<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CCIE Blog &#187; Security</title>
	<atom:link href="http://blog.ipexpert.com/category/ccie/security-ccie/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ipexpert.com</link>
	<description>CCIE Candidates blog for all technical overviews relating to CCIE R&#38;S, CCIE Voice, CCIE Security &#38; CCIE SP</description>
	<lastBuildDate>Thu, 02 Sep 2010 13:04:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Free CCIE Lab Training: Links to This Weeks &amp; Last Weeks Recorded vLectures</title>
		<link>http://blog.ipexpert.com/2010/09/02/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-11/</link>
		<comments>http://blog.ipexpert.com/2010/09/02/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-11/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 13:01:28 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[free ccie]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie vlectures]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4828</guid>
		<description><![CDATA[Did you Miss our vLectures that were scheduled for this week &#38; last week? No worries! All our vLecture sessions are recorded and available for those who have missed our FREE CCIE vLectures and for participants who want to review the vLecture sessions again. We have saved the session recordings for you. Watch our world [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F09%2F02%2Ffree-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-11%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F09%2F02%2Ffree-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-11%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Did you Miss our vLectures that were scheduled for this week &amp; last week? No worries!</p>
<p>All our vLecture sessions are recorded and available for those who have missed our FREE CCIE vLectures and for participants who want to review the vLecture sessions again. We have saved the session recordings for you. Watch our world renowned <a href="https://www.ipexpert.com/Company/Team">CCIE instructors</a> explaining specific technical topic in our technology-focused classes and capture the technical knowledge needed to increase your chances of passing CCIE exam.</p>
<p><span id="more-4828"></span></p>
<p>CCIE Security</p>
<ul>
<li>Instructor: Tyson Scott</li>
<li>Topic: VRF Aware VPN</li>
<li>Link: <strong><a href="http://ipexpert.acrobat.com/p72556833/">http://ipexpert.acrobat.com/p72556833/</a></strong><strong></strong></li>
</ul>
<p>CCIE Routing &amp; Switching &amp; CCIE Service Provider</p>
<ul>
<li>Instructor: Marko Milivojevic</li>
<li>Topic: Frame Relay</li>
<li>Link: <a href="http://ipexpert.acrobat.com/p65152326/">http://ipexpert.acrobat.com/p65152326/</a></li>
</ul>
<ul>
<li>Instructor: Marko Milivojevic</li>
<li>Topic: Interdomain Multicast Routing</li>
<li>Link: <a href="http://ipexpert.acrobat.com/p12735927/">http://ipexpert.acrobat.com/p12735927/</a></li>
</ul>
<p>Do not miss our vLectures scheduled for the coming weeks. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/09/02/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join One of IPexpert’s Industry-Recognized Instructors for FREE Online CCIE Training This Week</title>
		<link>http://blog.ipexpert.com/2010/08/31/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-6/</link>
		<comments>http://blog.ipexpert.com/2010/08/31/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-6/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 13:14:43 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[General Announcements]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[free ccie r&s training]]></category>
		<category><![CDATA[free ccie routing & switching training]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie service provider training]]></category>
		<category><![CDATA[free ccie sp training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie vlectures]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4811</guid>
		<description><![CDATA[Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes? Have you ever had problems really understanding a specific technical topic? Do you want to improve your chances at pass the CCIE Lab? Do you want to see why IPexpert’s  CCIE instructors are considered the best in the training industry? Do you want [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F31%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-6%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F31%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-6%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes?<br />
Have you ever had problems really understanding a specific technical topic?</p>
<p>Do you want to improve your chances at pass the CCIE Lab?</p>
<p>Do you want to see why IPexpert’s  <a href="http://www.ipexpert.com/company/team">CCIE instructors</a> are considered the best in the training industry?</p>
<p>Do you want IPexpert, the company who has trained <a href="http://www.ipexpert.com/company/success">more CCIEs</a> in the world, to help you?</p>
<p>…How would you like some FREE CCIE Lab training?</p>
<p><span id="more-4811"></span></p>
<p>IPexpert is now offering FREE online training sessions to all IPexpert clients. If you want to improve your chances at passing Cisco’s rigorous and prestigious CCIE certifications, or if you simply want to fully-understand a specific technical topic – you can’t miss our FREE Online <strong>vLectures</strong>! Several times a week, you will be able to sit in, watch and interact with the IPexpert Instructor who will be teaching technology-focused classes on a specific track and topic. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
<p>CCIE Security:</p>
<ul>
<li>Date / Time: Aug 31<sup>st</sup> at 4 PM EST</li>
<li>Instructor:  Tyson      Scott</li>
<li>Topic: VRF Aware      VPN</li>
</ul>
<ul>
<li>Date / Time: Sept 7<sup>th</sup> at 2 PM EST</li>
<li>Instructor:  Tyson      Scott</li>
<li>Topic: Troubleshooting      IPset</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Security/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Routing and Switching:</p>
<ul>
<li>Date / Time: Sept 2<sup>nd</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: RIP</li>
</ul>
<ul>
<li>Date / Time: Sept 10<sup>th</sup> at 2 PM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Routing      protocol redistribution</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Routing-and-Switching/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Service Provider:</p>
<ul>
<li>Date / Time: Sept 2<sup>nd</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: RIP</li>
</ul>
<ul>
<li>Date / Time: Sept 10<sup>th</sup> at 2 PM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Routing      protocol redistribution</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Service-Provider/Free-Mentoring/vLecture">Schedule Now!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/31/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join One of IPexpert’s Industry-Recognized Instructors for FREE Online CCIE Training This Week</title>
		<link>http://blog.ipexpert.com/2010/08/24/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-5/</link>
		<comments>http://blog.ipexpert.com/2010/08/24/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-5/#comments</comments>
		<pubDate>Tue, 24 Aug 2010 13:01:55 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[Ask the Expert]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[Techtorials]]></category>
		<category><![CDATA[free ccie]]></category>
		<category><![CDATA[free ccie r&s training]]></category>
		<category><![CDATA[free ccie routing & switching training]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie service provider training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie vlectures]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4593</guid>
		<description><![CDATA[Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes? Have you ever had problems really understanding a specific technical topic? Do you want to improve your chances at pass the CCIE Lab? Do you want to see why IPexpert’s  CCIE instructors are considered the best in the training industry? Do you want [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F24%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-5%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F24%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-5%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes?<br />
Have you ever had problems really understanding a specific technical topic?</p>
<p>Do you want to improve your chances at pass the CCIE Lab?</p>
<p>Do you want to see why IPexpert’s  <a href="http://www.ipexpert.com/company/team">CCIE instructors</a> are considered the best in the training industry?</p>
<p>Do you want IPexpert, the company who has trained <a href="http://www.ipexpert.com/company/success">more CCIEs</a> in the world, to help you?</p>
<p>…How would you like some FREE CCIE Lab training?</p>
<p><span id="more-4593"></span></p>
<p>IPexpert is now offering FREE online training sessions to all IPexpert clients. If you want to improve your chances at passing Cisco’s rigorous and prestigious CCIE certifications, or if you simply want to fully-understand a specific technical topic – you can’t miss our FREE Online <strong>vLectures</strong>! Several times a week, you will be able to sit in, watch and interact with the IPexpert Instructor who will be teaching technology-focused classes on a specific track and topic. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
<p>CCIE Security:</p>
<ul>
<li>Date / Time: Aug 31<sup>st</sup> at 2 PM EST</li>
<li>Instructor:  Tyson      Scott</li>
<li>Topic: VRF Aware      VPN</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Security/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Routing and Switching:</p>
<ul>
<li>Date / Time: Aug 24<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Frame      Relay &#8211; From Basics to QoS</li>
</ul>
<ul>
<li>Date / Time: Sept 2<sup>nd</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: RIP</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Routing-and-Switching/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Service Provider:</p>
<ul>
<li>Date / Time: Aug 24<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Frame      Relay &#8211; From Basics to QoS</li>
</ul>
<ul>
<li>Date / Time: Sept 2<sup>nd</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: RIP</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Service-Provider/Free-Mentoring/vLecture">Schedule Now!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/24/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-5/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Seeing is Believing- How can I see the entire config on an ASA?</title>
		<link>http://blog.ipexpert.com/2010/08/23/seeing-is-believing-how-can-i-see-the-entire-config-on-an-asa/</link>
		<comments>http://blog.ipexpert.com/2010/08/23/seeing-is-believing-how-can-i-see-the-entire-config-on-an-asa/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 13:04:29 +0000</pubDate>
		<dc:creator>Brandon Carroll</dc:creator>
				<category><![CDATA[Ask the Expert]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[CCIE Security 3.0]]></category>
		<category><![CDATA[ccie security strategy]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=2813</guid>
		<description><![CDATA[I remember a time when I taught a class called CIT (Cisco Internetwork Troubleshooting) and there was a wonderful rule that made all the students sweat a little more and all the instructors give that old Dr.Claw laugh (From Inspector Gadget if you have no idea what I&#8217;m talking about).  Essentially it allowed the Instructor [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F23%2Fseeing-is-believing-how-can-i-see-the-entire-config-on-an-asa%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F23%2Fseeing-is-believing-how-can-i-see-the-entire-config-on-an-asa%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>I remember a time when I taught a class called CIT (Cisco Internetwork Troubleshooting) and there was a wonderful rule that made all the students sweat a little more and all the instructors give that old Dr.Claw laugh (From Inspector Gadget if you have no idea what I&#8217;m talking about).  Essentially it allowed the Instructor to do things that were really mean and evil and forced the students NOT to take the easy way out.  What was that rule?  When troubleshooting you may NOT use the command Show Running-Config or any variant of it. <span id="more-2813"></span></p>
<p>Some of you are thinking&#8230;.wow- I would be lost.  To be honest I would be as well depending on the technology and the situation I&#8217;m in.  So I won&#8217;t burden you with that rule.  However, I would like to share a command that does&#8217;t just give you the running configuration on the ASA, rather it gives you the &#8220;real&#8221; running configuration.  What am I talking about?  Well, simply put- show run all&#8230;</p>
<p>That&#8217;s right!  While many of you know this deep dark secret (it&#8217;s not really a secret)  other don&#8217;t.  So there ya go!  A little tipt to put in your tip jar.</p>
<p>So the next time the boss says, &#8220;Man I cant remember the syntax of the default group policy on our ASA,&#8221; you can quickly respond with&#8230;</p>
<p><em>(type..type..type&#8230;)</em></p>
<pre>ciscoasa# <strong>sh run all group-policy</strong></pre>
<pre>group-policy DfltGrpPolicy internal</pre>
<pre>group-policy DfltGrpPolicy attributes</pre>
<pre>banner none</pre>
<pre>wins-server none</pre>
<pre>dns-server none</pre>
<pre>dhcp-network-scope none</pre>
<pre>vpn-access-hours none</pre>
<pre>vpn-simultaneous-logins 3</pre>
<pre>vpn-idle-timeout 30</pre>
<pre>vpn-session-timeout none</pre>
<pre>vpn-filter none</pre>
<pre>ipv6-vpn-filter none</pre>
<pre>vpn-tunnel-protocol IPSec l2tp-ipsec webvpn</pre>
<pre>password-storage disable</pre>
<pre>ip-comp disable</pre>
<pre>re-xauth disable</pre>
<pre>group-lock none</pre>
<pre>pfs disable</pre>
<pre>ipsec-udp disable</pre>
<pre>ipsec-udp-port 10000</pre>
<pre>split-tunnel-policy tunnelall</pre>
<pre>split-tunnel-network-list none</pre>
<pre>default-domain none</pre>
<pre>split-dns none</pre>
<pre>intercept-dhcp 255.255.255.255 disable</pre>
<pre>&lt;--- More ---&gt;</pre>
<p>&#8220;It&#8217;s DfltGrpPolicy boss.  Anything else you need before I head to lunch?&#8221;</p>
<p>-Regards</p>
<p>Brandon Carroll – CCIE #23837</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/23/seeing-is-believing-how-can-i-see-the-entire-config-on-an-asa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Accessing ProctorLabs Devices (Mac and Linux)</title>
		<link>http://blog.ipexpert.com/2010/08/16/accessing-proctorlabs-devices-mac-and-linux/</link>
		<comments>http://blog.ipexpert.com/2010/08/16/accessing-proctorlabs-devices-mac-and-linux/#comments</comments>
		<pubDate>Mon, 16 Aug 2010 13:04:39 +0000</pubDate>
		<dc:creator>Marko Milivojevic</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Proctor Labs]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[Support]]></category>
		<category><![CDATA[Voice]]></category>
		<category><![CDATA[CCIE Rack]]></category>
		<category><![CDATA[CCIE Rack Rental]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4441</guid>
		<description><![CDATA[Couple of months ago, I wrote an article on various convenient methods of accessing ProctorLabs CCIE rack rental devices. That article focused on Windows users. This is part two of that series, with focus on students using Mac or Linux. The biggest challenge for Mac and Linux users is selecting good terminal program to use. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F16%2Faccessing-proctorlabs-devices-mac-and-linux%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F16%2Faccessing-proctorlabs-devices-mac-and-linux%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Couple of months ago, I wrote <a href="http://blog.ipexpert.com/2010/02/24/accessing-proctorlabs-devices/" target="_blank">an article</a> on various convenient methods of accessing ProctorLabs CCIE rack rental devices. That article focused on Windows users. This is part two of that series, with focus on students using Mac or Linux.<span id="more-4441"></span></p>
<p>The biggest challenge for Mac and Linux users is selecting good terminal program to use. There are many choices, but they all share almost the same difficulty &#8211; lack of consistency in supporting &#8220;bookmarks&#8221;, or in some cases, even the basic lack of support for tabs. </p>
<p>With this in mind, we looked into what these platforms had in common and we found one thing. By default, they all support CLI access to terminal, regardless of which application is in use. Many power users are quite happy to use command line to access our rack rental anyway. Capitalizing on that and making that single task is the approach we took. Before I examine that in more detail, here is something very nice for our Mac users.</p>
<h2>SecureCrt for Mac</h2>
<p>SecureCRT beta is now available for download from the manufacturer, <a href="http://vandyke.com/" target="_blank">VanDyke</a>. We tested our bookmark set with Mac version and it works flawlessly! Good job, VanDyke.</p>
<p>You can download SecureCRT bookmarks from here: <a href="http://blog.ipexpert.com/wp-content/uploads/2010/02/ProctorLabs-SecureCRT.zip">ProctorLabs-SecureCRT.zip</a></p>
<h2>IPexpert&#8217;s PodConnect</h2>
<p>IPexpert&#8217;s approach to remote Pod access from Mac and Linux is quite simple. When you are in your CLI, simply type the command &#8220;PodConnect.pl r1&#8243; and you will be connected to the R1 on the ProctorLabs pod you choose as default. If you specified your username and password, PodConnect will log you in. You are now ready to work. Take a look at the example session I use:</p>
<pre>Mac ~> <span style="background-color: gray">PodConnect.pl r2</span>
Trying 74.126.20.111...
Won't send login name and/or authentication information.
Connected to pod111ts1.proctorlabs.com.
Escape character is '^]'.

         ****PROCTOR LABS, INC. SECURE ONLINE RACK SYSTEM****
      WELCOME to Proctor Labs, Inc. CCIE preparation vRack.

    WARNING:  This system is for the use of authorized clients only.
          Unauthorized access is a violation of federal, state,
                        civil and criminal laws.

http://www.ProctorLabs.com

User Access Verification

Username: myusername
Password: 

            You are on line number: 2

R2#</pre>
<p>That&#8217;s all I have to do. Regardless of the terminal emulator program I use, it will work. Here&#8217;s how you install it.</p>
<ul>
<li>Make sure you have Perl installed.
</li>
<li>Make sure you have Expect and Perl Expect module installed.
</li>
<li>Download the <a href="http://blog.ipexpert.com/wp-content/uploads/2010/08/PodConnect.zip">PodConnect.zip</a> file.
</li>
<li>Unzip the file into the folder in your path. Personally, I use $HOME/bin for this
</li>
<li>Make the file executable: chmod 700 PodConnect.pl
</li>
<li>Try it out!
</li>
</ul>
<p>If you run PodConnect.pl, you will probably notice error message telling you that you need to specify the Pod. You can do that after the device name. For example, running &#8220;PodConnect.pl r1 111&#8243;, will connect you to the R1 on Pod #111. You can set the default pod by setting &#8220;PL_POD&#8221; environment variable. </p>
<p>Once you run the Pod, if environment variable PL_USERNAME and PL_PASSWORD are set, PodConnect.pl will attempt to automatically log you in using those credentials. If those variables are not set, you will need to log-in manually.</p>
<p>To make things even quicker, here are couple of tricks you can do. Add the following lines to your $HOME/.profile:</p>
<pre>alias c="$HOME/bin/PodConnect.pl"
export PL_POD="111"
export PL_USERNAME="myusername"
export PL_PASSWORD="mypassword"</pre>
<p>Next time you open the terminal, you should be able to connect to ProctorLabs devices in your pod by simply typing &#8220;c device&#8221;, like this:</p>
<pre>Mac ~> <span style="background-color: gray">c r2</span>
Trying 74.126.20.111...
Won't send login name and/or authentication information.
Connected to pod111ts1.proctorlabs.com.
Escape character is '^]'.

         ****PROCTOR LABS, INC. SECURE ONLINE RACK SYSTEM****
      WELCOME to Proctor Labs, Inc. CCIE preparation vRack.

    WARNING:  This system is for the use of authorized clients only.
          Unauthorized access is a violation of federal, state,
                        civil and criminal laws.

http://www.ProctorLabs.com

Username: myusername
Password: 

            You are on line number: 2

R2#</pre>
<p><strong><u>NOTE:</u> If you store your password in .profile, make sure the file is readable only by your user account. The best way to ensure this is to set permissions to 600 on it (chmod 600 ~/.profile).</strong></p>
<p>Enjoy your studies!</p>
<p>&#8211;<br />
<a href="http://facebook.com/ccie18427" target="_blank">Marko Milivojevic</a> &#8211; CCIE #18427<br />
Senior Technical Instructor &#8211; <a href="http://www.ipexpert.com/" target="_blank">IPexpert</a><br />
Join our <a href="http://www.onlinestudylist.com/" target="_blank">Online Study List</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/16/accessing-proctorlabs-devices-mac-and-linux/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Join One of IPexpert’s Industry-Recognized Instructors for FREE Online CCIE Training This Week</title>
		<link>http://blog.ipexpert.com/2010/08/10/join-one-of-ipexperts-industry-recognized-instructors-for-free-online-ccie-training-this-week-4-2/</link>
		<comments>http://blog.ipexpert.com/2010/08/10/join-one-of-ipexperts-industry-recognized-instructors-for-free-online-ccie-training-this-week-4-2/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 13:10:05 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[General Announcements]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[Voice]]></category>
		<category><![CDATA[free ccie r&s training]]></category>
		<category><![CDATA[free ccie routing & switching training]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie sp training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie voice training]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4517</guid>
		<description><![CDATA[Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes? Have you ever had problems really understanding a specific technical topic? Do you want to improve your chances at pass the CCIE Lab? Do you want to see why IPexpert’s  CCIE instructors are considered the best in the training industry? Do you want [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F10%2Fjoin-one-of-ipexperts-industry-recognized-instructors-for-free-online-ccie-training-this-week-4-2%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F10%2Fjoin-one-of-ipexperts-industry-recognized-instructors-for-free-online-ccie-training-this-week-4-2%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes?<br />
Have you ever had problems really understanding a specific technical topic?</p>
<p>Do you want to improve your chances at pass the CCIE Lab?</p>
<p>Do you want to see why IPexpert’s  <a href="http://www.ipexpert.com/company/team">CCIE instructors</a> are considered the best in the training industry?</p>
<p>Do you want IPexpert, the company who has trained <a href="http://www.ipexpert.com/company/success">more CCIEs</a> in the world, to help you?</p>
<p>…How would you like some FREE CCIE Lab training?</p>
<p><span id="more-4517"></span></p>
<p>IPexpert is now offering FREE online training sessions to all IPexpert clients. If you want to improve your chances at passing Cisco’s rigorous and prestigious CCIE certifications, or if you simply want to fully-understand a specific technical topic – you can’t miss our FREE Online <strong>vLectures</strong>! Several times a week, you will be able to sit in, watch and interact with the IPexpert Instructor who will be teaching technology-focused classes on a specific track and topic. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
<p>CCIE Security:</p>
<ul>
<li>Date / Time: Aug 10<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Tyson      Scott</li>
<li>Topic: DMVPN</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Security/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Voice:</p>
<ul>
<li>Date / Time: Aug 12<sup>th</sup> at 1 PM EST</li>
<li>Instructor:  Vik Mahli</li>
<li>Topic: Cube</li>
</ul>
<ul>
<li>Date / Time: Aug 17<sup>th</sup> at 4 PM EST</li>
<li>Instructor:  Amy Ryan</li>
<li>Topic: Unity      Connections Integrations</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Voice/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Routing and Switching:</p>
<ul>
<li>Date / Time: Aug 19<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Interdomain      Multicast Routing</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Routing-and-Switching/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Service Provider:</p>
<ul>
<li>Date / Time: Aug 19<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Marko Milivojevic</li>
<li>Topic: Interdomain      Multicast Routing</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Service-Provider/Free-Mentoring/vLecture">Schedule Now!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/10/join-one-of-ipexperts-industry-recognized-instructors-for-free-online-ccie-training-this-week-4-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free CCIE Lab Training: Links to This Weeks &amp; Last Weeks Recorded vLectures</title>
		<link>http://blog.ipexpert.com/2010/08/05/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-8/</link>
		<comments>http://blog.ipexpert.com/2010/08/05/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-8/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 13:15:12 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[Ask the Expert]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Techtorials]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie vlectures]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4398</guid>
		<description><![CDATA[Did you Miss our vLectures that were scheduled for this week &#38; last week? No worries! All our vLecture sessions are recorded and available for those who have missed our FREE vLecture and for participants who want to review the vLectures sessions again. We have saved the session recordings for you. Watch our world renowned [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F05%2Ffree-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-8%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F05%2Ffree-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-8%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Did you Miss our vLectures that were scheduled for this week &amp; last week? No worries!</p>
<p>All our vLecture sessions are recorded and available for those who have missed our FREE vLecture and for participants who want to review the vLectures sessions again. We have saved the session recordings for you. Watch our world renowned <a href="https://www.ipexpert.com/Company/Team">CCIE instructors</a> explaining specific technical topic in our technology-focused classes and capture the technical knowledge needed to increase your chances of passing CCIE exam.</p>
<p><span id="more-4398"></span></p>
<p>CCIE Security</p>
<ul>
<li>Instructor: Tyson Scott</li>
<li>Topic: ASA &amp; IOS based NAT</li>
<li>Link: <strong><a href="http://ipexpert.acrobat.com/p92268115/">http://ipexpert.acrobat.com/p92268115/</a></strong><strong></strong></li>
</ul>
<p>Do not miss our vLectures scheduled for the coming weeks. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/05/free-ccie-lab-training-links-to-this-weeks-last-weeks-recorded-vlectures-8/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Join One of IPexpert’s Industry-Recognized Instructors for FREE Online CCIE Training This Week</title>
		<link>http://blog.ipexpert.com/2010/08/03/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-3/</link>
		<comments>http://blog.ipexpert.com/2010/08/03/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-3/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 13:01:57 +0000</pubDate>
		<dc:creator>Sanjana Desai</dc:creator>
				<category><![CDATA[Ask the Expert]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[General Announcements]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Techtorials]]></category>
		<category><![CDATA[Voice]]></category>
		<category><![CDATA[free ccie]]></category>
		<category><![CDATA[free ccie security training]]></category>
		<category><![CDATA[free ccie training]]></category>
		<category><![CDATA[free ccie vlectures]]></category>
		<category><![CDATA[free ccie voice training]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4376</guid>
		<description><![CDATA[Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes? Have you ever had problems really understanding a specific technical topic? Do you want to improve your chances at pass the CCIE Lab? Do you want to see why IPexpert’s  CCIE instructors are considered the best in the training industry? Do you want [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F03%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-3%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F08%2F03%2Fjoin-one-of-ipexpert%25e2%2580%2599s-industry-recognized-instructors-for-free-online-ccie-training-this-week-3%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Have you ever wanted to attend one of IPexpert’s industry-leading CCIE classes?<br />
Have you ever had problems really understanding a specific technical topic?</p>
<p>Do you want to improve your chances at pass the CCIE Lab?</p>
<p>Do you want to see why IPexpert’s  <a href="http://www.ipexpert.com/company/team">CCIE instructors</a> are considered the best in the training industry?</p>
<p>Do you want IPexpert, the company who has trained <a href="http://www.ipexpert.com/company/success">more CCIEs</a> in the world, to help you?</p>
<p>…How would you like some FREE CCIE Lab training?</p>
<p><span id="more-4376"></span></p>
<p>IPexpert is now offering FREE online training sessions to all IPexpert clients. If you want to improve your chances at passing Cisco’s rigorous and prestigious CCIE certifications, or if you simply want to fully-understand a specific technical topic – you can’t miss our FREE Online <strong>vLectures</strong>! Several times a week, you will be able to sit in, watch and interact with the IPexpert Instructor who will be teaching technology-focused classes on a specific track and topic. If you’re an IPexpert client and wish to join these sessions, please be sure to reserve a “virtual seat” now, these have been highly anticipated and we’re quite confident that these online training seats will fill up quickly.</p>
<p>CCIE Security:</p>
<ul>
<li>Date / Time: Aug 8<sup>th</sup> at 10 AM EST</li>
<li>Instructor:  Tyson      Scott</li>
<li>Topic: DMVPN</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Security/Free-Mentoring/vLecture">Schedule Now!</a></p>
<p>CCIE Voice:</p>
<ul>
<li>Date / Time: Aug 12th at 1 PM EST</li>
<li>Instructor:  Vik Mahli</li>
<li>Topic: Cube</li>
</ul>
<p>If you&#8217;re interested in this FREE online session, click here to <a href="http://www.ipexpert.com/Cisco/CCIE/Voice/Free-Mentoring/vLecture">Schedule Now!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/08/03/join-one-of-ipexpert%e2%80%99s-industry-recognized-instructors-for-free-online-ccie-training-this-week-3/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Are You Looking to Hire a CCIE, or Are You a CCIE Seeking a New Career?</title>
		<link>http://blog.ipexpert.com/2010/07/30/ccie-jobs-ccie-recruiter/</link>
		<comments>http://blog.ipexpert.com/2010/07/30/ccie-jobs-ccie-recruiter/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 18:22:10 +0000</pubDate>
		<dc:creator>Wayne Lawson II</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[General Announcements]]></category>
		<category><![CDATA[Info Center]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Routing & Switching]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Voice]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[ccie headhunter]]></category>
		<category><![CDATA[CCIE Job]]></category>
		<category><![CDATA[ccie job placement]]></category>
		<category><![CDATA[CCIE Jobs]]></category>
		<category><![CDATA[ccie recruiter]]></category>
		<category><![CDATA[CCIE Salary]]></category>
		<category><![CDATA[CCNP job]]></category>
		<category><![CDATA[CCNP jobs]]></category>
		<category><![CDATA[CCVP job]]></category>
		<category><![CDATA[CCVP jobs]]></category>
		<category><![CDATA[IT Job Search]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=4367</guid>
		<description><![CDATA[We&#8217;re pleased to announce the launch of a service that&#8217;s been requested for years, a CCIE job / recruiting service. In the past we&#8217;ve attempted to partner with various firms, but in the end &#8211; it just didn&#8217;t work. So &#8211; if you&#8217;re a CCIE (or even a CCVP or CCNP) and you&#8217;re seeking a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F07%2F30%2Fccie-jobs-ccie-recruiter%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F07%2F30%2Fccie-jobs-ccie-recruiter%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>We&#8217;re pleased to announce the launch of a service that&#8217;s been requested for years, a CCIE job / recruiting service. In the past we&#8217;ve attempted to partner with various firms, but in the end &#8211; it just didn&#8217;t work. So &#8211; if you&#8217;re a CCIE (or even a CCVP or CCNP) and you&#8217;re seeking a new job or interested in hearing about new career opportunities &#8211; or, if you&#8217;re on the opposite end of the spectrum and you&#8217;re the company, organization (or even another recruiting firm) looking for the ideal high-end CCIE for a job opening you have &#8211; I encourage you to visit <a href="http://www.PlatinumPlacementServices.com" target="_blank"><strong>Platinum Placement Services</strong></a><strong>. </strong>You can also follow their <a href="http://www.facebook.com/pages/Platinum-Placement-Services/141214389236769?v=info" target="_blank">Facebook</a>, <a href="http://twitter.com/ppsforcciejobs" target="_blank">Twitter </a>and <a href="http://www.linkedin.com/pub/platinumplacement-services/23/547/7aa" target="_blank">LinkedIn</a> social initiatives where various CCIE jobs will be posted periodically.</p>
<p>- Wayne</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/07/30/ccie-jobs-ccie-recruiter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ASA Accelerated Security Path</title>
		<link>http://blog.ipexpert.com/2010/07/29/asa-accelerated-security-path/</link>
		<comments>http://blog.ipexpert.com/2010/07/29/asa-accelerated-security-path/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 13:24:07 +0000</pubDate>
		<dc:creator>Stuart Hare</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Techtorials]]></category>
		<category><![CDATA[Accelerated Path]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[CCIE 3.0 Security]]></category>

		<guid isPermaLink="false">http://blog.ipexpert.com/?p=2590</guid>
		<description><![CDATA[This post will provide a brief overview of a seldom referred to part of the ASA, the Accelerated Security Path (ASP). As we know the ASA’s Adaptive Security Algorithm is responsible for inspecting all traffic that traverses the ASA, and based on its configured security policies will either permit or deny the traffic. As a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F07%2F29%2Fasa-accelerated-security-path%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fblog.ipexpert.com%2F2010%2F07%2F29%2Fasa-accelerated-security-path%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>This post will provide a brief overview of a seldom referred to part of the ASA, the Accelerated Security Path (ASP). As we know the ASA’s Adaptive Security Algorithm is responsible for inspecting all traffic that traverses the ASA, and based on its configured security policies will either permit or deny the traffic.<span id="more-2590"></span></p>
<p>As a new connection enters the ASA it is processed using the Session Management Path.</p>
<p>Part of the Session Management Path’s processing is to inspect and create the relevant entry in the ASA’s state/connection table, if a policies exists allowing the traffic.</p>
<p>Generally any further packets received for these established connections, does not require further inspection and are subsequently handled by the Fast Path. Although, there may be certain packets that would continue to use the session management path or be passed to the control plane path, such as flows requiring HTTP inspection, FTP or H.232 etc.</p>
<p>This is akin to Process switching and CEF switching in IOS Routers.</p>
<p>The Session Management Path and Fast Path combined are what make up the Accelerated Security Path.</p>
<p>ASP can come in handy when we want to troubleshoot traffic flows through the ASA. This is done via a suite of ASP show commands, and can also be incorporated into packet captures, using a capture type of asp-drop.</p>
<p>With ASP debugging we can drill down into the output to see what functions or methods are responsible for dropping the traffic on the ASA. There are two set of commands available to us, both of which have a substantial amount of optional keywords; these are, ‘show asp drop’ and show asp table’.</p>
<p>Starting with ‘show asp drop’ will give us a summary of packets or connections that have been denied by ASP providing an associated reason and hits on each. As we can see from the output below it is split into 2 sections; Frame Drop &#8211; which is based on packet failures; and Flow Drop &#8211; based on inspected traffic flow failures.</p>
<p>It gives us a brief breakdown of denies based on malformed TCP sessions, Reverse Path Forwarding violations, or simply denies based on ACL entries etc.</p>
<pre>ASA# <span style="background-color: gray">show asp drop</span>
Frame drop:
Reverse-path verify failed (rpf-violated)                                 1432
Flow is denied by configured rule (acl-drop)                         100495787
First TCP packet not SYN (tcp-not-syn)                                    2234
TCP failed 3 way handshake (tcp-3whs-failed)                                20
TCP packet SEQ past window (tcp-seq-past-win)                               28
TCP replicated flow pak drop (tcp-fo-drop)                                   8
TCP RST/SYN in window (tcp-rst-syn-in-win)                                   2
TCP packet failed PAWS test (tcp-paws-fail)                                  3
Slowpath security checks failed (sp-security-failed)                         1
Expired flow (flow-expired)                                                  2
ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched)          6
FP L2 rule drop (l2_acl)                                               7911378
Interface is down (interface-down)                                        1143
Dropped pending packets in a closed socket (np-socket-closed)               19
Last clearing: Never
Flow drop:
Inspection failure (inspect-fail)                                            2
Last clearing: Never</pre>
<p>You can also further drill into more specific output using optional keywords, based on either frame or flow drop, such as &#8220;show asp drop frame ifc-classify&#8221; &#8211; when in virtual firewall mode shows counts for packets that failed to be classified to context; or &#8220;show asp drop flow conn-limit-exceeded&#8221; &#8211; increments when the value applied to set connection conn-max is breached.</p>
<p>These are just a couple of the vast amount of options available for use. Check out the ASA Command Reference document for a full listing.</p>
<p>A key point with the ASP drop output is when running in Multi Context Mode, the information provided is a summary for all of the virtual contexts not just the context you are currently logged into.</p>
<p>The other side of ASP is the &#8220;show asp table&#8221; commands. These are typically used by TAC, so contain a great deal of info on a production appliance. These tables are primarily used for debugging, so the output is prone to regular changes.</p>
<p>Below are the asp tables available:</p>
<pre>ASA# <span style="background-color: gray">show asp table ?</span>
arp
classify    Show ASP classifier tables
interfaces  Show ASP interfaces tables
routing     Show ASP route tables
socket      Show ASP socket info</pre>
<p>The &#8220;show asp table arp&#8221; for instance can be used to check that traffic is flowing to/from a specific host/s based on an incrementing hit count. It is important to remember that this is dynamic real time output though and will be subject to resetting.</p>
<pre>ASA# <span style="background-color: gray">sh asp table arp</span>
Context: LEFT, Interface: Inside
10.1.1.66                            Active   0050.56a5.35b9 hits 15
10.1.1.65                            Active   0050.56a5.7d06 hits 0</pre>
<p>The &#8220;show asp table routing&#8221; can give us further info into how specific nets are routed. This is provided based on two tables; an input routing table and an output routing table, each showing the routable nets and their associated interfaces.</p>
<pre>ASA# <span style="background-color: gray">sh asp table routing</span>
in   	10.1.1.64   	255.255.255.192	Inside
out  	10.1.1.64   	255.255.255.192	Inside
in 	0.0.0.0		0.0.0.0			Outside
out 	0.0.0.0		0.0.0.0			via 10.1.1.254, Outside</pre>
<p>And to finish off a quick look at the classify table. This table consists of multiple classifier domains which correspond to a specific rule action within the ASA, I.e. Inspection rules, filtering rules nat rules etc. Again check out the command reference for a list of the options.</p>
<p>Below is an example showing SMTP traffic is being inspected and allowed to the inside interface:</p>
<pre>ASA# <span style="background-color: gray">sh asp table classify domain inspect-smtp</span>
Interface Inside:
in  id=0x1d43bbf0, priority=70, domain=inspect-smtp, deny=false
hits=89, user_data=0x1d1a18f0, cs_id=0x0, use_real_addr, flags=0x0, protocol=6
src ip=0.0.0.0, mask=0.0.0.0, port=0
dst ip=0.0.0.0, mask=0.0.0.0, port=25, dscp=0x0</pre>
<p>The documentation for ASP is minimal, the best way forward with this is get your head into the output and retain what you feel is useful.</p>
<p>So the next time your caught in a troubleshooting exercise check out the ASP output and see whether combining this with your debug, captures and logs, can assist in resolving your issues!!</p>
<p>&#8211;<br />
Stuart Hare<br />
CCIE #25616 (Security), CCSP, Microsoft MCP<br />
Sr. Support Engineer – IPexpert, Inc.<br />
URL: <a href="http://www.ipexpert.com">http://www.ipexpert.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ipexpert.com/2010/07/29/asa-accelerated-security-path/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
