<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New CCIE Security Core Knowledge Questions &#8211; Part 1</title>
	<atom:link href="http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/</link>
	<description>Helping you become a Cisco Certified Internetwork Expert</description>
	<lastBuildDate>Wed, 28 Jul 2010 22:47:55 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Keith Barker</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-65150</link>
		<dc:creator>Keith Barker</dc:creator>
		<pubDate>Thu, 10 Sep 2009 23:26:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-65150</guid>
		<description>Thanks for the question HAT!   I hear you.   The question on the ASAs indeed could be very lengthy, such as:

Hardware Requirement:

Same hardware configuration. They must be the same model, have the same number and types of interfaces, and the same amount of RAM.  However, an exception to this is that the two ASAs do not need to have the same size Flash memory, but make sure the unit with the smaller Flash memory has enough space to store  the software image files and the configuration files. If it does&#039;t, configuration synchronization from the unit with the larger Flash memory to the unit with the smaller Flash memory doesn&#039;t work. 

Software Requirement 

Same operational modes (routed or transparent, single or multiple context). They must have the same major (first number) and minor (second number) software version, but you can use different versions of the software within an upgrade process; for example, you can upgrade one unit from Version 7.0(1) to Version 7.0(2) and have failover remain active.   You can upgrade from the last minor release of the previous version to the next major release.  For example, you can upgrade from 7.9 to 8.0, assuming that 7.9 is the last minor version in the 7.x release. 

The answer could also be less than 10 characters or less, like Anthony’s response (thank you Anthony).


My coaching would be to keep it concise, and accurate.

Thanks again for the question-

Keith</description>
		<content:encoded><![CDATA[<p>Thanks for the question HAT!   I hear you.   The question on the ASAs indeed could be very lengthy, such as:</p>
<p>Hardware Requirement:</p>
<p>Same hardware configuration. They must be the same model, have the same number and types of interfaces, and the same amount of RAM.  However, an exception to this is that the two ASAs do not need to have the same size Flash memory, but make sure the unit with the smaller Flash memory has enough space to store  the software image files and the configuration files. If it does&#8217;t, configuration synchronization from the unit with the larger Flash memory to the unit with the smaller Flash memory doesn&#8217;t work. </p>
<p>Software Requirement </p>
<p>Same operational modes (routed or transparent, single or multiple context). They must have the same major (first number) and minor (second number) software version, but you can use different versions of the software within an upgrade process; for example, you can upgrade one unit from Version 7.0(1) to Version 7.0(2) and have failover remain active.   You can upgrade from the last minor release of the previous version to the next major release.  For example, you can upgrade from 7.9 to 8.0, assuming that 7.9 is the last minor version in the 7.x release. </p>
<p>The answer could also be less than 10 characters or less, like Anthony’s response (thank you Anthony).</p>
<p>My coaching would be to keep it concise, and accurate.</p>
<p>Thanks again for the question-</p>
<p>Keith</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yohon</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64999</link>
		<dc:creator>Yohon</dc:creator>
		<pubDate>Wed, 09 Sep 2009 19:25:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64999</guid>
		<description>Hi Anthony. Sorry, my bad. You are correct, I do see the &quot;more info&quot; links in the answer key. Again, great updates and keep up the great work.</description>
		<content:encoded><![CDATA[<p>Hi Anthony. Sorry, my bad. You are correct, I do see the &#8220;more info&#8221; links in the answer key. Again, great updates and keep up the great work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Sequeira, #15626</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64989</link>
		<dc:creator>Anthony Sequeira, #15626</dc:creator>
		<pubDate>Wed, 09 Sep 2009 17:48:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64989</guid>
		<description>All of our Core Knowledge Sim questions include a More Information link. They are located in the Answer key version.</description>
		<content:encoded><![CDATA[<p>All of our Core Knowledge Sim questions include a More Information link. They are located in the Answer key version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yohon</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64970</link>
		<dc:creator>Yohon</dc:creator>
		<pubDate>Wed, 09 Sep 2009 13:25:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64970</guid>
		<description>Great work INE. These are great questions and I do appreciatee the links for more info, something that is missing in the current product for security.</description>
		<content:encoded><![CDATA[<p>Great work INE. These are great questions and I do appreciatee the links for more info, something that is missing in the current product for security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anthony Sequeira, #15626</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64931</link>
		<dc:creator>Anthony Sequeira, #15626</dc:creator>
		<pubDate>Wed, 09 Sep 2009 03:48:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64931</guid>
		<description>RAM, MODEL, INTERFACES, MODE (ROUTED, TRANS, SINGLE, MULTIPLE)

:-)</description>
		<content:encoded><![CDATA[<p>RAM, MODEL, INTERFACES, MODE (ROUTED, TRANS, SINGLE, MULTIPLE)<br />
 <img src='http://blog.ine.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tacack</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64929</link>
		<dc:creator>Tacack</dc:creator>
		<pubDate>Wed, 09 Sep 2009 03:44:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64929</guid>
		<description>AWESOME! :) Great job guys! :)</description>
		<content:encoded><![CDATA[<p>AWESOME! <img src='http://blog.ine.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Great job guys! <img src='http://blog.ine.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HAT</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64918</link>
		<dc:creator>HAT</dc:creator>
		<pubDate>Wed, 09 Sep 2009 02:46:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64918</guid>
		<description>Hi Keith, 

I heard that the answers for these questions are short ones which have about 4, 5 word length.

But the failover question is rather long and without referencing Cisco documentation it&#039;s a bit difficult to tell all the details

Could you give me some advices on this?

Thanks
HAT</description>
		<content:encoded><![CDATA[<p>Hi Keith, </p>
<p>I heard that the answers for these questions are short ones which have about 4, 5 word length.</p>
<p>But the failover question is rather long and without referencing Cisco documentation it&#8217;s a bit difficult to tell all the details</p>
<p>Could you give me some advices on this?</p>
<p>Thanks<br />
HAT</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rizzo</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64882</link>
		<dc:creator>Rizzo</dc:creator>
		<pubDate>Tue, 08 Sep 2009 23:37:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64882</guid>
		<description>Great stuff

I love those question and links provided by Keith</description>
		<content:encoded><![CDATA[<p>Great stuff</p>
<p>I love those question and links provided by Keith</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keith Barker</title>
		<link>http://blog.ine.com/2009/09/08/new-ccie-security-core-knowledge-questions-part-1/comment-page-1/#comment-64837</link>
		<dc:creator>Keith Barker</dc:creator>
		<pubDate>Tue, 08 Sep 2009 21:11:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.ine.com/?p=1918#comment-64837</guid>
		<description>Question:  Why is it that ASDM and WebVPN, using their defaults, cannot be enabled on the same interface of the ASA?

Answer: Both are listening on the same port – 443. 

More Information: 
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807be2a1.shtml#topic1

Question: What ASA feature produced the following output? 

Answer: The WebVPN Capture Tool

More Information:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00804a3718.shtml#output

Question: What are the hardware and software requirements for 2 ASAs to perform failover?

Answer: 
Hardware: Must have the same hardware configuration, must be the same model, have the same number and types of interfaces, the same amount of RAM, and have the same SSMs installed (if any).
Software: Must be in the same operating modes (routed or transparent, single or multiple context). 

More Information:
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1155967

Question: What is the mechanism used to transmit the MD5 signature between two BGP authenticated speakers?

Answer:  TCP Option 19

More Information
http://www.rfc-editor.org/rfc/rfc2385.txt</description>
		<content:encoded><![CDATA[<p>Question:  Why is it that ASDM and WebVPN, using their defaults, cannot be enabled on the same interface of the ASA?</p>
<p>Answer: Both are listening on the same port – 443. </p>
<p>More Information:<br />
<a href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807be2a1.shtml#topic1" rel="nofollow">http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807be2a1.shtml#topic1</a></p>
<p>Question: What ASA feature produced the following output? </p>
<p>Answer: The WebVPN Capture Tool</p>
<p>More Information:<br />
<a href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00804a3718.shtml#output" rel="nofollow">http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00804a3718.shtml#output</a></p>
<p>Question: What are the hardware and software requirements for 2 ASAs to perform failover?</p>
<p>Answer:<br />
Hardware: Must have the same hardware configuration, must be the same model, have the same number and types of interfaces, the same amount of RAM, and have the same SSMs installed (if any).<br />
Software: Must be in the same operating modes (routed or transparent, single or multiple context). </p>
<p>More Information:<br />
<a href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1155967" rel="nofollow">http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1155967</a></p>
<p>Question: What is the mechanism used to transmit the MD5 signature between two BGP authenticated speakers?</p>
<p>Answer:  TCP Option 19</p>
<p>More Information<br />
<a href="http://www.rfc-editor.org/rfc/rfc2385.txt" rel="nofollow">http://www.rfc-editor.org/rfc/rfc2385.txt</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
