Method Posts

Showing posts with label Methods. Show all posts
Showing posts with label Methods. Show all posts

Thursday, 21 February 2019

MPLS/L3VPN Lab

I wanted a little more for L3VPN practice so I figured I would make my own topology compatible with the INE topology (easier to switch to it).

I made this lab based on the INE topology that I made available here: https://nickccieprogress.blogspot.com/2019/01/method-post-using-eve-ng-for-ine-atc.html



It uses 15 routers.  You can find/replace to change them for the IOS version you are using (topologies are for IOL/IOSv/CSRv).  

Link: INE-CCIE-RSv5-Topologies.zip
Description: Contains 10-Router + 4-Switch and 20-Router + 4-Switch INE ATC topology for IOL, IOSv, and CSR1000v



Link: L3VPN Configurations

Description: Contains some basic configs for the above lab - nothing fancy but it'll get things started

Sunday, 3 February 2019

Re: Please Share Your Anki Decks With Me.. (More Information on Creating Anki Cards)

I recently received a message for a request to share my CCIE Prep deck.  The body was just the same as the title: "please share your deck".

My Response:
Have you checked both of the decks in my "Using Anki For CCIE Preparation" blog post? :

http://nickccieprogress.blogspot.com/2019/01/method-post-using-anki-for-ccie.html

I make some recommendations about how to use the Neckercube deck. My personal deck is full of material that is copyrighted so it is probably not OK to share. If you follow my instructions though, you can use that Neckercube deck as a "base" (over 3500 cards in there) to make your own as you go.

Requestor's Reply
Yes I did, my problem is i really don't know how to create flashcards. Questions about concepts? Questions about piece of configurations? How many chunks do i have to make? How many splits?

My Response 

(I actually just made this post, and then sent them a link):
I am serious when I tell you, it is worth your time to learn and practice to make your own flash cards.  This has helped me greatly for my CCIE preparation, but it is a skill that will continue to help me throughout the rest of my life.  You will get better at doing it, and making cards that have meaning to you, and help you remember the concepts.

Check out this post by Petr Lapukhov about how to study in general (Both the "Active Reading" and "Spaced Repetitions"  are amazing).  The "Active Reading" section is where you pick the concepts to make a flash card about:
https://blog.ine.com/2009/03/22/how-to-study

Petr's post refers to older training materials, but I highly recommend reading it carefully, and really taking the time to learn what he is communicating.  I have probably read that post 10 times now, as it has had the greatest influence on me out of everything that I have read about preparing for my CCIE.  Active reading and spaced repetition is the best way that I have found by far to learn a large amount of material such as with the CCIE.

Check out these great posts by Jedediah Casey About Anki as well:
Anki: My New Love
On Learning: Creating Meaningful Flash Cards
On Learning: Flash Card Review

Also this may be useful (also Jedadiah Casey):
On Learning: Knowledge Management

Also, my Anki deck is *not* complete.  It has about 2,800 cards in it but it is missing like 30-40% of the blueprint still.  I am building it as I go along (with about 70% of my cards being from that Neckercube deck, some with a little modification).  I highly suggest that you do the same, since the act of making the flash cards is a part of the learning process.  The trick is that you are forcing yourself to understand a concept yourself first, and then make a card that helps remind you of it so you don't forget as time passes and you are focusing on new material.  If you just go through a flash card that someone else made, then you didn't have to spend the time properly figuring it out in the first place.  This only hurts you in the long run in terms of gaining and retaining a proper understanding of the concepts.

Here are the main reasons why my current deck wouldn't be as good as one that you create:
  1. A big part of what gives my flash cards value is the process of creating them in the first place.  Before I create a set of concept flash cards, I try to make sure I understand everything well. A good exercise is to try to explain the concept to your imaginary friend.  If you have trouble explaining it, then you don't understand it well enough - keep learning it. Once you can explain it, make a "quiz" for that imaginary friend using the flash cards that you create.  You want to make sure that your imaginary friend is able to retain everything that you have taught them :)
  2. It is not done - I am probably just over half way through the material... tons of stuff is still missing
  3. It contains vendor materials - lots of INE and Networklessons.com images (and text) in there.  I don't know all of the applicable laws, but from an ethical standpoint sharing these is "uncool".
  4. It still contains mistakes/incomplete information - this is because I am still building it.  I end up going back and changing some of the flash cards because they were partially (or sometimes completely...) wrong, or required modification to clarify later after learning more.  You can avoid this to some extent by trying to make sure you understand a topic completely before making flash cards, but in my experience it is going to happen sometimes...

To answer the specific questions you asked:


Questions about concepts? 

Once you fully understand the concept:
There will be plenty of information that you just need to memorize.  The Neckercube deck contains most all of what you would need in this department (as well as a lot of the concepts).

Examples of these are stuff like:
Q: Which OSPF LSA type advertises a host route to reach an ASBR?
A: Type4

and

Q: What does BGP use for transport
A: TCP port 179

Some of them are a little longer, but Jedadiah did a great job breaking them into smaller parts.  For example, he has a separate card for each of the letters in the mnemonic "N WLLA OMNI".

Q: In the BGP bestpath decision process, what does the first N in the N WLLA OMNI mnemonic mean?
A: Is the NEXT_HOP PA reachable? If not, reject the route from the decision process.

Q: In the BGP bestpath decision process, what does the W in the N WLLA OMNI mnemonic mean?
A: Weight: Cisco-proprietary, higher is better. The administrative weight can be assigned to each NLRI locally on the router, and is not passed on in Update messages.

Etc...
Sometimes I had trouble remembering or applying some of these, so I would make additional cards that "quizzed" me on those.  Here is an example on BGP path selection:


I have four of these, one for each combination of "bgp deterministic-med on/off" and "bgp always-compare-med on/off".  Note that I put a "More info" link at the bottom.  If I get the flash card wrong, then I can go to the source of that information to brush up on it.  Most of the cards that I added to the Neckercube deck are either like this (with actual device output) or with pictures.

I will just use an example, but you can apply this logic to any line on the blueprint.

Pick a topic in the INE CCIE RSv5 expanded blueprint in the area that you are currently studying.  For this example I will choose "3.6.6.2. Totally Stubby Areas".  Read about the topic and make sure that you understand what a stub area is, and what a "Totally" stub area is and how it is different.  I used a combination of INE Videos (both Written and ATC), Networklessons.com, Routing TCP/IP Volume I, CiscoDocs, and RFCs.  I may have picked up some other information with random Googling/Forums, but 95%+ came from those sources.  Make sure that you go over the concepts from at least two sources, because no source of information is perfect.  Also, if you are studying for the CCIE, then one of those sources should absolutely be the Cisco DocCD.  Since you will have access to that information during the lab, you want to be proficient at quickly locating the information on there without a search function (which is not always easy to do if you aren't very familiar with the documentation).

You can get the image from the material that you are using to prepare, including taking "snips" from videos.  I love the Snipping Tool - and more recently Snip & Sketch, which allows you to just use the hotkey "Windows + Shift + S").  However you do it, get an image that uses the concept.  I created one in Visio real quick, but there is plenty of software out there for this.  Have the picture on the front of the flash card, maybe with some basic relevant config information, and ask yourself a question that will force you to properly recall the concept.  Here are some examples for the chosen topic "3.6.6.2. Totally Stubby Areas":

First, if you used the "Active Reading" approach in Petr's Post, you should have a list of things that you need to remember. For example:

  1. What LSAs do Totally Stub Routers filter?
  2. How do I configure an area to be Totally Stub
  3. If RouterA is filtering LSAs, how do Area 1 routers know how to get out?
  4. Etc..
Now that you have a list of concepts that you want to make sure that you remember, you can make cards for them.


<card1>
Front:
In this network, which LSA's will Router A allow from the backbone into Area 1?

Back:
None, it will block all LSAs coming from Area 0 and replace them with a Type3 LSA containing a default.

</card1>

If you run into a problem later on in your studies that show that this card was not enough to fully understand, then you can create another one using a slightly different situation.  There are some concepts that I have several different cards for, to make sure that I am fully understanding (and remembering) what the technology is doing.  You can even make multiple cards using that same image (I do this a lot).

<card2>

Front:
Describe what happens to the Type2 LSA for the network between RouterB and RouterD as it is advertised through the OSPF network.
Back:
RouterB translates the Type2 LSA into a Type3 and originates/floods it into Area 0.
RouterA does not re-originate the Type3 from Area 0 into Area 1 because it is the ABR for a Totally Stub area

</card2>

<card3>

Front:
Describe what happens to the Type5 LSA originated by RouterD as it passes through the OSPF network:
Back:
RouterB floods the Type5 LSA into Area 0
RouterA does not flood the Type5 from Area 0 because it is the ABR for a Totally Stub area

</card3>

<card4>

Front:
Describe what happens to the Type4 LSA originated by RouterB as it passes through the OSPF network:
Back:
RouterB is the originator of the Type4 LSA, because it is an ABR in the area containing an ASBR.
RouterA does not re-originate the Type4 from Area 0 because it is the ABR for a Totally Stub area

</card4>


<card5>

Front:
What type of LSAs does RouterA automatically originate into Area 1?
Back:
RouterA will automatically originate a default summary Type3 LSA into Area 1.

</card5>


Continue to make cards until you feel that you have all of the concepts covered.  You may use different scenarios, but I recommend using pictures often because they really help information "stick".  At least for me, anyway...

As you may notice, many of these cards also tie in other concepts which you may need to make additional cards for, depending on how much review you need.  For example, they also contain information about the origination and re-origination of multiple LSA types.

Questions about piece of configurations?

You can use the same images to quiz yourself on configuration:

<card6>

Front:
What are the configuration statements required to configure Area1 as a Totally Stubby Area?
Back:
# RouterA
router ospf 1
 area 1 stub no-summary

# RouterC
router ospf 1
 area 1 stub

</card6>

You can also ask questions in the reverse (maybe remove the clue in the picture, in this case the label of Area 1):

<card7>

Front:
RouterA and RouterC are in Area 1, with RouterA having a connection to the backbone.  What does the following configuration do:

# RouterA
router ospf 1
 area 1 stub no-summary

# RouterC
router ospf 1
 area 1 stub

Back:
It configures Area 1 as a Totally Stubby area.

</card7>

How many chunks do i have to make?

As many as it takes for you to remember the concept completely.  You may not have it 100% after your first pass.  As you go back and do your knowledge reviews, you will easily spot information that you either didn't have quite right, or are missing in your flash cards.  Modify/create flash cards as necessary.  This is part of the learning process.

As you go through the labs (I am using INE, but from what I hear the other vendors are good as well), if you run into things that give you trouble then make additional flashcards about those concepts.  You can directly pull from the Lab diagram/scenario and make a flash card forcing you to recognize the particular topic that was giving you trouble.  Pretty much every time I run into something new, or that I didn't understand properly, I try to make a card to help me remember that piece of information.

How many splits?

I'm not sure exactly what you are asking here, but the answer is probably the same as above.  Once you start using your flash cards regularly, you will easily notice the things that you don't already have a flash card for, or that you weren't quite understanding properly.  Make new cards and modify existing ones as necessary when this happens.

Friday, 25 January 2019

Method Post - Using Anki For CCIE Preparation


Here I will cover the basics of how to use Anki for CCIE preparation, and include links to Anki decks to help get you started.

Monday, 21 January 2019

Method Post - Using EVE-NG for INE ATC Labs

** Update April 25, 2019**
As I have been going through these myself, I have found that a bunch of these configs were not working properly (pretty much all the IPv6 labs + switch labs + some misc labs).  I have updated the config file link accordingly.  If you downloaded it before and some of the labs are "invalid" when you try to load them, please try downloading the newest version.  Please let me know if you have any troubles.  I will include a link in the file section to a package of PowerShell scripts that I ended up making while working with all these (2,000+) config files.
*** End Update ***

OK, so this is probably going to be a pretty long post.  After messing around with a bunch of different options, I have found this to be the best setup for using the INE ATC topology for studying for my CCIE.  I used VIRL for the first few months, but it was annoying to have to load the configurations for each of the labs into the routers each time I loaded the topology.  I started out with some SuperPuttY scripts that automatically did it each time, but it was a less-than-perfect solution.

Bottom line:  Properly followed, this guide will allow you to send "config replace flash:config/atc.lab.name.here.cfg force" to all devices, and immediately configure all devices for the appropriate lab.  It should continue to work if you shut the topology down/restart your computer, and then reboot the topology.

NOTE: Feel free to use these configs with your own topology.  This post shows how to build one with EVE-NG but the configs will work with pretty much any setup of the INE topology.  The same can be said about the Secure_CRT-AutoConfig python script - it should work to more easily set up the configurations with pretty much any setup of the INE topology with little or no modification.

On my computer with CSR1000v routers, it takes only a few seconds to switch between initial configurations of any of the ATC labs.  This is extremely useful for using the "lab card" strategy that I will be putting forth in a future post.

If something in this guide is wrong, please let me know in the comments so I can correct it.

Credits

Credit to Calin Chiorean for making the EVE-NG topology that mine is based off of.
Credit to 

Credit to everyone else that I missed - as I have tons of links in here :)


Link: INE-CCIE-RSv5-Topologies.zip
Description: Contains 10-Router + 4-Switch INE ATC topology for IOL, IOSv, and CSR1000v
Update: Also contains 20-Router + 4 Switch INE topology for IOL, IOSv, and CSR1000v

Link: CCIE_RSv5_INE_ATC_CFG.zip
Description: (Updated April 2019Contains INE ATC configs for all three (IOL/IOSv/CSR1000v) image types to go with the above topologies
Note: Only contains configs for ATC labs at the moment - I will update with foundations/mock labs once the time comes for me to do those

Link: eveNG-SecureCRT-AutoConfig.zip
Description: If using SecureCRT, this python script will save you some time

Link: ConfigManipulationScripts.zip
Description: A collection of PowerShell scripts that I ended up making while working with all these (2,000+) config files.  I figured some may find them useful.
prepend_lines_to_targets.ps1 - (add some lines to the front of a list of files)
print_first_lines_of_targets.ps1 - (print the first x lines of a list of files)
recursive_find_replace.ps1 - (very useful bulk/recursive "find and replace")
remove_blank_lines.ps1 - (remove all blank lines from a bunch of files)
targetfiles.txt - (used by some of the above to narrow down actions/results)
tar_subfolders.ps1 - (use to tar everything back up)



Quick note: UKSM (Ultra Kernel Samepage Merging) allows EVE-NG to use the CPU to reduce memory (Google if you want more info).

I have built topologies for three different IOS images:


## IOL (IOS on Linux)
After messing around with these, I can recommend this option as long as you keep in mind that some things aren't going to work properly, or aren't supported at all.  It is very fast, and doesn't require much in the way of resources.  I haven't been using it that long, but I have had a few problems with some of the features working properly, and there are tons of BGP features missing.

How it runs on my system: Hardly anything + fast boot

Recommended System: as long as your computer isn't super-old, most systems should run this


## IOSv
Slower and more resource-hungry than IOL.  This is what I recommend using unless you have a bunch of RAM like I do (in which case, I recommend the CSR1000V).

How it runs on my system (10 IOSv Routers + 4 IOSv switches):
 UKSM Off: 6GB RAM used, All 8 logical processors running about 50%
 UKSM On: 2.5GB RAM used, All 8 logical processors running about 55%

How it runs on my system (20 IOSv Routers + 4 IOSv switches):
 UKSM Off: 9GB RAM used, All 8 logical processors running about 75%

Recommended System: 8GB RAM minimum + processor with 8 logical cores


## CSR1000v (This is what I have been using these days - I like it best)
This is fast (after it finishes booting - it boots slowest of all for me) but requires tons of RAM and slightly more CPU than IOSv.  Supposedly supports more features than any other virtual option, but I haven't had problems with IOSv in the context of my CCIE studies yet.  Each CSR1000v instance uses 3GB of RAM.  With UKSM turned on, you may be able to get along with just 16 GB of RAM, but you better have a decent processor.

How it runs on my system (10 CSR1000v Routers + 4 IOSv switches):
 UKSM Off: 33.5GB RAM used, All 8 logical processors running about 60%
 UKSM On: 10.5GB RAM used, All 8 logical processors running about 75-80%%

How it runs on my system (20 CSR1000v Routers + 4 IOSv switches):
 UKSM Off: Does not run - CPU could not handle it - couldn't tell if RAM would have been enough.  CPU-wise I was close (booted up 15 CSR1000v OK).  I imagine a 6-core equivalent like the i7-8086k (almost same proc as mine, but 6-core) could do the trick, but still unsure about RAM (it will be close and some paging/swapping will probably have to happen if it works).
 UKSM On: Eve-NG's website specifically states not to use this with more than 10 CSR1000vs

Recommended System: 32GB RAM + decently quick processor with 8 logical cores


Obtaining Images
I was able to download the IOSv/CSR1000v image from the Cisco VIRL portal, because I also purchased a VIRL licence ($200).  If you have a VIRL license, go to the download section in the portal and download "vios-adventerprisek9-m.vmdk.SPA.156-1.T" and/or "csr1000v-universalk9.16.6.1.qcow2" and "vios_l2-adventerprisek9-m.03.2017.qcow2".  IOL images are available around the internet.  Bottom line: you have to figure out how to get your own CSR1000v/IOSv/IOL images.
Google Compute

I tested out the IOSv topology with the "n1-highcpu-8" instance type, and it ran OK but changing configs took over 1 minute so  Still, that is your best bet if you want to make the most of your $300 free credits.  If you use more than 8 vCPUs, performance is much better, but I don't think you can use your $300 free credits when using more than 8 vCPUs :/  I tested out the CSR-1000v topology on there with 10 vCPUs and 40GB of RAM (costs about 36 cents/hour) and the performance was pretty good, even though the CPU stayed pegged out at 100%.  I didn't try with only 8 vCPUs...

This guide is mostly focused on doing things with VMWare, so if you are using Google Compute, then read a whole section before taking action because you may have special instructions.  One note that I have about using Google compute is that you want to select a 40GB hard drive or so (more like 400GB if you are using CSR images!).  Even though you don't need this much space, your hard drive throughput is tied to your hard drive size, so the topologies will take a long time to boot up if you only give it 10GB :)

Install VMWare Workstation (I am using VMWare Workstation 12 Pro, but I am pretty sure VMWare Workstation Player will work just fine).  AFAIK, VirtualBox will not work.

Install EVE-NG (free - and amazing!). 

If choosing Google Compute:
This will take a little more tinkering (it did for me anyway), but if I was able to get it to work then you probably can too.

I recommend starting with the video but checking out the blog post at the same time.

Once you have EVE-NG installed:
The following blog shows how to add your VMNet connection into EVE-NG: https://www.petenetlive.com/KB/Article/0001432

Here is what my "/etc/network/interfaces" looks like for eth1:
# Cloud devices
iface eth1 inet manual
auto pnet1
iface pnet1 inet static
    address 172.16.1.132/24
    bridge_ports eth1
    bridge_stp off

Note that I used "172.16.1.132" as my IP.  You may use something different for your VMNet1 address space...  You can check what your VMNet1 IP space is by issuing "ipconfig" at the command prompt, and looking for "Ethernet adapter VMware Network Adapter VMnet1", or by going to Edit -> Virtual Network Editor in the VMWare Workstation main window.

Here is what mine looks like:


And the interface that I added in the VM:

Note: You should be able to "ping 172.16.1.132" (or whatever IP you use) if this step was successful.

If you are using Google Compute, then you can set your EVE instance to the IP that your workstation would be in the VMWare setup.  That way my scripts will work for you as well during step 5.  Here is what my Google Compute instance "/etc/network/interfaces" looks like for eth1/pnet1:
# Cloud devices
iface eth1 inet manual
auto pnet1
iface pnet1 inet static
   address 172.16.1.1/24
   bridge-ports eth1
   bridge-stp off


EVE-NG HowTo Add IOL Images

I used WinSCP to transfer the files (SecureFX/FileZilla/Others are fine..)
I use SecureCRT to SSH, but there are many other clients out there

In the upper left, there is a button to "import" - click it and select the "IINE-CCIE-RSv5-Topologies.zip" file (no need to unzip). 

Click "Upload" in the upper right

It should import the .unl topologies and make them available on the left pane.  You can click on the topology for the images that you uploaded and click "Open" to bring up the lab.  You should now be able to boot up the devices.  Depending on your computer, booting them all at once might take much longer than booting them up in a staggered order.

Staggering Boot-Up
I boot up the devices in three "groups".  For example, I select R1-R5 and start them up.  My CPU will spike for a few minutes and then settle down.  Once it does, I select R6-R10 and start those up.  Once those are done, I boot up the switches.  Depending on your config/system, it will take different amounts of time.  Once you figure out how long it takes, you can right click a node and click Edit, and then set a startup delay on that node.  For my CSR1000v lab, I have routers 6-10 with a 160 second delay, and the switches with a 400 second delay.  The whole thing takes around 8-9 minutes to be ready from when I hit "start all nodes".

If your routers don't boot up, right click one of them and click "Edit".  There should be an image listed (mine is "vios-adventerprisek9-m.SPA.156-2.T").  You may have to select the image from the drop-down if it is there.  If it is not, then something went wrong during Step 3.

Note for Google Compute: Sometimes (often) I have to try to start the nodes several times, but they eventually go if I keep trying


As you can see, each of the routers are connected to "VmnetNet1", which should be able to talk to your local VMNet interface.  Mine has an IP of "172.16.1.1" - you can check what yours is by issuing "ipconfig" at the command prompt, and looking for "Ethernet adapter VMware Network Adapter VMnet1"

If you don't have one, download a TFTP server.  I used Tftpd32 but there are many out there.

Unzip the "CCIE_RSv5_INE_ATC_CFG.zip" somewhere.  For this example, I chose "C:\TFTP_Server\CCIE_RSv5_INE_ATC_CFG: - where xxx = the image you are using.

Open up your TFTP server, and make sure that it is using that exact folder (with the .tar files in it).  Also, I had to make sure my "Server Interface" was set to VMnet1 (172.16.1.1 in my case):




If you are using SecureCRT: Here is python script to do the steps that follow automatically:
eveNG-SecureCRT-AutoConfig.zip (download/extract - you'll need to browse to the ".py" file with SecureCRT)

You will need to edit the Python script to select the image that you are using, and set up IP information if it is different.  If you right click the .py file and click edit, it should be self-explanatory.

To run them from SecureCRT:
Make sure you have the tab active for the device open and connected.  You can connect to the routers by making SecureCRT your default telnet application, or you can manually create sessions.  To see the IP/port, hover over the router in the EVE-NG Topology Window and look in the lower left.

Once you are connected and the tab is active, make sure you get the device to the user mode "Router>", not the autoconfig dialog.  In SecureCRT go to Script -> Run from the file menu, and then select the script.  Give it a little bit, and it should automatically do the below steps for you.


If not using SecureCRT: Then perform the following steps manually (at least it is only once!)

Notes for anything other than IOSv
If you are using something other than IOSv, replace the interface name with the interface that is connected to "Net1" in the EVE topology, and change IOSv in the archive command to CSRv or IOL as appropriate.

Also, for IOL, use "unix:/config" instead of "flash:config/"

Note: I tried to remember to export the configs for all of the topologies so that the IP addresses were included.  If the router already has a name on initial bootup then it probably already has a "172.16.1.x" ip address

Log into R1 and do this:
Router>enable
Router#delete /f /r flash:config
Router#
Router#conf t
Router(config)#int g0/0
Router(config-if)#ip add 172.16.1.201 255.255.255.0
Router(config-if)#no shut
Router(config-if)#end
Router#archive tar /xtract tftp://172.16.1.1/IOSv/R1.tar flash:config/

You should see the router copy all 65 configurations to the flash.

Note1: "delete /f /r flash:config" is necessary on IOSv (not for CSR1000v or IOL) - I don't know the reason, but if you don't do it then it will not take all of the configs, even though there is plenty of free space in the flash.  This caused me some heartache lol.

Note2: If your VMNet interface had a different IP address, then you need to choose another IP address in the same subnet.  Since this is a CCIE blog I am going to assume you know what I mean.  After you change the IP on the router and "no shut" the interface, you should be able to ping it from your local machine; Ex: "ping 172.16.1.201".  If you can't, then double-check the actions that you took in "Step 2".  The Eve-NG website has some great resources if you get stuck here.

Note3: This should be obvious, but do not continue on to R2 if this does not work, because something is wrong.  It is time to troubleshoot.  Check back through the steps and use Google.

Log into R2 and do this (note the last octet, and R2.tar):
Router>enable
Router#delete /f /r flash:config
Router#
Router#conf t
Router(config)#int g0/0
Router(config-if)#ip add 172.16.1.202 255.255.255.0
Router(config-if)#no shut
Router(config-if)#end
Router#archive tar /xtract tftp://172.16.1.1/IOSv/R2.tar flash:config/

Log into R3 - R10 following the same pattern, making sure you change the last octet for the IP, and the name of the file to "RX.tar", where X = the router number

Log into SW1 and do this:
Switch>enable
Switch#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Switch(config)#int g0/1
Switch(config-if)#no switchport
Switch(config-if)#ip add 172.16.1.111 255.255.255.0
Switch(config-if)#no shut

Switch(config-if)#end
Switch#archive tar /xtract tftp://172.16.1.1/IOSv/SW1.tar flash:config/

Log into SW2 - SW4 following the same pattern, making sure you change the last octet for the IP, and the name of the file to "SWX.tar", where X = the switch number

I also recommend setting the hostnames and saving the configs (copy run start) at this point.  That way when the routers boot up, they will boot directly into IOS instead of the auto-configuration dialog.  They will also be ready for you to TFTP more configs if that is what you want to do.

Step 5 - With Google Compute Instance

To do this, I had to make my Ubuntu instance server the TFTP server.

root@instance-1:/# apt-get install -y tftpd-hpa

After tftpd-hpa has been installed, you need to configure tftpd-hpa (I can't remember if I had to change anything, so here is my config):

root@instance-1:~# more /etc/default/tftpd-hpa
# /etc/default/tftpd-hpa

TFTP_USERNAME="tftp"
TFTP_DIRECTORY="/var/lib/tftpboot"
TFTP_ADDRESS=":69"
TFTP_OPTIONS="--secure"
root@instance-1:~# 

If you had to change something, then you need to restart the tftpd-hpa service for it to take effect:

service tftpd-hpa restart

Now you just have to use SCP (or whatever you want) to move all three folders (IOSv, CSRv, IOL) to "/var/lib/tftpboot". This should allow you to continue as above, except you are using your EVE-NG server itself as the TFTP server.  Follow the rest of the steps above to move/extract the configurations to each of the devices.

Step 6 - Get to Labbing!

Now, when I want to switch initial configurations on all of the devices, I simply use config replace and send it to all of the devices in the topology.  For IOL, you would use "config replace unix:config/authenticating.bgp.peerings.cfg force" instead





Note: If you are using this for INE ATC preparation, I highly recommend you check out this post: Using Anki For CCIE Preparation
It includes a link to an Anki deck that can be used to schedule the INE ATC labs, which works perfectly with the above solution.

Saturday, 19 January 2019

Method Post - Progress Tracking


I don't know about you, but tracking my progress gives me a more concrete sense of progression.  It also gives me a good idea of how far along in my studies that I am, which is useful when studying something as vast as the CCIE.  I have created a Monthly Knowledge Assessment based on INE's CCIE RSv5 Expanded Blueprint.  I encourage you to use my spreadsheet, or to make something similar-but-better yourself.  Updating this spreadsheet each month should only take 5 or so minutes.  Some people may not find it particularly useful, but it is the best way that I have found so far to track my progress.


Directions for using the spreadsheet

  1. Save a copy of my spreadsheet
  2. Create a new column each month
  3. Update all fields
    1. Fields with black text/borders = DO NOT UPDATE (auto formula updated)
    2. Fields with blue text/no borders = update
    3. I have found that the easiest way to update after first month is to copy the whole column from last month by highlighting it, and then using the little "copy cells" drag marker in the lower right


As you can see if you look at  my example, I rate myself from 1-5 on each of the items in the expanded blueprint.  Here is a general guideline for how to use the numbers:

1 = weak on this topic, don't know it well or at all
2 = familiar with this topic, but not enough
3 = capable with this topic, but may need to use DocCD to perform all tasks
4 = pretty good with the topic, unlikely to need DocCD reference to perform all tasks
5 = I can do this in my sleep

Final Note

There is an obvious flaw in the way that my spreadsheet calculates the "Total Readiness" score.  That is, that it does not take the weighting of the topics into consideration.  I am sure that I could try to remedy this with a better formula using the weightings from the official Cisco blueprint, but I'm not going to bother.  The most important thing (to me) is that it is tracking progress, and lets me easily see what I still need to cover or cover more thoroughly.

Popular Posts