Anda di halaman 1dari 4

www.CareerCert.

info

CCIE Security Workbooks V3 (VA+)

Updated NOV 2009

www.CareerCert.info

In VA+, some new questions are added into ccie security real lab.
Following are the new questions which appear on VA+:
Section 8.3:
In order to deny the attack from BB2,R3 should not advertise routes into
BB2,The protocol between R3 and BB2 is BGP.
Solution:
R3 fa0/1
(Config-if)#no ip unreachable
#no cdp enable
#no ldp receive
(Config) #ip prefix-list abc deny 0.0.0.0 0.0.0.0 le 32
#route-map abc
#match ip address prefix-list abc
(Config)#router bgp 100
#neighb 150.2.45.1 route-map abc

Section 7.2:
New Added: The switch should auto-recovery within 500 seconds
Solution:
(Config)#errdisable recovery caue speeure-violation
#errdisable recovery interval 500

www.CareerCert.info

Section 7.1:
TCP intercept
Solution:
#access-list 100 permit tcp any host 45.45.19.20
#ip tcp intercept mode watch
#ip tcp intercept list 100
#ip tcp intercept watch-timeout 5
#ip tcp intercept max-incomplete high 1200
#ip tcp intercept max-incomplete low 1000

Section 6.2:
SNMP V3
Solution:
#snmp-server view rootview internet included
Snmp-server view nocview interfaces included
Snmp-server group root v3 auth read rootview write rootview
Snmp-server group noc v3 auth read nocview
Snmp-server user root root v3 auth md5 cisco
Snmp-server user noc noc v3 auth md5 cisco

www.CareerCert.info

Section 6.3:
Storm-control
Solution:
SW1 f0/9
#storm-control broadcast level 70 60
#storm-control action shutdown

Section 5.2:
ASA agent and tacacs+
Solution:
#static (inside,outside) 45.45.7.88 45.45.7.88
#access-list auth permit tcp any host 24.1.2.2 eq www
#aaa authentication match auth inside acs1
#aaa authorization match auth inside acs1
#aaa-server acs1 protocol tacacs+
#aaa-server acs1 (inside) host 45.45.18.10
#key cisco123
SW3
#ip http server

Anda mungkin juga menyukai