Skip to Content

August 2006

New CallManager Express Configuration GUI

Cisco has finally released the CallManager Express configuration GUI as an official "beta" product. This was originally engineered by a Cisco employee as a sort of 'hack' to make CCME configuration easier. It looks like it became popular enough that Cisco adopted it as it's own product. Here's the email blurb I received this morning:

Bi-Directional NAT on PIX Firewalls

For those of you that work with PIX firewalls on a regular basis, you might know that when you upgrade to use the ASDM GUI, it no longer supports the alias command (kudos to the no-longer-supported alias command). The first time I saw the error message from teh ASDM GUI, it made me feel like a moron. It was something like:
"Alias commands are no longer supported in ASDM. Before you can use the configuration utility, you must convert all alias entries to bidirectional NAT."
So matter of fact...meanwhile, I'm staring at the screen thinking, "what the heck is bidirectional NAT?" A search of Cisco's website provided no useful information.
Mike Storm (a fellow instructor of mine at Interface TT in Phoenix, AZ) did a quick write-up describing what took me 6 hours to figure out. You can grab it here.

Ideal CCNA Lab Setup

CCNADiagram.jpg

Many of my CCNA-desiring friends have asked me if I could create a post that shows the ideal budget-conscious "study-lab" to prepare for the CCNA exam. Here's my suggestion:
The minimal equipment that I would purchase for the lab is as shown in the image on this post.

VPN Virtual Tunnel Interfaces

VTI.gif

While doing a recent deployment, I ran across this concept. It's a
slightly different way to configure VPNs on a Cisco router that (for me)
is far less confusing and finicky. If you've ever configured VPNs using
a PIX firewall or IOS router, you probably know of the pain associated
with making sure your crypto map is correctly configured. There are SO
MANY pieces of it, you're almost assured that something is not going to
match between one side of the connection and the other (especially that
"interesting traffic" ACL). That's where these IPSec Virtual Tunnel
Interfaces come in. Check this out...



Dr. Radut