skip to main | skip to sidebar

Friday, December 27, 2013

BGP (Interview Questions)

0 comments
1. BGP is IGP or EGP?
2. BGP is link state or distance vector protocol?
3. BGP uses which port? 
4. When to use BGP?
5. Can I use BGP instead of any IGP?
6. Can I run two BGP process on single router?
7. What is Autonomous System?
8. Types of BGP routing table?
9. What is the BGP path selection criteria?
10. Define various BGP path attributes.
11. Why weight doesn’t fall under path attribute category?
12. What is confederation?
13. What is route reflector and why it is required?
14. What is no-synchronization rule?
15. Default BGP timers.
16. When does BGP use 0.0.0.0 router id?
17. Does route reflector come in actual path during traffic forwarding?
18. What is Site of origin aka SOO?
19. What is the cost of external and internal BGP routes?
20. Can we use local preference outside the autonomous system?
21. Does it require that BGP router-id should reachable in cloud?
22. What is recursive lookup in BGP and how it works?
23. What is the meaning of update source loopback?
24. If a static route is advertised in BGP without using update source what will be the next hop address in update?
25. Define various types of communities and why they are used?
26. If BGP neighbor state is showing idle what does it mean?
27. In Multihoming scenario if primary link gets fail, after how long traffic will be shifted to secondary link.
28. I am having two routes for remote destination but only single route is installing in routing table, what’s the reason for this?
29. How many links can be assigned for load balancing or sharing?
30. In eBGP I am establishing my neighbourship with loopback address but it’s not coming up. Please specify different reasons for not coming up.
31. Can we redistribute BGP in IGP? Please explain your answers.
32. What is cluster id?
33. I am receiving updates from eBGP peer, will the next hop change or not?
34. I am receiving updates from iBGP peer, will the next hop change or not?
35. A router is receiving same route from two different eBGP peers. The AS information contains in peer 1 is {65500, 65550, 65555} and in peer 2 is {65501, 65501}. But I want to make peer 1 preferred.
36. What is the difference between next-hop-self and update source loopback?
37. Define loop prevention mechanism in BGP.
38. What will happen if route reflector is not getting proper updates?
39. What will happen if route reflectors does not synchronize?
40. What is the advantage of using BGP AS Prepend?
41. Can we use BGP as backdoor link for customers instead of OSPF? If yes, please let us know what could the issues BGP create?
42. What is BGP PIC?
43. Use BGP as Link Protection in case of Dual PoP?
44. How to achieve Inter-AS Communication-MP-eBGP?
45. What can happen if Route Reflector(RR) is not getting proper route updates?
46. What is route reflector synchronization?
47. How to use BGP as PE-CE backdoor link?
48. What is Hierarchical FIB - BGP-PIC?
49. BGP Graceful Restart, NSR and NSF
50. BGP Redistribution Vs MPLS, which one you will select

Switching ( Interview Questions )

0 comments
1. Difference between hub, bridge and switch?
2. What is mac address and why it is required?
3. In layer 2 domain do we need ip address for communication?
4. What is arp and why it is required?
5. What is Spanning Tree Protocol aka STP?
6. What is the difference between STP, MSTP, PVST and RSTP?
7. Can we use the two same paths for same vlan?
8. What is the difference between broadcast and collision domain?
9. Define type of lan traffic.
10. What is destination address of broadcast frame?
11. Can we connect a switch to switch with straight cable?
12. Define functions of switch.
13. What is arp timeout?
14. What is aging process?
15. What is BPDU?
16. What is path cost?
17. Define selection criteria of STP root bridge.
18. How to non bridge decide which port will elect as root port?
19. If a nonroot bridge has two redundant ports with the same root path cost, how does the bridge choose which port will be the root port?
20. Port states of spanning tree protocol.
21. If the users face delay during initial login, what you will suggest to implement?
22. Why spanning tree BPDU filter is used?
23. Can I use BPDU filter on trunk ports?
24. What is port security?
25. I want to learn only a single mac from the port, what need to be configured?
26. Can we use spanning port-fast on trunk ports?
27. If management ip address is changed, will user’s traffic will be dropped?
28. Difference between trunk and access port?
29. What is UDLD and why it is required?
30. What is interface vlan on switch?
31. How to perform inter vlan routing without layer 3 device?
32. How to stop superior bpdu participating in switching domain?
33. How Vlan In Local Switching Domain is selected?
34. How to provide redundancy to MPLSVPN customer?

ROUTING ( Inetview Questions )

0 comments


1. Difference between RIPv1 and RIPv2?
2. How many number of routes carried by RIP packet?
3. Is OSPF link state or distance vector or path vector protocol?
4. What is the difference between OSPF and IS-IS and which one is preferred?
5. Can we use BGP instead of any IGP?
6. How many network types available in OSPF?
7. Different type of Link State Advertisements aka LSA?
8. LSA 3 and LSA 4 are generated by which router?
9. When to use Stub and Not So Stubby Area?
10. How to get the external routes without making area Not So Stubby?
11. What is the different type of route summarization available in OSPF?
12. What is the requirement of doing summarization?
13. A major network is advertised as summary in one area and few of the routes from that network is configured in another area. What will happen in that case?
14. If any of the OSPF area is not stabilized, does it impact another area? 
15. What is the use of forwarding address in LSA 5 and LSA 7?
16. External routes are available in OSPF database but not installing in routing table?
17. If loopback is not configured, what will be the router-id selected by OSPF process?
18. Can we run multiple OSPF process in single router and what is the advantage of using it?
19. What are timers of OSPF?
20. Multicast address of used by OSPF.
21. OSPF works on which layer?
22. What is backbone area in OSPF?
23. Can we use OSPF without backbone area?
24. Is it required that OSPF router-id must reachable in IGP cloud?
25. After configuring new router-id, automatically it will be used or do we need to use some type of command to get it operational.
26. Why the secondary ip address of interface is not advertising in IGP cloud?
27. OSPF neighbourship is not coming up. Please tell the various steps to troubleshoot it.
28. One side MTU is 1500 and another side MTU is 1600. Does it affect neighbourship?
29. Provide process of DR and BDR election.
30. If DR is down and no BDR is configured what will happen?
31. What is the difference between a neighbor and adjacent neighbor?
32. My OSPF neighbourship is showing 2-way, what does it mean?
33. Define different type of OSPF neighbor states?
34. OSPF external routes are not redistributing?
35. What is Layer 3 routing loop?
36. OSPF LSA and Packet Format
37. How does OSPF Sham Link in different area work?
38. What is Link State Advertisement (LSA) - 1?
39. What is Link State Advertisement (LSA) - 2?
40. What is Link State Advertisement (LSA) - 3?
41. What is Link State Advertisement (LSA) - 4?
42. How to design OSPF Network or OSPF Design Consideration?
43. What to ask from customer if he demands OSPF as PE - CE Routing Protocol?
44. What is C and R in OSPF debug?
45. How does CPE Area 0 & PE Super backbone Communicate?
46. Why OSPF VPNv4 Routes Look As External Routes Instead Of Inter Area Routes?
47. How does ISP hack by using OSPF as PE-CE routing protocol?
48. OSPF High Availability with SSO,NSF and NSR
49. How does OSPF behave with SSO,NSF and NSR? 
50. How does CISCO EIGRP DUAL Algorithm works for selecting successor?
51. Define various tools which participates in OSPF fast convergence
52. How does event propagation tool help OSPF to converge fast?
53. How does OSPF Fast Convergence Tools - Event Processing helps to reduce convergence time?
54. OSPF Fast Convergence Tools - Updating RIB
 55. What is Discard Route or Null0 Route?
56. How does static routing behaves?
57. What are the fundamentals of route redistribution?
58. Which routing protocol is best between OSPF and EIGRP?

Intrusion Detection Systems Interview Questions

0 comments

This section is also a very good resource for preparation of job interviews for IDS.

What is Intrusion Detection?
Intrusion Detection is the active process to document and catch attackers and malicious code on a network. It is described in two types of software: Host based software and Network based software.
Why is an Intrusion Detection System (IDS) important?
Computers connected directly to the Internet are subject to relentless probing and attack.While protective measures such as safe configuration, up-to-date patching, and firewalls are all prudent steps they are difficult to maintain and cannot guarantee that all vulnerabilities are shielded. An IDS provides defense in depth by detecting and logging hostile activities. An IDS system acts as "eyes" that watch for intrusions when other protective measures fail.

What is the difference between a Firewall and a Intrusion Detection System?
A firewall is a device installed normally at the perimeter of a network to define access rules for access to particular resources inside the network. On the firewall anything that is not explicitly allowed is denied. A firewall allows and denies access through the rule base.

An Intrusion Detection System is a software or hardware device installed on the network (NIDS) or host (HIDS) to detect and report suspicious activity.

In simple terms you can say that while a firewall is a gate or door in a superstore, a IDS device is a security camera. A firewall can block connection, while a IDS cannot block connection. An IDS device can however alert any suspicious activities.
An Intrusion Prevention System is a device that can start blocking connections proactively if it finds the connections to be of suspicious in nature.

If an IDS device cannot prevent a hack, then why have IDS devices?

Agreed that an IDS device cannot prevent a hack and can only alert any suspicious activities. However, if we are to go by past experiences, hacks and system compromises are not something that happens over night. Planned compromise attempts can take several days, weeks, months and in some cases even years. So a IDS device can alert you so that you can take the desired precaution in protecting the resources.
What is a network based IDS system?

An IDS is a system designed to detect and report unauthorized attempts to access or utilize computer and/or network resources. A network-based IDS collects, filters, and analyzes traffic that passes through a specific network location.
< Are there other types of IDS besides network based?

The other common type of IDS is host-based. In host-based IDS each computer (or host) has an IDS client installed that reports either locally or to a central monitoring station. The advantage of a host-based IDS is that the internal operation and configuration of the individual computers can be monitored.
What is the difference between Host based (HIDS) and Network based IDS (NIDS)?

HIDS is software which reveals if a machine is being or has been compromised. It does this by checking the files on the machine for possible problems. Software described as host based IDS could include File Integrity checkers (TripWire), Anti-virus software (Norton AV, MacAfee), Server Logs (Event viewer or syslog), and in some ways even backup software can be a HIDS. ISS Realsecure has many HIDS products.
NIDS is software which monitors network packets and examines them against a set of signatures and rules. When the rules are violated the action is logged and the Admin could be alerted. Examples of NIDS software are SNORT, ISS Real Secure, Enterasys Dragon and Intrusion.
Are there are any draw backs of host based IDS systems?

There are three primary drawbacks of a host-based ID:
(1) It is harder to correlate network traffic patterns that involve multiple computers;
(2) Host-based IDSs can be very difficult to maintain in environments with a lot of computers, with variations in operating systems and configurations, and where computers are maintained by several system administrators with little or no common practices;
(3) Host-based IDSs can be disabled by attackers after the system is compromised.

Why, when and where to use host based IDS systems?

Host based IDS systems are used to closely monitor any actions taking place on important servers and machines. Host based IDS systems are used to detect any anomalies and activities on these important and critical servers. You use Host based IDS systems when you cannot risk the compromise of any server. The server has to be very important and mission critical to use Host based IDS systems on these servers. Host based IDS systems are agents that run on the critical servers. The agent is installed on the server that is being monitored.
What is a Signature?

A signature is Recorded evidence of a system intrusion, typically as part of an intrusion detection system (IDS). When a malicious attack is launched against a system, the attack typically leaves evidence of the intrusion in the system’s logs. Each intrusion leaves a kind of footprint behind (e.g., unauthorized software executions, failed logins, misuse of administrative privileges, file and directory access) that administrators can document and use to prevent the same attacks in the future. By keeping tables of intrusion signatures and instructing devices in the IDS to look for the intrusion signatures, a system’s security is strengthened against malicious attacks.
Because each signature is different, it is possible for system administrators to determine by looking at the intrusion signature what the intrusion was, how and when it was perpetrated.

What are the common types of attacks and signatures?

There are three types of attacks:

Reconnaissance These include ping sweeps, DNS zone transfers, e-mail recons, TCP or UDP port scans, and possibly indexing of public web servers to find cgi holes.

Exploits Intruders will take advantage of hidden features or bugs to gain access to the system.

Denial-of-service (DoS) attacks Where the intruder attempts to crash a service (or the machine), overload network links, overloaded the CPU, or fill up the disk. The intruder is not trying to gain information, but to simply act as a vandal to prevent you from making use of your machine.

Note:The signatures are written based on these types of attacks.

Interview Questions for Check Point Firewall Technology

0 comments
Question 1 – Which of the applications in Check Point technology can be used to configure security objects?
Answer:SmartDashboard

Question 2 – Which of the applications in Check Point technology can be used to view who and what the administrator do to the security policy?
Answer:SmartView Tracker

Question 3 – What are the two types of Check Point NG licenses?
Answer:Central and Local licenses

Central licenses are the new licensing model for NG and are bound to the SmartCenter server. Local licenses are the legacy licensing model and are bound to the enforcement module.

Question 4 – What is the main different between cpstop/cpstart and fwstop/fwstart?
Answer:Using cpstop and then cpstart will restart all Check Point components, including the SVN foundation. Using fwstop and then fwstart will only restart VPN-1/FireWall-1.

Question 5 – What are the functions of CPD, FWM, and FWD processes?
Answer:CPD – CPD is a high in the hierarchichal chain and helps to execute many services, such as Secure Internal Communcation (SIC), Licensing and status report.

FWM – The FWM process is responsible for the execution of the database activities of the SmartCenter server. It is; therefore, responsible for Policy installation, Management High Availability (HA) Synchronization, saving the Policy, Database Read/Write action, Log Display, etc.

FWD – The FWD process is responsible for logging. It is executed in relation to logging, Security Servers and communication with OPSEC applications.

Question 6 – What are the types of NAT and how to configure it in Check Point Firewall?
Answer:Static Mode (Manually Defined)

Friday, September 23, 2011

Cisco CCNP TSHOOT 642-832 CBT

30 comments
Cisco CCNP TSHOOT 642-832 Certification Guide

              English ISO 2.09Gb
Genre: elearning
Cisco Certified Network Professional (CCNP®) validates the ability to plan, implement, verify and troubleshoot local and wide-area enterprise networks and work collaboratively with specialists on advanced security, voice, wireless and video solutions.

The CCNP certification is appropriate for those with at least one year of networking experience who are ready to advance their skills and work independently on complex network solutions. Those who achieve CCNP have demonstrated the skills required in enterprise roles such as network technician, support engineer, systems engineer or network engineer.

The official study guide helps you master all the topics on the CCNP TSHOOT exam, including
* Common network maintenance tasks and tools
* Troubleshooting models
* Cisco IOS® troubleshooting commands and features
* Troubleshooting Cisco Catalyst® Switches and STP
* Troubleshooting BGP, OSPF, and EIGRP routing protocols
* Route redistribution, security, and router performance troubleshooting
* IP services and IP communications troubleshooting
* IPv6 troubleshooting
* Large enterprise network troubleshooting

CLICK Here1           CLICK Here2    

CLICK Here3           CLICK Here4




Friday, June 10, 2011

Cisco Firewalls

0 comments

Cisco Firewalls By Alexandre M.S.P. Moraes
Publisher: Cis.co Pre.ss 2011 | 912 Pages | ISBN: 1587141094 | PDF | 13 MB


Concepts, design and deployment for Cisco Stateful Firewall solutions

Cisco Firewalls thoroughly explains each of the leading Cisco firewall products, features, and solutions, and shows how they can add value to any network security design or operation. The author tightly links theory with practice, demonstrating how to integrate Cisco firewalls into highly secure, self-defending networks. Cisco Firewalls shows you how to deploy Cisco firewalls as an essential component of every network infrastructure. The book takes the unique approach of illustrating complex configuration concepts through step-by-step examples that demonstrate the theory in action. This is the first book with detailed coverage of firewalling Unified Communications systems, network virtualization architectures, and environments that include virtual machines. The author also presents indispensable information about integrating firewalls with other security elements such as IPS, VPNs, and load balancers; as well as a complete introduction to firewalling IPv6 networks. Cisco Firewalls will be an indispensable resource for engineers and architects designing and implementing firewalls; security administrators, operators, and support professionals; and anyone preparing for the CCNA Security, CCNP Security, or CCIE Security certification exams.

  • Create advanced security designs utilizing the entire Cisco firewall product family
  • Choose the right firewalls based on your performance requirements
  • Learn firewall configuration fundamentals and master the tools that provide insight about firewall operations
  • Properly insert firewalls in your network’s topology using Layer 3 or Layer 2 connectivity
  • Use Cisco firewalls as part of a robust, secure virtualization architecture
  • Deploy Cisco ASA firewalls with or without NAT
  • Take full advantage of the classic IOS firewall feature set (CBAC)
  • Implement flexible security policies with the Zone Policy Firewall (ZPF)
  • Strengthen stateful inspection with antispoofing, TCP normalization, connection limiting, and IP fragmentation handling
  • Use application-layer inspection capabilities built into Cisco firewalls
  • Inspect IP voice protocols, including SCCP, H.323, SIP, and MGCP
  • Utilize identity to provide user-based stateful functionality
  • Understand how multicast traffic is handled through firewalls
  • Use firewalls to protect your IPv6 deployments
This security book is part of the Cisco Press Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end, self-defending networks.