Showing posts with label V5. Show all posts
Showing posts with label V5. Show all posts

CCIE Security v5: More (Fire)Power!

The CCIE Security v5 has just been announced. Coming as no surprise, it now follows the new format, and is broken down into a troubleshooting section (2 hours), diagnostic section (30 minutes) and the configuration section (5 hours).

So, naturally, as soon as I heard this, I went and booked the v4 lab exam for the end of September, which still gives me a chance to re-sit in December if I do not pass. Now my goal for readiness has been reduced from six months to three months.

What's new in the CCIE Security v5?

FirePOWER, FirePOWER and more FirePOWER. I did a word count and it mentions "FirePower" six times, and FTD (FirePOWER Threat Defense) eight times.

CCIE Security v5

I won't just copy and paste the whole list of topics here, you can find it here instead. Instead, I'll do a few bullet points of the salient topics:
  • FirePOWER
  • NAT for IPv6
  • IOS-XE
  • CWS (Content Web Security)
  • ESA (Email Security Appliance)
  • Proxying
  • DLP (Data Loss Prevention)
  • OpenDNS
  • SMA (Security Management Appliance)
  • Lancope
  • FlexVPN
  • ASA VPN Clustering
  • VRF-Lite / VRF-Aware VPN
  • VSG (Virtual Security Gateway)
  • ACI, EVPN, VXLAN, NVGRE
  • NetFlow and IPFIX
  • eSTREAMER
  • REST / Python
Then you have the "evolving technologies" section, which is all about the Cloud, SDN, and IoT.

The v5 is a natural progression, and the changes within are a natural progression. We still have a few old favourites, and I am surprised that ACS is still listed.

More virtualization?

There does seem to be a greater emphasis on virtualized technologies with the v5.  It's easier and cheaper to run these for the lab then having racks of equipment. ASAv, WSAv, ESAv, and NGIPSv are all listed. This may mean that we see support for them in VIRL (ASAv is already supported), which means that it would be MUCH easier to study them, currently, it's hard(er) to do this with the v4.

Here is a list of the hardware and software for the new v5:

Virtual Machines:
Security Appliances
Cisco Identity Services Engine (ISE): 2.1.0
Cisco Secure Access Control System (ACS): 5.8.0.32
Cisco Web Security Appliance (WSA): 9.2.0
Cisco Email Security Appliance (ESA): 9.7.1
Cisco Wireless Controller (WLC): 8.0.133
Cisco Firepower Management Center Virtual Appliance: 6.0.1 and/or 6.1
Cisco Firepower NGIPSv: 6.0.1
Cisco Firepower Threat Defense: 6.0.1
Core Devices
IOSv L2: 15.2
IOSv L3: 15.5(2)T
Cisco CSR 1000V Series Cloud Services Router: 3.16.02.S
Cisco Adaptive Security Virtual Appliance (ASAv): 9.6.1
Others
Test PC: Microsoft Windows 7
Active Directory: Microsoft Windows Server 2008
Cisco Application Policy Infrastructure Controller Enterprise Module : 1.2
Cisco Unified Communications Manager: 8.6.(1)
FireAMP Private Cloud
AnyConnect 4.2

Physical Devices
Cisco Catalyst Switch
C3850-12S: 16.2.1
Cisco Adaptive Security Appliance
5512-X: 9.6.1
Cisco 2504 Wireless Controller
2504: 8.0.133.0
Cisco Aironet
1602E: 15.3.3-JC
Cisco Unified IP Phone
7965: 9.2(3)

CCIE Security v5 Study material

Ignore their book list! It really needs updating, they still list v3 books on there! I will do a separate post with the up-to-date books on it, but don't rush out and buy all the books they have listed just yet.

When does the v5 start?


January 31st, 2017 is the start date for the new written and lab exams.
The last day for the written exam (350-018) is July 24th, 2016. As of July 25th, 2016 the written exam will be using the new 4.1 topics, which includes the evolving technologies stuff.

The last day for the lab exam is January 30th, 2017.
CCIE Security v5 Lab Predictions

CCIE Security v5 Lab Predictions

The current version of the CCIE Security lab exam (v4) came in 2012. It is now 2016, so after three to four years, it's probably due for an update shortly.

In fact there are rumours and mentions that there will be an announcement at the Berlin Cisco Live event on the 15th February.

So, what could go out, and what could be in?

This is the current list of software versions:

  • Cisco ISR Series running IOS Software Version 15.1(x)T and 15.2(x)T
  • Cisco Catalyst 3560/3750 Series Switches running Cisco IOS Software Release 12.2SE/15.0(x)SE
  • Cisco ASA 5500 Series Adaptive Security Appliances OS Software Versions 8.2x, 8.4x, 8.6x
  • Cisco IPS Software Release 7.x
  • Cisco VPN Client Software for Windows, Release 5.x
  • Cisco Secure ACS System software version 5.3x
  • Cisco WLC 2500 Series software 7.2x
  • Cisco Aironet 1200 series AP Cisco IOS Software Release 12.4J(x)
  • Cisco WSA S-series software version 7.1x
  • Cisco ISE 3300 series software version 1.1x
  • Cisco NAC Posture Agent v4.X
  • Cisco AnyConnect Client v3.0X

Let's break it down and see what could be likely contenders! note - this is just my guesses!

Cisco ISR 15.1(x)T and 15.2(x)T

These are still relatively new. The latest version is 16.01, released in November 2015. 15.1 and 15.2 have been around for over a year, so we might see a jump to a newer version.

Probability/Impact: Low-Medium

Cisco Catalyst 3560/3750 Series Switches 12.2SE/15.0(x)SE

The 3560 and 3750's had an announcement in 2013 that they would be End-of-Life starting mid-2016.

The later versions of these (3560-X and 3750-X) had an EOL in October 2015, and shipping these stops in October 2016, however, support does not end until 2021. Support (in terms of patches) does not stop till 2017.

It it more likely that these will move to 3650s. These do MACSec and TrustSec, among other things, or 3850s.

Probability/Impact: Medium

Cisco ASA 5500 (8.2x, 8.4x, 8.6x)

I think there will be big changes here. The majority of the ASAs will move to the ASAv, which makes sense as there will be much more virtualization within the new lab exam. Expect more ASA 9.x and less 8.2.

Probability/Impact: High

Cisco IPS 7.x

Again, there will be big changes here. EOL was announced in 2013! Support will stop in 2019. Therefore it is highly likely that this will be replaced with FirePower/SourceFire.

Probability/Impact: High

Cisco VPN Client 5.x

EOL as of mid-2011, EOS (End-of-Support) mid-2012. Another contender for complete removal, with more focus on AnyConnect.

Probability/Impact: High

Cisco Secure ACS System 5.3x

5.3 went had an EOL (End-of-Life) announcement back in 2014. With the last day to order it being January 31st 2014, and it will no longer be supported by 31st January 2017. Similarly 5.7 is now EOL as well, as of 2nd November 2015. Looks very likely for complete removal.

This will be replaced with ISE 2.0

Probability/Impact: High

Cisco WLC 2500 Series software 7.2x

The 2500 series line is still going strong, but changes are that the software used will be 8.x (8.2 being the latest).

However, the current trend is to make more use of virtualization, so this may switch to the vWLC, which is also version 8.

Probability/Impact: Medium

Cisco Aironet 1200 series AP 12.4J(x)

This is EOL, so it'll probably move to the 1700 series.

Probability/Impact: High

Cisco WSA S-series software version 7.1x

These are still going strong, so it will stay in the exam, in one form or another. Most likely switching to the vWSA (virtual). Version 7.1 will not be supported beyond August 31st 2016, so expect the version to move to 9.0 (as per the vWSA).

Probability/Impact: High

Cisco ISE 3300 series software version 1.1x

Totally EOL. It'll be ISE 2.0

Probability/Impact: High

Cisco NAC Posture Agent v4.X

4.9 is still going strong, so there probably won't be any change.

Probability/Impact: Low

Cisco AnyConnect Client v3.0X

3.0 will be out and 4.0 will be in.

Probability/Impact: Low
Month five done, seven to go

Month five done, seven to go

Welcome to 2014 everyone! Hope you have had a great holiday, and a happy new year to all!

It's going to be a short post today. Things are going well, and, admittedly, although I have gone off on a little tangent, I have been studying pretty hard this month. I finished work mid-December and am back at work tomorrow. It's been a good holiday, fairly relaxing, I even cooked all the Christmas dinner (pork with crackling), all by myself (but my mum did chop the sprouts for me). Drunk a lot of wine and played with my boys. can't ask for more really. It's been a good end to 2013.

January is looking to be an exciting month, but I can't really say at the moment why. Sorry, but I will tell more as and when I can.

I havn't progressed much further in the QoS side of things, but am working on something pretty big. It's still CCIE related, so I havn't lost focus, if anything it has served to focus me more, it just means that it might prolong things a bit. I am pretty excited about it and hope to have it complete within the next couple of weeks, it's certainly the biggest and most concentrated thing I have done since my Psychology dissertation.

In the end though I think it will help others going through the CCIE as well, and hopefully it will be the start of something that will continue, especially as the new V5 is now firmly on the horizon.

Anyway, like I said, its a short post today. So happy new year all, and hopefully 2014 will bring CCIE numbers to many of you!
V5.0 certification guide in May, by Narbik!

V5.0 certification guide in May, by Narbik!

Narbik is taking up the helm for the new v5 certification guide, to be released in May 2014.
It will be released in two volumes which can be bought separately, or in a pack together. 
Volume 1 will cover: LAN switching, IP networking, and IGP routing:

Part 1. LAN Switching

1. Switched Networking Basics
2. Virtual LANs and VLAN Trunking
3. Spanning Tree Protocol

Part 2. IP Networking

4. Layer 3 Basics
5. IP Services

Part 3. IP IGP Routing

6. IP Forwarding (Routing)
7. RIPv2 and RIPng
8. EIGRP
9. OSPF v2 and v3
10. ISIS
11. IGP Route Redistribution, Route Summarization, and Default Routing

Volume 2 will cover: BGP, QoS, IP multicast, security, WANs, and MPLS. 

Part 1. IP BGP Routing

1. Fundamentals of BGP Operations
2. BGP Routing Policies

Part 2. QoS

3. Classification and Marking
4. Congestion Management and Avoidance
5. Shaping and Policing

Part 3. Wide-Area Networks

6. Wide Area Networks

Part 4. IP Multicast

7. Introduction to IP Multicast
8. IP Multicast Routing

Part 5. Security

9. Device and Network Security
10. Tunneling Technologies

Part 6. MultiProtocol Label Switching (MPLS)

11. MPLS

Amazon have made this available for preorder now! I'll post more details when they come out...

Buy from Amazon.com

Volume 1
Volume 2
Volumes 1 & 2

Buy from Amazon UK

Volume 1
Volume 2
Volumes 1 & 2
CCIE R+S v5.0 Lab exam - full breakdown

CCIE R+S v5.0 Lab exam - full breakdown

There are somethings that really stand out on the new v5.0 Lab exam blueprint, firstly is that there is quite a few mentions of Wireshark, so I would hazard a guess that VIRL/CML connects easily to Wireshark in the same way that IOU/IOL and GNS3 do. RIPv2 gets a very brief mention, but BGP is really ramped up when compared to the v4 blueprint. I am starting to think that RIP might not even make it onto the v6.0 blueprint (yes, you heard it first here, folks), and we also have the new versions of Netflow as well now.

Here is the complete list of things you need to cover for the new v5.0 written exam:

CCIE R+S v5.0 Written exam - full breakdown

CCIE R+S v5.0 Written exam - full breakdown

The v5.0 Written exam has many changes from the v4.0, if you want to remind yourself what's in the V4 then have a look here. The new exam topic lists make the v4.0 look almost too generic really. If you have been following this blog then hopefully you will have seen that as I cover a topic I am linking it back to a very early post where I listed the v4.0 topics, well it looks like I will have to start linking again, and hopefully as I am now into the fifth month of my studies there wont be too many (completely) new topics!

There are some quite new things, such as IOS XE, ISIS, Wireshark but many are just extensions of topics we should already be covering.

Here is the complete list of things you need to cover for the new v5.0 written exam:

CCIE R+S v5.0 Confirmed - Find out what's new!

CCIE R+S v5.0 Confirmed - Find out what's new!

Cisco have released details of the new v5.0 blueprint for the CCIE Routing and Switching exams.

Here's a breakdown of what is in the new exam.

Last date of the v4.0

You have until June 3rd 2014 to take the V4 blueprint.

Start date of the v5.0

The v5.0 exams will start on July 4th 2014.

Hardware

As previously thought the lab will be 100% virtualised, though if you want to buy equipment you will need Cisco ISR 2900 series running IOS 15.3T Universal, and Catalyst 3560Xs running 15.0SE universal (IP services).

v5.0 Written exam

The new code for the written exam is 400-101, and is much the same format as before.

It is now broken down into six areas, with the percentage for each topic in brackets:

1.0 Network Principles (10%)
2.0 Layer 2 Technologies (15%)
3.0 Layer 3 Technologies (40%)
4.0 VPN Technologies (15%)
5.0 Infrastructure Security (5%)
6.0 Infrastructure Services (15%)

A full breakdown of the v5.0 Written Exam topics

v5.0 Lab Exam

The lab exam has also been simplified, with now just 5 areas:

1.0 Layer 2 Technologies (20%)
2.0 Layer 3 Technologies (40%)
3.0 VPN Technologies (20%)
4.0 Infrastructure Security (5%)
5.0 Infrastructure Services (15%)

There is a big change to the format of the lab exam, and now it is split into three parts.

Troubleshooting - 2 hours with an optional 30 minutes
Diagnostic - 30 minutes
Configuration - 5 hours 30 minutes with an optional 30 minutes (if you havn't already used it in the troubleshooting)

The diagnostic module is ticket based - similar to the CCNP TSHOOT, whereby you are required to make a choice between pre-defined options and show either where or what the root cause is, or what lead you to this conclusion, or what is missing to make a judgement about the root cause. There will be multiple sources of information such as logs, diagrams and emails - though given some of the "The internet is broken" emails I get, I hope Cisco won't go down to end-user level...

A full breakdown of the v5.0 Lab Exam topics

What's been added, moved or removed

Indications from various sources were pretty spot-on.

The following have been removed:

• Flexlink, ISL, Layer 2 Protocol Tunneling
• Frame-Relay (LFI, FR Traffic Shaping)
• WCCP
• IOS Firewall and IPS
• RITE, RMON
• RGMP
• RSVP QoS, WRR/SRR

The following have been moved from the Lab exam to the new written exam:

• Describe IPv6 Multicast
• Describe RIPv6 (RIPng)
• Describe IPv6 Tunneling Techniques
• Describe Device Security using IOS AAA with TACACS+ and RADIUS
• Describe 802.1x
• Describe Layer 2 QoS
• Identify Performance Routing (PfR)

New topics on the written exam are:

• Describe basic software architecture differences between IOS and IOS XE
• Identify Cisco Express Forwarding Concepts
• Explain General Network Challenges
• Explain IP, TCP and UDP Operations
• Describe Chassis Virtualization and Aggregation Technologies
• Explain PIM Snooping
• Describe WAN Rate-based Ethernet Circuits
• Describe BGP Fast Convergence Features
• ISIS (for IPv4 and IPv6)
• Describe Basic Layer 2 VPN - Wireline
• Describe Basic L2VPN - LAN Services
• Describe GET VPN
• Describe IPv6 Network Address Translation

And finally new topics on the both the written and lab exams:

• Use IOS Troubleshooting Tools
• Apply Troubleshooting Methodologies
• Interpret Packet Capture
• Implement and Troubleshoot Bidirectional Forwarding Detection
• Implement EIGRP (multi-address) Named Mode
• Implement, Troubleshoot and Optimize EIGRP and OSPF Convergence and Scalability
• Implement and Troubleshoot DMVPN (single hub)
• Implement and Troubleshoot IPsec with pre-shared key
• Implement and Troubleshoot IPv6 First Hop Security

As I thought in my previous post on what's probably going to come up in the v5.0 there is a greater emphasis on IPv6. Some older technologies have been removed such as ISL, and Frame-Relay, and other technologies that are more suited to the Security track (WCCP, Firewall and IPS) have also been removed.

The changes do make a lot of sense, certainly as IPv6 adoption increases then the exam-provable skill sets must also increase.

All in all it's not an overly scary change. The current reading list is still pretty valid, even the 4th edition certification guide by Wendell Odom is still very useful, but we would expect the new version to be released in the first half of next year.

I will go through the complete changes to the v5.0 Written and Lab exams in separate posts, so stay tuned!
Month four done, eight to go

Month four done, eight to go

Studies are starting to pick up again, mainly because I am trying to push myself a bit more. I have finally finished BGP in the Odom book, and now it's on to QoS. Not the most interesting topic, but then not all every topic will be, you got to take the rough with the smooth really.

I am spending a bit too much time playing with the layour of this blog though. I am sure that this time could be better spent... But it does keep me amused, and I know that I need to do things other than study otherwise I will start to burn out and things won't get learned.

CCIE and home life

My shoulder is much better now, it cost a couple of hundred in chiropractor bills, but all I am left with is a slightly tingly end to one of my fingers, but at least it's not complete agony! I had my 36th birthday as well, and the wife took me to a cabaret club in London (the Wam Bam Club) - we had an excellent night, ended up getting exceedingly drunk and can't remember some parts of getting home, but we did at least make it home.

I have booked some time off in the lead up to and through Christmas, should be able to get some studying some there, I would like to get through QoS and move on to Multicast, not sure if I will go through Frame Relay as I will probably get the V5 when I am taking the exam, and all signs point to the fact that Frame Relay will not appear on the V5 - more details will be released in January so I can always go back to that if it does remain on the new blueprint.

CCIE and work life

Things are quietening down in the build up to Christmas, so am managing to get little snippets done at work. Still ironing out a few Lync "issues" but its business as usual mainly.

CCIE R+S V5 - DMVPN

So with the news about the change from the CCIE Routing and Switching V4 blueprint to the V5 many (i.e. some good sources) reckon that DMVPN will be on the new V5 blueprint.

What is DMVPN?

DMVPN stands for Dynamic Multipoint Virtual Private Network, what it does is allow multiple IPSec VPN connections with just one tunnel configuration, so for a site with one central "hub" and three other sites (or "spokes") instead of having three separate VPN configurations there is just one - it does mean that the traffic say from spoke1 to spoke3 needs to go through the hub, but from a configuration standpoint, life is much easier.

DMVPN is based on GRE (and we have covered GRE tunnels before, or mGRE if we are doing spoke-to-spoke tunnels), NHRP (next-hop resolution protocol) and IPSec (because VPN tunnels should be secure). DMVPN also requires a dynamic routing protocol, and CEF (Cisco Express Forwarding).

When it comes to the routing protocol to use within the tunnel EIGRP is preferred because it is an advanced distance vector protocol, better suited to the NBMA network that is built when using DMVPN.

DMVPN can be configured as Hub-and-Spoke or (using mGRE) Spoke-to-Spoke.

Consider the following topology:


We have a central site (called "Hub") and three different spoke at the bottom. In the middle is the cloud, which can be frame-relay or any other method of providing a connection between the hub and the spoke routers.

From the viewpoint of the routers, with our DMVPN in place, they will see the 10.10.1.0/24 network:


We start of with a basic configuration to provide connectivity:

Hub:
hostname Hub
!
interface Serial0/0
 ip address 10.25.1.2 255.255.255.0
!
ip route 10.35.1.0 255.255.255.0 10.25.1.1
ip route 10.45.1.0 255.255.255.0 10.25.1.1
ip route 10.55.1.0 255.255.255.0 10.25.1.1
Cloud:
hostname Cloud
!
interface Serial0/0
 ip address 10.25.1.1 255.255.255.0
!
interface Serial0/1
 ip address 10.35.1.1 255.255.255.0
!
interface Serial0/2
 ip address 10.45.1.1 255.255.255.0
!
interface Serial0/3
 ip address 10.55.1.1 255.255.255.0
Spoke1
hostname Spoke1
!
interface Loopback0
 ip address 10.50.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.35.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.35.1.1
Spoke 2
hostname Spoke2
!
interface Loopback0
 ip address 10.60.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.45.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.45.1.1
Spoke3
hostname Spoke3
!
interface Loopback0
 ip address 10.70.1.1 255.255.255.0
!
interface Serial0/0
 ip address 10.55.1.2 255.255.255.0
!
ip route 10.25.1.2 255.255.255.255 10.55.1.1
So you can see that we are starting off easy, with just basic connectivity from the Hub to each of the Spokes using the cloud to pass the traffic through. At this stage none of the spoke have any knowledge of each other.

DMVPN Tunnel configuration

The tunnel configuration is much like a standard GRE tunnel but with a couple of additional commands.

The Hub is where everything points to, and we associate the tunnel with a network-id (this is the NBMA identifier), setting the mode as gre multipoint. The spokes map the tunnel IP set on the Hub (10.10.1.1) to the external IP address of the Hub (10.25.1.2), and set this as the next-hop-server (ip nhrp nhs 10.10.1.1).

Hub tunnel:
interface Tunnel0
 ip address 10.10.1.1 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map multicast dynamic
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 tunnel source 10.25.1.2
 tunnel mode gre multipoint
Spoke 1 tunnel:
interface Tunnel0
 ip address 10.10.1.2 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.35.1.2
 tunnel mode gre multipoint
Spoke 2 tunnel
interface Tunnel0
 ip address 10.10.1.3 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.45.1.2
 tunnel mode gre multipoint
Spoke 3 tunnel:
interface Tunnel0
 ip address 10.10.1.4 255.255.255.0
 no ip redirects
 ip mtu 1416
 no ip next-hop-self eigrp 1
 ip nhrp map 10.10.1.1 10.25.1.2
 ip nhrp map multicast 10.25.1.2
 ip nhrp network-id 1
 no ip split-horizon eigrp 1
 ip nhrp nhs 10.10.1.1
 tunnel source 10.55.1.2
 tunnel mode gre multipoint
We can check that our DMVPN tunnel is working using the "sh dmvpn" command:
Hub#sh dmvpn | beg Interface

Interface: Tunnel0, IPv4 NHRP Details
Type:Hub, NHRP Peers:3,

 # Ent Peer NBMA Addr  Peer Tunnel Add State UpDn Tm  Attrb
 ----- --------------- --------------- ----- -------- -----
   1   10.35.1.2       10.10.1.2       UP    00:06:19  D
   1   10.45.1.2       10.10.1.3       UP    00:05:06  D
   1   10.55.1.2       10.10.1.4       UP    00:04:28  D
We can also use basic ping tests:
Hub#ping 10.10.1.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms
Hub#ping 10.10.1.3

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 16/20/24 ms
Hub#ping 10.10.1.4

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.1.4, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms

Adding IPSec to DMVPN

One of the requirements of DMVPN is IPSec, and this is quite easy to add, the same configuration can go on the Hub and the three spokes.The major thing to point out is that we associate the "dmvpn123" key with any IP address by using the 0.0.0.0 0.0.0.0 address and subnet.
crypto isakmp policy 10
 encryption 3des
 hash md5
 authentication pre-share
crypto isakmp key dmvpn123 address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set MyIPSEC esp-3des
!
crypto ipsec profile DMVPN
 set transform-set MyIPSEC
!
interface Tunnel0
 tunnel protection ipsec profile DMVPN

Adding EIGRP to DMVPN

DMVPNs require a routing protocol within the tunnel (otherwise they would be rather useless), and this is a simple case of adding one!
Hub#sh run | beg router
router eigrp 1 
 network 10.0.0.0
 no auto-summary

Spoke1#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Spoke2#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Spoke3#sh run | beg router
router eigrp 1
 network 10.0.0.0
 no auto-summary

Bringing all of DMVPN together

With all of the nuits and bolts in place now we should have some good visilibilty between our spoke routers. We should see routers learned through EIGRP (indicated with a "D") and be able to ping to the loop back addresses that we configured at the start.
 
Spoke1#sh ip route | beg Gateway
Gateway of last resort is not set

   10.0.0.0/8 is variably subnetted, 10 subnets, 2 masks
C    10.10.1.0/24 is directly connected, Tunnel0
L    10.10.1.2/32 is directly connected, Tunnel0
D    10.25.1.0/24 [90/27392000] via 10.10.1.1, 00:09:46, Tunnel0
S    10.25.1.2/32 [1/0] via 10.35.1.1
C    10.35.1.0/24 is directly connected, Serial0/0
L    10.35.1.2/32 is directly connected, Serial0/0
C    10.50.1.0/24 is directly connected, Loopback0
L    10.50.1.1/32 is directly connected, Loopback0
D    10.60.1.0/24 [90/28288000] via 10.10.1.3, 00:08:06, Tunnel0
D    10.70.1.0/24 [90/28288000] via 10.10.1.4, 00:07:02, Tunnel0
Spoke1#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent Peer NBMA Addr  Peer Tunnel Add State UpDn Tm  Attrb
 ----- --------------- --------------- ----- -------- -----
   3   10.25.1.2       10.10.1.1       UP    00:34:25 S
                       10.10.1.3       UP    00:02:07 D
                       10.10.1.4       UP    00:02:11 D
Spoke1#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/43/48 ms
Spoke1#ping 10.60.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.60.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/44/48 ms
Spoke1#

Hub-and-spoke or Spoke-to-Spoke?

Depending on the requirements you can either setup a hub-to-spoke or spoke-to-spoke topology. We have been using spoke-to-spoke through this, we can see this using the command "sh ip nhrp", because tunnels will drop if there is no traffic (apart from the one to the hub) we can see what NHRP believes to be the next hop for the end-point - so with the tunnel from Spoke1 to Spoke3 down we can issue a ping and see the tunnel come back up again - also showing the tunnel is a spoke-to-spoke.
Spoke1#sh ip nhrp
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 01:15:40, never expire 
   Type: static, Flags: used 
   NBMA address: 10.25.1.2 
Spoke1#ping 10.70.1.1      

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/40/40 ms
Spoke1#sh ip nhrp    
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 01:15:47, never expire 
   Type: static, Flags: used 
   NBMA address: 10.25.1.2 
10.10.1.4/32 via 10.10.1.4
   Tunnel0 created 00:00:01, expire 00:03:03
   Type: dynamic, Flags: temporary
   NBMA address: 10.25.1.2 
Spoke1#
We can, should we wish make it a true hub-to-spoke topology with adding the line "ip nhrp server-only" to the spokes
With our configuration before we can see that the tunnel to the Hub always remains up. We can ping Spoke3 and confirm that another tunnel is created:
Spoke2#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:01:18     S

Spoke2#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/43/48 ms
Spoke2#sh dmvpn | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     2       10.25.1.2       10.10.1.1    UP 00:01:28     S
                             10.10.1.4    UP 00:00:03     D
If we then go into the interface and add the "ip nhrp server-only" command we can confirm that we still have reachability to Spoke3, but only have one tunnel:
Spoke2(config)#int tunnel 0
Spoke2(config-if)#ip nhrp server-only
Spoke2(config-if)#exit
Spoke2(config)#exit
Spoke2#sh dmvp | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:02:24     S

Spoke2#ping 10.70.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.70.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 40/42/48 ms
Spoke2#sh dmvp | beg Interface
Interface: Tunnel0, IPv4 NHRP Details
Type:Spoke, NHRP Peers:1,

 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1       10.25.1.2       10.10.1.1    UP 00:02:31     S

There are some more commands we can use to confirm that our tunnels are looking how they should:
Spoke2#sh ip nhrp
10.10.1.1/32 via 10.10.1.1
   Tunnel0 created 00:14:31, never expire
   Type: static, Flags: used
   NBMA address: 10.25.1.2
Spoke2#sh ip cef 10.70.1.0
10.70.1.0/24
  nexthop 10.10.1.4 Tunnel0
So we have full reachability between the spokes! Pretty neat, and so much easier than creating three different VPNs on each router! It is pretty simple really, if you have created a GRE tunnel before then really we are only looking at a couple of extra lines - and these extra few lines can be copied from one spoke router and pasted onto every other spoke router because they are identical!
CCIE R&S set for update to V5 in 2014

CCIE R&S set for update to V5 in 2014

** UPDATE :- The information has been released - find out more **

At the forthcoming CiscoLive! In Milan between January 27th - 31st there is a session on the V5 version of the CCIE Routing and Switching exam. Information is sparse at the moment, but the two hour session will focus on:
  • CCIE RSv5 Program refresh
  • Overview
  • RSv5 New Curriculum presentation
  • Exams Overview 
  • Written
  • Lab: Structure, Delivery, Hardware/Software requirements, 
  • Lab modules sequence, stake, logic, format, demo
  • Cisco360 Training Overview 
  • New content 
  • QA
According to the INE blog post, the exam will, most likely, be 100% virtualised and platform independent - which will be great news for those using the likes of GNS3, IOU or (sooner or later) VIRL.

According to INE older topics such as Frame-Relay will disappear, along with ZBF, WCCP, IPv6 Multicast and PfR, because the lab will probably be 100% virtualised we can also probably consider the following as topics that will be removed:

  • QinQ Tunneling
  • ISL trunks
  • DHCP Snooping
  • Layer 3 Port Channel
  • Private VLANs
  • SPAN/RSPAN/ERSPAN
I would think that RIPv2 will also feature less, if at all in the new exam, with the focus being EIGRP.

New lab topics might include IPSec, DMVPN, and Embedded Packet Capture. I would also suggest that the exam will be more IPv6 centric, including IPv6 security.

There is also a very good chance that the IOS version will move away from 12.4 and up to 15.

New written topics might include ISIS and IOS XE commands.

Will the lab exam format change from the current 2.5 troubleshooting and 5 hour configuration? Perhaps, there might be a diagnostic element to the exam.
Those with exams booked before the end of March should be ok, but after March the chances of getting V5 labs greatly increases as the V4 is phased out.

Once more information is released I'll update. In the meantime take the poll on the right-hand side and let us know what you would like to see removed for the V5!