Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Thursday, 6 August 2015

Not passing the Cisco CCDA exam

"Do not underestimate this exam" - comment seen on the Cisco Learning Network.

Over the years, I've published a few posts with the title "Passing the [insert_cert] exam". Sadly, this post is "Not passing the Cisco CCDA exam". I've taken the exam twice, and failed both times.

While I can't talk about the exam (for NDA reasons), I can talk about the studying...

The CCDA is an odd certification. It sits alongside the more familiar CCNA certifications (R&S, Security, Voice etc.) and, as an "Associate" certification, is classed as entry level. Despite that, reading the Cisco Learning Community discussions reveals that a lot of people only tackle it once they have most, or all, of their CCNP or have at least taken all the CCNA concentrations. There is a common theme in the discussion forums that I've read, that this is not an easy exam.

My CCNA R&S and Security certifications were coming up for renewal, so I thought I'd give CCDA a go. I'd bought the (now out-dated) 640-863 "Designing for Cisco Internetwork Solutions" years ago and while I'd found parts of it interesting, I'd never put the effort into actually studying it.

So I equipped myself with the following:

  • Designing for Cisco Internetwork Solutions (third edition)
  • The Cisco CCDA Official Cert Guide
  • CCDA Simplified

To go alongside that, I also bought the ARCH book, "Designing Cisco Network Service Architectures" which is actually part of the CCDP and goes into a lot more detail. I also read a bunch of the Cisco SAFE reference guides.

All in all, a lot of reading!

I then spent nearly two months of study, going through the above and learning the material. I've seen some people comment how the CCDA is a Cisco sales/marketing certification, and I sort of see where they're coming from because it does use a lot of Cisco jargon that relates to Cisco products.

However, that's not to say it's easy or that it isn't technically demanding. There are a lot of details to understand and the main challenge is that while it's very broad and in some ways theoretical, the material expects you to have an understanding of some pretty technical details, such as:

  • In OSPF, what does LSA type 7 do?
  • Syslog level 5 is what level of severity?
  • Which H.323 protocol is responsible for call setup and signaling?
  • Which IPv6 routing protocol uses FF02::9?

Quite a lot to understand and know.


So, in order to cover all the bases, I dived into:
  • Network architectures (three layer, modular enterprise, borderless, collaboration, data centre)
  • Campus LAN and Data centre design
  • Branch office and WAN design
  • IP addressing (both IPv4 and IPv6)
  • Routing protocols: RIPv2, EIGRP, OSPF, BGP
  • Security
  • Wireless
  • Voice
  • Network management procotols

My first attempt, a couple of weeks ago, was a bit shakey. As I went into the exam I felt it was going to be a close thing and I failed with a score of 752 out of 1000 (pass score was 790). However, I was able to see the areas that I was not strong in and focus on that. So with nearly two weeks of additional revision and study, I took it again, feeling more confident...

This time I got 777, much closer than before and potentially only a couple of questions away from a pass. Without wanting to sound like a sore loser, I've actually flagged a couple of the questions with Cisco as the wording was very poor and ambiguous. I'm not honestly expecting much to change, but we'll see.

Sadly, this is the end of the road for my Cisco certifications for the time being. My current certs will expire in a few days, so I'll have to take them all again if I want to get back to this point. Disappointing, but that's how it goes sometimes.

So is it worth doing the CCDA? I think so. Once you get past the marketing stuff, there is a lot of good content that helps focus the architect in identifying what's important in designing a network solution. It's not a hands-on exam, but you do learn a lot that can be applied to actual network implementations. The current syllabus is getting pretty old and refers to products that have now gone end-of-life, but the concepts are sound and I assume an update will fix that.

After all these weeks of spending spare time studying, I might take a few days to sit in the sun (weekend's coming!), spend time with my neglected family and play some Elite:Dangerous. I think I deserve it.


Wednesday, 8 August 2012

Passing the CCNA Security exam

The CCNA certification is valid for 3 years and mine was due to expire at the end of August 2012. I could either retake the same exam and recertify, or take another CCNA "concentration" exam that would give me a new certification and renew the original certification at the same time. I opted to tackle the CCNA Security exam, IINS 640-553.

I'd originally bought the Cisco Press "Authorized Self-Study Guide", Implementing Cisco IOS Network Security by Catherine Paquet back in 2010, but the material is a bit dry and I didn't have the motivation to get into it very far. By booking the exam, I suddenly acquired the motivation required.

As things happen, the 640-553 exam is due to be retired in September 2012, to be replaced by 640-554. The main difference in the new exam appears to be an additional focus on the Cisco ASA platform, as well as de-emphasising the Cisco Secure Device Manager (SDM). This means that any advice I give here will be redundant soon, and also I'm bound by the NDA, so can't obviously comment on what is in the exam.

What I can do though is give some general thoughts on the revision process:

The Good

The Implementing Cisco IOS Network Security book is very thorough. It covers a lot of detail and assumes little prior knowledge of security. Some of it is dry, especially the first chapter which weighs in at about 100 pages and gives an introduction to the world of security. Once that's passed, the content gets better and even the chapter on cryptography was interesting(!).

I also bought the Cisco CCNA Security Lab manual for the CCNA Security course. This gave some very good exercises to run through which were very useful in grounding the theory in the practical.

All of this was made possible using the amazing GNS3 router simulation software. I installed this on a meaty Windows Server VM and was able to run the 3 routers and 2 XP images (in Virtualbox, under ESXi) without any problems. The ability to save configurations and easily re-import them was a great time saver. GNS3 doesn't do everything (specifically switches, due to the custom silicon in them), but it made the whole process of learning the syllabus a lot easier.

There is some very good material at the Cisco Learning Network including free study chapters, training videos and discussions. Highly recommended.

The Bad

Cisco sell the book for self-study, but make it very difficult to practice because IOS images are not available without having the correct support contract. If you work for a large company with either old routers sat on a shelf or a contract with the ability to download the image then you'll be okay. Otherwise I guess you'll be searching the Internet for a dodgy copy of an old image. Seriously Cisco, how about making them freely available? You can do the study material with a 2600 series router and how old is that?

The same is true of the IPS signatures. A valid contract is required just to learn how the IPS works and again, this could mean a trip to the darker parts of the Internet to find them.

The Cisco Press book covers the Cisco Access Control Server software but it's not in the syllabus or lab manual. It can be used to learn about AAA and specifically authentication and authorization with RADIUS and TACACS+. Unfortunately Cisco don't have a trial version to help self-studying students.

The Ugly

Getting the Cisco Security Device Manager (SDM) working requires jumping through a number of hoops. To cut a long story short, you need an old version of Java (1.4 worked for me) and Windows XP. I'm guessing the latter requirement is due to Internet Explorer 6 as I couldn't get it working on Server 2008 R2 no matter what settings I tried.

Conclusion

Having worked through the labs a number of times and then setting things up "blind" (without referring to any notes), I felt fairly confident as I went into the exam. I passed with a good mark well above the passing level, so I'm naturally very pleased with this. It's a good subject to read up on since security requirements impact on so much of what we design these days. The CCNA Security should demonstrate I now have a solid grounding in the subject, even if I'm still a long way from being an expert.

Saturday, 17 September 2011

Cisco SG200-26 review

Until recently I was using a Netgear GS108 switch for my home lab. This eight port, unmanaged switch performed well, but with the addition of a couple of HP Microservers, I ran out of free ports and needed something bigger.

Although not essential to the lab, I wanted a switch with a few more features. I initially looked at the Cisco SG200-18, the HP V1810-24G and a couple of other makes that I hadn't come across before (TP-Link and ZyXEL). The one requirement was that the new switch should be silent. The fans of a Cisco Catalyst switch would dominate the home office and was unacceptable.

I discounted the switches from TP-Link and ZyXEL because I couldn't find any decent reviews of them online. The HP V1810 was then discounted because the price hiked up to over £230. This left the Cisco SG200-18. I then noticed that the SG200-26 was only £3 more expensive at £188 (from Ebuyer), so buying the smaller switch would not have made financial sense. You can't have too many ports, right?




The first thing to say about the Cisco SG200-26 is that it is not an IOS switch. I assume it's the result of the purchase of Linksys. Having said that, the build quality is good, the switch is absolutely silent in operation but doesn't get hot (in contrast, the Netgear was hot to touch). The SG200-26 is a managed, layer 2 switch.

The SG200-26 has 24 standard 10/100/1000 ports, plus another two ports for uplinks. These can be RJ-45 10/100/1000 ports or SFP fibre ports (SFP modules not included). The form factor is standard rack-mount 1U (rack mount kit included) but also has attachable rubber feet for desktop use.


Configuration is through the web interface only (no SSH or serial interface), but does support external logging to a syslog server.

Be sure to upgrade to the latest firmware. This enabled the Cisco Discovery Protocol (CDP) which is very useful in vSphere networking for identifying which physical ports a NIC is plugged into.

In the web interface, ports can be given a description and those of us with OCD can spend a happy evening mapping this information into the switch. The port settings can also be used to state the speed and duplex setting of each port.

The SG200-26 supports up to four Link Aggregation Groups (LAGs) and can load balance based on either MAC address or IP/MAC address. Both static and dynamic (LACP) LAG groups can be configured. Up to eight ports can be assigned to a static LAG and sixteen ports to a dynamic LAG.

Multiple VLANs can be setup and managed as the switch supports 802.1q. Ports can be setup as trunk, general, access or Q-in-Q mode. VLAN pruning can be applied to trunk ports so that only specific VLANs are accessible to particular ports. The interface for this wasn't immediately obvious to me (and setting up the same in IOS initially seemed easier), but once I'd spent some time with it, the VLAN configuration was fairly straightforward. These VLAN options can be applied to either individual ports or a LAG.

In addition to these features, the SG200-26 can also be configured for QoS, there are numerous security features including 802.1X, Smartport macros to configure the port type (e.g, Printer, Desktop, Guest, Server etc.). Jumbo frames can be enabled, although this applies is a global setting that affects all ports (most switches, even expensive Cisco switches, work the same way). A "Green Ethernet" function reduces the power requirements of the switch by calculating the length of cable, and also by turning off unused ports to save energy.

As a lab switch, the SG200-26 is ideal. Personally, I would have liked to see a command line option for configuration as some tasks can be repetitive (e.g., setting up VLANs). Beyond that though, there is little to complain about. The SG200-26 is an excellent entry-level switch, with plenty of ports and a good range of options.



Some useful links:

The Cisco Small Business 200 Series Smart Switch Administration Guide

The Cisco Small Business Online Device Emulators page has a demo of the web interface for the SF300. The 300 series has additional layer 3 functionality, but you can get a good idea what the interface is like on the 200 series.

* Update 10/07/2012 * I experienced an issue where traffic between two ports (e.g., ports 1 and 2) would cause significant latency issues on other, unrelated ports. This was demonstrated by putting a ping on a host and watching the timings when there was significant network load (such as VM backups). This was resolved by upgrading the firmware to 1.1.2.0.

Friday, 9 September 2011

ISP router ARP cache problems when replacing servers

I experienced a problem today that took a while to understand so figured it was worth sharing...

Our external mail gateway was due for replacement and a new virtual machine was built, configured and tested alongside the old production server. Happy that everything was functioning as expected, the only remaining task was to disconnect the old server from the network and rename the IP address of the new server from its test IP to that of the old server. This would require no changes to DNS and total downtime would be about a minute.

The change was made and... nothing. No traffic to the new server.

Huh? I tested it from another IP on the public network and it was fine. We tried from another network and... nothing.

I changed the IP back to the test address and the server sprang into life.

After a significant amount of time brainstorming with colleagues as to what was happening, we hit upon the possible problem being an ARP cache issue on the ISP provided router. Unfortunately, we don't have administrative access to this router.

Fortunately, the ISP hadn't locked down the console port of the Cisco router and I was able to connect in and run a "show ip arp" command. Sure enough, it showed the MAC address of the old server. This meant that when packets arrived from the Internet the router was trying to forward them to the old server that was no longer on the network. If I had administrative access to the router, I would have been able to flush the ARP cache and all would have been good. But because this was a "managed" router, I wasn't able to do this. I could see the problem, I knew the solution, but couldn't fix it.

I did some research online to see what the default ARP cache timeout was: typically 4 hours.

I logged a call with the ISP which was not a particularly useful experience. The ISP is a subsidiary of Cable & Wireless, and if you've ever had the misfortune of working with that company you'll understand what I'm talking about! I was told I'd get a call back in 8 hours. Brilliant! Not.

There were a couple of other options: Pulling the Ethernet cable from the router would down the interface which I *think* will cause the ARP cache to flush. I didn't have the luxury of doing this in hours.

The final option was to try and get the new server to send a gratuitous ARP request. This is an ARP request that a server broadcasts about itself. The idea is that other devices on the network will update their ARP caches with the information.

My server however was hidden behind a Cisco ASA firewall.

As I was searching for ways to get this working, the ARP cache timed out (possibly due to the router configuration being lower than the default, although I can't see the config to confirm this) and the new server sprang into life.

At first I wasn't sure whether it was the gratuitous ARP that fixed it, but within the next hour, the ISP called and confirmed they cleared the cache. So fair play to them for getting on with it and sorting the problem.


It's been a learning experience in that even the simplest and quickest network change can have unforeseen side effects!

Thursday, 27 August 2009

Passing the CCNA: My experience

This blog explains why I've been quiet for a few weeks...

I did the CCNA exam back in 2002, but by the time it expired in 2005, I wasn't doing anything specifically with networks so didn't bother re-certifying. A couple of months ago I thought it would be a good cert to pick-up again, so decided to dive in and do some self-study.

The original CCNA was the entry level Cisco exam, but in the last few years this has been replaced by the CCENT. The CCNA is a lot harder than it used to be with many new subjects and a deeper level of understanding required. You can either approach the certification using two tests (ICND1 which gives you the CCENT and ICND2 which results in the CCNA) or by using one combined exam. I opted for the one exam.

I bought the latest version of Todd Lammle's CCNA Study Guide and started studying one chapter per night (there are 14 chapters, but real life meant that it took more than 14 days). I also spent weekends studying as well. The book is generally very good, although I found that because I wasn't replicating the example network used in the book, some sections required me to visualise and absorb what was being shown without any hands on experience. I would highlight the chapter on understanding subnet masks though; probably the best way to learn subnetting I can imagine.

I also purchased the Cisco Press Official Exam Certification Library by Wendell Odom. I planned on using this to get another perspective on the material and started reading bits of this book to clarify areas after I had completed the Lammle book. In comparison with the Lammle book, Odom is a lot more detailed (some might say dry but I enjoyed it). I discovered that, for my learning style, the Odom book helped me more. I found the thorough details showing how something works, step by step, to be very useful.

I managed to borrow some old Cisco kit from work and a laptop from work. This consisted on two 2600 routers, two Catalyst 2900XL switches and a 1700 series router. I didn't have the proper serial cable so couldn't do any WAN activities, but did use the kit to validate my understanding of VLANs, VTP and IOS commands (including the boot process, wiping configs etc).

The final part of my studying involved the CDs provided with the books. The test questions with the Lammle book were pretty straightforward and I was able to get 80%+ in the mock exams without too much trouble.

The Odom book was a completely different matter. These questions are hard. Really hard. I initially found that the time limit in the exam was running out on me, and that I was struggling to get my head around some of the questions at all. Whereas in the original exam, you might be asked a question like:

Given an IP address of 10.2.66.8/18, what is the subnet address, first host, last host and broadcast address?


Now the exam was asking you to look at a network topology diagram with maybe six of these networks and you have to choose a spare subnet range. In other words, you have to do six times the work for single question.

Although I managed to get faster at the questions, and especially enjoyed the simulator questions (where you have to log into simulators of routers and either fix the configuration or use the show commands to identify certain things), I never managed to achieve a pass mark.

I resigned myself to the fact that I wasn't going to pass this exam and instead decided to treat it as an educational experience to work out how difficult it was going to be.

Now the actual exam itself is covered by NDA, so it would be improper of me to comment on the specifics. There were simulations but they weren't too difficult and the majority of the questions were more of the difficulty level found in the Lammle book vs the Odom book.

For those looking at getting the CCNA, I would strongly recommend the two books I used. If you can master the Lammle book, you'll probably do okay. If you can master the Odom book, you'll walk the exam with one arm tied behind your back.

On a personal note, I actually enjoyed the process of learning. I find the networking concepts fascinating, and might even look at doing another cert at some point (we all need a hobby, right?). Not sure T will be too happy about losing me for another month.

At least now I can chillax a bit and enjoy what remains of summer... :-)

Monday, 2 June 2008

A day with Cisco Network Assistant

Today I spent a significant amount of time using the freely available Cisco Network Assistant. This tool allows you to probe your [Cisco] LAN and identify the topology. This proved very useful as although I had a rough idea of how the network was wired, the software highlighted a couple of issues that I need to resolve. Once identified, you can directly interact with the devices, renaming switches, creating VLANs, enabling and disabling ports. Really, really nice - especially for the price.

The reason I'm doing this is that I want to get the topology accurately mapped before starting my Nagios deployment for network monitoring.

The only downside was discovering the SFP modules we bought for server interlinking were not "Cisco Compatible", so we'll have to spend double to get the same thing!