Archive for the 'CCIE R&S' category

Cisco’s NTP authentication is b0rked

 | 25 Jul 2006 11:35

Master:
ntp authentication-key 14 md5 ladida
ntp authenticate (see comment below)
ntp source Loopback0
ntp master
ntp server source FastEthernet0/0
ntp trusted-key 14 (see comment below)

Client:
ntp authentication-key 14 md5 ladida
ntp authenticate
ntp source Loopback0
! ntp trusted-key 14 (only required when not specifying a key on the line below)
ntp server key 14

Debug on the client:

21:05:03: NTP: rcv packet from 134.14.1.1 to 134.14.7.7 on Loopback0:
21:05:03: leap 0, mode 4, version 3, stratum 2, ppoll 64

21:05:03: Authentication key 0
21:05:03: NTP: packet from 134.14.1.1 failed validity tests 10
21:05:03: Authentication failed
21:06:06: NTP: xmit packet to 134.14.1.1:
21:06:06: leap 3, mode 3, version 3, stratum 0, ppoll 64

21:06:06: Authentication key 14

The Client does send authenticated packets but the Master doesn’t. Mind you configuring a ‘peer’ is symmetric (same stratum) and ‘server’ is asymmetric (ntp stratum hierarchy). Apparently Cisco knows about it for years but it’s too low a priority to fix it, so don’t bother running to TAC with this…

Even configuring peers so one can set the key on the master doesn’t help. The authentication error disappears but no association forms.

Just like the bootcamp

 | 23 Jul 2006 14:16

The weather is hot, I’m studying hard and BBQ for lunch. Now where’s my wine and the quad?

My lovely wife knows I like a German Riessling to that’s cold in the fridge for tonight and my oldtimer moped should be insured next week. Almost there… 😉

Oooh, I hate cosmetic bugs!

 | 10:29

C7500(config-router-af)#$-map D-list_EIGRP13_r2_in in f5/1/0.201
% Access-list filter exists, de-config first

I got this notification when trying to work my way around what I thought was a config line that did not generate an error nor ended up in configuration. When trying to configure a different distribute-list, this time with a route-map, it told me that I’d have to remove the old list first. So it should be in config and active.

Show me more… »

Final approach

 | 09:27

Sounds very definite doesn’t it. Well I know that on average it should take me 3 labs to pass but hey you can’t blame me for having a positive attitude. Last friday I started my last ‘week’ of studying before my 1st lab attempt. I’m curently working on the last ‘few’ lines of config to my own lab environment. Was counting on remote lab access to Heinz’s lab (delayed ‘one week access’ after the bootcamp). But due to a miscommunication it was scheduled for the week of my exam which isn’t very usefull as obviously I’ll be resting and taking the exam that week.

Anyway, I’ll get there myself as long as I don’t find any other dead Ethernet interfaces. The 7500 in my lab is upgraded to 12.4(8) Enterprise and is happily running VRF-lite on all routing protocols. As such I’m using it to simulate about 7 routers, only problem is that it’s config has become enormous but at the moment it’s working fine.

For those who still wonder were I’ve disappeared to this week, I’ve locked myself in my attick to get some serious studying done. I’ll be out on the 31st in an attempt to relax in preparation of the 2nd (of Aug) which is my lab date.

1st guy that passed (from my R&S bootcamp)

 | 18 Jul 2006 13:56

Wilfried HiemetzbergerHe passed yesterday, congratulations Wilfried! CCIE #16567

Back to studying

 | 14 Jul 2006 11:58

It’s been a while since my last post, the bootcamp was very tiring (believe it or not). So I’ve taken almost 2 weeks off from studying. Now this time is over I’m back with my nose in my laptop, at home trying to give some lab like shape to the equipment I have stacked up in the DataCenter (DC).

I managed to get hold of some back to back cables, 2 to be precise and I discovered I had 2 V.35 back-to-back links already active. So I’m about to re shuffle my layout, all in a days fun…

In case you hadn’t heard yet my lab is booked for the 2nd of August, 17 days and counting. not sure yet whether I’ll drive up in the morning (very early) or whether I should get a hotel.

Living life dangerously…

 | 24 Jun 2006 10:44

Heinz’s camp is trying on a technical level, his quad adds a physical dimension to the danger: Me on quad

Lab is booked

 | 23 Jun 2006 16:39

Another mile stone: A few days ago I booked my lab, was going to wait untill after the bootcamp but heard here that it’s quite crowded to get into the lab as Cisco is apparently about to change something this summer. No-one seems to know exactly what though, if you do then please drop me a mail. I have untill the 5th of July to reschedule, if I want to once the Drill Sergeant is finished with me.

The booked date is the 2nd of August (this year). A number of days weren’t available anymore, among them the 30th of July which was my planned date for the lab. I’m glad I don’t have to do it in September when ‘Piglet‘ is due.

Bootcamp update #1

 | 20 Jun 2006 00:48

A running update, as you can see from the time of posting…

Some pictures of the bootcamp can be found here. More will be made and uploaded when time permits so come back later and you might find more things to see. Haven’t driven the quad yet, so more adventure will surely be captured on digital film.

Till next posting…

Woohoo, 1st step made today

 | 31 May 2006 11:37

My 3rd try at the CCIE R&S written of this morning proved successful. (74%)

  • General networking theory: 100% (same again)
  • Bridging and LAN switching: 62%
  • IP: 100%
  • IP routing: 71%
  • QoS: 70%
  • WAN: 50%
  • IP multicast: 71%
  • Security: 100%
  • Enterprise Wireless mobility: 67%

Now on to a worry free bootcamp as the written is a prerequisite, woot! Or should I be worried? Check out the comment the trainer of the bootcamp left…

New tactics

 | 16 May 2006 11:52

Next written exam is planned for the 31st (May), I have to get it so can’t really stop. As the exam gets harder every time one tries I’ve decided to invest in testking(.com for those who wonder due to all the hoaxes) so that I can verify where I’m lacking. As it’s not just a question of upping Multicast anymore I need to nip any lack on knowledge in the bud.

P.S. Don’t bother asking me for the latest testking Q&A as they’ve done a good job at securing their stuff. If you don’t want to pay you’ll just have to live with not having the latest version, which is #76 btw… 😉

29 May: Update it has 50 questions on Enterprise WLAN, my goodness how I underestimated this topic…

Failed…

 | 15 May 2006 12:53

/me feels like digging a hole to crawl into…

I know that the average for the lab is 3 takes to pass but has anyone got some stats about the written? I also wonder whether they deliberately go for the things that one failed at the previous time(s).

I did manage to up my score on Multicast but went down enough on other subjects to end up at 63% again.

Todays score:

  • General networking theory: 100% (same) 🙂
  • Bridging and LAN switching: 43% (-5%)
  • IP: 90% (+10%) 🙂
  • IP routing: 71% (-3%)
  • QoS: 60% (-20%) 🙁
  • WAN: 50% (same)
  • IP multicast: 57% (+43%) 😐
  • Security: 67% (same)
  • Enterprise Wireless mobility: 33% (same)

WLAN doesn’t bug me so much, but QoS does as it’s something I do daily and I went down 20%!

What to do now? First I’m leaving this crap alone for a week, flying out to Mallorca with the family for a week this Wednesday morning. Then I’ll have to spend the 2nd week of my holiday studying so I can try again on the 31st.

My subjects will have to be:

  • Bridging & LAN switching
  • WAN
  • Multicast

Don’t think I’ll have too much time left over for WLAN, Security or QoS.

No more posts untill at least the 25th…

Multicast quick ref

 | 13 May 2006 01:16

Well I’m working away, but think that it’s late enough now. I really need some good sleep. So far I’ve managed to get through to IGMPv1, 2 & 3. CGMP and multicat routing is there for tomorrow.

Check out Multicast quick ref for what I’ve assimilated so far.

Zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz…

Grrr (lol)

 | 9 May 2006 14:26

CISCO Retake Policy Notification
Previous results for this exam are not yet updated in the system. Please try back in one business day.

Booked the retake for Monady 15th May (2006 in case you were wondering ;)) 10:00

Bugger bugger bugger!

 | 12:14

Please excuse the language…

This morning I failed the CCIE R&S written with 63% (70% required).
You get 2 hours, plus 30 minutes for non native speakers, for 100 questions which are quite random. They even have errors in them like listing IP addresses and leaving the first octet off, very helpfull in all.

Enough ranting, here’s my score:

  • General networking theory: 100% 🙂
  • Bridging and LAN switching: 48% 😐
  • IP : 80% 🙂
  • IP routing: 71%
  • QoS: 80% 🙂
  • WAN: 50% 😐
  • IP multicast: 14% 🙁
  • Security: 67%
  • Enterprise Wireless mobility: 33% 🙁

So I need to work on WAN (F/R) and multicast, mcast is heavilly tested imho. WLAN was only 3 questions so not sure I want to spend too much time on that… Bridging and LAN switching has more questions so is probably time better spent. Watch the CCIE pages for more quick ref topics, as I’ll be working on improving my knowledge to pass the written next time.

I’m not allowed to retake the exam before May 15th so I’ll resit the exam next monday or tuesday.