Rabu, 09 Maret 2005

Passed My CCNA Test

I just finished testing for my Cisco Certified Network Associate certification. I passed with a 973 out of 1000. The test was 90 minutes long and I finished with only 8 minutes to spare. I think I missed one question, maybe two. The exam was as tough as I expected, meaning it was not easy. I know it was difficult since I usually breeze through majority multiple-choice exams. (For example, I answered all 250 questions on the CISSP exam in 90 minutes, and walked out the door.)

cannot say enough about the CCNA class I took with Todd Lammle at GlobalNet Training. He was not kidding when he said students need to know everything he writes in his slides and says while teaching. I was amazed how much of my knowledge Cisco managed to test with a 55 question exam. Also, if I did not know Todd's block size method of IP subnetting, I do not think I would have finished the test in time.

If you want to pass the CCNA, I recommend the following:

1. Take GlobalNet Training's CCNA class. I do not think you will find another training source who provides as much gear for each student to configure. The labs are first-rate.

2. Read Todd's book.

3. Practice using Todd's CertSim software. This was invaluable because it taught me to slow down and be more careful. I learned this lesson even though I only had a chance to use the software once, 2 hours before my test. I blazed through the simulation and scored only a 749 -- 100 points too low to pass! I vowed to be more careful on the real exam, and it payed off.

4. Practice configuring real Cisco gear, and use Todd's RouterSim Network Visualized software. I did not get a chance to play with this much outside of class, but it's a great way to build, configure, and test Cisco gear in a virtual environment.

5. For deeper knowledge, check out Alex Zinin's book.

Later this year I plan to start working towards the CCNP.

Selasa, 08 Maret 2005

Review of Cisco IP Routing Posted

Amazon.com just posted my five star review of Alex Zinin's exceptional Cisco IP Routing. From the review:

"With my CCNA exam date staring straight at me, I decided to finally read my copy of Alex Zinin's Cisco IP Routing. This book clearly exceeds the level of knowledge to pass Cisco's entry level certification. It is aimed more at CCNPs or CCIEs who need a deeper understanding of Cisco routing. Nevertheless, I found the book's explanations of certain subjects to be absolutely outstanding, even for a CCNA candidate. I recommend anyone wishing to learn Cisco router operations read Cisco IP Routing."

ourcefire VRT Rules License Audit Rights

Don't be too quick to register to receive the latest Snort rules if you use Snort in your organization. This snort-users post brought this section of the VRT Certified Rules License Agreement to my attention:

"11. Audit Rights.

You will, from time to time and as requested by Sourcefire, provide assurances to Sourcefire that you are using the VRT Certified Rules consistent with a Permitted Use, and you grant Sourcefire access, at reasonable times and in a reasonable manner, to the VRT Certified Rules in your possession or control, and to your books, records and facilities to permit Sourcefire to verify appropriate use of the VRT Certified Rules and compliance with this Agreement.

Sourcefire's non-exercise of this right, or its failure to discover or object to any inappropriate use or other breach of this Agreement by you, shall not constitute its consent thereto or waiver of Sourcefire's rights hereunder or under law.

In the event your use of the VRT Certified Rules is not in compliance with a Permitted Use, or if you otherwise violate the terms of this Agreement, Sourcefire may, since remedies at law may be inadequate, in addition to its other remedies:

(a) demand return of the VRT Certified Rules;

(b) forbid and enjoin your further use of the VRT Certified Rules;

(c) assess you the cost of Sourcefire's inspection and enforcement efforts (including attorney fees); and/or

(d) assess you a use fee appropriate to your actual use of the VRT Certified Rules."

The snort-users poster said "our corporate counsel had apoplexy when he saw the license terms." I would have to agree. I can not see any corporate lawyer agreeing to these terms. Does anyone know of any similar licensing agreements for other projects or products?

I have not yet registered to receive the VRT rules, and at this point I am not sure I am willing to subject my company to this level of intrusiveness.

Update: Does Marty read this blog? Maybe -- he's looking at this audit provision, according to his recent snort-users post: "Any time you get lawyers involved things sometimes don't work out quite like you were planning." Stay tuned!

Senin, 07 Maret 2005

Book Featured by Net Optics

This image is an excerpt from what appears to be a new marketing slick (.pdf) from Net Optics, a California company that makes excellent network taps. I profiled two of their products in my first book. I am working with them to evaluate a set of new products for my next book, with an eye towards internal monitoring. If all goes well I may speak to some of their users in May, at their Sunnyvale, California headquarters.

New Snort.org Web Site Launched

Sometime during this afternoon, the new Snort.org Web site was launched. It features a message from Marty that says "We will continue to dedicate our research, development and QA resources to ensuring that Snort remains the de facto standard in intrusion detection and prevention technology." I noticed the Snort.org Web page titles also use the same "de facto" language. While I more or less agree with the IDS aspect, I believe Marty and crew are being pushed by market forces to adopt the IPS stance. This is a shame, as we all know an "IPS" is a layer 7 firewall that inverts the access control best practice of "allow some, deny everything else." (In other words, an IPS performs a "deny some, allow everything else" function.) I absolutely detest the IPS label and wish access control devices were simply identified as such, and not confused with audit devices (e.g., IDSs).

The new site features a comprehensive FAQ that links to the VRT Certified Rules License Agreement. I encourage everyone to read the documents themselves, but here's my summary:

- If you absolutely must have the latest rules, as soon as Sourcefire's Vulnerability Research Team (VRT) develops them, you should subscribe. "Introductory pricing" is $195/month, $495/quarter, or $1795/year. You are not allowed to redistribute these rules outside of your organization.

- If you can afford to wait five days after a new rule is deployed, you should register. This is free, but again you cannot redistribute these rules outside of your organization.

- If you don't want to subscribe or register, you can remain anonymous and receive new rules with every new Snort point release. In other words, if/when Snort 2.4.0 or 3.0.0 arrives, you'll get a new batch of rules with it.

Where does this leave the companies with products like Lucid Security's ipANGEL or services like Versign's (previously Guardent's) managed intrusion detection, that use Snort as their IDS? Sourcefire calls these organizations Snort Integrators: "any company that distributes Snort or Snort rules in their commercial offerings. This includes vendors bundling Snort or Snort rules, MSSPs and SIMs." These companies will need to buy a Snort Integrator License. I have emailed the listed point of contact to find out more about this.

The last item I'd like to mention is the Snort rules themselves. There are now two "flavors:"

"Sourcefire VRT Certified Rules are the official rules of snort.org. Each rule has been rigorously tested against the same standards the VRT uses for Sourcefire customers. These rules are distributed under the new VRT Certified Rules License Agreement that restricts commercial redistribution."

"Community Rules [are] rules submitted by members of the open source community. While these rules are available 'as is,' the VRT performs basic tests to ensure that new rules will not break Snort. These rules are distributed under the GPL and are freely available to all open source Snort users."

It looks like Bleeding Snort will be the focal point for the new Community Rules, although this has not been confirmed.

Stay tuned for more commentary as I figure out how this is all working. I am meeting with Marty on Thursday at the Sourcefire HQ, so expect a good follow-up Thursday or Friday.

Review of CCNA: Cisco Certified Network Associate, Deluxe Edition (640-801), 4th Ed Posted

Amazon.com just posted my five star review of CCNA: Cisco Certified Network Associate, Deluxe Edition (640-801), 4th Ed. From the review:

"Last week I attended Todd Lammle's CCNA class, where I received a free copy of his 'CCNA: Cisco Certified Network Associate, Deluxe Edition (640-801), 4th Ed' (CCNADE4E). Todd's class was excellent, and his book is almost literally Todd in written form. There is hardly a wasted word in this book. If Todd mentions a detail concerning a protocol or a certain default value in a configuration parameter, it's important. If he calls out that same item in a 'Note', it's definitely important. This is not 'teaching to the test' -- it's ensuring students and readers are familiar with material Cisco considers relevant. Cisco started its certification program to ensure administrators could properly configure and deploy its gear. By reading CCNADE4E, you will gain that knowledge."

I test Wednesday afternoon. I'll report the results.

Minggu, 06 Maret 2005

Use FTP Instead of TFTP to Transfer IOS Images

Michael Lucas' book Cisco Routers for the Desperate saved me this evening. I was trying to update the flash image on my Cisco 2950T-24 switch via TFTP, and had this problem (twice, actually):

gruden#copy tftp flash
Address or name of remote host [192.168.2.7]?
Source filename [c2950-i6k2l2q4-mz.121-22.EA3.bin]?
Destination filename [c2950-i6k2l2q4-mz.121-22.EA3.bin]?
Accessing tftp://192.168.2.7/c2950-i6k2l2q4-mz.121-22.EA3.bin...
Loading c2950-i6k2l2q4-mz.121-22.EA3.bin from 192.168.2.7 (via Vlan1):
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
...edited...
!!!!!!!!!!!O!O!O!O!OO!OO!OO!OOOO
%Error reading tftp://192.168.2.7/c2950-i6k2l2q4-mz.121-22.EA3.bin (Transfer aborted)

Luckily the switch was not hosed at this point. I still had my command prompt and normal functionality. For some reason TFTP kept failing. The image stored on the TFTP server appeared good, since its MD5 hash matched that provided by Cisco. What to do?

I remember Michael Lucas describing how to use FTP to transfer IOS images, so I tried that:

gruden#copy ftp://richard:pasword@192.168.2.7/c2950-i6k2l2q4-mz.121-22.EA3.bin flash
Destination filename [c2950-i6k2l2q4-mz.121-22.EA3.bin]?
Accessing ftp://richard:password@192.168.2.7/c2950-i6k2l2q4-mz.121-22.EA3.bin...
Loading c2950-i6k2l2q4-mz.121-22.EA3.bin !!!!!!!!!!!!!!!!!!!!!!!!!!!!!
...edited...
2867200 bytes copied in 256.536 secs (11177 bytes/sec)

I then reloaded the switch and it came up without any problems. Thanks Michael!