بحث هذه المدونة الإلكترونية

الثلاثاء، ٢٥ سبتمبر ٢٠١٢

IP SLA


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم





 
ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الأحد، ٢٣ سبتمبر ٢٠١٢

IPv6 Stateless Autoconfiguration


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم


ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم


Default Redistribution Metrics



بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

Default Redistribution Metrics


ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم.

السبت، ١٥ سبتمبر ٢٠١٢

OSPF Virtual Links


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

OSPF Virtual Links




Watch On YouTube
 ولا تنسوني والمسلمين من صالح الدعاء وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الثلاثاء، ٤ سبتمبر ٢٠١٢

Cisco Router As TFTP Server


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

Cisco Router As TFTP Server
sometimes you may need TFTP server urgently, but you do not have one, in this situations you can use your Cisco router as the TFTP server. simply you can use the first command without using an ACL to filter traffic, nonetheless you can use both commands to apply the ACL.

R(config)#tftp-server flash:r1-confg alias Labconfig 1
R(config)#access-list 1 permit host 192.168.1.2

Watch on Youtube
لا تنسوني والمسلمين من صالح الدعاء وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الأحد، ٢ سبتمبر ٢٠١٢

HSRP Simple Lab Using SVI Interface


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

HSRP Simple Lab Using SVI Interface

Download HD


Watch on Youtube
لا تنسوني والمسلمين من صالح الدعاء
وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الخميس، ٢٣ أغسطس ٢٠١٢

CCNP Switching Summary From Chapter 4 Till the end

بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

Dear All,
This is my CCNP Switching summary from chapter 4 till the end. the first 3 chapters are a hrad copy, if i got a new scanner, i will upload them for you by Allah's willing

Download


ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الجمعة، ١٠ أغسطس ٢٠١٢

Using CoreFTP With GNS3


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم
 
Using CoreFTP With GNS3  



Download Video HD

بسم الله

 
ولا تنسوني والمسلمين من صالح الدعاء
وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الأحد، ٥ أغسطس ٢٠١٢

Dot1x in Gns3 Using Cisco ACS on Windows Server 2003


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

 Dot1x in Gns3 Using Cisco ACS on Windows Server 2003

i was searching on the internet how to implement Dot1x in GNS3, the problem was that 802.1x depends on physical ports, i tried it on GNS3 but failed. thanks to Allah finally i came across the following video, it solved it, yes. the magic is that you make the SVI of the switch the default gateway for your client and for your router, thus the switch redirect your authentication request to the Radius " ACS " server.

   
ولا تنسوني والمسلمين من صالح الدعاء
وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

how to deny access to certain website using your cisco router


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

how to deny access to certain website using your cisco  router

i know it may be silly to talk about this method of denying acceess to certain websites, but i mainly intend to show you a quick method of denying access to certain websites without the need to use advanced web filtering programs that may need a dedicated server or even multiple servers to do this task. look this method may be vulnerable or easily bypassed  but anyway this is the case over here.

this method depends on using class maps to filter the website:

class-map match-any SOCIAL_NET
match protocol http host www.facebook.com
match protocol http host www.youtube.com
match protocol http host twitter.com
!
policy-map DROP_SOCIAL_NET
class SOCIAL_NET
drop
!
!
interface FastEthernet0/1
service-policy output DROP_SOCIAL_NET
!
but what about using https???

if you noted that in the class map i did not mentioned https, but you can using the following command:

match protocol secure-http

but this will deny the https access to any web content that is encrypted using https "port 443". this is because cisco has other web filtering solutions that give you more flexibility of web filtering so it did not allowed us to use the https with the website name.
so if you decided to prevent the https, Firefox has a powerful addons that allows you to open whatever you need using https, i came a cross a powerful one called "https every where", really awesome.

hope that has been informative to you and i would like to thank your for following this blog.

Best Regards
Ahmed Mustafa

ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الجمعة، ٢٠ يوليو ٢٠١٢

Multiple SSID With Multiple VLANs configuration example on Cisco Aironet APs


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

Multiple SSID With Multiple VLANs configuration example on Cisco Aironet APs

we have three vlans
SMH-NATIVE
SMH-Employees
SMH-VOIP
each has an SSID.


Step 1
Configure the SSID and Map it to respective VLANS..


Dot11 ssid SMH-NATIVE
Vlan 1
Authentication open
  authentication key-management wpa version 2
  wpa-psk ascii  AMNPASS1
  Mbssid Guest-mode
  Exit
 
Dot11 ssid SMH-Employees
Vlan 2
  authentication open
  authentication key-management wpa version 2
  wpa-psk ascii AMNPASS2
  Mbssid Guest-mode
  Exit
 
Dot11 ssid SMH-VOIP
Vlan 4
authentication open
authentication key-management wpa version 2
wpa-psk ascii AMNPASS3
Mbssid Guest-mode
Exit


Step 2
 Assigning the Encryption to different SSIDs with respective VLANs.

Int dot11 0
Mbssid
ssid SMH-NATIVE
ssid SMH-Employees
ssid SMH-VOIP


encryption vlan 1 mode ciphers aes-ccm
encryption vlan 2 mode ciphers aes-ccm
encryption vlan 4 mode ciphers aes-ccm


Step 3
Configuring the sub interface for Dot11 radio 0 and Ethernet.


interface Dot11Radio0.1
encapsulation dot1Q 1 native
bridge-group 1
exit


interface GigabitEthernet0.1
bridge-group 1
encapsulation dot1Q 1 native
exit


interface Dot11Radio0.2
encapsulation dot1Q 2
bridge-group 2
exit


interface GigabitEthernet00.2
bridge-group 2
encapsulation dot1Q 2
exit


interface Dot11Radio0.4
encapsulation dot1Q 4
bridge-group 4
exit


interface GigabitEthernet00.4
bridge-group 4
encapsulation dot1Q 4
exit


bridge irb
bridge 1 route ip
exit


Configuration on the Switch


int fa 0/1
switchport mode trunk
switchport trunk encapsulation dot1q
switchport trunk native vlan 1
switchport trunk allowed vlan 1,2,3

Download the video Tutorial HD


watch on youtube
     

ولا تنسوني و المسلمين من صالح الدعاء   وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه  وسلم

الأربعاء، ١٨ يوليو ٢٠١٢

CCNA Wireless Summary


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

CCNA Wireless Summary


This is my summary for CCNA Wireless course, you can use it as your last paper before the exam, or even for a quick review for wireless concepts.

Download
.docx


enjoy your studies

ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الاثنين، ١٦ يوليو ٢٠١٢

How To Configure Cisco Aironet 1140 Access Point single SSID and single VLAN


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

How To Configure Cisco Aironet 1140 Access Point single SSID and single VLAN






interface dot11radio 0
no shutdown
encryption vlan 1 mode ciphers tkip aes-ccm
channel 1
antenna gain 128
station-role root
ssid AMNetwork
vlan 1
authentication open
authentication key-management wpa version 2
guest-mode
wpa-psk ascii P@ssw0rd


Notes:

1- the radio interface will be down if the vlan is not defined on the access point: 
services >> VLAN and define the vlan

2- to broadcast the ssid

ssid manager >> Guest Mode/Infrastructure SSID Settings select single bssid and the ssid you want broadcast from the list, and use the apply button below (not the one right above) or from the CLI under the ssid insert "guest-mode"

3- security

admin access
 make the authentication local only to get rid of the default user and pass Cisco

Download Video High Quality

Watch on YouTube
       
ولا تنسوني والمسلمين من صالح الدعاء
وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الأحد، ١٥ يوليو ٢٠١٢

Switch port is Trunk and Access in the same time


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

Switch port is Trunk and Access in the same time


this happened when i was configuring a 2960 PoE-8 switch.
the concept here is that the port will be trunk if the opposite port in the other switch is trunk and vice versa. in other words it will be access if the other port is access.
this depends on the DTP default mode in the switches for example , the 3550 Switch ports defaults to dynamic-desirable , while on the 3560 Switch ports its default to Dynamic-auto.
also it depends on the version of the IOS
The "older" switches wanted to form trunks, hence the dynamic desirable was the default.
Newer switches are a tad more conservative, so the dynamic auto is now the default.

Best Regards
Ahmed Mustafa

ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم

الخميس، ٥ يوليو ٢٠١٢

AVAYA IP Phone No Dial Tone


بسم الله والحمد لله والصلاة والسلام علي رسول الله وآله وصحبه وإخوانه وسلم

AVAYA IP Phone No Dial Tone


This is a common problem in AVAYA  IP phones, no dial tone when picking up a line, just restart the ip phone, by unplugging the power adapter and plugging it again.

Best Regards

Ahmed Mustafa

ولا تنسوني والمسلمين من صالح الدعاء

وصلي الله وسلم وبارك علي النبي وآله وصحبه وإخوانه وسلم