This blog was originally started to better help me understand the technologies in the CCIE R&S blueprint; after completing the R&S track I have decided to transition the blog into a technology blog.

CCIE #29033

This blog will continue to include questions, troubleshooting scenarios, and references to existing and new technologies but will grow to include a variety of different platforms and technologies. Currently I have created over 185 questions/answers in regards to the CCIE R&S track!! Note: answers are in the comment field or within "Read More" section.

You can also follow me on twitter @FE80CC1E


Sunday, January 22, 2012

Layer 2 Security Best Practices

Here are a couple of recommendations from Cisco when it comes to securing layer 2

  • STP - Leverage Root Guard and BPDU Guard
  • Shutdown unused ports
  • Leverage DHCP snooping and DAI (Dynamic Arp Inspection)
  • Disable unneeded services
  • Use port security to restrict the number of MAC addresses that a port can learn
  • Limit management access to a layer 2 switch
  • Use SNMPv3
  • Do not use the native VLAN to send user data. Create a native VLAN and do not add any ports to it.

This was not mentioned but I would also add PVLAN (Private VLANs) and VACL's where appropriate.

Monday, January 16, 2012

CCIE Security.....

Well I have started the long process of becoming a CCIE in security. I am going to start right from the beginning (CCNA Security---> CCNP Security---> CCIE Security Written ---> CCIE Lab) to ensure that no topics are left unturned. I am not sure that I learned my lesson from the R&S track but I have to renew by May of 2013 so Security made the most sense.

Anyone going down the same path?


Cisco UCS Blades Deploy 47% Faster versus HP

A partner at Cisco shared this link with me showing the time differences between the deployment of blade servers. Cisco vs HP....imagine if you were deploying tens or hundreds of blades.

Tuesday, December 13, 2011

Fortinet - HA Master Selection


Master Selection - High Availability with Fortinet

Master (also known as the Primary) is chosen based on the following

  1. monitored port - (highest number of connected non failed monitored interfaces)
  2. system up time (age) -  (longest up-time)
  3. unit priority - (default 128 - higher priority is selected as Master)
  4. serial number - (highest serial number)
As soon as the FGCP protocol hits the first criteria that meets the requirement of the master selection process the rest of the evaluation process is no longer evaluated and the master node is selected.


Friday, December 9, 2011

Brocade Certification

I know its been awhile and I am looking forward to posting again. I most recently have been asked to look deeper into Brocade so I looked up their certification path and was surprised to find the following


Sunday, October 30, 2011

Data Center Enhanced Ethernet


Data Center Enhanced Ethernet (NGDC - Next Generation Data Centers)


  • Priority Based Flow Control (802.1Qbb) - Supports storage traffic and provides CoS flow control
  • CoS Based BW Management (802.1Qaz) - CoS based enhanced transmission, grouping of classes into "service lanes"
  • Backward Congestion Notification (BCN/QCN - 802.1Qau)- end to end congestion management for L2 network
  • Data Center Bridging Capacity Exchange Protocol (DCBXP - 802.1AB) - Auto-negotiation for enhanced Ethernet capabilities (switch to nic)

Sunday, September 11, 2011

Availabilty

I have heard some engineers and administrators claim that their systems are available 100% of the time. I wanted to ensure that there is a clear understanding on what 100% availability means. Up-time does not equal availability; you can have a system that is up but the services may not be available. You also need to consider maintenance windows as this impacts your overall availability. If you do not have the ability to do maintenance without  impacting the services that you are providing then your overall availability percentages take a hit. Other things that may impact your ability of achieving 100% availability includes environmental's such as power, cooling, etc and other services that are required to provide access to the very services that you are providing such as internet connectivity, WAN, LAN, SAN, etc....

Below is a chart showing the availability percentages and the expected downtime per year based on these percentages.
 
So.....are you really providing 100% availability?

Saturday, September 10, 2011

vSphere 5.0 High Availability vs Previous Versions of VMware


This post is a follow up to a previous post "Virtualization-Vmware-Clusters and Blade Servers" where we discussed limitations with HA in previous versions of VMware.

In vSphere 5.0 the concept of 5 primary/secondary hosts has been eliminated and the concept of master/slave exists. A single host is the master and all other hosts are slaves, if the master fails then an election process is kicked off and a new master is elected.

This eliminates issues in previous versions of VMware where the primary/secondary concept existed and we needed to consider

  • Number of hosts in a cluster
  • Managing the role of the host
  • Number of consecutive host failures
  • Placement of hosts across blade chassis and stretched clusters
  • Partition scenarios likely to occur in stretched cluster environment

By the way Dave thanks for the link

Monday, September 5, 2011

You Never Know When You Need......

Cisco Borderless Network Architecture

Cisco's borderless networks provides secure, seamless, and reliable connectivity to anyone, anywhere, anytime to anything. Borderless network architecture is a technical architecture that allows organizations to realize these benefits.