Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

Cisco Secure VPN Exam Certification Guide - Cisco press

.pdf
Скачиваний:
64
Добавлен:
24.05.2014
Размер:
19.64 Mб
Скачать

348 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Monitoring the Cisco VPN 3000 Series Concentrator

Figure 7-49 shows the Monitoring screen.

Figure 7-49 Monitoring Screen

Table 7-5 describes the Monitoring screen menu options.

Table 7-5

Monitoring Menu System

 

 

 

 

 

 

Menu Option

Level

Usage

 

 

 

 

 

Monitoring

1

Main screen for monitoring the VPN 3000 Concentrator. Enables all of

 

 

 

the Monitoring submenus.

 

 

 

 

 

Routing Table

2

Shows the currently configured routes.

 

 

 

 

 

Filterable Event Log

2

Allows you to show events as defined by the debugging options set

 

 

 

within the configuration. These events may be filtered. This screen is

 

 

 

updated periodically based on the setting in the Administration |

 

 

 

Monitoring Refresh screen.

 

 

 

 

 

Live Event Log

3

Shows all events for which logging is enabled. These events are not

 

 

 

filterable and show up in real time.

 

 

 

 

 

System Status

2

Shows the status and the serial number of the concentrator.

 

 

 

 

 

Sessions

2

Allows you to see the statistics for all of the current sessions on the

 

 

 

concentrator. This screen also enables the submenus for monitoring the

 

 

 

sessions by protocol or encryption, as well as the “top ten” list.

 

 

 

 

 

Statistics

3

Is similar to the Monitoring | Protocols screen but allows you to choose

 

 

 

the protocol on which to filter the statistics.

 

 

 

 

 

 

 

Sessions 349

 

 

 

 

Table 7-5

Monitoring Menu System (Continued)

 

 

 

 

 

Menu Option

Level

Usage

 

 

 

 

 

Encryption

3

Is similar to the Monitoring | Protocols screen, but allows you to

 

 

 

choose the encryption on which to filter the statistics.

 

 

 

 

 

Top Ten Lists

3

Enables the submenu that allows you to see the statistics for the 10

 

 

 

most active sessions sorted by total bytes transmitted, total time

 

 

 

connected, or average throughput.

 

 

 

 

 

Statistics

2

Enables the submenu for statistics. These statistics are divided into a

 

 

 

great number of submenus.

 

 

 

 

 

MIB-II Stats

3

Enables the submenu for those statistics that are reported through the

 

 

 

MIB system.

 

 

 

 

System Status

The System Status screen is the closest equivalent available on the concentrator to the show version command on a router. See Figure 7-50.

Figure 7-50 System Status

Sessions

The Sessions screen shows the statistics for the currently connected sessions (see Figure 7-51).

350 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

Figure 7-51 Sessions

Top Ten Lists

The Top Ten Lists screen is shown in Figure 7-52.

Figure 7-52 Top Ten Lists

Figure 7-53 shows the Top Ten Lists Data screen.

Statistics 351

Figure 7-53 Top Ten Lists | Data

Statistics

Following is a list of the Monitoring | Statistics submenu options:

Accounting

Address Pools

Administrative AAA

Authentication

Bandwidth Management

Compression

DHCP

DNS

Events

Filtering

HTTP

IPSec

L2TP

Load Balancing

NAT

352Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

PPTP

SSH

SSL

Telnet

VRRP

MIB II Statistics

The MIB-II Statistics submenu system is shown in the following list in order for you to familiarize yourself with the options available:

Interfaces

TCP/UDP

IP

RIP

OSPF

ICMP

ARP Table

Ethernet

SNMP

Basically, if you think in terms of the ISO layers, you will see all of the Layer 1, Layer 2, Layer 3, and Layer 4 statistics here. You will also see your routing protocols and TCP/UDP and SNMP packets here. Virtually everything else is seen in the Statistics screen.

Q&A 353

Q&A

As mentioned in Chapter 1, “All About the Cisco Certified Security Professional,” these questions are more difficult than what you should experience on the CCSP exam. The questions do not attempt to cover more breadth or depth than the exam; however, the questions are designed to make sure you know the answer. Rather than allowing you to derive the answer from clues hidden inside the question itself, your understanding and recall of the subject are challenged. Questions from the “Do I Know This Already?” quiz from the beginning of the chapter are repeated here to ensure that you have mastered the chapter’s topic areas. Hopefully, these questions will help limit the number of exam questions on which you narrow your choices to two options and guess!

1What screen is used to set the password for the administrator?

2You wish to limit HTTP access to the concentrator to hosts on the same subnet as the inside interface of the concentrator. What is the format of the access control list?

3What types of AAA servers can the VPN 3000 Series Concentrator use for authenticating management sessions?

4What is the upper limit for a management session timeout?

5What form of encryption may be used on a configuration file?

354 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

6On what screen can routes be cleared?

7Where can you see the CPU utilization on a Cisco 3000 Series Concentrator?

8Where can you troubleshoot an IPSec connection?

9Where can you troubleshoot TCP/IP connections?

10Where can you see the number of collisions on an Ethernet interface?

11What is the major difference between the Monitoring | Statistics and the Monitoring | Statistics | MIB II sections?

12You wish to limit the number of concurrent management connections. Where is this done?

Q&A 355

13You wish to use a AAA server to authenticate management access to the concentrator. What must you use?

14What are the differences between the Filterable Event Log screen and the Live Event Log screen?

15On what screen can you see if a certificate has been requested but has not yet been received?

16What section should you look in if you want to see the number of pings sent and received? From where on the concentrator do you send a ping?

17Name two places that you can see the current software version on a concentrator.

18What are the access control lists as defined in the Administration | Access Rights | Access Control Lists screen used for?

356 Chapter 7: Monitoring and Administering the VPN 3000 Series Concentrator

19You find out that your assistant has changed the configuration and saved that new configuration. However, something was configured incorrectly. None of remote sites or remote users can connect to the concentrator. What is the quickest way to resolve the issue?

20A remote client with a VPN 3002 Hardware Client calls you on the phone saying that he is unable to connect to your network. He says that he may have incorrectly configured the preshared key on his end. You have access through HTTP to your concentrator. Where is the first place you look to see if this is a preshared key issue?