt;/b&gt;&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.6&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside 20 match address ACL_Cry_map_20&lt;br /&gt;crypto map MAP_Outside 20 set peer 10.10.1.10&lt;br /&gt;crypto map MAP_Outside 20 set transform-set TRANS_1&lt;br /&gt;!   Binden der Crypto Map auf das Extern Interface&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-1&lt;/b&gt;&lt;br /&gt;crypto ipsec transform-set TRANS_1 esp-aes-256 esp-sha-hmac&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.2&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-2&lt;/b&gt;&lt;br /&gt;crypto map MAP_Outside 10 match address ACL_Cry_map_10&lt;br /&gt;crypto map MAP_Outside 10 set peer 10.10.1.2&lt;br /&gt;crypto map MAP_Outside 10 set transform-set TRANS_1&lt;br /&gt;crypto map MAP_Outside interface IF_Outside&lt;br /&gt;crypto isakmp enable IF_Outside&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Grundlegend ist nun alle Bereit um als VPN Tunnel zu arbeiten. Oft wird jedoch vergessen das auf der PIX/ASA NAT definiert ist. Dann versucht die Firewall Aufgrund der NAT Regeln den Traffic im Tunnel zu NATen.&lt;br /&gt;Daher wird im Beisiel noch NAT 0 mit zugehöriger ACL konfiguriert. NAT 0 bedeutet das der Traffic der auf diese ACL zutrifft vom generellen NAT Prozess ignoriert wird. &lt;br /&gt;Wieder erfolgt die Konfiguration der ACLs nach dem Syntax Erlaube von Netz A nach Remote Netz B.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW-Main&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;!   Kein NAT für Verbindungen von Main Lan zu den Remote Standorten&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Main object-group OBJ_VPN_Customer&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 1 zu Kundennetz 1&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 1 zu Kundennetz 2&lt;br /&gt;access-list ACL_NAT_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;!   aktivieren der Nat Aufnahme für Traffic der der ACL entspricht und über das Interface IF_Outside geht&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-1&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 1 zum Main Netz&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Main&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 1 zu Kundennetz 2&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_1 object-group OBJ_VPN_Customer_2&lt;br /&gt;!   aktivieren der Nat Aufnahme für Traffic der der ACL entspricht und über das Interface IF_Outside geht&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Gerät: FW-Cust-2&lt;/b&gt;&lt;br /&gt;access-list ACL_NAT_0 remark ### Nat ZERO ###&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 2 zum Kundennetz 1&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Customer_1&lt;br /&gt;!   Kein NAT für Verbindungen von Kundennetz 2 zum Main Netz&lt;br /&gt;access-list ACL_Nat_0 extended permit ip object-group OBJ_VPN_Customer_2 object-group OBJ_VPN_Main&lt;br /&gt;!   aktivieren der Nat Aufnahme für Traffic der der ACL entspricht und über das Interface IF_Outside geht&lt;br /&gt;nat (IF_Outside) 0 access-list ACL_Nat_0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Zu Guterletz muss eine Restriktion der ASA / PIX aufgegeben werden, damit die Remote Netzwerke sich gegenseitig sehen können. Grundsätzlich dürfen Interfaces mit gleichem Security Level keine Daten austauschen. Dies wird generell mit folgendem Befehl aufgehoben.&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Gerät: FW-Main&lt;/b&gt;&lt;br /&gt;same-security-traffic permit intra-interface &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Wenn alles glatt gelaufen ist, sollten sich von allen Drei Hosts nun Pings zu den Remote Hosts absetzen lassen. &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKTk-RxI/AAAAAAAAAA8/wn-qUNyzYus/s1600-h/Host_Cust_2.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 106px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKTk-RxI/AAAAAAAAAA8/wn-qUNyzYus/s200/Host_Cust_2.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5313545149421078290" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKcwm3ZI/AAAAAAAAAA0/aj2crKyyOxQ/s1600-h/Host_Cust_1.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 112px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKcwm3ZI/AAAAAAAAAA0/aj2crKyyOxQ/s200/Host_Cust_1.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5313545151885794706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKOrOcLI/AAAAAAAAAAs/YJ_KTetyAcc/s1600-h/Host_Main.PNG"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 200px; height: 102px;" src="http://2.bp.blogspot.com/_qoVkk4XAzPw/Sb2BKOrOcLI/AAAAAAAAAAs/YJ_KTetyAcc/s200/Host_Main.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5313545148105126066" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Auf den PIXen /ASA zeigt sich ein „wunderschönes“ MM_Active sobald man show crypto isakmp sa eingibt.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Für Anregungen ,Idee und so weiter(gern auch Fragen und Richtigstellungen) bin ich gern zu haben. Einfach in die Kommentare posten.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Links zu den Konfigs&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/ISP_Main.txt"&gt;ISP1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/ISP_Cust_1.txt"&gt;ISP2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/ISP_Cust_2.txt"&gt;ISP3&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/Host_Main.txt"&gt;Host_Main&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/Host_Cust_1.txt"&gt;Host_Cust_1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/Host_Cust_2.txt"&gt;Host_Cust_2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/FW-Main.txt"&gt;FW-Main&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/FW-Cust-1.txt"&gt;FW-Cust-1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.unimatrix01.de/Tasks/FW-Cust-2.txt"&gt;FW-Cust-2&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-578767779865005993?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/578767779865005993/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-hub-spoke-konfiguration-pix-asa-task.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/578767779865005993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/578767779865005993'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-hub-spoke-konfiguration-pix-asa-task.html' title='DE - Hub-Spoke Konfiguration Pix /ASA - Task 1'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qoVkk4XAzPw/Sb2GxQbT34I/AAAAAAAAABE/HRxd6j7-Jwk/s72-c/TASK.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5511797808837439397</id><published>2009-03-14T02:38:00.000+01:00</published><updated>2009-04-02T02:17:55.880+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE / ENG Task 1 Update</title><content type='html'>Nachdem ich nun auf Seite 8 angekommen bin wird es morgen wohl ein Update zu Task 1 Geben (endlich) &lt;br /&gt;&lt;br /&gt;Since I´v just managed to complete the first 8 pages of the German description to Task 1 I think the update will take place within the next 3 days.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5511797808837439397?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5511797808837439397/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-eng-task-1-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5511797808837439397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5511797808837439397'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-eng-task-1-update.html' title='DE / ENG Task 1 Update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6419514759726974490</id><published>2009-03-04T21:16:00.000+01:00</published><updated>2009-04-02T01:56:53.436+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE - Diskussionen und die Erkenntnisse daraus</title><content type='html'>Vor einiger Zeit hatte ich eine interessante Diskussion mit &lt;a href="http://zifs.blogspot.com/"&gt;Zif&lt;/a&gt; einem Arbeitskollegen und gutem Freund über das Konfigurieren von Routern und Firewalls nur so zum Spaß. &lt;br /&gt;Ich glaube mittlerweile ist das basteln an Netzwerkkomponenten (echt oder virtuell) so was wie ein Hobby für mich geworden.&lt;br /&gt;Ähnlich wie ich noch vor einiger Zeit in diversen &lt;a href="http://de.wikipedia.org/wiki/MMORPG"&gt;MMORPGs&lt;/a&gt; Quests gelöst habe und mich über die EXP gefreut habe, freue ich mich jetzt darüber das eine Konfiguration so arbeitet wie ich es wollte. Es ist quasi eine &lt;a href="http://wow.buffed.de/guides/2306/tages-quests"&gt;DAILY Quest&lt;/a&gt; für mich geworden.&lt;br /&gt;Natürlich spiele ich hin und wieder auch noch MMOs aber das eher weniger aber auch viel bewusster.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6419514759726974490?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6419514759726974490/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-diskussionen-und-die-erkenntnisse.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6419514759726974490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6419514759726974490'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-diskussionen-und-die-erkenntnisse.html' title='DE - Diskussionen und die Erkenntnisse daraus'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-5560680184892788953</id><published>2009-03-04T21:06:00.000+01:00</published><updated>2009-04-02T01:56:53.436+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>ENG - Discussions</title><content type='html'>Some time ago I had a interesting discussion with &lt;a href="http://zifs.blogspot.com/"&gt;Zif&lt;/a&gt; a good friend and colleague about configuring routers and Firewalls just for fun.&lt;br /&gt;In this discussion I realized that playing around with networks is kind of entertainment in my spare time. &lt;br /&gt;In the past I used to play &lt;a href="http://en.wikipedia.org/wiki/Mmorpg"&gt;MMORPGs&lt;/a&gt; and solved quest and spent quite a lot of time hunting for EXPs and levels.&lt;br /&gt;Today I´m happy when a configuration works as i wanted.  It has become a kind of &lt;a href="http://www.wowwiki.com/Daily_quest"&gt;daily quest&lt;/a&gt; to me.&lt;br /&gt;Of course I´m still playing MMOs. ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-5560680184892788953?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/5560680184892788953/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-discussions.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5560680184892788953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/5560680184892788953'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-discussions.html' title='ENG - Discussions'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6343268888035798192</id><published>2009-03-04T13:54:00.000+01:00</published><updated>2009-04-02T02:18:42.762+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><title type='text'>DE- Update von IOS v12.4.22T auf 12.4.24T</title><content type='html'>Servus&lt;br /&gt;&lt;br /&gt;nachdem ich gestern ca. 8 Stunden bei einem Kunden mich mit 2 Router herumgeschlagen habe, konnte ich das Problem durch einen Releasewechsel von 12.4.22T auf 12.4.24T beheben. Ich glaube 22T ist keine gute Wahl für Router vor allem wenn man bedenkt das von den aktuell &lt;a href="http://tools.cisco.com/Support/BugToolKit/action.do?hdnAction=searchBugs"&gt;2015 Bugs&lt;/a&gt; 1200 innerhalb der letzten 3 Wochen hinzu kamen. AUA! &lt;br /&gt;Mal sehen wie sich 12.4.24T macht, ich will es mal in GNS3 testen.&lt;br /&gt;&lt;br /&gt;Cheers NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6343268888035798192?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6343268888035798192/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-update-von-ios-v12422t-auf-12424t.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6343268888035798192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6343268888035798192'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-update-von-ios-v12422t-auf-12424t.html' title='DE- Update von IOS v12.4.22T auf 12.4.24T'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-6424739655897146848</id><published>2009-03-04T13:52:00.000+01:00</published><updated>2009-04-02T02:18:42.762+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><title type='text'>ENG -Update from IOS 12.4.22T to 12.4.24T</title><content type='html'>Hi Folks&lt;br /&gt;&lt;br /&gt;after about 8 hours fighting with 2 routers on a customer location i solved the problem with switching from 12.4.22T to 12.4.24T, guess 22T is not a good choice for routers. According to the &lt;a href="http://tools.cisco.com/Support/BugToolKit/action.do?hdnAction=searchBugs"&gt;Bugtracking tool&lt;/a&gt; from the Cisco website their are 2015 Bugs level 1-3 listed. Approximately 1200 added within the last week. Ouch!&lt;br /&gt;Lets see how 12.4.24T is working. I´ll test this release in GNS3.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;NWG&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-6424739655897146848?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/6424739655897146848/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-update-from-ios-12422t-to-12424t.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6424739655897146848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/6424739655897146848'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-update-from-ios-12422t-to-12424t.html' title='ENG -Update from IOS 12.4.22T to 12.4.24T'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-8368090857792583546</id><published>2009-03-02T23:59:00.000+01:00</published><updated>2009-04-02T02:19:20.060+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>ENG - Why nothing new on Task 1</title><content type='html'>A small update on task 1&lt;br /&gt;since the task is not that hard nearly everything is working as desired but I´d like to write some comments on this task. This is the main part why I didn´t publish the post.&lt;br /&gt;But why no time? Well I´m involved in a project on a customer location with this setting:&lt;br /&gt;&lt;br /&gt;Network + 2Gate Routers – 2 ISP routers &lt;br /&gt;Aim: Build a 100% failsafe VPN solution. But of course we cant start from the scratch, we´ve got to pa attention to a grown configuration.&lt;br /&gt;&lt;br /&gt;More to come later&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-8368090857792583546?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/8368090857792583546/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-why-nothing-new-on-task-1.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8368090857792583546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/8368090857792583546'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/eng-why-nothing-new-on-task-1.html' title='ENG - Why nothing new on Task 1'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-263495173325837477</id><published>2009-03-02T23:50:00.000+01:00</published><updated>2009-04-02T02:19:20.061+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><title type='text'>DE - Aufgabe 1 kein Update</title><content type='html'>Warum nichts neues?&lt;br /&gt;&lt;br /&gt;Ganz kurzes update zu Aufgabe 1:&lt;br /&gt;Es ist soweit alles fast fertig und tut es auch so gut oder schlecht, da ich aber noch ein bisschen was dazu schreiben will noch kein Lösungspost.&lt;br /&gt;&lt;br /&gt;Warum ich keine Zeit habe? Ich sitze gerade an einem Problem eines Kunden:&lt;br /&gt;Netzwerk + 2 Gateway Router – 2 ISP Router &lt;br /&gt;Dabei soll eine möglichst 100% ausfallsicher VPN-Lösung gebaut werden. Leider gibt es keine grüne Fläche sondern eine über Jahre gewachsen Konfig.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-263495173325837477?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/263495173325837477/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-aufgabe-1-kein-update.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/263495173325837477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/263495173325837477'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/03/de-aufgabe-1-kein-update.html' title='DE - Aufgabe 1 kein Update'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-1800902056944191566</id><published>2009-02-27T10:08:00.000+01:00</published><updated>2009-04-02T02:22:49.551+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='basic'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><category scheme='http://www.blogger.com/atom/ns#' term='static route'/><title type='text'>DE/ ENG Basic VPN Hub-Spoke</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Aufgabe 1 &lt;/span&gt;&lt;br /&gt;Anbinden zweier PIX per VPN an eine Zentrale PIX.. (Hub-Spoke)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Task 1&lt;/span&gt;&lt;br /&gt;Building a VPN between 2 PIX and a main PIX. (Hub-Spoke)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools &lt;/span&gt;&lt;br /&gt;GNS3 &lt;br /&gt;* PIX Images v8.0.4&lt;br /&gt;* 3725 IOS 12.4.15T7 advanced security&lt;br /&gt;&lt;br /&gt;Setting:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_qoVkk4XAzPw/Saex68z-y1I/AAAAAAAAAAM/bcZa3ec44Ig/s1600-h/setting.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 270px;" src="http://3.bp.blogspot.com/_qoVkk4XAzPw/Saex68z-y1I/AAAAAAAAAAM/bcZa3ec44Ig/s320/setting.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5307406312194100050" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-1800902056944191566?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/1800902056944191566/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/02/de-eng-basic-vpn-hub-spoke.html#comment-form' title='1 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1800902056944191566'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/1800902056944191566'/><link rel='alternate' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/02/de-eng-basic-vpn-hub-spoke.html' title='DE/ ENG Basic VPN Hub-Spoke'/><author><name>NetWorkGuy</name><uri>http://www.blogger.com/profile/05375192099910018977</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://1.bp.blogspot.com/_qoVkk4XAzPw/Scq1iNjQURI/AAAAAAAAAB4/YI7YbFwsNt0/S220/WAR_gotrek.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qoVkk4XAzPw/Saex68z-y1I/AAAAAAAAAAM/bcZa3ec44Ig/s72-c/setting.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5977838822789730906.post-7156804045616311347</id><published>2009-02-26T23:17:00.000+01:00</published><updated>2009-04-02T02:20:45.987+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='smalltalk'/><category scheme='http://www.blogger.com/atom/ns#' term='asa'/><category scheme='http://www.blogger.com/atom/ns#' term='router'/><category scheme='http://www.blogger.com/atom/ns#' term='ios'/><category scheme='http://www.blogger.com/atom/ns#' term='gns3'/><category scheme='http://www.blogger.com/atom/ns#' term='pix'/><category scheme='http://www.blogger.com/atom/ns#' term='pemu'/><title type='text'>ENG - Tools and Hardware</title><content type='html'>To build my labs I use several tools here are some of them including some links&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Tools&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.gns3.net"&gt;GNS3&lt;/a&gt; – graphical interface for the router simulator Dynamips&lt;br /&gt;* mainly I use the 7200 routers with 12.4.22T IOS&lt;br /&gt;&lt;br /&gt;Pemu – PIX and ASA simulator&lt;br /&gt;* my PIX are running v7.2.4 or v8.0.4&lt;br /&gt;* the ASA is running v8.0.3&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.vmware.com"&gt;VMWare&lt;/a&gt; – nothing more to say I guess&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Hardware&lt;/span&gt;&lt;br /&gt;2x ASA 5505&lt;br /&gt;* both ASAs are running 8.0.4&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5977838822789730906-7156804045616311347?l=playingwithnetworks.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://playingwithnetworks.blogspot.com/feeds/7156804045616311347/comments/default' title='Kommentare zum Post'/><link rel='replies' type='text/html' href='http://playingwithnetworks.blogspot.com/2009/02/to-build-my-labs-i-use-several-tools.html#comment-form' title='0 Kommentare'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/7156804045616311347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5977838822789730906/posts/default/71568040456163113
