Showing posts with label V5. Show all posts
Showing posts with label V5. Show all posts

CCIE Security v5: More (Fire)Power!

The CCIE Security v5 has just been announced. Coming as no surprise, it now follows the new format, and is broken down into a troubleshooting section (2 hours), diagnostic section (30 minutes) and the configuration section (5 hours).

So, naturally, as soon as I heard this, I went and booked the v4 lab exam for the end of September, which still gives me a chance to re-sit in December if I do not pass. Now my goal for readiness has been reduced from six months to three months.

What's new in the CCIE Security v5?

FirePOWER, FirePOWER and more FirePOWER. I did a word count and it mentions "FirePower" six times, and FTD (FirePOWER Threat Defense) eight times.

CCIE Security v5

I won't just copy and paste the whole list of topics here, you can find it here instead. Instead, I'll do a few bullet points of the salient topics:
  • FirePOWER
  • NAT for IPv6
  • IOS-XE
  • CWS (Content Web Security)
  • ESA (Email Security Appliance)
  • Proxying
  • DLP (Data Loss Prevention)
  • OpenDNS
  • SMA (Security Management Appliance)
  • Lancope
  • FlexVPN
  • ASA VPN Clustering
  • VRF-Lite / VRF-Aware VPN
  • VSG (Virtual Security Gateway)
  • ACI, EVPN, VXLAN, NVGRE
  • NetFlow and IPFIX
  • eSTREAMER
  • REST / Python
Then you have the "evolving technologies" section, which is all about the Cloud, SDN, and IoT.

The v5 is a natural progression, and the changes within are a natural progression. We still have a few old favourites, and I am surprised that ACS is still listed.

More virtualization?

There does seem to be a greater emphasis on virtualized technologies with the v5.  It's easier and cheaper to run these for the lab then having racks of equipment. ASAv, WSAv, ESAv, and NGIPSv are all listed. This may mean that we see support for them in VIRL (ASAv is already supported), which means that it would be MUCH easier to study them, currently, it's hard(er) to do this with the v4.

Here is a list of the hardware and software for the new v5:

Virtual Machines:
Security Appliances
Cisco Identity Services Engine (ISE): 2.1.0
Cisco Secure Access Control System (ACS): 5.8.0.32
Cisco Web Security Appliance (WSA): 9.2.0
Cisco Email Security Appliance (ESA): 9.7.1
Cisco Wireless Controller (WLC): 8.0.133
Cisco Firepower Management Center Virtual Appliance: 6.0.1 and/or 6.1
Cisco Firepower NGIPSv: 6.0.1
Cisco Firepower Threat Defense: 6.0.1
Core Devices
IOSv L2: 15.2
IOSv L3: 15.5(2)T
Cisco CSR 1000V Series Cloud Services Router: 3.16.02.S
Cisco Adaptive Security Virtual Appliance (ASAv): 9.6.1
Others
Test PC: Microsoft Windows 7
Active Directory: Microsoft Windows Server 2008
Cisco Application Policy Infrastructure Controller Enterprise Module : 1.2
Cisco Unified Communications Manager: 8.6.(1)
FireAMP Private Cloud
AnyConnect 4.2

Physical Devices
Cisco Catalyst Switch
C3850-12S: 16.2.1
Cisco Adaptive Security Appliance
5512-X: 9.6.1
Cisco 2504 Wireless Controller
2504: 8.0.133.0
Cisco Aironet
1602E: 15.3.3-JC
Cisco Unified IP Phone
7965: 9.2(3)

CCIE Security v5 Study material

Ignore their book list! It really needs updating, they still list v3 books on there! I will do a separate post with the up-to-date books on it, but don't rush out and buy all the books they have listed just yet.

When does the v5 start?


January 31st, 2017 is the start date for the new written and lab exams.
The last day for the written exam (350-018) is July 24th, 2016. As of July 25th, 2016 the written exam will be using the new 4.1 topics, which includes the evolving technologies stuff.

The last day for the lab exam is January 30th, 2017.
CCIE Security v5 Lab Predictions

CCIE Security v5 Lab Predictions

The current version of the CCIE Security lab exam (v4) came in 2012. It is now 2016, so after three to four years, it's probably due for an update shortly.

In fact there are rumours and mentions that there will be an announcement at the Berlin Cisco Live event on the 15th February.

So, what could go out, and what could be in?

This is the current list of software versions:

  • Cisco ISR Series running IOS Software Version 15.1(x)T and 15.2(x)T
  • Cisco Catalyst 3560/3750 Series Switches running Cisco IOS Software Release 12.2SE/15.0(x)SE
  • Cisco ASA 5500 Series Adaptive Security Appliances OS Software Versions 8.2x, 8.4x, 8.6x
  • Cisco IPS Software Release 7.x
  • Cisco VPN Client Software for Windows, Release 5.x
  • Cisco Secure ACS System software version 5.3x
  • Cisco WLC 2500 Series software 7.2x
  • Cisco Aironet 1200 series AP Cisco IOS Software Release 12.4J(x)
  • Cisco WSA S-series software version 7.1x
  • Cisco ISE 3300 series software version 1.1x
  • Cisco NAC Posture Agent v4.X
  • Cisco AnyConnect Client v3.0X

Let's break it down and see what could be likely contenders! note - this is just my guesses!

Cisco ISR 15.1(x)T and 15.2(x)T

These are still relatively new. The latest version is 16.01, released in November 2015. 15.1 and 15.2 have been around for over a year, so we might see a jump to a newer version.

Probability/Impact: Low-Medium

Cisco Catalyst 3560/3750 Series Switches 12.2SE/15.0(x)SE

The 3560 and 3750's had an announcement in 2013 that they would be End-of-Life starting mid-2016.

The later versions of these (3560-X and 3750-X) had an EOL in October 2015, and shipping these stops in October 2016, however, support does not end until 2021. Support (in terms of patches) does not stop till 2017.

It it more likely that these will move to 3650s. These do MACSec and TrustSec, among other things, or 3850s.

Probability/Impact: Medium

Cisco ASA 5500 (8.2x, 8.4x, 8.6x)

I think there will be big changes here. The majority of the ASAs will move to the ASAv, which makes sense as there will be much more virtualization within the new lab exam. Expect more ASA 9.x and less 8.2.

Probability/Impact: High

Cisco IPS 7.x

Again, there will be big changes here. EOL was announced in 2013! Support will stop in 2019. Therefore it is highly likely that this will be replaced with FirePower/SourceFire.

Probability/Impact: High

Cisco VPN Client 5.x

EOL as of mid-2011, EOS (End-of-Support) mid-2012. Another contender for complete removal, with more focus on AnyConnect.

Probability/Impact: High

Cisco Secure ACS System 5.3x

5.3 went had an EOL (End-of-Life) announcement back in 2014. With the last day to order it being January 31st 2014, and it will no longer be supported by 31st January 2017. Similarly 5.7 is now EOL as well, as of 2nd November 2015. Looks very likely for complete removal.

This will be replaced with ISE 2.0

Probability/Impact: High

Cisco WLC 2500 Series software 7.2x

The 2500 series line is still going strong, but changes are that the software used will be 8.x (8.2 being the latest).

However, the current trend is to make more use of virtualization, so this may switch to the vWLC, which is also version 8.

Probability/Impact: Medium

Cisco Aironet 1200 series AP 12.4J(x)

This is EOL, so it'll probably move to the 1700 series.

Probability/Impact: High

Cisco WSA S-series software version 7.1x

These are still going strong, so it will stay in the exam, in one form or another. Most likely switching to the vWSA (virtual). Version 7.1 will not be supported beyond August 31st 2016, so expect the version to move to 9.0 (as per the vWSA).

Probability/Impact: High

Cisco ISE 3300 series software version 1.1x

Totally EOL. It'll be ISE 2.0

Probability/Impact: High

Cisco NAC Posture Agent v4.X

4.9 is still going strong, so there probably won't be any change.

Probability/Impact: Low

Cisco AnyConnect Client v3.0X

3.0 will be out and 4.0 will be in.

Probability/Impact: Low
Month five done, seven to go

Month five done, seven to go

Welcome to 2014 everyone! Hope you have had a great holiday, and a happy new year to all!

It's going to be a short post today. Things are going well, and, admittedly, although I have gone off on a little tangent, I have been studying pretty hard this month. I finished work mid-December and am back at work tomorrow. It's been a good holiday, fairly relaxing, I even cooked all the Christmas dinner (pork with crackling), all by myself (but my mum did chop the sprouts for me). Drunk a lot of wine and played with my boys. can't ask for more really. It's been a good end to 2013.

January is looking to be an exciting month, but I can't really say at the moment why. Sorry, but I will tell more as and when I can.

I havn't progressed much further in the QoS side of things, but am working on something pretty big. It's still CCIE related, so I havn't lost focus, if anything it has served to focus me more, it just means that it might prolong things a bit. I am pretty excited about it and hope to have it complete within the next couple of weeks, it's certainly the biggest and most concentrated thing I have done since my Psychology dissertation.

In the end though I think it will help others going through the CCIE as well, and hopefully it will be the start of something that will continue, especially as the new V5 is now firmly on the horizon.

Anyway, like I said, its a short post today. So happy new year all, and hopefully 2014 will bring CCIE numbers to many of you!
V5.0 certification guide in May, by Narbik!

V5.0 certification guide in May, by Narbik!

Narbik is taking up the helm for the new v5 certification guide, to be released in May 2014.
It will be released in two volumes which can be bought separately, or in a pack together. 
Volume 1 will cover: LAN switching, IP networking, and IGP routing:

Part 1. LAN Switching

1. Switched Networking Basics
2. Virtual LANs and VLAN Trunking
3. Spanning Tree Protocol

Part 2. IP Networking

4. Layer 3 Basics
5. IP Services

Part 3. IP IGP Routing

6. IP Forwarding (Routing)
7. RIPv2 and RIPng
8. EIGRP
9. OSPF v2 and v3
10. ISIS
11. IGP Route Redistribution, Route Summarization, and Default Routing

Volume 2 will cover: BGP, QoS, IP multicast, security, WANs, and MPLS. 

Part 1. IP BGP Routing

1. Fundamentals of BGP Operations
2. BGP Routing Policies

Part 2. QoS

3. Classification and Marking
4. Congestion Management and Avoidance
5. Shaping and Policing

Part 3. Wide-Area Networks

6. Wide Area Networks

Part 4. IP Multicast

7. Introduction to IP Multicast
8. IP Multicast Routing

Part 5. Security

9. Device and Network Security
10. Tunneling Technologies

Part 6. MultiProtocol Label Switching (MPLS)

11. MPLS

Amazon have made this available for preorder now! I'll post more details when they come out...

Buy from Amazon.com

Volume 1
Volume 2
Volumes 1 & 2

Buy from Amazon UK

Volume 1
Volume 2
Volumes 1 & 2
CCIE R+S v5.0 Lab exam - full breakdown

CCIE R+S v5.0 Lab exam - full breakdown

There are somethings that really stand out on the new v5.0 Lab exam blueprint, firstly is that there is quite a few mentions of Wireshark, so I would hazard a guess that VIRL/CML connects easily to Wireshark in the same way that IOU/IOL and GNS3 do. RIPv2 gets a very brief mention, but BGP is really ramped up when compared to the v4 blueprint. I am starting to think that RIP might not even make it onto the v6.0 blueprint (yes, you heard it first here, folks), and we also have the new versions of Netflow as well now.

Here is the complete list of things you need to cover for the new v5.0 written exam:

CCIE R+S v5.0 Written exam - full breakdown

CCIE R+S v5.0 Written exam - full breakdown

The v5.0 Written exam has many changes from the v4.0, if you want to remind yourself what's in the V4 then have a look here. The new exam topic lists make the v4.0 look almost too generic really. If you have been following this blog then hopefully you will have seen that as I cover a topic I am linking it back to a very early post where I listed the v4.0 topics, well it looks like I will have to start linking again, and hopefully as I am now into the fifth month of my studies there wont be too many (completely) new topics!

There are some quite new things, such as IOS XE, ISIS, Wireshark but many are just extensions of topics we should already be covering.

Here is the complete list of things you need to cover for the new v5.0 written exam: