请输入您要查询的百科知识:

 

词条 CCIE
释义

CCIE,全称Cisco Certified Internetwork Expert,是美国Cisco公司于1993年开始推出的专家级认证考试。被全球公认为IT业最权威的认证,是全球Internetworking领域中最顶级的认证证书。

简介

目前,CCIE(思科认证互联网专家)持有者占思科认证总人数还不足3%,全球网络从业者的1%不到(思科官方数据)。Cisco认证主要提供工程师在今日快速变动的网络环境中驾驭Cisco设备所需的专业知识。CCIE是Cisco(除了新推出的CCA以外)最高级技术能力的认证,位于Cisco金字塔认证体系中塔尖,也是IT界公认的最权威、最受尊重证书之一,2003年被评为全球十大IT认证榜首,具有IT终极认证的美称。取得CCIE证书除了整个行业的认同之外,CCIE也是你不断持有最新网络知识的指标;你将会在你的专业技术领域中成为一位最具竞争力的人

CCIE认证分active和inactive两种状态,Cisco公司为了让CCIE能够跟踪新技术,并保持CCIE的专家水平,从通过CCIE认证开始,每二年就要进行一次重认证,否则你虽然仍然拥有你的CCIE number,但是你的状态就从active变成inactive,相应的享有在cisco公司赋予的一些权利就没了,但是CCIE号码是永久保留。苛刻的认证规则使CCIE成为IT业界中含金量最高的证书之一,当然也成了最受尊重、最难取得的证书之一。

Cisco公司从1993年开设CCIE考试,截止到2011年12月底,全球共有CCIE 31000多名中国大陆共有CCIE 近6000人.(CCIE人数统计是现在CCIE号码减去1024就是全球CCIE人数)CCIE号是从CCIE#1024开始算起的。为了纪念CCIELab这个艰辛的考试,思科确定:CCIE Lab考试本身就是一个CCIE#号(所以CCIE Lab考试就被冠于第一个CCIE#1024)所以第一位通过CCIE的考生是CCIE#1025(Stuart Biggs)然而Stuart Biggs本人当时就是思科CCIE考试的考官,所以第一位通过CCIE非cisco的考生是CCIE#1026 (Terry Slattery)【Netcordia的CEO】

获得CCIE认证不仅证明你的技术达到专家水平,得到业界认可与肯定,更是一种荣誉的象征,一种自我价值的体现。获得CCIE认证成为每位网络技术人员的梦想。Cisco公司为了让客户获得专家级技术支持,在其认证代理体系中规定金银牌认证代理商必须拥有一定数量的CCIE,这直接刺激了对CCIE的需求,在1999年期间,在中国大陆CCIE的年薪高达80万RMB。现在在系统集成项目中,许多业主提出承包商必须拥有CCIE认证专家,才有资格承接项目,由此可见CCIE专家在业界中的认可程度。

通过苛刻的CCIE认证后,您将获得一个CCO帐号,直接得到Cisco 二级专家的支持,享受CCIE拥有的特权。如果您打算技术移民,通过CCIE认证可以获得额外的加分,在中国通过的CCIE超过半数已经移民到国外。目前,CCIE在美国年薪可达15万美元,还不包括股票期权和其他福利,在中国大陆,一位CCIE的年薪一般在10万元以上,如果加上奖金及其他福利将远远超过这个数目。

要想获得苛刻的CCIE认证,必须先通过笔试,获取资格后才可以参加实验考试。通过了实验才最终成为CCIE。学习并获得CCIE认证途径大致有两种:第一,自学。要想通过自学方式获取CCIE认证您必须要有两年以上的工作经验,有充足的时间和精力,并要有一个完善的实验环境,此外最重要的是您必须具备坚忍不拔的毅力与永不放弃信念。第二,参加培训。找一家货真价实的培训机构利用业余或集中时间参加培训,充分利用培训机构的实验设备,在良好的学习氛围下,学员之间不但可以互相交流技术更重要的是还可以得到培训机构的CCIE专家辅导,提高学习效率,这是一种事半功倍的途径。

先修课程及考试

CCIE 认证是目前Cisco认证体系中最顶级的证书。要取得CCIE认证证书,需要取得以下课程考试:

1.CCIE资格考试(即笔试,2.5小时)考试费:350美元

2.CCIE实验考试(一天,6小时) 考试费:1500美元,北京考点为RMB10250元

笔试部分考试在中国各个城市基本都能考,而实验室部分考试在世界范围内只有10个考场:研究三角园区(美)、圣何塞(美)、悉尼(澳)、香港(中)、北京(中)、班加罗尔(印)、东京(日)、布鲁塞尔(比)、圣保罗(巴)、迪拜(阿)。

分类

Routing & Switching(R&S) 路由交换CCIE

Service Provider(ISP) 电信运营商CCIE

Security 安全CCIE

Voice 语音CCIE

Storage Networking 存储CCIE

Wireless无线CCIE

SP Operations电信运营商运维CCIE

Track Comparison数据中心CCIE

CCIE考试大纲和学习内容

路由交换CCIE认证内容

认证介绍:

路由和交换领域的CCIE认证资格表示网络人士在不同的LAN、WAN接口和各种路由器、交换机的联网方面拥有专家级知识。R&S 领域的专家可以解决复杂的连接问题,利用技术解决方案提高带宽、缩短响应时间、最大限度地提高性能、加强安全性和支持全球性应用。考生应当能够安装、配置和维护LAN、WAN和拨号接入服务。

再认证

CCIE认证有效期为两年,且必须在之后每两年进行再认证。 要进行再认证,请在认证过期之前通过下列考试之一: 通过任何一门目前提供的642-XXX Professional(资深工程师)级别考试; 通过任何一门目前提供的CCIE笔试; 通过目前提供的CCDE笔试或目前提供的CCDE实践考试; 通过思科认证架构师(CCAr)面试和CCAr委员会审核,延长较低等级认证的有效期。 未能在再认证期限之前通过资格考试或实验考试的CCIE和CCDE专业人士,将被置于暂缓状态,他们的雇主也会被告知这一情况。对处于暂缓状态的CCIE和CCDE专业人士,在他们的专家级别认证永久失效之前,将有一年时间来通过需要的考试或实验考试。失效了的CCIE和CCDE专业人士将失去所有利益,并且必须再次通过CCIE笔试和实验考试或CCDE笔试和实践考试。 获取或再认证CCIE、CCDE或CCAr将自动延长您的入门级、工程师、资深工程师、其他专家级别认证或专业化认证的有效期,至最新获得的CCIE、CCDE或CCAr认证过期日。Exam Sections and Sub-task Objectives

1.00 Implement Layer 2 Technologies √

1.10 Implement Spanning Tree Protocol (STP)

(a) 802.1d

(b) 802.1w

(c) 801.1s

(d) Loop guard

(e) Root guard

(f) Bridge protocol data unit (BPDU) guard

(g) Storm control

(h) Unicast flooding

(i) Port roles, failure propagation, and loop guard operation

1.20 Implement VLAN and VLAN Trunking Protocol (VTP)

1.30 Implement trunk and trunk protocols, EtherChannel, and load-balance

1.40 Implement Ethernet technologies

(a) Speed and duplex

(b) Ethernet, Fast Ethernet, and Gigabit Ethernet

(c) PPP over Ethernet (PPPoE)

1.50 Implement Switched Port Analyzer (SPAN), Remote Switched Port Analyzer (RSPAN), and flow control

1.60 Implement Frame Relay

(a) Local Management Interface (LMI)

(b) Traffic shaping

(c) Full mesh

(d) Hub and spoke

(e) Discard eligible (DE)

1.70 Implement High-Level Data Link Control (HDLC) and PPP

2.00 Implement IPv4

2.10 Implement IP version4 (IPv4) addressing, subnetting, and variable-length subnet masking (VLSM)

2.20 Implement IPv4tunneling and Generic Routing Encapsulation (GRE)

2.30 Implement IPv4 RIP version 2 (RIPv2)

2.40 Implement IPv4 Open Shortest Path First (OSPF)

(a) Standard OSPF areas

(b) Stub area

(c) Totally stubby area

(d) Not-so-stubby-area (NSSA)

(e) Totally NSSA

(f) Link-state advertisement (LSA) types

(g) Adjacency on a point-to-point and on a multi-access network

(h) OSPF graceful restart

2.50 Implement IPv4 Enhanced Interior Gateway Routing Protocol (EIGRP)

(a) Best path

(b) Loop-free paths

(c) EIGRP operations when alternate loop-free paths are available, and when they are not available

(d) EIGRP queries

(e) Manual summarization and autosummarization

(f) EIGRP stubs

2.60 Implement IPv4 Border Gateway Protocol (BGP)

(a) Next hop

(b) Peering

(c) Internal Border Gateway Protocol (IBGP) and External Border Gateway Protocol (EBGP)

2.70 Implement policy routing

2.80 Implement Performance Routing (PfR) and Cisco Optimized Edge Routing (OER)

2.90 Implement filtering, route redistribution, summarization, synchronization, attributes, and other advanced features

3.00 Implement IPv6

3.10 Implement IP version 6 (IPv6) addressing and different addressing types

3.20 Implement IPv6 neighbor discovery

3.30 Implement basic IPv6 functionality protocols

3.40 Implement tunneling techniques

3.50 Implement OSPF version 3 (OSPFv3)

3.60 Implement EIGRP version 6 (EIGRPv6)

3.70 Implement filtering and route redistribution

4.00 Implement MPLS Layer 3 VPNs

4.10 Implement Multiprotocol Label Switching (MPLS)

4.20 Implement Layer 3 virtual private networks (VPNs) on provider edge (PE), provider (P), and customer edge (CE) routers

4.30 Implement virtual routing and forwarding (VRF) and Multi-VRF Customer Edge (VRF-Lite)

5.00 Implement IP Multicast

5.10 Implement Protocol Independent Multicast (PIM) sparse mode

5.20 Implement Multicast Source Discovery Protocol (MSDP)

5.30 Implement interdomain multicast routing

5.40 Implement PIM Auto-Rendezvous Point (Auto-RP), unicast rendezvous point (RP), and bootstrap router (BSR)

5.50 Implement multicast tools, features, and source-specific multicast

5.60 Implement IPv6 multicast, PIM, and related multicast protocols, such as Multicast Listener Discovery (MLD)

6.00 Implement Network Security

6.01 Implement access lists

6.02 Implement Zone Based Firewall

6.03 Implement Unicast Reverse Path Forwarding (uRPF)

6.04 Implement IP Source Guard

6.05 Implement authentication, authorization, and accounting (AAA) (configuring the AAA server is not required, only the client-side (IOS) is configured)

6.06 Implement Control Plane Policing (CoPP)

6.07 Implement Cisco IOS Firewall

6.08 Implement Cisco IOS Intrusion Prevention System (IPS)

6.09 Implement Secure Shell (SSH)

6.10 Implement 802.1x

6.11 Implement NAT

6.12 Implement routing protocol authentication

6.13 Implement device access control

6.14 Implement security features

7.00 Implement Network Services

7.10 Implement Hot Standby Router Protocol (HSRP)

7.20 Implement Gateway Load Balancing Protocol (GLBP)

7.30 Implement Virtual Router Redundancy Protocol (VRRP)

7.40 Implement Network Time Protocol (NTP)

7.50 Implement DHCP

7.60 Implement Web Cache Communication Protocol (WCCP)

8.00 Implement Quality ofService (QoS)

8.10 Implement Modular QoS CLI (MQC)

(a) Network-Based Application Recognition (NBAR)

(b) Class-based weighted fair queuing (CBWFQ),modified deficit round robin (MDRR), and low latency queuing (LLQ)

(c) Classification

(d) Policing

(e) Shaping

(f) Marking

(g) Weighted random early detection (WRED) and random early detection (RED)

(h) Compression

8.20 Implement Layer 2 QoS: weighted round robin (WRR), shaped round robin (SRR), and policies

8.30 Implement link fragmentation and interleaving (LFI) for Frame Relay

8.40 Implement generic traffic shaping

8.50 Implement Resource Reservation Protocol (RSVP)

8.60 Implement Cisco AutoQoS

9.00 Troubleshoot a Network

9.10 Troubleshoot complex Layer 2 network issues

9.20 Troubleshoot complex Layer 3 network issues

9.30 Troubleshoot a network in response to application problems

9.40 Troubleshoot network services

9.50 Troubleshoot network security

10.00 Optimize the Network

10.01 Implement syslog and local logging

10.02 Implement IP Service Level Agreement SLA

10.03 Implement NetFlow

10.04 Implement SPAN, RSPAN, and router IP traffic export (RITE)

10.05 Implement Simple Network Management Protocol (SNMP)

10.06 Implement Cisco IOS Embedded Event Manager (EEM)

10.07 Implement Remote Monitoring (RMON)

10.08 Implement FTP

10.09 Implement TFTP

10.10 Implement TFTP server on router

10.11 Implement Secure Copy Protocol (SCP)

10.12 Implement HTTP and HTTPS

10.13 Implement Telnet

安全CCIE认证内容

认证介绍:

安全领域的CCIE 认证表示网络人士在IP 和IP 路由,以及特定的安全协议和组件方面拥有专家级知识。获得安全CCIE,能够设计安全的网络。熟练使用ASA/PIX,IPS,VPN产品以及各种安全技术。

备考推荐资料:

CISCO VPN配置完全手册

路由器防火墙

安全原理与实践

……

课程设计内容:

Implement secure networks using Cisco ASA Firewalls

Perform basic firewall Initialization Configure device management Configure address translation (nat, global, static) Configure ACLs Configure IP routing Configure object groups Configure VLANs Configure filtering Configure failover Configure Layer 2 Transparent Firewall Configure security contexts (virtual firewall) Configure Modular Policy Framework Configure Application-Aware Inspection Configure high availability solutions Configure QoS policies

Implement secure networks using Cisco IOS Firewalls Configure CBAC Configure Zone-Based Firewall Configure Audit Configure Auth Proxy Configure PAM Configure access control Configure performance tuning Configure advanced IOS Firewall features

Implement secure networks using Cisco VPN solutions Configure IPsec LAN-to-LAN (IOS/ASA) Configure SSL VPN (IOS/ASA) Configure Dynamic Multipoint VPN (DMVPN) Configure Group Encrypted Transport (GET) VPN Configure Easy VPN (IOS/ASA) Configure CA (PKI) Configure Remote Access VPN Configure Cisco Unity Client Configure Clientless WebVPN Configure AnyConnect VPN Configure XAuth, Split-Tunnel, RRI, NAT-T Configure High Availability Configure QoS for VPN Configure GRE, mGRE Configure L2TP Configure advanced Cisco VPN features

Configure Cisco IPS to mitigate network threats Configure IPS 4200 Series Sensor Appliance Initialize the Sensor Appliance Configure Sensor Appliance management Configure virtual Sensors on the Sensor Appliance Configure security policies Configure promiscuous and inline monitoring on the Sensor Appliance Configure and tune signatures on the Sensor Appliance Configure custom signatures on the Sensor Appliance Configure blocking on the Sensor Appliance Configure TCP resets on the Sensor Appliance Configure rate limiting on the Sensor Appliance Configure signature engines on the Sensor Appliance Use IDM to configure the Sensor Appliance Configure event action on the Sensor Appliance Configure event monitoring on the Sensor Appliance Configure advanced features on the Sensor Appliance Configure and tune Cisco IOS IPS Configure SPAN & RSPAN on Cisco switches

Implement Identity Management Configure RADIUS and TACACS+ security protocols Configure LDAP Configure Cisco Secure ACS Configure certificate-based authentication Configure proxy authentication Configure 802.1x Configure advanced identity management features Configure Cisco NAC Framework

Implement Control Plane and Management Plane Security Implement routing plane security features (protocol authentication, route filtering) Configure Control Plane Policing Configure CP protection and management protection Configure broadcast control and switchport security Configure additional CPU protection mechanisms (options drop, logging interval) Disable unnecessary services Control device access (Telnet, HTTP, SSH, Privilege levels) Configure SNMP, Syslog, AAA, NTP Configure service authentication (FTP, Telnet, HTTP, other) Configure RADIUS and TACACS+ security protocols Configure device management and security

Configure Advanced Security Configure mitigation techniques to respond to network attacks Configure packet marking techniques Implement security RFCs (RFC1918/3330, RFC2827/3704) Configure Black Hole and Sink Hole solutions Configure RTBH filtering (Remote Triggered Black Hole) Configure Traffic Filtering using Access-Lists Configure IOS NAT Configure TCP Intercept Configure uRPF Configure CAR Configure NBAR Configure NetFlow Configure Anti-Spoofing solutions Configure Policing Capture and utilize packet captures Configure Transit Traffic Control and Congestion Management Configure Cisco Catalyst advanced security features

Identify and Mitigate Network Attacks Identify and protect against fragmentation attacks Identify and protect against malicious IP option usage Identify and protect against network reconnaissance attacks Identify and protect against IP spoofing attacks Identify and protect against MAC spoofing attacks Identify and protect against ARP spoofing attacks Identify and protect against Denial of Service (DoS) attacks Identify and protect against Distributed Denial of Service (DDoS) attacks Identify and protect against Man-in-the-Middle (MiM) attacks Identify and protect against port redirection attacks Identify and protect against DHCP attacks Identify and protect against DNS attacks Identify and protect against Smurf attacks Identify and protect against SYN attacks Identify and protect against MAC Flooding attacks Identify and protect against VLAN hopping attacks Identify and protect against various Layer2 and Layer3 attacks

电信运营商CCIE认证内容

认证介绍:

电信运营商CCIE认证(以前被称为通信和服务)表示网络人士在IP原理和核心IP技术(例如单播IP路由、QoS、组播、MPLS、MPLS VPN、流量工程和多协议BGP)方面拥有专家级知识,并且在至少一项与电信运营商有关的网络领域具有专业知识。这些领域包括拨号、DSL、有线网络、光网、WAN交换、IP电话、内容网络和城域以太网。

备考用书:

MPLS VPN 体系结构卷一

MPLS VPN 体系结构卷二

MPLS 流量工程

高级MPLS VPN设计

域间多播技术

……

课程内容:

.

Bridging and Switching VTP, VLAN, Trunk, Spanning tree Frame Relay, DLCI, FR multilink ATM PVC, SVC, FR/ATM interworking PPPoE

IGP Routing IS-IS, Level 1/2, Metric OSPF, LSA, Area Redistribution, Summarization, Filtering Policy routing

EGP Routing IBGP, EBGP BGP attributes Confederation, Route reflector Synchronization, Aggregation, Stability Redistribution, Filtering Multipath

SP Multicast PIM-SM, PIM-DM, SSM, PIM-BIDIR, IGMP Auto RP, Static RP, BSR, Anycast RP MP-BGP for multicast, MSDP

MPLS Label distribution, LDP/ TDP Label filtering, Label merging, Multipath MPLS COS MPLS Netflow MPLS over ATM MPLS Traffic Engineering

L3/L2 VPN MPLS VPN, MP-iBGP PE-CE routing, RIPv2, OSPF, EIGRP, Static, ISIS, EBGP BGP Extended Community Inter AS MPLS VPN Carrier Supporting Carrier VRF-Lite, VRF Select Multicast MPLS VPN GRE, multipoint GRE AToM, L2TPv3 802.QinQ

SP QoS and Security DSCP/EXP, TOS, NBAR Marking, Shaping, Policing CAR, FRTS WRQ, CBWFQ, LLQ, PQ, CQ RED, WRED LFI, cRTP RSVP ACL, RPF, Filtering Routing update security Common attacks

High Availability NSF, GLBP Fast reroute, Link/Node protection HSRP, VRRP

Management SNMP, SYSLOG, RMON Accounting Netflow NTP

相关书籍

基本信息

书名:CCIE 2.0学习指南(附光盘)ISBN:711109535

作者:(美)Roosevelt Giles著//任宇飞

出版社:机械工业出版社

定价:99

页数:912

出版日期:2002-1-1

开本:16开

包装:附带光盘

简介

本书对CCIE考试主题进行了详尽、全面、透彻的讲解。每部分都就某个专题进行详细讨论,紧紧把握考试重点,并给出了大量习题与解答。本书的作者有专业的CCIE培训经验,使读者能够较快地掌握考试主题,提高应试技巧。配套光盘包含大量实境模拟试题与分析,帮助应试人员迅速熟悉考试环境,增强考试信心。

目录

译者序

第1章 起步

第2章 数据链路层

第3章 逻辑链路控制层

第4章 桥接体系结构

第5章 NetBIOS体系结构

第6章 了解AppleTalk

第7章 掌握Novell NetWare

第8章 TCP/IP体系结构概述

第9章 路由信息协议

第10章 内部网关路由协议和增强的IGRP

第11章 开放最短路径优先

第12章 边界网关协议

第13章 数据链路交换

第14章 ATM结构

第15章 广域网

附录A CCNA考试题及答案

附录B CCNP考试题及答案

附录C 关于本书附带光盘

随便看

 

百科全书收录4421916条中文百科知识,基本涵盖了大多数领域的百科知识,是一部内容开放、自由的电子版百科全书。

 

Copyright © 2004-2023 Cnenc.net All Rights Reserved
更新时间:2024/12/23 17:21:00