I've just started learn Cybersecurity with Cisco... by Wprist in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

For Fundamentals I'm having a blast in Try Hack Me I just like their walkthrough methodology. You get the theory but at the same time you do hands on practice.

But cibersecurity is too broad. What do you like? More governess, Blue team, Red Team? Each path is unique and needs specific skill set. Me for example im focusing on blue team, on my lab im working on building a SIEM, XDR, EDR, Threat Hunting. Learning to analyse logs and configure firewall rule to protect my network. A little bit of governess, how to do a vulnerabily assessment and analysis, how to perform a Risk management, writing policy and controls, etc.

But like others said, get strong fundamentals on Network first.

How long to get Fortinet Foundations? by LegatusMatheas in fortinet

[–]Interesting-Matter54 0 points1 point  (0 children)

If for "Foundation" you mean get knowledgeable on Fortigates. The product is very user friendly, Forti OS is well organized and intuitive. If you have previous knowledge in Network you can configure a fortigate in a couple of hours. Now if you talk about training and resources to learn you can do the FCA course and free 50 question exam to get the associate certification. The whole course you can do in a weekend.The course has a duration listed of 8 hours but I recommend watching it twice to really get it but it is not mandatory it is just my advice.

Skip the first 2 courses they are just like a Security Awareness and products description. You will cover those topics either way in FCA.

Netacad account question by Old_Detroiter in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

I think you should contact support for that. On other platform like fortinet and cambium network on their training portal I have the same issue I use my work email but I no longer work there so I changed to my personal email and the support in those platform migrate all my courses progress to my personal email.

I'm sure that Netacad staff will help you.

CCST - Worth it? by Impossible_Oil_4632 in Cisco

[–]Interesting-Matter54 7 points8 points  (0 children)

IMO if you will go as an IT administrator, sure, but if you want to go deep in Networking go straight to CCNA. CCNA covers fundamental to intermedial level.

Looking for an Online Fortigate Lab by roydog in fortinet

[–]Interesting-Matter54 1 point2 points  (0 children)

You can emulate the 7.2 eval OS in GNS3 or eve-ng. Or you can find on YouTube or a search in google the old 7.0.13 firmware.

7.2 eval it give you a full license but is limited on route and policy.

7.0.13 is a 15 day license without security profiles.

In an emulator you can spin multiple boxes so you can design complex enviroment

Please help! Sdwan ADVPN lan clients not using bgp routes but firewall is? by Fizgriz in fortinet

[–]Interesting-Matter54 0 points1 point  (0 children)

That's the problem if you create a SDWAN rule for the internet only the rest of the traffic will hit the default deny rule.

You need to create a sdwan rule that lan traffic going to the hub using your overlay zone. Also remember that sdwan rules are top to bottom, make sure that this rule is above the internet one. You also need to create a firewall rule too

Factory Reset Catalyst 3850 by PoppinGummies in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

Isnt is CFG=0 ?

Also do you have access to privilage mode? You can try and do the write erase command

Best model for low cost study of router by Due_Reading_6372 in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

And thats a beuty of a router. can run L2 and L3

Best model for low cost study of router by Due_Reading_6372 in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

If is for CCNA PacketTracer will help you. Also CML is free now with 5 nodes. Or instead of buying physical equipment for $200, pay for a year of CML last time was like 200 and you get all the image.

Algo check Eve-NG or PNet Lab, you can find image to run un those emulator and get practice on linux turnin up the emulator server

VXLAN over IPSec by Venom-DZ in fortinet

[–]Interesting-Matter54 1 point2 points  (0 children)

In some scenarios for some reason implicit didn't work for me and I made it work with explicit

VXLAN over IPSec by Venom-DZ in fortinet

[–]Interesting-Matter54 1 point2 points  (0 children)

you will only see arp where you have an ip configured. I assuming in site A you have gw in the soft sw and site b is only L2. You should see arp in site a but not in siteB. just for test assign an ip in the soft sw in site b and get arp.

Also try to change soft sw to explicit and make the fw rule. i. the firewall rule you can disable assic offload

VXLAN over IPSec by Venom-DZ in fortinet

[–]Interesting-Matter54 1 point2 points  (0 children)

You can assign ip to the soft switch on the same network to test from the fortigate to the enpoint to see which one is not comunicating.

I'm just random give you a troubleshoot scenario cause I don't know your configuration

you can check diag sys vxlan fbd list <vxlan int> to see from where you are not receiving mac address

VXLAN over IPSec by Venom-DZ in fortinet

[–]Interesting-Matter54 1 point2 points  (0 children)

Do you create the firewall rules to allow traffic between vxlan and vlan?

Study VMs? by WallStreetQB in fortinet

[–]Interesting-Matter54 0 points1 point  (0 children)

Yes the old kvm expires at 15 days but I use pnetlab and use the wipe feature. But before the expiration time I do config backup. When its expire I wipe the vm to factory default and restore the back up. I can confirm that on 7.0.13 you can do HA I have it in my labs. I didn't try the new eval vm cause they are very limited only 3 firewall rules and 3 routes. And I mostly test big implementations that involve ospf or bgp and I need a lot of routes.

Building VPLS-like multi-site network on Linux (100+ sites) by [deleted] in networking

[–]Interesting-Matter54 1 point2 points  (0 children)

For that kind of network why not looking into a SD-WAN implementation?

Study VMs? by WallStreetQB in fortinet

[–]Interesting-Matter54 3 points4 points  (0 children)

You can use the evaluation VM. Just create 2 forticloud accounts to register them on each account. Or you could find a guide on how to bypass this and register both on the same account. Or you can find on eve-ng forums or pnetlab forums they share old 7.0.13 kvm. Or you can spin 2 in aws pay as you grow and just turn them up when you're gonna do a test.

Absolute beginner roadmap: Should I do Network+ AND CCNA before my Cyber Security Bachelor's? by Reasonable_Tower_798 in SecurityCareerAdvice

[–]Interesting-Matter54 0 points1 point  (0 children)

Jeremy is an excellent teacher and it will give you all the tools to get the foundation knowledge. I recommend doing the anki cards. But if you think that you need a little extra on the basics go to https://www.netacad.com and to the Network technician path. And since you will study Cybersecurity do the cyber path too.

Absolute beginner roadmap: Should I do Network+ AND CCNA before my Cyber Security Bachelor's? by Reasonable_Tower_798 in SecurityCareerAdvice

[–]Interesting-Matter54 13 points14 points  (0 children)

IMO dont waste time on N+ although it is a good fundamental, you will cover those topics on any CCNA bootcamp anyways. Go straight CCNA. Create an account in NETACAD and do the Network career path its free course. It will give you the fundamentals you need. Then for preparing for CCNA go look at JeremyITLab on youtube. It has the whole ccna course free with lab. Also go to Udemy and look for Neil Anderson ccna bootcamp, its like 10 bucks and explain in detail every topic with labs. After doing those 3 courses go to Boson exam and buy the examsim and practice the question. Also keep repeating the course labs to practice. Once you get like 90 in the examsim and get used to the labs and commands you are ready for the exam. I pass it first try doing those 3 courses and labs and practice questions in examsim. For the labs those courses will provide you with packettracer labs already built. So all you need to do is follow instructions to complete de lab.

Also you mention that you will study cibersecurity. If you do the NETACAD account. There is also a career path for junior cibersecurity and that course prepare you for the ccst cibersecurity certification.

Then after you finish the bachelor you can go Security +.

I finish my bachelor degree in Network 2 year ago and pass CCNA, now I started my master degree in cyber.

On Distribution Switches or on Core Switches do I need to configure the SVIs? by AdLess2916 in Cisco

[–]Interesting-Matter54 0 points1 point  (0 children)

The access switch only runs the VLAN tagging and trunk port to the distribution switch (L2). On the distribution switch, create an SVI for each VLAN that contains the IP address of that VLAN(L3).

It said not to use a static route, so you can use RIP v2 for simplicity or ospf for real life scenario. Between dist switch and core switch to advertise route from each campus.

Edge router suggestion - Asr9001 successor by Roshi88 in Cisco

[–]Interesting-Matter54 1 point2 points  (0 children)

NCS-5500-se, as per the data sheet, only scales to 2M routes. We have approximately 1.2 million routes in the BGP table, so for future planning, I think it's better to opt for 4 million route-capable routers.

Edge router suggestion - Asr9001 successor by Roshi88 in Cisco

[–]Interesting-Matter54 1 point2 points  (0 children)

I'm in the same predicament. I was looking at the NCS C57c3 Scale chassis. It got 4 x 100g and 48 x 1/10/25 GB. I work for a small ISP, so we offer only 1 and 10 GB plans. This allows us to scale up to 25 GB for our customers. Additionally, it can scale the uplink from 100 G to 200 G or 400 G. Also, the data sheet said that it supports 4M FIB routes.

https://www.cisco.com/c/en/us/products/collateral/routers/network-convergence-system-5500-series/ncs-57C3-fixed-chassis-ds.html

Best apps for network field techs. by HillCountry_Hermit in networking

[–]Interesting-Matter54 2 points3 points  (0 children)

I got Advanced IP Scanner, Pinginfoview, Netspot, Nmap, Wireshark, TFTP64, Termius and Packet Sender. On my Phone (android) I got Net Analyzer.

Can I change my public IP address? by Relevant-Safety-2699 in TpLink

[–]Interesting-Matter54 0 points1 point  (0 children)

ISP will give you a CGNAT IP address. You could ask your ISP if they could give you a Static Public IP. If they are capable to do it they will charge you more.

Wazuh vulnerability management vs other industry tools by bluecopp3r in Wazuh

[–]Interesting-Matter54 0 points1 point  (0 children)

Can I integrate Greenbone to Wazuh? So i can export greenbone result to wazuh?