Core Knowledge Questions Removed for CCIE R&S and Voice Lab Exams

Cisco removed the Core Knowledge Questions section from the CCIE R&S and Voice Lab exams.

This sections STILL exist on CCIE Service Provider, CCIE Security, CCIE Storage Networking and  CCIE Wireless Lab.

Please find below the official announcement and the reasons regarding this section removal from R&S and Voice lab exams:

With more than six months of exam results now available, Cisco is able to report that the troubleshooting components of the CCIE R&S v4.0 and CCIE Voice v3.0 lab exams are performing well in validating expert level networking skills.  Considering these results, Cisco has decided to eliminate the Core Knowledge questions from the current CCIE R&S v4.0 and CCIE Voice v3.0 Lab Exams.  Beginning on May 10, 2010, CCIE R&S and CCIE Voice Lab Exams, in all global locations, will no longer include the four open-ended Core Knowledge questions.  The total lab time will remain eight hours.  For the CCIE R&S Lab Exam, this means candidates will begin with the two-hour Troubleshooting section, followed by a six-hour Configuration section.  For CCIE Voice, candidates will have the full eight hours to complete the integrated exam.  At this time, only the R&S and Voice tracks will be eliminating the Core Knowledge questions.
You can read more here:

https://learningnetwork.cisco.com/docs/DOC-6484

New Service Provider Operations Track Training and Exams

The Cisco CCNA Service Provider (SP) Operations certification and the written exam for the CCIE Service Provider (SP) Operations certification are now available.
The Cisco CCNA SP Operations certification targets entry-level students with a foundation of network operations skills in SP IP NGN environments required of associate-level operations personnel. Both the Supporting Cisco Service Provider IP NGN Operations (SSPO) course and required # 640-760 exam are now available. Interested students should access the CCNA SP Operations home page for more information.

The Cisco CCIE® SP Operations certification assesses and validates core IP NGN service provider network operations expertise and broad theoretical knowledge of operations management processes, frameworks and network management systems. Registration for the for CCIE SP Operations written exam is now available. In addition, students may download the blueprint for the CCIE SP Operations practical exam from the CCIE SP Operations practical exam overview page. The practical exam for the CCIE SP Operations certification is scheduled to be made available in the third quarter of 2010.

For more info:
https://learningnetwork.cisco.com/community/certifications/ccna_sp_operations
https://learningnetwork.cisco.com/index.jspa?ciscoHome=true
https://learningnetwork.cisco.com/community/certifications/ccie_sp_operations/practical_exam

Cisco: Mark voice packets at the network edge

You know how Cisco always advise to mark the packet as close to the your network edge as you can? Even more you can find a lot of example where Cisco show how to trust the packets directly on the access switch, but not all the time you can do this.

First because not everybody has devices that mark correct packets (like Cisco IP Phones) but we still have to deal somehow with packet marking as maybe your provider treat packets different on their backbone based on their marking.

In this idea what I’m taking care the most are the voice packets as usually this has to be prioritized on the network. Let’s face it, if you have a TCP connection and some FTP packet are retransmitted you don’t notice this too much, but if you have delay on your phone conversation with your boss, that it’s not so good.

Please have a look at the topology below:

qos voice packet marking

In this scenario we have a Voice server and some IP Phones (I know they look like Cisco IP phone, but pretend they are not) connected to the access switch. Let’s assume that  we cannot trust marking on this packets as they arrive from this devices.

Here we run into one of the two issues. First if we trust the marking on the access port, than we don’t know what we are stuck with. If we don’t trust them, then the packets header DiffServ (TOS) bits are rewrite with a value of zero making no difference between voice packets and regular ones.

My solution is the following. I’m not saying that’s the only solution or the best, but it’s working:

On the access switch:

1. enable globally:

mls qos

2. configure and access-list that match the voice packet; this is a very general list:

access-list 101 permit udp any any range 16384 32767
access-list 101 permit udp any range 16384 32767 any
access-list 101 permit udp any any range 5060 5061
access-list 101 permit udp any range 5060 5061 any

3. match the access-list in a class-map

class-map match-all VOIP
match access-group 101

4.configure a policy-map with the class-map above and set the DSCP value to EF (decimal 46) or COS or whatever you need

policy-map ASTERISK
class VOIP
set dscp ef

5.on the access port configure the service-policy direction inbound

int x/y
service-policy input ASTERISK

6.on all trunks from your access switch to your first Layer 3 device trust this DSCP  value (or what you have set, as now we are sure what values we set) with:

mls qos trust dscp

Let me know if it’s working!

INE released GNS3 config for v5 topology

A few days ago one friend on mine announced me that InternetworkExpert released a GNS3 configuration for their v5 topology.

When I had check INE’s website, I could not found the link to GNS3 topology. To be honest I was expecting INE to announce with big letters this new development, but I was quite silent (or I’m not reading carefully enough their website).

To fin GNS3 configuration, there is a small catch. You have to go to INE resources webpage, and from there to Dynamips (there is no GNS3 link). If you ever used the INE’s Dynamips config, that this page is familiar for you. Somewhere in the middle there is a link with “Click here to download the INE Topologies for Dynagen“. You download this archive file and inside you’ll find among other configuration a file called ine.routing.and.switching.topology.5.00.gns3.net:

INE V5 GNS3 topology config

This is the file which you are looking for. Of course you need to edit and adapt it to your local configuration (IOS, path location…).  What is different from Dynamips file? Almost nothing, but you have a graphical view of the topology and if you put your mouse over a link, you’ll see where is the connection pointing too. It can help you spare some time in the configuration, but there is a drawback. Don’t get used too much with this feature, as in the CCIE lab exam you don’t have where to point your mouse to show the connection and you have to figure it by your own from the paper (or lately computer screen).

If you don’t want to follow the steps above, then:

Download the INE’s v5 topology GNS3 configuration


How to emulate ASA in Ubuntu 9.10 and GNS3

Cisco ASA

Brainbump.net has an excellent and very complete how to emulate ASA using just the following components:

  • Ubuntu 9.10 – 32 bit Edition
  • GNS3 v0.7 RC1 tgz
  • Dynamips 0.2.8-RC2 binary for Linux x86 platforms
  • Qemu-0.11.0 tar.gz
  • Qemu-0.11.0 Patch
  • ASA Binary Version 8.0(2) – (asa802-k8.bin)

How-to is divided in 3 video tutorial parts for easy understanding and start with the most basic installation on GNS3 under Ubuntu 9.10 and continue with the actually configuration on the emulation.
If you are interested in security or you just want to test ASA and don’t have access to real hardware you definetely will want to try Brainbump.net tutorial.

READ THE FULL TUTORIAL on Brainbump.net