CCNA Security Commands

#01 solara

As part of my study for CCNA Security I have been making a list of all the commands I need to be adept with. I thought I would share this list of commands with others who may be interested.

For simplicty the list doesn’t offer explanations and in most cases there are a variety of options that could be used with each command that are not shown. It is also not suitable for copy/paste into a router or switch. However, I think it is still a useful quick reference sheet.

#02 B Haines

You are running both RADIUS as well as TACACS+ servers in your example configuration. I was wondering what RAD/TACS you were running on those two servers? FreeRadius? And what Tac Plus? Just trying to determine what software you are using for your lab studies! Thanks!

By the way, thanks for sharing your config!

#03 solara

The previous example isn’t my config but rather just a list of commands to be familiar with and so I’m not actually running TACACS+ and RADIUS on the separate server addresses that I have shown.

I do my lab work using GNS3 with the C3745-ADVENTERPRISEK9_SNA-M IOS and currently I’m using the 90-day trial version of Cisco ACS 4.2 running on a Win2k3 VMWare box.

Just for interest I’ve attached a text file showing a basic config I’ve used for testing TACACS+. I have enabled debugs on aaa authentication and IP packets between the router and the ACS server and then attempted to logon to the router via SSH.

642-072:Cisco Unity Design and Networking(CUDN)

信息安全專業人員認證的技能包括:實施基本的身份識別、授權和核算;思科入侵檢測系統/入侵防禦系統傳感器; 思科VPN 3000系列連接器 使用訪問控制列表避開路由器、網絡和通用2層攻擊,據IT認證考試資源網介紹同時該證書也符合美國國家安全協會的CNSS 4011聯邦安全認證和培訓標準的要求,此標準是在美國在聯邦政府機構從事安全職業必須遵守的。

642-072是思科認證中壹項考試科目,642-072:Cisco Unity Design and Networking(CUDN),642-072包含了72道真題,真題的類型與642-072的考題題型基本吻合,目的就是為了保證考生100%通過642-072。Others 642-072(Cisco Unity Design and Networking(CUDN))考題由我們的資深IT認證講師和Others產品專家精心打造,包括了當前最新的真實642-072考題,全部附有正確答案。642-072題庫更新時間:2008年9月1日。

思科認證最常考到的考點:(壹)OSI七層結構體系:必須知道每層的作用,各種應用各屬於那壹層以及數據流通過每壹層時(從上往下,從下往上)的加HERDER和拆包情況。(二)幀中繼(FRAMERELAY)應用:CCNA認證考試中把幀中繼作為廣域網(WAN)部分的測試內容。妳將在考試中遇到大量屬於幀中繼的內容。所以,妳必須在準備時特別註意對幀中繼的學習。(三)ISDN問題:知道如TE-1、TE-2、NT-1、U界面(U-INTERFACE)、B-CHANNAL、D-CHANNAL以及壹些子通道(SUB-CHANNAL)等術語(ISDN涉及到的術語及縮寫特別多,必須知道各自的意思及作用),懂得BRI與PRI之間的區別。(四)清楚AccessList:了解DenyAccesslist對流入和流出數據流的限制,清楚DENYALL的隱含意義等。能夠熟練通過對子網掩碼的設置限制子網用戶。(五)以太網交換:熟悉以太網交換機以及交換原理,了解網絡沖突域分段原理及VLAN。