来自当知百科
跳转到: 导航搜索

目录

简介

  目前,CCIE持有者占思科认证总人数还不足3%,全球网络从业者的1%不到(思科官方数据)。Cisco认证主要提供工程师在今日快速变动的网络环境中驾驭Cisco设备所需的专业知识。CCIE是Cisco(除了新推出的CCA以外)最高级技术能力的认证,位于Cisco金字塔认证体系中塔尖,也是IT界公认的最权威、最受尊重证书之一,2003年被评为全球十大IT认证榜首,具有IT终极认证的美称。取得CCIE证书除了整个行业的认同之外,CCIE也是你不断持有最新网络知识的指标;你将会在你的专业技术领域中成为一位最具竞争力的人

  CCIE认证分active和inactive两种状态,Cisco公司为了让CCIE能够跟踪新技术,并保持CCIE的专家水平,从通过CCIE认证开始,每两年就要进行一次重认证,否则你虽然仍然拥有你的CCIEnumber,但是你的状态就从active变成inactive,相应的享有在cisco公司赋予的一些权利就没了。苛刻的认证规则使CCIE成为IT业界中含金量最高的证书之一,当然也成了最受尊重、最难取得的证书之一。

  Cisco公司从1993年开设CCIE考试,截止到2010年4月30日,全球共有CCIE 20860名,中国大陆共有CCIE3560名,其中超过半数在国外工作。

  获得CCIE认证不仅证明你的技术达到专家水平,得到业界认可与肯定,更是一种荣誉的象征,一种自我价值的体现。获得CCIE认证成为每位网络技术人员的梦想。

  Cisco公司为了让客户获得专家级技术支持,在其认证代理体系中规定金银牌认证代理商必须拥有一定数量的CCIE,这直接刺激了对CCIE的需求,在1999年期间,在中国大陆CCIE的年薪高达80万RMB。现在在系统集成项目中,许多业主提出承包商必须拥有CCIE认证专家,才有资格承接项目,由此可见CCIE专家在业界中的认可程度。

  通过苛刻的CCIE认证后,您将获得一个CCO帐号,直接得到Cisco二级专家的支持,享受CCIE拥有的特权。如果您打算技术移民,通过CCIE认证可以获得额外的加分,在中国通过的CCIE超过半数已经移民到国外。目前,CCIE在美国年薪可达15万美元,还不包括股票期权和其他福利,在中国大陆,一位CCIE的年薪至少在10万元以上,如果加上奖金及其他福利将远远超过这个数目。

  要想获得苛刻的CCIE认证,必须先通过笔试,获取资格后才可以参加实验考试。通过了实验才最终成为CCIE。学习并获得CCIE认证途径大致有两种:第一,自学。要想通过自学方式获取CCIE认证您必须要有两年以上的工作经验,有充足的时间和精力,并要有一个完善的实验环境,此外最重要的是您必须具备坚忍不拔的毅力与永不放弃信念。第二,参加培训。找一家货真价实的培训机构利用业余或集中时间参加培训,充分利用培训机构的实验设备,在良好的学习氛围下,学员之间不但可以互相交流技术更重要的是还可以得到培训机构的CCIE专家辅导,提高学习效率,这是一种事半功倍的途径。

先修课程及考试

  CCIE 认证是目前Cisco认证体系中最顶级的证书。要取得CCIE认证证书,需要取得以下课程考试:

  1、CCIE资格考试(即笔试,2.5小时) 考试费:¥3000

  2、CCIE实验考试(一天) 考试费:¥12000

  3、CCIE面试(英文)

  笔试部分考试在中国各个城市基本都能考,而实验室部分考试在世界范围内只有9个考场:研究三角园区(美)、圣何塞(美)、悉尼(澳)、香港(中)、北京(中)、班加罗尔(印)、东京(日)、布鲁塞尔(比)、圣保罗(巴)。

分类

  Routing & Switching(R&S) 路由交换CCIE

  Service Provider(ISP) 电信运营商CCIE

  Security 安全CCIE

  Voice 语音CCIE

  Storage Networking 存储CCIE

  Wireless 无线CCIE

CCIE考试大纲和学习内容

路由交换CCIE认证内容

  认证介绍:

  路由和交换领域的CCIE认证资格表示网络人士在不同的LAN、WAN接口和各种路由器、交换机的联网方面拥有专家级知识。R&S领域的专家可以解决复杂的连接问题,利用技术解决方案提高带宽、缩短响应时间、最大限度地提高性能、加强安全性和支持全球性应用。考生应当能够安装、配置和维护LAN、WAN和拨号接入服务。

  备考参考用书:

  TCP /IP路由协议卷一

  TCP /IP路由协议卷二

  3560交换机配置指南

  端到端的QOS网络设计

  IPV6设计与实现

  MPLS和VPN体系结构

  课程涉及内容:

  桥接部分

  Frame relay

  VLANs, VTP, STP, MSTP, RSTP, Trunk, Etherchannel, management,features, advanced configuration, Layer 3

  Tunneling

  IGP部分:

  OSPF

  EIGRP

  RIPv2

  IPv6: Addressing, RIPng, OSPFv3

  GRE

  ODR

  Filtering, redistribution, summarization and other advancedfeatures

  BGP 部分

  IBGP

  EBGP

  Filtering, redistribution, summarization, synchronization,attributes and other advanced features

  IP特性部分:

  IP addressing

  DHCP

  HSRP

  IP services

  IOS user interfaces

  System management

  NAT

  NTP

  SNMP

  RMON

  Accounting

  SLA

  多播部分:

  PIM, bi-directional PIM

  MSDP

  Multicast tools, source specific multicast

  DVMRP

  Anycast

  服务质量:

  Quality of service solutions

  Classification

  Congestion management, congestion avoidance

  Policing and shaping

  Signaling

  Link efficiency mechanisms

  Modular QoS command line

  安全特性部分:

  AAA

  Security server protocols

  Traffic filtering and firewalls

  Access lists

  Routing protocols security, catalyst security

  CBAC

  Other security features

安全CCIE认证内容

  认证介绍:

  安全领域的 CCIE 认证表示网络人士在 IP 和 IP路由,以及特定的安全协议和组件方面拥有专家级知识。获得安全CCIE,能够设计安全的网络。熟练使用ASA/PIX,IPS,VPN产品以及各种安全技术。

  备考推荐资料:

  CISCO VPN配置完全手册

  路由器防火墙

  安全原理与实践

  ……

  课程设计内容:

  Implement secure networks using Cisco ASA Firewalls

  Perform basic firewall Initialization Configure device managementConfigure address translation (nat, global, static) Configure ACLsConfigure IP routing Configure object groups Configure VLANsConfigure filtering Configure failover Configure Layer 2Transparent Firewall Configure security contexts (virtual firewall)Configure Modular Policy Framework Configure Application-AwareInspection Configure high availability solutions Configure QoSpolicies

  Implement secure networks using Cisco IOS FirewallsConfigure CBAC Configure Zone-Based Firewall Configure AuditConfigure Auth Proxy Configure PAM Configure access controlConfigure performance tuning Configure advanced IOS Firewallfeatures

  Implement secure networks using Cisco VPN solutionsConfigure IPsec LAN-to-LAN (IOS/ASA) Configure SSL VPN (IOS/ASA)Configure Dynamic Multipoint VPN (DMVPN) Configure Group EncryptedTransport (GET) VPN Configure Easy VPN (IOS/ASA) Configure CA (PKI)Configure Remote Access VPN Configure Cisco Unity Client ConfigureClientless WebVPN Configure AnyConnect VPN Configure XAuth,Split-Tunnel, RRI, NAT-T Configure High Availability Configure QoSfor VPN Configure GRE, mGRE Configure L2TP Configure advanced CiscoVPN features

  Configure Cisco IPS to mitigate network threats ConfigureIPS 4200 Series Sensor Appliance Initialize the Sensor ApplianceConfigure Sensor Appliance management Configure virtual Sensors onthe Sensor Appliance Configure security policies Configurepromiscuous and inline monitoring on the Sensor Appliance Configureand tune signatures on the Sensor Appliance Configure customsignatures on the Sensor Appliance Configure blocking on the SensorAppliance Configure TCP resets on the Sensor Appliance Configurerate limiting on the Sensor Appliance Configure signature engineson the Sensor Appliance Use IDM to configure the Sensor ApplianceConfigure event action on the Sensor Appliance Configure eventmonitoring on the Sensor Appliance Configure advanced features onthe Sensor Appliance Configure and tune Cisco IOS IPS ConfigureSPAN & RSPAN on Cisco switches

  Implement Identity Management Configure RADIUS and TACACS+security protocols Configure LDAP Configure Cisco Secure ACSConfigure certificate-based authentication Configure proxyauthentication Configure 802.1x Configure advanced identitymanagement features Configure Cisco NAC Framework

  Implement Control Plane and Management Plane SecurityImplement routing plane security features (protocol authentication,route filtering) Configure Control Plane Policing Configure CPprotection and management protection Configure broadcast controland switchport security Configure additional CPU protectionmechanisms (options drop, logging interval) Disable unnecessaryservices Control device access (Telnet, HTTP, SSH, Privilegelevels) Configure SNMP, Syslog, AAA, NTP Configure serviceauthentication (FTP, Telnet, HTTP, other) Configure RADIUS andTACACS+ security protocols Configure device management and security

  Configure Advanced Security Configure mitigationtechniques to respond to network attacks Configure packet markingtechniques Implement security RFCs (RFC1918/3330, RFC2827/3704)Configure Black Hole and Sink Hole solutions Configure RTBHfiltering (Remote Triggered Black Hole) Configure Traffic Filteringusing Access-Lists Configure IOS NAT Configure TCP InterceptConfigure uRPF Configure CAR Configure NBAR Configure NetFlowConfigure Anti-Spoofing solutions Configure Policing Capture andutilize packet captures Configure Transit Traffic Control andCongestion Management Configure Cisco Catalyst advanced securityfeatures

  Identify and Mitigate Network Attacks Identify and protectagainst fragmentation attacks Identify and protect againstmalicious IP option usage Identify and protect against networkreconnaissance attacks Identify and protect against IP spoofingattacks Identify and protect against MAC spoofing attacks Identifyand protect against ARP spoofing attacks Identify and protectagainst Denial of Service (DoS) attacks Identify and protectagainst Distributed Denial of Service (DDoS) attacks Identify andprotect against Man-in-the-Middle (MiM) attacks Identify andprotect against port redirection attacks Identify and protectagainst DHCP attacks Identify and protect against DNS attacksIdentify and protect against Smurf attacks Identify and protectagainst SYN attacks Identify and protect against MAC Floodingattacks Identify and protect against VLAN hopping attacks Identifyand protect against various Layer2 and Layer3 attacks

电信运营商CCIE认证内容

  认证介绍:

  电信运营商CCIE认证(以前被称为通信和服务)表示网络人士在IP原理和核心IP技术(例如单播IP路由、QoS、组播、MPLS、MPLSVPN、流量工程和多协议BGP)方面拥有专家级知识,并且在至少一项与电信运营商有关的网络领域具有专业知识。这些领域包括拨号、DSL、有线网络、光网、WAN交换、IP电话、内容网络和城域以太网。

  备考用书:

  MPLS VPN 体系结构卷一

  MPLS VPN 体系结构卷二

  MPLS 流量工程

  高级MPLS VPN设计

  域间多播技术

  ……

  课程内容:

  .

  Bridging and Switching VTP, VLAN, Trunk, Spanning treeFrame Relay, DLCI, FR multilink ATM PVC, SVC, FR/ATM interworkingPPPoE

  IGP Routing IS-IS, Level 1/2, Metric OSPF, LSA, AreaRedistribution, Summarization, Filtering Policy routing

  EGP Routing IBGP, EBGP BGP attributes Confederation, Routereflector Synchronization, Aggregation, Stability Redistribution,Filtering Multipath

  SP Multicast PIM-SM, PIM-DM, SSM, PIM-BIDIR, IGMP Auto RP,Static RP, BSR, Anycast RP MP-BGP for multicast, MSDP

  MPLS Label distribution, LDP/ TDP Label filtering, Labelmerging, Multipath MPLS COS MPLS Netflow MPLS over ATM MPLS TrafficEngineering

  L3/L2 VPN MPLS VPN, MP-iBGP PE-CE routing, RIPv2, OSPF,EIGRP, Static, ISIS, EBGP BGP Extended Community Inter AS MPLS VPNCarrier Supporting Carrier VRF-Lite, VRF Select Multicast MPLS VPNGRE, multipoint GRE AToM, L2TPv3 802.QinQ

  SP QoS and Security DSCP/EXP, TOS, NBAR Marking, Shaping,Policing CAR, FRTS WRQ, CBWFQ, LLQ, PQ, CQ RED, WRED LFI, cRTP RSVPACL, RPF, Filtering Routing update security Common attacks

  High Availability NSF, GLBP Fast reroute, Link/Nodeprotection HSRP, VRRP

  Management SNMP, SYSLOG, RMON Accounting Netflow NTP

个人工具
名字空间

变换
查看
操作
导航
工具箱