Monthly Archives: March 2008

Default Route via DHCP on an ASA 5505

March 22, 2008
By Aaron Conaway

I finally got my ASA 5505 up and running at the house, but I ran into a little problem — the box wouldn’t add the DHCP-provided default route into its routing table.  That one threw me for a loop since the box is made for SOHOs, but it makes sense in some corporate, lazy...

Read more »

Configuring GLBP

March 21, 2008
By Aaron Conaway

Believe it or not, I got a request for an article on how to configure GLBP. I’m as shocked as you are, so here it goes. The Gateway Load Balancing Protocol (GLBP) is another Cisco-proprietary protocol for providing highly-available gateways on a network…but there’s a twist. GLBP, as you can figure out from the...

Read more »

Trunking on a Catalyst Switch

March 21, 2008
By Aaron Conaway

If you didn’t now already, trunks are connections between switches that carry traffic for all VLANs. It allows you to have, say, VLAN 10 and VLAN 20 on two switches appear as the same network. Unless you’re a really small shop, you’ve already dealt with trunks, so there’s no need for an introduction. Let’s...

Read more »

HSRP vs. GLBP

March 18, 2008
By Aaron Conaway

HSRP (Hot Standby Router Protocol) is a Cisco-proprietary method for supplying a highly-available gateway for hosts to use. GLBP (Gateway Load Balancing Protocol) does the same thing. So, what’s the difference? HSRP works on layer 3 and provides a standby IP address for hosts on that network to use as their gateway (or other...

Read more »

GRE Tunnels and Encryption

March 18, 2008
By Aaron Conaway

GRE tunnels rock.  They are interfaces on a router that are used to “connect” to another router somewhere on your LAN, your WAN, the Internet, wherever.  The most popular use for them is for router-to-router VPNs. I’ll let my friend Josh from blindhog.net show you how to do it.  He’s got a video on...

Read more »

Resetting Sections of the Config

March 18, 2008
By Aaron Conaway

I was configuring a switch the other day and realized I had configured a trunk on the wrong port. God, I hate that. Instead of dumping the configuration for the port and doing a “no” on each line, I used the default command. Switch(config)#default interface G0/1 This resets the configuration on interface G0/1 to...

Read more »

AFOL-KE and Above.net

March 17, 2008
By Aaron Conaway

It looks like there was another bad BGP announcement over the weekend.  This time, a 24-bit network belonging to the country of Kenya was being advertised by Above.net.  The heart of the problem is the same as it was with the YouTube problem a few weeks ago:  someone who wasn’t authoritative for a network...

Read more »

NAT on a PIX/ASA

March 13, 2008
By Aaron Conaway

NATting sucks and can be confusing. I’m sure everyone agrees to that, but you have to use it at some times. In a PIX/ASA, it’s easy to configure a simple setup, but can be super-complicated in larger networks. In a simple lab, we have set up an ASA with inside and outside interfaces, with...

Read more »

Commenting Access-lists

March 12, 2008
By Aaron Conaway

There’s a very-overlooked feature of access-lists — the remark. Yes, this is very basic, but it’s worth mentioning, as it has saved me anguish time and time again. I use remarks to document each line of an ACL (on IOS, PIX, FWSM, ASA, etc.) so that when I go back later, I actually know...

Read more »

Wireless Headsets

March 5, 2008
By Aaron Conaway

We all have these at our desks. Not the bluetooth guys for your phone (we could talk about that for a while), but the 900MHz headsets that your company gave you for those long and annoying calls with the boss. These things rocks, but they are oh-so insecure. A coworker who fields support calls...

Read more »

Page 1 of 2
1 2

Calendar

March 2008
S M T W T F S
« Feb   Apr »
 1
2345678
9101112131415
16171819202122
23242526272829
3031  

Switch to our mobile site