IEOC CCIE Forums

IEOC - INE's Online Community

Welcome to INE's Online Community - IEOC - a place for CCIE and CCENT candidates to connect, share, and learn. Our Online Community features CCIE forums and discussions for all tracks including Routing & Switching, Voice, Security, Service Provider, Wireless,, and Storage. Through these online communities you can discuss your questions with thousands of your peers, hundreds of CCIE's and INE's own team of world renowned CCIE instructors and authors, Brian Dennis - Quintuple CCIE #2210, Brian McGahan – Triple CCIE #8593, Petr Lapukhov - Quad CCIE #16379, and Mark Snow - Dual CCIE #14073.

Search

Page 1 of 35 (341 items) 1 2 3 4 5 Next > ... Last »
  • Re: a Q regarding guest users and ISE

    due to the lack of the response here, I'm going to post my own answer here that I found by myself. hope this help someone else who needs this. I was using a very comprehensive rule that matched most of the conditions. So I added a static EndPoint Group and placed my manually created known MAC addresses inside that group and edited the condition
    Posted to CCIE Security Technical (Forum) by timaz on 01-09-2017
  • Re: a Q regarding guest users and ISE

    Hi guys; the new year holidays are over. isn't there anybody here to take a look at my problem? I appreciate any reply.
    Posted to CCIE Security Technical (Forum) by timaz on 01-04-2017
  • a Q regarding guest users and ISE

    Hi; I configure ISE to redirect the guest users toward the Guest portal and everything works fine. but at the end, ISE adds the guest's MAC address to the local DB and the second time the same person wants to access the network, its MAC address matches an authorization rule that I had created for known clients. how can prevent ISE from adding MAC
    Posted to CCIE Security Technical (Forum) by timaz on 12-29-2016
  • Re: a question regarding helper-address

    [quote user="cristian.matei"] As said, IP Phone will start sending untagged traffic initially, after it learns via CDP about the voice VLAN it will start sending tagged traffic so the switch will put the Phone in the proper VLAN in the end. You have a chicken-egg-issue: to apply the dACL on the port the switch needs to learn the IP address
    Posted to CCIE Security Technical (Forum) by timaz on 11-29-2016
  • Re: Qs about Anyconnect

    isn't there anybody who has seen this error? I wonder why I cannot save any new profile with NAM Profile Editor!
    Posted to CCIE Security Technical (Forum) by timaz on 11-21-2016
  • Re: applying NAT (port-map) on VPN clients

    Hi; I tested the config and it worked fine in this case, becasue I chosed "any" as output interface in NAT configuration. But if we need to point to the vpn traffic in nat, which interface do we need to write in NAT configuration?
    Posted to CCIE Security Technical (Forum) by timaz on 11-16-2016
  • applying NAT (port-map) on VPN clients

    Hi. I have ASA 9.x with 2 IKEv1 site-to-site VPNs to 2 branches. I have also a web server inside the main office that services the web requests sent to TCP 8080. clients which access this web server are inside the main office as well as the branches. the IP addresses of the branch clients has been assigned to them bu their local DHCP server. I want
    Posted to CCIE Security Technical (Forum) by timaz on 11-15-2016
  • Re: a question regarding helper-address

    hi guys; hope u are doing well. would u mind, please taking a look at this simple topology of mine. I've missed a thing but i don't know what. sw is default gateway for both of vlan 500 and vlan 1. the IP on switch are shown above. the switch is configured as dhcp server to assign IPs to phones in vlan 500. ip phone 2 is connected to g0/7 and
    Posted to CCIE Security Technical (Forum) by timaz on 11-10-2016
  • Qs about Anyconnect

    Hi; first of all, I want to creat a new profile on Anyconnect NAM Profile editor and while saving the following error appears and doesn't let me to save the profile: I searched the Internet and found some same issues with recommendations to recreate the pre-shared keys. but I didn't create any pre-shared keys or even didn't write any credentials
    Posted to CCIE Security Technical (Forum) by timaz on 11-08-2016
  • Re: ISE certificates

    I didn't find the doc you had said, but read some docs from the Cisco.com and managed to solve the issue. I checked the Allow Vildcard Certificate checkbox in the CSR page on ISE, typed anyname for CN and put the actual ISE hostname in the SAN DNS field. then imported the root CA from the win cert server onto my PC and everything went OK this time
    Posted to CCIE Security Technical (Forum) by timaz on 10-31-2016
Page 1 of 35 (341 items) 1 2 3 4 5 Next > ... Last »
IEOC CCIE Forums Internetwork Expert CCIE Training
About IEOC | Terms of Use | RSS | Privacy Policy
© 2010 Internetwork Expert, Inc. All Rights Reserved