<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GlobalConfig.net&#187; CCIE Security</title>
	<atom:link href="http://globalconfig.net/category/ccie-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://globalconfig.net</link>
	<description>Studying for Network Certifications</description>
	<lastBuildDate>Sat, 24 Dec 2011 02:07:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Last Day to Enroll in 6-Week CCIE Security Evening Class.</title>
		<link>http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/</link>
		<comments>http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/#comments</comments>
		<pubDate>Sun, 17 Jul 2011 05:40:09 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[bootcamps]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=2338</guid>
		<description><![CDATA[This is just a quick heads up for anyone interested in the 6-week evening class for CCIE Security candidates. Today, Sunday, July 17th is the final day to enroll in the 6-Week Evening CCIE Security Class. This is a unique opportunity to mix instructor-led training and the ability to move at your own pace through [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://globalconfig.net/wp-content/uploads/2010/10/bullhorn2.jpg" alt="bullhorn.jpg" title="bullhorn.jpg" border="0" width="100" height="88" hspace="5"style="float:left;" />This is just a quick heads up for anyone interested in the 6-week evening class for CCIE Security candidates.  Today, Sunday, July 17th is the final day to enroll in the 6-Week Evening CCIE Security Class.  This is a unique opportunity to mix instructor-led training and the ability to move at your own pace through the material.  You can get all the details, including the course schedule, class outline and class topology by visiting  <a href="http://globalconfig.net/ccie_security">http://globalconfig.net/ccie_security</a>.</p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/' title='CCIE Security Bootcamp Topology'>CCIE Security Bootcamp Topology</a></li><li><a href='http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/' title='Recap of Changes and One Last Deal of the Year!!!'>Recap of Changes and One Last Deal of the Year!!!</a></li><li><a href='http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/' title='New Video: Comparing Crypto Maps and VTI&#8217;s Part 1'>New Video: Comparing Crypto Maps and VTI&#8217;s Part 1</a></li><li><a href='http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/' title='Bypassing NAT on Cisco ASA 8.2'>Bypassing NAT on Cisco ASA 8.2</a></li><li><a href='http://globalconfig.net/iegeneral/interview-with-scott-morris/' title='Interview with Scott Morris'>Interview with Scott Morris</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCIE Security Bootcamp Topology</title>
		<link>http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/</link>
		<comments>http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/#comments</comments>
		<pubDate>Fri, 17 Jun 2011 19:03:05 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[bootcamps]]></category>
		<category><![CDATA[CCIE Security Prep]]></category>
		<category><![CDATA[myietutor]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=2324</guid>
		<description><![CDATA[I&#8217;ve had some requests to post the CCIE Bootcamp topology. Here is a look at the Layer 3 Topology. The price has already gone up a bit, but if you&#8217;re still interested in the 1000.00 pricing I can work with you today. Just let me know. Please visit the course page for more details. Related [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had some requests to post the CCIE Bootcamp topology.  Here is a look at the Layer 3 Topology.  The price has already gone up a bit, but if you&#8217;re still interested in the 1000.00 pricing I can work with you today.  Just let me know.</p>

<p style="text-align: center;"><a href="http://globalconfig.net/wp-content/uploads/2011/06/ietutorbootcamp.jpg"><img class="size-LargeSize wp-image-2325 aligncenter" title="ietutorbootcamp" src="http://globalconfig.net/wp-content/uploads/2011/06/ietutorbootcamp-480x480.jpg" alt="" width="480" height="480" /></a></p>

<p>Please visit the <a title="CCIE Security Evening Bootcamp" href="http://globalconfig.net/ccie_security/">course page</a> for more details.</p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/' title='Last Day to Enroll in 6-Week CCIE Security Evening Class.'>Last Day to Enroll in 6-Week CCIE Security Evening Class.</a></li><li><a href='http://globalconfig.net/ccie-security/ccie-security-adds-core-knowledge-questions/' title='CCIE Security Adds Core Knowledge Questions'>CCIE Security Adds Core Knowledge Questions</a></li><li><a href='http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/' title='New Video: Comparing Crypto Maps and VTI&#8217;s Part 1'>New Video: Comparing Crypto Maps and VTI&#8217;s Part 1</a></li><li><a href='http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/' title='Bypassing NAT on Cisco ASA 8.2'>Bypassing NAT on Cisco ASA 8.2</a></li><li><a href='http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/' title='Recap of Changes and One Last Deal of the Year!!!'>Recap of Changes and One Last Deal of the Year!!!</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Video: Comparing Crypto Maps and VTI’s Part 2</title>
		<link>http://globalconfig.net/ccie-security/new-video-comparing-crypto-maps-and-vti%e2%80%99s-part-2/</link>
		<comments>http://globalconfig.net/ccie-security/new-video-comparing-crypto-maps-and-vti%e2%80%99s-part-2/#comments</comments>
		<pubDate>Fri, 15 Apr 2011 20:44:44 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[Studies In VPN]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[static vti]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[vti]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=2013</guid>
		<description><![CDATA[In this video I show the configuration of a site-to-site IPsec VPN using static VTI interfaces. I really like using this method because its very straight forward in my eyes. You dont have to use ACL&#8217;s to define what gets encrypted but you can use them to filter what goes across the tunnel. Find more [...]]]></description>
			<content:encoded><![CDATA[<p>In this video I show the configuration of a site-to-site IPsec VPN using static VTI interfaces.  I really like using this method because its very straight forward in my eyes.  You dont have to use ACL&#8217;s to define what gets encrypted but you can use them to filter what goes across the tunnel.  Find more information on VTI interface at <a href="http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/sec_ipsec_virt_tunnl_ps6441_TSD_Products_Configuration_Guide_Chapter.html">Cisco.com in the 12.4T documentation</a></p>

<iframe title="YouTube video player" width="640" height="390" src="http://www.youtube.com/embed/ESrA2TAtcnI?hd=1" frameborder="0" allowfullscreen></iframe>

<p><br /></p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/security/ikev1-aggressive-mode-vs-ikev1-main-mode/' title='IKEv1 Aggressive Mode vs. IKEv1 Main Mode'>IKEv1 Aggressive Mode vs. IKEv1 Main Mode</a></li><li><a href='http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/' title='New Video: Comparing Crypto Maps and VTI&#8217;s Part 1'>New Video: Comparing Crypto Maps and VTI&#8217;s Part 1</a></li><li><a href='http://globalconfig.net/security/configuring-site-to-site-ipsec-for-ipv6-using-static-vti/' title='Configuring Site-to-Site IPsec for IPv6 using Static VTI'>Configuring Site-to-Site IPsec for IPv6 using Static VTI</a></li><li><a href='http://globalconfig.net/security/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2/' title='Configuring SSL VPN with Full Tunnel Access on Cisco ASA 8.2 Part 1'>Configuring SSL VPN with Full Tunnel Access on Cisco ASA 8.2 Part 1</a></li><li><a href='http://globalconfig.net/ccie-security/studies-in-vpn-part-3/' title='Studies in VPN: Part 3'>Studies in VPN: Part 3</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/ccie-security/new-video-comparing-crypto-maps-and-vti%e2%80%99s-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Video: Comparing Crypto Maps and VTI&#8217;s Part 1</title>
		<link>http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/</link>
		<comments>http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/#comments</comments>
		<pubDate>Wed, 06 Apr 2011 19:02:54 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>
		<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Studies In VPN]]></category>
		<category><![CDATA[Crypto]]></category>
		<category><![CDATA[Crypto Maps]]></category>
		<category><![CDATA[IOS VPN]]></category>
		<category><![CDATA[Static Crypto Maps]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1993</guid>
		<description><![CDATA[I&#8217;m trying something new here.  I seem to do that alot!  Let me explain why.  Basically it takes to long to type up a full post and worry about all the screenshots and command line snippets to be able to get you good content quickly.  And the since the members area of Global Config is [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m trying something new here.  I seem to do that alot!  Let me explain why.  Basically it takes to long to type up a full post and worry about all the screenshots and command line snippets to be able to get you good content quickly.  And the since the members area of Global Config is video focused I have gotten quite a bit faster at creating videos and editing them.  So, here is the first of what I hope will become a number of video tutorials.</p>

<p>This one covers Crypto Map configurations for a site-to-site VPN between two routers.  In the second video I&#8217;ll cover the VTI configuration for comparison.</p>

<iframe title="YouTube video player" width="640" height="390" src="http://www.youtube.com/embed/sFhiR-vLpw4?hd=1" frameborder="0" allowfullscreen></iframe>

<p><br />
<br />
<strong>Useful Links:</strong><br />
<a href="http://members.globalconfig.net/sign-up">Become a Member</a><br />
<a href="http://www.cisco.com/en/US/docs/ios/sec_secure_connectivity/configuration/guide/sec_cfg_vpn_ipsec_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1047631">How to Configure IPSec VPN&#8217;s (Cisco.com)</a>
<br />
<br /></p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/' title='Last Day to Enroll in 6-Week CCIE Security Evening Class.'>Last Day to Enroll in 6-Week CCIE Security Evening Class.</a></li><li><a href='http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/' title='CCIE Security Bootcamp Topology'>CCIE Security Bootcamp Topology</a></li><li><a href='http://globalconfig.net/security/ikev1-aggressive-mode-vs-ikev1-main-mode/' title='IKEv1 Aggressive Mode vs. IKEv1 Main Mode'>IKEv1 Aggressive Mode vs. IKEv1 Main Mode</a></li><li><a href='http://globalconfig.net/ccie-security/new-video-comparing-crypto-maps-and-vti%e2%80%99s-part-2/' title='New Video: Comparing Crypto Maps and VTI’s Part 2'>New Video: Comparing Crypto Maps and VTI’s Part 2</a></li><li><a href='http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/' title='Bypassing NAT on Cisco ASA 8.2'>Bypassing NAT on Cisco ASA 8.2</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Today Only!  Lifetime Video Membership for $99.99 USD.</title>
		<link>http://globalconfig.net/ccie-security/today-only-lifetime-video-membership-for-99-99-usd/</link>
		<comments>http://globalconfig.net/ccie-security/today-only-lifetime-video-membership-for-99-99-usd/#comments</comments>
		<pubDate>Thu, 31 Mar 2011 18:32:06 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[General Training]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[sales]]></category>
		<category><![CDATA[video membership]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1986</guid>
		<description><![CDATA[*** This Offer Ended on Friday April 1st at 5pm PST. *** Visit http://members.globalconfig.net/sign-up/ for an even better offer! While the GlobalConfig.net Members area is growing in both members and content I felt like giving people an opportunity to get in on a special deal today. The standard Web Session Membership is $75.00 USD per [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;"><strong>*** This Offer Ended on Friday April 1st at 5pm PST. *** Visit <a href="http://members.globalconfig.net/sign-up/">http://members.globalconfig.net/sign-up/</a> for an even better offer!</strong></span></p>

<p>While the GlobalConfig.net Members area is growing in both members and content I felt like giving people an opportunity to get in on a special deal today.  The standard <a href="http://members.globalconfig.net/sessioninfo/web-sessions/">Web Session Membership</a> is $75.00 USD per month and this includes access to the following:
    <li>Live Webinars (~ once a month)</li>
    <li>Access to recordings of the live Webinars</li>
    <li>Access to Video Training specific to CCIE Security that is NOT covered in the Webinars.</li>
    <li>Technology Specific Lab Exercises (To Be Released Soon)</li>
    <li>And of course, access to all the free videos.</li>
Today we are offering a &#8220;Video Only&#8221; membership that will give you access to all the existing videos and all upcoming videos.  This includes the recordings of live sessions.  For today only a lifetime membership will run you $99.99 USD.  Follow the &#8220;Buy Now&#8221; link below to complete your purchase and registration.  Upon completion you will gain access to all existing videos, and you will be updated when new videos are added.</p>

<p><strong>To purchase lifetime access to the &#8220;Video Only&#8221; members area for just $99.99 UDS click the &#8220;Buy Now&#8221; button.</strong></p>

<p><span style="color: #ff0000;"><strong>*** This Offer Ended on Friday April 1st at 5pm PST. ***</strong></span></p>

<form action="https://www.paypal.com/cgi-bin/webscr" method="post"><span style="font-family: 'Lucida Grande'; font-size: small;"><span style="font-size: 11px; line-height: normal;">
</span></span> </form>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li>No Related Posts</li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/ccie-security/today-only-lifetime-video-membership-for-99-99-usd/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Configuring Etherchannel on Cisco ASA 8.4</title>
		<link>http://globalconfig.net/security/firewalls/configuring-etherchannel-on-cisco-asa-8-4/</link>
		<comments>http://globalconfig.net/security/firewalls/configuring-etherchannel-on-cisco-asa-8-4/#comments</comments>
		<pubDate>Thu, 17 Feb 2011 20:45:07 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[8.4]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[Etherchannel]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1953</guid>
		<description><![CDATA[With the recent release of Cisco ASA 8.4 code a new feature has emerged. Yes, Etherchannel. I&#8217;ll spare you the gory details of how etherchannel works. Rather lets just get right into how you set it up. Lets begin with the switch configuration: Rack1SW1# sh run int f0/1 Building configuration... Current configuration : 109 bytes [...]]]></description>
			<content:encoded><![CDATA[<p>With the recent release of Cisco ASA 8.4 code a new feature has emerged.  Yes, Etherchannel.  I&#8217;ll spare you the gory details of how etherchannel works.  Rather lets just get right into how you set it up.</p>

<p>Lets begin with the switch configuration:</p>

<p><pre><code>Rack1SW1# sh run int f0/1
Building configuration...</p>

<p>Current configuration : 109 bytes
!
interface FastEthernet0/1
 switchport access vlan 146
 switchport mode access
 channel-group 1 mode active
 spanning-tree portfast
end</p>

<p>Rack1SW1# sh run int f0/2
Building configuration...
</code></pre></p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/security/ikev1-aggressive-mode-vs-ikev1-main-mode/' title='IKEv1 Aggressive Mode vs. IKEv1 Main Mode'>IKEv1 Aggressive Mode vs. IKEv1 Main Mode</a></li><li><a href='http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/' title='Bypassing NAT on Cisco ASA 8.2'>Bypassing NAT on Cisco ASA 8.2</a></li><li><a href='http://globalconfig.net/security/quick-tip-preview-commands-before-sending/' title='Quick Tip: Preview Commands Before Sending!'>Quick Tip: Preview Commands Before Sending!</a></li><li><a href='http://globalconfig.net/news/join-me-for-a-twitterchat/' title='Join me for a (Twitter)chat.'>Join me for a (Twitter)chat.</a></li><li><a href='http://globalconfig.net/bcmsn/5-ways-to-make-sure-etherchannels-work/' title='5 ways to make sure Etherchannels work.'>5 ways to make sure Etherchannels work.</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/security/firewalls/configuring-etherchannel-on-cisco-asa-8-4/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bypassing NAT on Cisco ASA 8.2</title>
		<link>http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/</link>
		<comments>http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 13:00:18 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TipTorials]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[NAT]]></category>
		<category><![CDATA[nat 0]]></category>
		<category><![CDATA[nat exemption]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1899</guid>
		<description><![CDATA[There are a number of ways to bypass NAT using a Cisco ASA. I suppose the easiest way would be to leave it alone when you install it and don&#8217;t use NAT at all. Why? Because the ASA does not have NAT-Control enabled by default. This means that you can configure you ASA just as [...]]]></description>
			<content:encoded><![CDATA[<p>There are a number of ways to bypass NAT using a Cisco ASA.  I suppose the easiest way would be to leave it alone when you install it and don&#8217;t use NAT at all.  Why?  Because the ASA does not have NAT-Control enabled by default.  This means that you can configure you ASA just as you would a router and exchange routes between the inside and outside.  Aside from needing an ACL on the outside interface, applied in an inbound direction, you should notice that if functions very similar to what you would expect a router to function like.</p>

<p>However, for most of us, this is not feasible.  Because of the use of RFC 1918 addresses we are required to use NAT or PAT when we make connections to the Internet.  Still situations may arise where you have NAT configured but for some reason you need to bypass it.  Here are a few examples of how to do this along with the terminology that  these methods are referred to in ASA 8.2.</p>

<h2>Identity NAT</h2>

<p>When you use Identity NAT the connections can only be originated by the address that&#8217;s covered in the statement.  Of course, return traffic will be allowed, but you can&#8217;t originate an outside connection into the address in the NAT statement.</p>

<p>Here is how you configure it:</p>

<p><pre><code>ASA1(config)# nat (inside) 0 10.1.1.0 255.255.255.0</code></pre></p>

<p>In this code example you can initiate an outbound connection from addresses on the 10.1.1.0/24 subnet and it will not translate the source.</p>

<h2>Static Identity NAT</h2>

<p>A Static Identity NAT Translation is always active.  This means that a connection can be initiated into this address, provided there is an ACL inbound on the lower security-level interface that permits the connection.  You can also originate connections from the address defined in the statement for outbound connections and the ASA will not Translate the source.</p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/' title='Last Day to Enroll in 6-Week CCIE Security Evening Class.'>Last Day to Enroll in 6-Week CCIE Security Evening Class.</a></li><li><a href='http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/' title='CCIE Security Bootcamp Topology'>CCIE Security Bootcamp Topology</a></li><li><a href='http://globalconfig.net/security/ikev1-aggressive-mode-vs-ikev1-main-mode/' title='IKEv1 Aggressive Mode vs. IKEv1 Main Mode'>IKEv1 Aggressive Mode vs. IKEv1 Main Mode</a></li><li><a href='http://globalconfig.net/general/new-video-comparing-crypto-maps-and-vtis-part-1/' title='New Video: Comparing Crypto Maps and VTI&#8217;s Part 1'>New Video: Comparing Crypto Maps and VTI&#8217;s Part 1</a></li><li><a href='http://globalconfig.net/security/firewalls/configuring-etherchannel-on-cisco-asa-8-4/' title='Configuring Etherchannel on Cisco ASA 8.4'>Configuring Etherchannel on Cisco ASA 8.4</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Destination NAT on Cisco ASA 8.2</title>
		<link>http://globalconfig.net/security/firewalls/destination-nat-on-cisco-asa-8-2/</link>
		<comments>http://globalconfig.net/security/firewalls/destination-nat-on-cisco-asa-8-2/#comments</comments>
		<pubDate>Fri, 21 Jan 2011 13:00:01 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[CCSP Study]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[SNAF]]></category>
		<category><![CDATA[ASA 8.2]]></category>
		<category><![CDATA[Destination NAT]]></category>
		<category><![CDATA[NAT]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1858</guid>
		<description><![CDATA[This week I had a few students in a neighboring class that are trying to accomplish a destination nat using Cisco ASA 8.x. They were apparently told by Cisco TAC that this was not possible on anything prior to ASA 8.3 code. This isn&#8217;t the case. In fact, it&#8217;s been possible for some time on [...]]]></description>
			<content:encoded><![CDATA[<p>This week I had a few students in a neighboring class that are trying to accomplish a destination nat using Cisco ASA 8.x.  They were apparently told by Cisco TAC that this was not possible on anything prior to ASA 8.3 code.  This isn&#8217;t the case.  In fact, it&#8217;s been possible for some time on the ASA.  Now as it sits they have an ASA sitting behind a Juniper Firewall which is currently providing the destination NAT services, but that&#8217;s the only reason they have the Juniper there.  So, by being able to do the NAT on the ASA the Juniper Firewall can be removed.</p>

<p>So the scenario goes a little something like this.  Originally we had two servers with IP addresses 172.18.0.99 and 172.18.0.100 that are hard coded into a few thousand clients.  The servers were consolidated into one server and the IP address is now in a different address space.  Rather than changing the static assignment on so many clients, can we just configure the ASA so that when they go to the old hard coded addresses they will be destination NAT&#8217;d to the new server IP address?  The answer is yes and here is how you do it.</p>

<p>First, We can take a look at the old Topology.  Here we note the addresses that are hard coded to the clients on the left.</p>

<p><a href="http://globalconfig.net/wp-content/uploads/2011/01/destnat1-21.jpg"><img src="http://globalconfig.net/wp-content/uploads/2011/01/destnat1-21.jpg" alt="destnat1-2.jpg" title="destnat1-2.jpg" border="0" width="600" height="229"  /></a></p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/security/bypassing-nat-on-cisco-asa-8-2/' title='Bypassing NAT on Cisco ASA 8.2'>Bypassing NAT on Cisco ASA 8.2</a></li><li><a href='http://globalconfig.net/security/configuring-ssl-vpn-with-full-tunnel-access-on-cisco-asa-8-2/' title='Configuring SSL VPN with Full Tunnel Access on Cisco ASA 8.2 Part 1'>Configuring SSL VPN with Full Tunnel Access on Cisco ASA 8.2 Part 1</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/security/firewalls/destination-nat-on-cisco-asa-8-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recap of Changes and One Last Deal of the Year!!!</title>
		<link>http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/</link>
		<comments>http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/#comments</comments>
		<pubDate>Wed, 29 Dec 2010 17:37:25 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE General]]></category>
		<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[Cisco ASA]]></category>
		<category><![CDATA[General Training]]></category>
		<category><![CDATA[bootcamps]]></category>
		<category><![CDATA[community]]></category>
		<category><![CDATA[recap]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[web sessions]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1816</guid>
		<description><![CDATA[Many of you have noticed that there have been many changes here at GlobalConfig.net. We&#8217;ve added a podcast, web sessions and now a members area. Here is the run down. The Podcast The podcast is a resource to help people understand methods in preparation and with some recent interviews it will provide valuable tips for [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://globalconfig.net/wp-content/uploads/2010/10/bullhorn2.jpg" alt="bullhorn.jpg" title="bullhorn.jpg" border="0" width="263" height="208" style="float:left;" hspace="5" />Many of you have noticed that there have been many changes here at GlobalConfig.net.  We&#8217;ve added a podcast, web sessions and now a members area.  Here is the run down.</p>

<h2>The Podcast</h2>

<p><a href="http://podcast.globalconfig.net">The podcast</a> is a resource to help people understand methods in preparation and with some recent interviews it will provide valuable tips for finding employment and handling interviews.</p>

<h2>The Community Lab</h2>

<p>I announced a <a href="http://globalconfig.net/general-training/new-and-exciting-announcement/">community lab</a>, much in the style of Jeremy Stretch at Packetlife.net.  This lab should be ready for access sometime on February and will be free of charge.  The lab bandwidth and much of the equipment is provided by Ascolta.</p>

<h2>The Members Area</h2>

<p><img src="http://globalconfig.net/wp-content/uploads/2010/09/webinar1.jpg" alt="webinar.jpg" title="webinar.jpg" border="0" width="232" height="204" style="float:left;" / hspace="5">We&#8217;ve had great response to the 4-hour <a href="http://globalconfig.net/web-session-series/">CCIE Security ASA Web Session that will be running tomorrow, December 30th</a>, however, you may be wondering what you get with the web session.  Basically you get me for four hours teaching everything I can, minus VPN, about the ASA.  Will that be enough time to cover everything there is to cover for the ASA?  Not likely.  That&#8217;s where the members area comes in.</p>

<p>I decided that while I can&#8217;t run live web sessions every day I can record shorter sessions and make them available online.  These videos will rage from VPN configurations on the ASA to NAT to Failover and more.  But they don&#8217;t stop there.  The videos will also cover other aspects of the CCIE Security Lab Exam blueprint topics such as Zone Based Firewalls, Flexible Packet Matching, IOS CA Servers, AAA, 802.1x, and so on.</p>

<p>So, the web session itself is priced at 40 bucks.  The membership to the site is 75 bucks monthly.  What do you get for 75 bucks?  You get enrolled in every live session I do beginning with the first session following your registration, plus access to every video I post and all topics of the blueprint.</p>

<h2>The Bootcamps</h2>

<p>Finally, I&#8217;ve just launched a <a href="http://globalconfig.net/bootcamps/">Bootcamps</a> section where you can purchase a 12 day bootcamp here in Irvine, Ca, which will run in March of 2011.  This bootcamp will be lab focused and designed to prepare you in each aspect of the lab exam blueprint.  It will help you identify any weak areas you may have and you&#8217;ll get specific attention on those areas.  You&#8217;ll get a number of labs to work on during the 12 days as well as your own rack of equipment to work on.  The 12 day bootcamp is currently priced at 4500.00 but will go up after the 1st of the year.  If you get in early you score the lower price.</p>

<h2>The Last Deal of the Year!</h2>

<p>I promised one last deal of the year.  Actually I&#8217;m going to give you two deals to take advantage of.</p>

<h3>Deal #1: Sign up for the CCIE ASA web session and get a 2 month membership for free</h3>

<p><center><strong>This Special Has Ended</strong></center></p>

<p>If you enroll in the CCIE ASA web session using the &#8220;Buy Now&#8221; button just above this line, you&#8217;ll get a two month membership to all sessions and videos.  The cost of the CCIE ASA Web Session is $40.00.</p>

<h3>Deal #2: Sign up for the bootcamp and get a lifetime membership along with it.</h3>

<p><center></p>

<form action="https://www.paypal.com/cgi-bin/webscr" method="post">
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="85VJUL47VL8B2">
<input type="image" src="https://www.paypal.com/en_US/i/btn/btn_buynowCC_LG.gif" border="0" name="submit" alt="PayPal - The safer, easier way to pay online!">
<img alt="" border="0" src="https://www.paypal.com/en_US/i/scr/pixel.gif" width="1" height="1">
</form>

<p><strong>CCIE Security Bootcamp with Free Lifetime Membership Cost: $4500.00</strong></center></p>

<p>Enroll in the bootcamp using the button above, before January 1st, 2011, and I&#8217;ll throw in a lifetime membership to the web sessions and videos.  Of course, if you&#8217;d like to use one of the <a href="http://globalconfig.net/bootcamps/">flexible payment options</a> you are welcome to, however this deal applies only to bootcamps paid in full prior to January 1st, 2011.</p>

<h2>So what&#8217;s in the Pipeline</h2>

<p>We&#8217;re not stopping there.  I&#8217;m currently writing technology specific labs for CCIE Security candidates and plan to release them early next year.  Additionally members will receive an exclusive discount program on Cisco Training in other areas.</p>

<p>Also, there are more technical blog posts to come as well!</p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/ccie-security/last-day-to-enroll-in-6-week-ccie-security-evening-class/' title='Last Day to Enroll in 6-Week CCIE Security Evening Class.'>Last Day to Enroll in 6-Week CCIE Security Evening Class.</a></li><li><a href='http://globalconfig.net/ccie-security/ccie-security-bootcamp-topology/' title='CCIE Security Bootcamp Topology'>CCIE Security Bootcamp Topology</a></li><li><a href='http://globalconfig.net/ccie-security/free-bgp-authentication-thru-asa%e2%80%99s-web-session-december-23%e2%80%b2rd-2010/' title='Free CCIE Security Web Sessions!'>Free CCIE Security Web Sessions!</a></li><li><a href='http://globalconfig.net/general-training/new-and-exciting-announcement/' title='New and Exciting Announcement!'>New and Exciting Announcement!</a></li><li><a href='http://globalconfig.net/ccie-security/posted-topology-and-outline-for-asa-web-session/' title='Posted Topology and Outline for ASA Web Session!'>Posted Topology and Outline for ASA Web Session!</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free CCIE Security Web Sessions!</title>
		<link>http://globalconfig.net/ccie-security/free-bgp-authentication-thru-asa%e2%80%99s-web-session-december-23%e2%80%b2rd-2010/</link>
		<comments>http://globalconfig.net/ccie-security/free-bgp-authentication-thru-asa%e2%80%99s-web-session-december-23%e2%80%b2rd-2010/#comments</comments>
		<pubDate>Thu, 23 Dec 2010 07:40:00 +0000</pubDate>
		<dc:creator>Brandon Carroll, CCIE #23837</dc:creator>
				<category><![CDATA[CCIE Security]]></category>
		<category><![CDATA[web sessions]]></category>

		<guid isPermaLink="false">http://globalconfig.net/?p=1798</guid>
		<description><![CDATA[On December 23rd, 2010 at 11PM PDT I offered a free CCIE Security Web Session where i covered how to authenticate BGP Sessions through and ASA. The session was recorded and is being made available through the members only area of globalconfig.net. If you&#8217;d like to gain access to this, or any future web sessions, [...]]]></description>
			<content:encoded><![CDATA[<p>On December 23rd, 2010 at 11PM PDT I offered a free CCIE Security Web Session where i covered how to authenticate BGP Sessions through and ASA.  The session was recorded and is being made available through the members only area of globalconfig.net.  If you&#8217;d like to gain access to this, or any future web sessions, simply follow the link to register on the site.  Once registered you will need to &#8220;opt-in&#8221;.  You&#8217;ll then get an email with all the access details for the previous recordings and future free sessions.</p>

<p><a href="http://members.globalconfig.net/?/register/PUiq67"><img class="aligncenter size-standard wp-image-1804" title="register" src="http://globalconfig.net/wp-content/uploads/2010/12/register-300x141.jpg" alt="" width="300" height="141" /></a></p>

<h3 class='related_post_title'>Related Posts:</h3>

<ul class='related_post'><li><a href='http://globalconfig.net/iegeneral/recap-of-changes-and-one-last-deal-of-the-year/' title='Recap of Changes and One Last Deal of the Year!!!'>Recap of Changes and One Last Deal of the Year!!!</a></li><li><a href='http://globalconfig.net/ccie-security/posted-topology-and-outline-for-asa-web-session/' title='Posted Topology and Outline for ASA Web Session!'>Posted Topology and Outline for ASA Web Session!</a></li></ul>
]]></content:encoded>
			<wfw:commentRss>http://globalconfig.net/ccie-security/free-bgp-authentication-thru-asa%e2%80%99s-web-session-december-23%e2%80%b2rd-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

