Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  • Users: khaiyang
  • Order by date
  1. khaiyang

    Will CSPFA Change Since PIX OSv7 and ASDM5.0 Is Released ?!?

    I think so. I will be sitting for this paper soon, so i am afraid this. Personally, i think they will update the official student guides (current version 3.2) first before it'll reflect on the exam. :) United, We Stand
  2. khaiyang

    CCNA 1 part exam vs the 2 part exam.

    I took the single paper, but during my preparation, i study both. I find the singler paper in the overall easier but it covers less topic like "remote access", but you have to study into deeper for every chapter, of course. United, We Stand
  3. khaiyang

    VPN through PIX 501 works but VNC breaks connection

    i think you already have "sysopt connection permit-ipsec" , otherwise ur PING will not able to get thru vpn tunnel. Let us know your "interesting" traffic that is triggering the VPN, if you specify only ICMP/PING in the access-list, u cannot run VNC and any other application. I think there is...
  4. khaiyang

    Killing a VPN Session

    I use "clear crypto isakmp sa", basically will clear the previous connection vpn. United, We Stand
  5. khaiyang

    PIX 515E memory query.

    Hi, I had the similar questions b4, please read : http://www.tek-tips.com/viewthread.cfm?qid=1037778&page=2 . Apparently if u wanna get from cisco, upgrade to the 128MB is the only option. United, We Stand
  6. khaiyang

    Authenticating a VPN Client without Radius or AAA

    http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00800949d6.shtml#authen_author
  7. khaiyang

    Authenticating a VPN Client without Radius or AAA

    apart from TACACS+ and Radius, PIX also support local authentication. It means the username/password is stored locally inside pix configuration. Alternatively, u can download a 90days trial of Cisco Secure Access Control Server CSACS software from cisco website.
  8. khaiyang

    Trying to get IPSEC with split tunneling to work.. totally confused!

    He may have reason to use 193.168.x.x instead of 192.168.x.x , but having : route outside 0.0.0.0 0.0.0.0 193.168.2.1 1 would sure give problem bcos pointing to pix itself means no traffic would able to route out. Since you're using pppoe, i guess u need : ip address outside pppoe setroute (the...
  9. khaiyang

    I can ping from host to pix interfaces but no to the world.Why?

    for the NAT [id] statement, u need another global [id] statement to take effect. So i think you miss out : global (outside) 1 interface (this will translate the internal ip to pix outside interface ip , which is 192.168.20.219) also you need to add this : access-list outside_in permit icmp any...
  10. khaiyang

    IP Raw printing over a pix to pix vpn tunnel

    if ur vpn tunnel is a site-to-site (network to network), most probably you've already configured the whole network as the "interesting" traffic, and as long as the printer is treated as one host within the remote network, there should be any problem. pls let us know if u still face any...
  11. khaiyang

    How to Allow certain ports through to all hosts and...

    perhaps you should provide more information so that people here can help to troubleshoot. By default, traffic from more secured interface can access the less secured interface without having specify any rules, all you need is the "nat" and "global" command to perform addression translation...
  12. khaiyang

    CSPFA 642-521

    ya, many people recommended testking, so here i have the latest version with me. Planned to skip the boson software simulation exam questions though there are more than 1000 of them, but i am afraid some questions are really outdated. Will focus on the original test simulator come with...
  13. khaiyang

    CSPFA 642-521

    ops, didn't realize it was a old post. :) Wish me luck, i am doing many simulation exams to prepare for it.
  14. khaiyang

    Anyone tried the new 7.0(1) software?

    Yes, i tried it. :) And I have to go into monitor mode to load back the original 6.3(4) file. Placed my order for the 128MB RAM, will feedback once managed to upgrade it.
  15. khaiyang

    Will CSPFA Change Since PIX OSv7 and ASDM5.0 Is Released ?!?

    As I understand, the current 642-521 CSPFA paper is based on PIX Firewall version 6.3. I talked to a trainer that day and the official Cisco Student Guide they used is still at version 3.2 (as Cicso also recommend training course in their website - "....Candidates can prepare for this exam by...
  16. khaiyang

    CSPFA 642-521

    You can find more info from Cisco websites: http://www.cisco.com/en/US/learning/le3/current_exams/642-521.html As I understand, passing mark is 85% like CCNA, and there will be simulation question. As I understand, the exam topics will cover until PIX Firewall version 6.3. I am preparing for...
  17. khaiyang

    converting conduits to acl's

    Also use Turbo ACL, this allow you to easy insert / remove an ACL rule into/remove a long ACL list. (Turbo ACL is support in v6.2 and not supported in PIX501)
  18. khaiyang

    converting conduits to acl's

    Another way to reduce the line of ACL is to do some object grouping, particularly to the servers who has similar attributes.
  19. khaiyang

    Anyone tried the new 7.0(1) software?

    It is not possible to run the new version without matching the required RAM and flash. It will not run properly and PIX will keep on complain Insufficient Memory and ask you to upgrade, after that it reboots itself and prompt u the same message again.
  20. khaiyang

    PIX515 run VPN - Need Upgrade ?

    I tried to apply Cisco Easy VPN on the PIX and Client PC, but seems like this requires at least PIX Firewall Version 6.2 or above. I foresee that OS upgrade is surely a must to run this, do I need to upgrade to "PIX-515-VPN-3DES=" to run this setup ?

Part and Inventory Search

Back
Top