Archive for January, 2009

Security blueprint, quality books, and general thoughts

Posted in CCIE, Dynamips on January 2, 2009 by cciejournal

For the last two weeks I’ve been working at the new Westfield shopping centre in London. Apart from having Christmas day off I’ve been at work every other day. Fortunately, because its only a very short contract to fill in for the usual guy while he’s on leave I only have a few key things to look after; and if nothing goes wrong I don’t have to do a single thing! So overall its been a pretty quiet two weeks, and because most of management is away its very peaceful on my floor of the building which has given me a LOT of time to get immersed in my new books.

Most of this free time has been spent reading Yusuf Bhaiji’s Network Security Technologies and Solutions which is just fantastic. Considering how many different products, and technologies he covers I think it goes into just the right amount of detail on each one. The book can be used as a quick reference, or it can be used to get a baseline understanding of new security concepts. If you are looking to get a lot of coverage on the written blueprint then this is the book you need, and even if you aren’t studying for the security lab, I would highly recommend it for any budding network professional in the Cisco areana.

In addition to this I got myself a Safari account and started reading Network Security Principals and Practices by Saadat Malik, and after seeing various Amazon reviews I went straight to the IPSEC section to see what all the fuss was about. If you had any doubts about how ISAKMP, IPSEC, ESP, AH or any other related topic function…this book will sort you out. Although it is a few years old, it’s written extremely well and goes into a lot of detail on most of the technologies that make up the 2.0 blueprint.

—-

Considering my progress so far and how much I’m enjoying studying, I anticipate that i’ll be sitting the written a lot sooner than April. February seems more realistic. If I wait 3-4 months before taking the written, its just going to mean that i’ll need do do a lot more review for stuff that I’ve learnt in the last two weeks…its better to strike while the irons hot! And since the written is mostly theory there is no real need to be hammering away on the CLI playing with stuff, which is really what I want to get stuck into.

My Dynamips machine is slowly coming together. I’m probably going to do most of my study on a virtualized system so that I can go at my own pace for next to nothing. Dynamips will run my routers, PEMU will run PIX’s with 8.x images (i’m not going to worry about ASA’s at this stage), and VMware will run both the ACS server on Windows 2003 and IPS with the 5.x image. Obviously i’ll be missing some key things for the 3.x lab, but most of it is going to be there and in the beginning its plenty to start with.