CCIE Security Multiprotocol Mock (4.0) Lab Preparation Workbook (Volume 2) with Detailed Solution Guide

 
 

About Our Volume 2 Workbook

IPexpert's industry-recognized CCIE Security Multi-protocol Lab Preparation Workbook (Volume 2) and Detailed Solution Guide workbook combination is the second workbook used in most candidate's preparation routine. After completing our Technology-Focused CCIE Security Lab Preparation Workbook (Volume 1) our candidates move on to this challenging phase of scenarios which consists of 5 8-hour mock lab exercises designed to walk you through each of the elements covered in the CCIE Security 4.0 Lab blueprint, ensuring that you have a complete understanding of structure of the lab (Troubleshooting and Lab), the fundamentals and also the complex implementations of each protocol that you may encounter in the real lab.  

Note: Our complete Structured Learning Approach should be referenced at any time if you're unsure where a particular product fits into your preparation cycle.

Each multi-protocol lab, in Volume 2, contains networking challenges designed to teach you integrated protocol inter-operation amongst complex variants of topics including configuration and troubleshooting of ASA 8.2/8.6 firewalls, IOS firewalls, VPN solutions, IPS 4200 sensors, ACS server 5.3, ISE, IronPort, wireless security, control plane security, management plane security, advanced security, network attack mitigation amongst others with the course being frequently reviewed to ensure that it is up to date and meets the latest topics tested on the CCIE Security 4.0 Lab exam. In addition, our Instructor will give you invaluable tips on lab strategy and test preparation techniques to ensure you will maximize your opportunity to pass your real CCIE Lab.  

IPexpert's CCIE Security Multi-protocol Lab Preparation Workbook (Volume 2) contains 5 mock lab scenarios scenarios, each designed to help you master the technologies you will be exposed to as you prepare to take on the CCIE Security lab exam.  These challenging lab scenarios, apart from Configuration sections also include Troubleshootingquestions - essentially, they're EXACTLY the same format as the current lab (Blueprint 4.0) and just as challenging!  Each lab delivers a complex, integrated scenario with multiple interdependencies that will take 8 hours or more to complete, once you have mastered it.  

All the solutions to the labs are provided in the accompanying Detailed Solution Guide, along with methods of verification and common mistakes to ensure that you have sound configuration, verification and troubleshooting skills that will allow you to demonstrate mastery as you become ready to take on the real CCIE Security Lab exam.

Table of Contents

Below, you will see that this workbook consists of 5 challenging CCIE Security mock lab scenarios all including Configuration sections and Troubleshooting parts of the lab.  Each lab scenario takes approximately 8 hours to complete and covers all or a large majority of the topics seen on the current CCIE Security lab blueprint.  

  • Lab 1: 8-hour One Day Lab Experience
  • Lab 2: 8-hour One Day Lab Experience
  • Lab 3: 8-hour One Day Lab Experience
  • Lab 4: 8-hour One Day Lab Experience
  • Lab 5: 8-hour One Day Lab Experience

Hardware / Topology

About Our Online Hardware / vRacks

Proctor Labs provides 24 CCIE Security vRacks that are second-to-none. Our Cisco equipment is the latest and greatest available and we provide an online experience like no other provider can. All Proctor Labs Security racks are structured around the IPexpert CCIE Security product topology consisting of 13 routers (including Frame Relay switch, Terminal Server and three Backbone routers) and four Catalyst switches. 

Maximize your study time by renting Proctor Labs' online hardware. You will be impressed by the customized graphical user interface that allows you full access and control of the devices in your rack!  

Remote Control Tools in the User Interface

  • All routers can be controlled via the web with our GUI remote control system.
  • You will not waste time on our racks... when you begin your session, your routers WILL BE set to the default (blank) setting.
  • Each device can be power cycled by our RPC (Remote Power Control) system with a click of a button.
  • Single Page Login (no need to telnet to rack's terminal server). Login and begin using our online hardware instantly.
  • Session Management (view scheduled time and reschedule without human intervention).
  • All routers can be controlled via the web with our GUI remote control system.
  • RDP access to PC Workstations & AD Server with SSL/IPSec clients.
  • Web GUI access to VMWare virtual servers (ACS, ISE) to Start / Stop / and Revert to clean configuration.

Hardware Details

  • Routers are 2800, 3800 ISR and 2900 series ISR G2 IOS 15.x routers (VERY fast!)
  • Four ASA's (including 5500-X series) running 8.2/8.4/8.6
  • IPS 4240
  • IronPort Web appliance (WSA)
  • ACS 5.3
  • ISE 1.1.x
  • Wireless devices (WLC 7.2 + AP)
  • RDP access to Win 2008 Active Directory Server
  • RDP access to Windows 7 Workstation with AnyConnect and IPSec client, NAC Agent and other applications to test all scenarios
  • Each rack is equipped with a single IP Phone (with another Windows 7 PC connected to it)
  • Racks are equipped with Catalysts 3560 running 12.2(46)SE and Catalysts 3750 switches running 15.0SE software
  • Each rack has Frame Relay, Fast Ethernet, Serial, and Gig Ethernet technologies
  • Each rack has three Backbone routers used to inject routes or other technologies; these are reachable and can be accessed by our clients

Standard CCIE Security Topology

Standard CCIE Security Connections Table

 

 
Piotr Kaluzny
Sr. Technical Instructor
Cisco CCIE Security
CCIE #25665 (Sec)

Piotr has been in the networking industry for over six years, working in several different capacities within enterprise-sized Cisco environments. His responsibilities include, but have not been limited to, implementation, design and high-end, level three technical support. Piotr holds a masters degree in computer science majoring in networking and network security


Samarth Chidanand
Sr. Technical Instructor / Developer
Cisco CCIE Routing & SwitchingCisco CCIE Security
CCIE #18535 (R&S Sec)

Samarth Chidanand is a dual CCIE who has passed the CCIE R&S and Security certifications during his university studies, making him one of the youngest double CCIE's. He is currently scheduled to take his CCIE SP lab, and should be a triple CCIE in the near future. He also holds a Bachelors Degree in Computer Networking from the University Of Greenwich, London, UK.

Samarth had previously worked for Cisco Systems as Network Consulting Engineer for Borderless Networks and Service Provider team. He has designed, implemented, migrated and supported several large scale networks for Cisco Enterprise, GET Accounts and Telco/Service Provider customers like British Petroleum, United Nations, Telstra, Safaricom, Barclays Bank, Deutsche Telecom Global, PCCW Global,T-Systems, Aircel, General Motors, Walt Disney, INSA-Govt Of Ethiopia and Oracle.

He has delivered several projects in many countries for technologies related Security, R&S, Service Provider and DCN.

Apart from project delivery he was actively involved in training CCIE bootcamps, Knowledge Transfer sessions and training materials preparations for Cisco employees and Cisco customers. He has won several awards for training, project delivery and job performance. He is an award winning master CCIE Security instructor.


IPexpert's Client Support Techniques

Although this product is specifically designed to be utilized as a self-study learning tool, IPexpert clients are never left on their own. In fact, IPexpert's commitment to top-notch customer support is a cornerstone of our mission statement

Many CCIE training entities promise support on their forums or within their communities. IPexpert is different.  We go above and beyond our competition by being available to serve you in many different ways.

  • 24x7 peer group and Instructor support through our active email list community (www.OnlineStudyList.com)
  • Tech support available directly through support@ipexpert.com
  • Friendly and knowledgeable support via phone, live chat or email by CCIE-focused Training Advisors, Support Engineers or Instructors, available Monday through Friday from 8am to 6pm Eastern.
  • Hardware and delivery issues addressed by Support Engineers 24x7 via telephone, live chat or email.
  • Our active blog provides insight, guidance and announcements pertaining to CCIE news, product updates or lab changes.
  • Dedicated Fulfillment Coordinators ensure that your order (whether hard copy or digital) is processed and delivered in a timely and accurate manner.
  • IPexpert also releases news and information to clients through its Facebook group and Twitter accounts, which can be subscribed to by clicking on those appropriate links.

In summary, you can be confident that IPexpert will stand by your side from the beginning of your CCIE preparation until you earn your numbers! The CCIE certification is a long journey. Having helped over a thousand CCIE hopefuls actually pass the real CCIE Lab exam, IPexpert knows what it takes to get you there and we are DEDICATED to your success!

Investment Assurance Program    

At IPexpert, we understand the importance of ensuring the value of your investment. When you embark on your certification path, you can rest assured that IPexpert will be your advocate along the way!  

As a valued IPexpert client, you are entitled to the following benefits related to this product:

As you begin working through your IPexpert materials, we are confident you will be extremely pleased with the content. Our renowned team of instructors developed a methodology for teaching engineers complex technologies in a structured manner that maximizes understanding during each study session.

From the accuracy and thoroughness of the material to the flow from topic to topic, our years of product refinement are evident throughout. That said, because we are constantly striving to improve, our Instructors may revise the materials you purchase. Whether the wording of single question is changed or an entire section is replaced, you will receive online access to the revised material at no charge.

NOTICE: The above-stated details are governed by the following program policies:

  • The lifetime of your Investment Assurance Program coverage correlates to the Cisco exam version in effect at the time of your purchase. When a new version of the certification exam you are pursuing becomes effective and enforced by Cisco, you will be offered a discounted upgrade path to purchase training solutions correlated to the new exam version.
  • Coverage is valid for products and courses directly purchased from and delivered by IPexpert. Training products and courses purchased through or delivered by third parties and partners of IPexpert may be governed by separate policies set forth by the third party vendor.
  • Coverage is valid for training purchased at full retail pricing. Coverage may not be applicable with sale prices, negotiated volume discounts, promotional giveaways, free samples or other non-standard pricing scenarios.
  • Regarding errata and revisions provided for self-study products, online access may not be applicable to all products. In that case, you will have the option to purchase new media for a nominal fee to cover production, shipping and handling.
  • If you purchase an IPexpert instructor-led course, but do not pass the exam afterwards, you are eligible to retake the class once again before your next lab exam attempt - at NO CHARGE. 

*If the original class was sold at a discount, the difference between the list price and the price paid will have to be paid in full prior to sitting the retake seat at the boot camp.

To Be Determined Policy    

  • To be determined (TBD) registrations are often requested when there is a promotion or special pricing available. These TBD registrations must be paid in full within 30 days of purchase. Payment plans are not accepted for TBD students. If purchase is initiated by purchase order, countdown begins at the date full payment is received.
  • Classes must be scheduled and taken within twelve (12) months from purchase date. If the class has not been scheduled or taken by the beginning of the thirteenth (13) month, the registration will be forfeit.
  • Rescheduling will be limited to two (2) additional times during that twelve (12) month period with the class date no more than three (3) months from the current date.
  • TBD registrations are non-refundable. In-store credit for the course fee (the amount paid less full-retail Self-Study/vRack price) will be issued if the TBD course is cancelled within the 12 month window.
  • Students are subject to rescheduling fees and course policies as outlined on the Course Registration Form.
  • If student registers and confirms a class date, registration cannot be converted to a TBD registration again at any time, the rescheduling policy must be followed.


    Note:
     Students are required to complete the Cisco Course Evaluation for the first class to qualify for a retake. Our courses are consistently in high-demand and fill up fast. Retake seats are limited, of course, so email your request to sales@ipexpert.com as soon as possible to have a better selection of dates and locations.

  •