networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 16 posts ] 
Author Message
 Post subject: Cisco FIREWALL 642-618
PostPosted: Tue Jun 19, 2012 6:04 am 
Offline
Junior Member
Junior Member

Joined: Tue Mar 20, 2012 6:39 pm
Posts: 76
Certs: CCNA, CCNA Security, FIREWALL v2.0
Hi Guys,

I'm about to start studying for the CCNP Security Firewall exam, I'm just waiting on the Cisco Press book to come through. I also plan on purchasing the CBT nuggets for the FIREWALL exam.

I'd just like to know from other people's experiences what they did for labs. ASAs cost in excess of £1,000 here (even used ones). I'm probably going to attempt to set an ASA up in GNS3 but from what I've heard, it seems pretty flakey. Can anyone point me in the right direction for GNS3+ASA?

In general I'd just like to hear about other peoples experiences with this exam.

Cheers!


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 8:17 am 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8296
Location: Frederick MD
Certs: Instanity
the GNS ASA emulation runs at most 8.0x something, you'll need at least 8.4 for the exam. I've been looking at a basic ASA 5505, here in US ~$250 on Ebay. I'm only seeing the 642-617 videos on cbt nuggets, I wouldn't go for that at full price - exam is retired although changes are minimal, but changes in NAT between the old exam and new exam is quite important to know both ways. For the labs, I have downloaded the 8.2 cli configuration guide from Cisco, there are some good configuration examples which I think would make good labs, i've finished reading this, less the VPN stuff, also downloaded the 8.4 cli configuation guide, using that to brush up on the NAT and ACL changes. also just started reading the CP 642-618 exam guide. stupid dog chewed up and ripped off half the binding on the book, pissed me off to no end, brand new 70 dollar book, grrrrr. i digress.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 8:32 am 
Offline
Senior Member
Senior Member

Joined: Sun Jan 02, 2011 7:50 pm
Posts: 282
Certs: CCNP, CCDA, ISE Field Engineer
Running 8.4 code in GNS3 right now - very nice - just make sure you have enough memory or your system or the ASA will crash.


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 9:48 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Apr 29, 2010 6:12 pm
Posts: 2079
Location: Texas
Certs: CCNP, CCDP, CCIP
ristau5741 wrote:
stupid dog chewed up and ripped off half the binding on the book, pissed me off to no end, brand new 70 dollar book, grrrrr. i digress.

That sucks dude!! This is a good reason for going with ebooks/PDFs :)

_________________
http://blog.movingonesandzeros.net/


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 11:36 am 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8296
Location: Frederick MD
Certs: Instanity
dgrizzard wrote:
Running 8.4 code in GNS3 right now - very nice - just make sure you have enough memory or your system or the ASA will crash.



humm, stupid web site says "up to version 8.0(2)."
i'll have to get it up and running. saved me $$$ thanks.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Tue Jun 19, 2012 12:52 pm 
Offline
Senior Member
Senior Member

Joined: Sun Jan 02, 2011 7:50 pm
Posts: 282
Certs: CCNP, CCDA, ISE Field Engineer
ristau5741 wrote:
dgrizzard wrote:
Running 8.4 code in GNS3 right now - very nice - just make sure you have enough memory or your system or the ASA will crash.



humm, stupid web site says "up to version 8.0(2)."
i'll have to get it up and running. saved me $$$ thanks.


Yeah its pretty nice - running ACS 5.3 in a VM then separate networks inside GNS3 with the ASA - all devices running auth through ACS, and running Anyconnect SSL VPN on the ASA with auth to the ACS.


Top
 Profile  
 
 Post subject: Cisco FIREWALL 642-618
PostPosted: Tue Jun 19, 2012 3:04 pm 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Mon Oct 06, 2008 8:01 am
Posts: 669
Certs: CCNA,CCNP
ristau5741 wrote:
dgrizzard wrote:
Running 8.4 code in GNS3 right now - very nice - just make sure you have enough memory or your system or the ASA will crash.



humm, stupid web site says "up to version 8.0(2)."
i'll have to get it up and running. saved me $$$ thanks.


It's pretty easy to do, there's a number of blogs where people have uploaded all the files (except the actually image), I got mine up and running in less than 10 mins...


Sent from my iPhone using Tapatalk


Top
 Profile  
 
PostPosted: Sat Jun 23, 2012 4:40 am 
Offline
Junior Member
Junior Member

Joined: Tue Mar 20, 2012 6:39 pm
Posts: 76
Certs: CCNA, CCNA Security, FIREWALL v2.0
I got it all working. For some reason the putty console wouldnt load and then GNS3 just kept crashing, all sorted now though.

Does anybody have an activation key for the failover feature, for use in GNS3.


Top
 Profile  
 
PostPosted: Fri Jun 29, 2012 7:57 am 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8296
Location: Frederick MD
Certs: Instanity
another good resource is to download and install the ASDM demo from Cisco,
I did this last night, and it's pretty cool, there like 6 or 8 sample configurations
that can be loaded.

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Fri Jun 29, 2012 8:13 am 
Offline
Member
Member
User avatar

Joined: Fri Apr 29, 2011 8:26 pm
Posts: 179
Location: Dallas
Certs: CCNP, CCIP, JNCIA, M&M, PB&J, etc.
Anyone seeing a high util on the cpu-core that qemu vm is running on?

Tried 'cpulimit' (linux) but it pushes qemu/asa into the background.
Shows as a stoped job. I tried: fg , fg 1 , fg %1 and nothing brings it back.


Top
 Profile  
 
PostPosted: Tue Dec 04, 2012 9:38 am 
Offline
New Member
New Member

Joined: Tue Dec 04, 2012 9:19 am
Posts: 1
I was found just one lab in dump ? is it only one lab sim question ? thanks ;)


Top
 Profile  
 
PostPosted: Tue Dec 04, 2012 6:42 pm 
Online
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12429
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
dforko wrote:
I was found just one lab in dump ? is it only one lab sim question ? thanks ;)

That's cheating, as well as breaking nda


Sent on the move...

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Wed Jan 16, 2013 11:30 am 
Offline
New Member
New Member

Joined: Wed Jan 16, 2013 11:22 am
Posts: 2
I would like to study for this exam but am pretty confused as to how to obtain all the material, and what material I would need to learn and pass the exam.

1. How do I get a copy of the Cisco ios and ASDM and at what vesions?
2. Do I need to purchase a actual ASA firewall or is there a simulator I can download somewhere?
3. Where can I find actual lab exercises that I can use in configuring the firewall?

It's no use to me in a sense to purchase over $1100 to watch cbt nugget video (and thats just for the first part of the exam, not the second 642-648 VPN training), while I'm not putting it into practice in a lab.

What did you guys use? What do you recommend? I see some people using GN3 but I would need an actualy copy of the Cisco ios which I dont have. Shame on Cisco for not offering free ios for training purposes only. Seems like just to get the training setup they make you woprk for it. I've spent a full day on the net researching for materials and have ended up more confused than when I started. It's not a difficult concept for a company to offer the training material (videos, books, ios, etc) in order to pass the exam, especially if you are willing to pay. Instead it seems that you have to dig around for pieces here and there and mix them all together just to get started.

Where can I start? Where should I start?
Thanks everyone!


Top
 Profile  
 
PostPosted: Wed Jan 16, 2013 11:58 am 
Online
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8296
Location: Frederick MD
Certs: Instanity
Use 642-618 OCG
download the ASDM Demo from the Cisco site
there are many many ASDM examples in the OCG of what you should learn how to do,

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Wed Jan 16, 2013 1:23 pm 
Offline
New Member
New Member

Joined: Wed Jan 16, 2013 11:22 am
Posts: 2
Thanks, any suggestions on the cli?
What did you use to study and prepare?
Thanks!


Top
 Profile  
 
PostPosted: Mon Jan 21, 2013 7:41 pm 
Offline
Member
Member
User avatar

Joined: Mon Jan 14, 2013 10:40 pm
Posts: 218
Certs: CCNP, CCDP, CCNP-Sec, CCNA-V
tolinrome1 wrote:
What did you guys use? What do you recommend? I see some people using GN3 but I would need an actualy copy of the Cisco ios which I dont have. Shame on Cisco for not offering free ios for training purposes only. Seems like just to get the training setup they make you woprk for it. I've spent a full day on the net researching for materials and have ended up more confused than when I started. It's not a difficult concept for a company to offer the training material (videos, books, ios, etc) in order to pass the exam, especially if you are willing to pay. Instead it seems that you have to dig around for pieces here and there and mix them all together just to get started.

Where can I start? Where should I start?
Thanks everyone!


You didn't look very hard did you..... took me 10 minutes to find a blog that had the right files attached. No I can't help you out any more.

Alternatively, how about trying to get hold of someone with a valid CCO to help out? (e.g. work?).
You do realise don't you even if you legitimately obtain an ASA OS image you'll need to run it through some linux scripts to produce something usable by Qemu.

And re: real hardware, guess what, it may involve a cost. An ASA5505 can be had second hand for around 400AUD (which is around the same USD). Not cheap but not exactly outrageous either.
I'm sorry you're confused after researching the internet, but if this stuff was easy then anybody could walk in off the street and do it.

I would suggest paying for an actual hands on real teacher CCNA and then going from there. (not sure if you're already done but I'm assuming not as its not on your sig? - you do know you need to do a CCNA R&S then CCNA Security as a prerequisite before any CCNP Sec material like FIREWALL?)


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 16 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: G1lgam3sh, mynd, williamtyrell78 and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group