内容简介
Part Ⅰ The CCIE Program and Your Lab Environment
Chapter 1 The CCIE Security Program
The Cisco CCIE Program
The CCIE Security Exam
Qualification Exam
Lab Exam
Summary
Chapter 2 Building a CCIE Mind-Set
What It Takes to Become a CCIE
Developing Proper Study Habits
Good Study Habits
Common Study Traps
Lab Experience Versus Real-World Experience
Summary
Chapter 3 Building the Test Laboratory
Study Time on a Lab
Work-Based Study Lab
Home-Based Study Lab
Remote Lab
Planning Your Home Lab
Sourcing the Lab Equipment
Windows-based Products and UNIX
Designing Your Practice Lab for This Book
Summary
Part Ⅱ Connectlvity
Chapter 4 Layer 2 and Layer 3 Switching and LAN Connectivity
Catalyst Operating System
Switching Overview
Switching Technologies
Transparent Bridging
Spanning Tree Overview
Bridge Protocol Data Unit
Election Process
Spanning-Tree Interface States
Spanning-Tree Address Management
STP and IEEE 802.1q Trunks
VLAN-Bridge STP
STP and Redundant Connectivity
Accelerated Aging to Retain Connectivity
RSTP and MSTP
Layer 3 Switching Overview
Virtual LAN Overview
Assigning or Modifying VLANs
Deleting VLANs
Configuring Extended-Range VLANs
VLAN Trunking Protocol Overview
The VTP Domain
VTP Modes
VTP Passwords
VTP Advertisements
VTP Version 2
VTP Pruning
VTP Configuration Guidelines
Displaying VTP
Switch Interface Overview
Access Ports
Trunk Ports
Routed Ports
EtherChannel Overview
Port-Channel Interfaces
Understanding the Port Aggregation Protocol
EtherChannel Load Balancing and Forwarding Methods
EtherChannel Configuration Guidelines
Creating Layer 2 EtherChannels
Optional Configuration Items
BPDU Guard
BPDU Filtering
UplinkFast
BackboneFast
Loop Guard
Switched Port Analyzer Overview
SPAN Session
Configuring SPAN
Basic Catalyst 3550 Switch Configuration
Case Study 4-1: Basic Network Connectivity
Case Study 4-2: Configuring Interfaces
Case Study 4-3: Configuring PortFast
Case Study 4-4: Creating a Layer 2 EtherChannel
Case Study 4-5: Creating Trunks
Case Study 4-6: Configuring Layer 3 EtherChannels
Case Study 4-7: EtherChannel Load Balancing
Case Study 4-8: Configuring a Routed Port
Case Study 4-9: Configuring SPAN
Summary
Review Questions
FAQs
Chapter 5 Frame Relay Connectivity
Frame Relay Overview
Frame Relay Devices
Frame Relay Topologies
Star Topologies
Fully Meshed Topologies
Partially Meshed Topologies
Frame Relay Subinterfaces
Frame Relay Virtual Circuits
Switched Virtual Circuits
Permanent Virtual Circuits
Frame Relay Signaling
LMI Frame Format
LMI Timers
LMI Autosense
Network-to-Network Interface
User-Network Interface
Congestion-Control Mechanisms
Frame Relay Discard Eligibility
DLCI Priority Levels
Frame Relay Error Checking
Frame Relay ForeSight
Frame Relay Congestion Notification Methods
Frame Relay End-to-End Keepalives
Configuring Frame Relay
Case Study 5-1: Configuring Frame Relay
Case Study 5-2: Configuring Frame Relay SVCs
Case Study 5-3: Frame Relay Traffic Shaping
Creating a Broadcast Queue for an Interface
Transparent Bridging and Frame Relay
Configuring a Backup Interface for a Subinterface
TCP/IP Header Compression
Configuring an Individual IP Map for TCP/IP Header Compression
Configuring an Interface for TCP/IP Header Compression
Disabling TCP/IP Header Compression
Troubleshooting Frame Relay Connectivity
The show frame-relay lmi Command
The show frame-relay pvc Command
The show frame-relay map Command
The debug frame-relay lmi Command
Summary
Review Questions
FAQs
Chapter 6 ISDN Connectivity
ISDN Overview
ISDN Standards Support
ISDN Digital Channels
ISDN Terminal Equipment and Network Termination Devices
Reference Points
ISDN Layers and Call Stages
Point-to-Point Protocol (PPP) Overview
Link Control Protocol (LCP)
Network Control Protocol (NCP)
Dial-on-Demand Routing (DDR) Overview
Configuring ISDN
Lesson 6-1: Beginning ISDN Configuration
Lesson 6-2: Configuring DDR
Lesson 6-3: Routing Over ISDN
Lesson 6-4: Configuring the Interface and Backup Interface
Lesson 6-5: Configuring PPP Options
Lesson 6-6: Configuring Advanced Options
Lesson 6-7: Monitoring and Troubleshooting ISDN
Summary
Review Questions
FAQs
Chapter 7 ATM Connectivity
ATM Overview
Configuring ATM
Lesson 7-1: RFC 2684: Multiprotocol Encapsulation over AAL5
Lesson 7-2: RFC 2225: Classical IP and ARP over ATM
Summary
Review Questions
FAQs
Part Ⅲ IP Routing
Chapter8 RIP
RIP Structure
Routing Updates and Timers
Routing Metric
Split-Horizon Issues
RIP and Default Routes
RIPvl Versus RIPv2
Configuring RIP
Case Study 8-1: Basic RIP Configuration
Case Study 8-2: RIPv1 over Router to PIX 5.2 Connection
Case Study 8-3:RIPv2 over Router to PIX 6.2 Connection withAuthentication
Lesson 8-1: Advanced RIP Configuration
Summary
Review Questions
FAQs
Chapter9 EIGRP
An EIGRP Overview
Configuring EIGRP
Lesson 9-1: Configuring Simple EIGRP
EIGRP Building Blocks
Packet Formats
EIGRP Tables
Feasible Successors
Route States
Route Tagging
IGRP and EIGRP Interoperability
An Example of DUAL in Action
Configuring EIGRP Options
Lesson 9-2: Adding a WAN Connection
Lesson 9-3: Logging Neighbor Adjacency Changes
Lesson 9-4: Disabling Route Summarization
Lesson 9-5: Configuring Manual Route Summarization
Lesson 9-6: Configuring Default Routing
Lesson 9-7: Controlling EIGRP Routes
Lesson 9-8: Redistributing EIGRP with Route Controls
Lesson 9-9: Configuring EIGRP Route Authentication
Lesson 9-10: Configuring EIGRP Stub Routing
Lesson 9-11: Configuring EIGRP Over GRE Tunnels
Lesson 9-12: Disabling EIGRP Split Horizon
Troubleshooting EIGRP
Summary
Review Questions
FAQs
Chapter 10 OSPF
Configuring OSPF
Case Study 10-1: Basic OSPF Configuration
Case Study 10-2: OSPF and Route Summarization
Case Study 10-3: OSPF Filtering
Case Study 10-4: OSPF and Non-IP Traffic over GRE
Monitoring and Maintaining OSPF
Verifying OSPF ABR Type 3 LSA Filtering
Displaying OSPF Update Packet Pacing
Summary
Review Questions
FAQs
Chapter 11 IS-IS
Integrated IS-IS Overview
Configuring IS-IS
Case Study 11-1: Configuring IS-IS for IP
IS-IS Building Blocks
The IS-IS State Machine
The Receive Process
The Update Process
The Decision Process
The Forward Process
Pseudonodes
IS-IS Addressing
The Simplified NSAP Format
Addressing Requirements
Limiting LSP Flooding
Blocking Flooding on Specific Interfaces
Configuring Mesh Groups
Generating a Default Route
Route Redistribution
Setting IS-IS Optional Parameters
Setting the Advertised Hello Interval
Setting the Advertised CSNP Interval
Setting the Retransmission Interval
Setting the LSP Transmission Interval
Configuring IS-IS Authentication
Case Study 11-2: IS-IS Authentication
Authentication Problems
Using show and debug Commands
Monitoring IS-IS
Debugging IS-IS
Summary
Review Questions
FAQs
Chapter12 BGP
Understanding BGP Concepts
Autonomous Systems
BGP Functionality
EBGP and IBGP
BGP Updates
Configuring BGP
Case Study 12-1: Single-Homed Autonomous System Setup
Case Study 12-2: Transit Autonomous System Setup
Case Study 12-3: BGP Confederations
Case Study 12-4: BGP Over a Firewall with a Private Autonomous System
Case Study 12-5: BGP Through a Firewall with Prepend
Summary
Review Questions
FAQ
Chapter13 Redistribution
Metrics
Administrative Distance
Classless and Classfui Capabilities
Avoiding Problems Due to Redistribution
Configuring Redistribution of Routing Information
Redistributing Connected Networks into OSPF
Lesson 13-1: Redistributing OSPF into Border Gateway Protocol
Lesson 13-2: Redistributing OSPF Not-So-Stubby Area External Routes into BGP
Lesson 13-3: Redistributing Routes Between OSPF and RIP Version 1
Lesson 13-4: Redistributing Between Two EIGRP Autonomous Systems
Lesson 13-5: Redistributing Routes Between EIGRP and IGRP in Two Different Autonomous Systems
Lesson 13-6: Redistributing Routes Between EIGRP and IGRP in the Same Autonomous System
Redistributing Routes to and from Other Protocols from EIGRP
Lesson 13-7: Redistributing Static Routes to Interfaces with EIGRP
Lesson 13-8: Redistributing Directly Connected Networks
Lesson 13-9: Filtering Routing Information
Summary
Review Questions
FAQs
Part Ⅳ Security Practices
Chapter 14 Security Primer
Important Security Acronyms
White Hats Versus Black Hats
Cisco Security Implementations
Cisco IOS Security Overview
CatalystOS Security Overview
VPN Overview
AAA Overview
IDS Fundamentals
Summary
Review Questions
FAQs
Chapter 15 Basic Cisco IOS Software and Catalyst 3550 Series Security
Cisco IOS Software Security
Network Time Protocol Security
HTTP Server Security
Password Management
Access Lists
Secure Shell
Basic IOS Security Configuration
Lesson 15-1: Configuring Passwords, Privileges, and Logins
Lesson 15-2: Disabling Services
Lesson 15-3: Setting up a Secure HTTP Server
Case Study 15-1: Secure NTP Configuration
Case Study 15-2: Configuring SSH
Catalyst 3550 Security
Lesson 15-4: Port-Based Traffic Control
Summary
Review Questions
FAQs
Chapter 16 Access Control Lists
Overview of Access Control Lists
Where to Configure an ACL
When to Configure an ACL
ACLs on the IOS Router and the Catalyst 3550 Switch
Basic ACLs
Advanced ACLs
Time-of-Day ACLs
Lock-and-Key ACLs
Why You Should Use Lock-and-Key
When You Should Use Lock-and-Key
Source-Address Spoofing and Lock-and-Key
Lock-and-Key Configuration Tips
Verifying Lock-and-Key Configuration
Maintaining Lock-and-Key
Manually Deleting Dynamic Access List Entries
Reflexive ACLs
Reflexive ACL Benefits and Restrictions
Reflexive ACL Design Considerations
Router ACLs
Port ACLs
VLAN Maps
Using VLAN Maps with Router ACLs
Fragmented and Unfragmented Traffic
Logging ACLs
Defining ACLs
The Implied “Deny All Traffic” ACE Statement
ACE Entry Order
Applying ACLs to Interfaces
Lesson 16-1: Configuring an ACL
Lesson 16-2: Creating a Numbered Standard IP ACL
Lesson 16-3: Creating a Numbered Extended IP ACL
Lesson 16-4: Creating a Named Standard IP ACL
Lesson 16-5: Creating a Named Extended IP ACL
Lesson 16-6: Implementing Time of Day and ACLs
Lesson 16-7: Configuring Lock-and-Key
Lesson 16-8: Configuring Reflexive ACLs
Lesson 16-9: Logging ACLs
Lesson 16-10: Configuring a Named MAC Extended ACL
Creating a VLAN Map
Lesson 16-11: Using ACLs with VLAN Maps
Maintaining ACLs
Displaying ACL Resource Usage
Troubleshooting Configuration Issues
ACL Configuration Size
Unsupported Features on the Catalyst 3550 Switch
Summary
Review Questions
FAQs
Chapter 17 IP Services
Managing IP Connections
ICMP Unreachable Messages
ICMP Redirect Messages
ICMP Mask Reply Messages
IP Path MTU Discovery
MTU Packet Size
IP Source Routing
Simplex Ethernet Interfaces
DRP Server Agents
Filtering IP Packets Using Access Lists
Hot Standby Router Protocol Overview
HSRP and ICMP Redirects
IP Accounting Overview
IP MAC Accounting
IP Precedence Accounting
Configuring TCP Performance Parameters
Compressing TCP Packet Headers
Setting the TCP Connection Attempt Time
Using TCP Path MTU Discovery
Using TCP Selective Acknowledgment
Using TCP Time Stamps
Setting the TCP Maximum Read Size
Setting the TCP Window Size
Setting the TCP Outgoing Queue Size
Configuring the MultiNode Load Balancing Forwarding Agent
Configuring the MNLB Forwarding Agent
Network Address Translation Overview
When to Use NAT
Configuring IP Services
Lesson 17-1: Configuring ICMP Redirects
Lesson 17-2: Configuring the DRP Server Agent
Lesson 17-3: Configuring HSRP
Lesson 17-4: Configuring IP Accounting
Lesson 17-5: Configuring NAT
Monitoring and Maintaining IP Services
Verifying HSRP Support for MPLS VPNs
Displaying System and Network Statistics
Clearing Caches, Tables, and Databases
Monitoring and Maintaining the DRP Server Agent
Clearing the Access List Counters
Monitoring the MNLB Forwarding Agent
Monitoring and Maintaining HSRP Support for ICMP Redirect Messages
Monitoring and Maintaining NAT
Summary
Review Questions
FAQs
Part V Authentication and Virtual Private Networks
Chapter 18 AAA Services
TACACS+ Versus RADIUS
Underlying Protocols
Packet Encryption
Authentication, Authorization, and Accounting Processes
Router Management
Interoperability
Traffic
Configuring AAA
Case Study 18-1: Simplified AAA Configuration Using RADIUS
Case Study 18-2: Configuring AAA on a PIX Firewall
Case Study 18-3: Configuring VPN Client Remote Access
Case Study 18-4: Authentication Proxy with TACACS+
Case Study 18-5: Privilege Levels with TACACS+
Case Study 18-6: Configuring PPP Callback with TACACS+
Summary
Review Questions
FAQs
Chapter 19 Virtual Private Networks
Virtual Private Network (VPN) Overview
Site-to-Site VPNs
Remote-Access VPNs
IPSec Overview
Authentication Header (AH)
Encapsulating Security Payload (ESP)
IPSec Protocol Suite
Tunnel and Transport Modes
IPSec Operation
Defining Interesting Traffic
IKE Phase 1
IKE Phase 2
IPSec Encrypted Tunnel
Tunnel Termination
Configuring IPSec in Cisco IOS Software and PIX Firewalls
Case Study 19-1: Configuring a Basic IOS-to-IOS IPSec VPN
Case Study 19-2: Configuring a Basic PIX-to-PIX IPSec VPN
Certificate Authority (CA) Support
Configuring CA
IOS-to-IOS VPN Using CA
PIX-to-PIX VPN Using CA
Summary
Review Questions
FAQs
Chapter 20 Advanced Virtual Private Networks
Issues with Conventional IPSec VPNs
Solving IPSec Issues with GREs
Solving IPSec Issues with DMVPNs
Configuring Advanced VPNs
Case Study 20-1: Using Dynamic Routing Over IPSec-Protected VPNs
Case Study 20-2: Configuring DMVPN
Summary
Review Questions
FAQs
Chapter 21 Virtual Private Dialup Networks
L2F and L2TP Overview
VPDN Process Overview
PPTP Overview
Configuring VPDNs
Case Study 21-1: Configuring the VPDN to Work with Local AAA
Case Study 21-2: Configuring TACACS+ Authentication and Authorization for VPDN
Case Study 21-3: Configuring the PIX Firewall to Use PPTP
Lesson 21-1: Configuring the Default VPDN Group Template
Summary
Review Questions
FAQs
Part Ⅵ Firewalls
Chapter 22 Cisco IOS Firewall
Creating a Customized Firewall
Configuring TCP Intercept
Lesson 22-1: Configuring TCP Intercept
CBAC Overview
Traffic Filtering
Traffic Inspection
Alerts and Audit Trails
Intrusion Detection
CBAC Limitations and Restrictions
CBAC Operation
When and Where to Configure CBAC
CBAC-Supported Protocols
Using IPSec with CBAC
Lesson 22-2: Configuring CBAC
Monitoring and Maintaining CBAC
Turning Off CBAC
Case Study 22-1: Configuring CBAC on Two Interfaces
Port-to-Application Mapping (PAM)
How PAM Works
When to Use PAM
Lesson 22-3: Configuring PAM
Monitoring and Maintaining PAM
Summary
Review Questions
FAQs
Chapter23 Cisco PIX Firewall
Security Levels and Address Translation
TCP and UDP
Configuring a Cisco PIX Firewall
Lesson 23-1: Configuring the PIX Firewall Basics
Lesson 23-2: Configuring Network Protection and Controlling Its Access and Use
Lesson 23-3: Supporting Specific Protocols and Applications
Lesson 23-4: Monitoring the PIX Firewall
Lesson 23-5: Using the PIX Firewall as a DHCP Server
Lesson 23-6: New Features in PIX Firewall Version 6.2
Summary
Review Questions
FAQs
Part Ⅶ Intrusion Detection
Chapter 24 IDS on the Cisco PIX Firewall and lOS Software
Cisco IOS Software Intrusion Detection
Cisco PIX Firewall Intrusion Detection
Cisco IOS Software and PIX IDS Signatures
Configuring Cisco IDS
Case Study 24-1: Configuring the Cisco IOS Software IDS
Case Study 24-2: Configuring the Cisco Secure PIX Firewall IDS
Summary
Review Questions
FAQs
Chapter 25 Internet Service Provider Security Services
Preventing Denial-of-Service Attacks
Committed Access Rate (CAR)
Reverse Path Forwarding (RPF)
Layer 2 VPN (L2VPN)
802.1Q
Layer 2 Protocol Tunneling
Configuring ISP Services
Case Study 25-1: DoS Prevention Through Rate Limiting
Case Study 25-2: DoS Prevention Through RPF
Case Study 25-3: Configuring L2VPN
Summary
Review Questions
FAQs
Part Ⅷ Sample Lab Scenarios
Chapter 26 Sample Lab Scenarios
Practice Lab Format
How the Master Lab Compares to the CCIE Security Lab Exam
CCIE Practice Lab 1: Building Layer 2
Equipment List
Prestaging: Configuring the Frame Relay Switch
Prestaging: Configuring the First Backbone Router, R9-BB 1
Prestaging: Configuring the Second Backbone Router, R7-BB2
Lab Rules
Timed Portion
CCIE Practice Lab 2: Routing
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 3: Configuring Protocol Redistribution and Dial Backup
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 4: Configuring Basic Security
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 5: Dial and Application Security
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 6: Configuring Advanced Security Features
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 7: Service Provider
Equipment List
Lab Rules
Timed Portion
CCIE Practice Lab 8: All-Inclusive Master Lab
Equipment List
Prestaging: Configuring the Frame Relay Switch
Prestaging: Configuring the First Backbone Router, R7-BB1
Prestaging: Configuring the Second Backbone Router, R7-BB2
Prestaging: Configuring the Reverse Telnet Router
Lab Rules
Timed Portion
Summary
Part Ⅸ Appendixes
Appendix A Basic UNIX Security
Appendix B Basic Windows Security
Appendix C ISDN Error Codes and Debugging Reference
Appendix D Password Recovery on Cisco IOS, Catalystos, and PIX
Appendix E Security-Related RFCs and Publications
Appendix F Answers to the Review Questions