
About this episode
Get every episode summarized
Each time Packet Protector publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
820 searchable segments. Every word is indexed and playable.
Full transcript
Packet Protector — PP126: Trying (and Failing) the CCIE Security Exam. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Welcome to Packup Protector, the podcast at the intersection of networking and security. I'm Drew Connery Murray here with Jennifer at the JJ Jabbush. Today we're going to talk about trying and failing. More specifically, our guest, Keith Tokash, wrote a pair of blogs on Packup pushers talking about taking but not passing the CCIE security exam. I have to say I really respect Keith for sharing these posts because failure is a hard thing to talk about. Technically, I feel like in this age of social media and LinkedIn where everything you put online has to be like, everything's great, always upward. So I really respect Keith for forgetting real. And frankly, sometimes you learn more from trying and not succeeding. So Keith, we're here to talk to you about your experience and what all of us might be able to learn from it. First off, welcome to the podcast. And I want people to know at the outset, you are not new to the certification game. Can you kind of walk us through the search you've already earned? Sure. I'll start saying I graduated with a Bachelor in Political Science in December, 1999.
I was a mid-year graduate. And with about two weeks later, I got my CCNA because I'd already been working on that because political science is not exactly a growth industry as far as jobs are concerned. So December, late December of 1999, I began this route, no pun intended. And then I, let's see, I think it was about two, I think 2002, I got the NP, the CCMP. And then back when it was four tests and then thought, well, okay, I'll do another one, get the DP, the design professional, which was one additional test. I passed the CIS SP twice because I didn't pay much attention to this, the continued energy education. I didn't feel too, I think I could have backfilled it, but I didn't feel all that honest about it because I hadn't been that active. I'd been kind of, you know, you straddle the fence and see, at some point, you have to
pick a team or you're going to be stuck, you really can't rise beyond a certain level until you focus. And so that's what I did. So I just went and took it again. So let's see what else. Oh, I should probably mention I passed the route, switch CCIE in 2008. Yes. That's actually how I am. Ethan. Ethan and I shared a class in Pasadena. We took Norbix class together. And then he passed soon after that. And I was about three months behind him. So he let me continue his, his blog at the time. Uh huh. Let's see what else, what else? Let's see my management. I wanted me to pass an eye told four tests a few years ago. I did that. I remember nothing. And I actually remember more of my political science stuff from 1999, but I did it. Uh, that sounds like par for the course for I tell like I've got the piece of paper. I never use it, but I got it. Yeah. I'll have to go look up every single term they use again if somebody quizzes me.
Uh, let me start. I'm sure I'm missing something in there, but um, but the general point is, oh, oh, yeah, yeah. Last year I actually wrote a couple of posts just like this one, but for the CWNA, the certified wireless network administrator. And I did the same stupid thing this time that I did last time, which is I didn't really research the certification. So I thought CWNA sounds like CCNA, it must be the entry tier because I don't know anything about wireless. I do that one. And it's the mid tier. So that was fun. Okay. So I spent six months studying for that one, but I actually did pass that one. Um, I think that's all of them. Okay. That's a good amount. So you've obviously got certifications. You're working your gamefully employed. Why did you want to take a swing at another industry cert? And why particularly in the security realm? Yeah. Well, that one that I was nudged in that direction by the more senior folks around me.
And what I should start by saying I'm a consultant. So it matters what's in the pipeline. And you know, I still find gameful employment, as you say, tapping on the CLI on a Cisco box, right? But the pipeline gets a little bit smaller every year for people who are who are typing Comf T router, BGP, you know, they it's just a little bit less work each year. So you look around the landscape and you just you just look at and you go, well, security and networking are are converging to a large degree. I have background knowledge in security. If some, you know, hands on with ice, although it's pretty dated, some hands on with firewall, this just seems like a logical fit. A lot of people are starting to move into zero trust, whether that be the full sassy or
just SSC or even just SD when I know that's not a zero trust base, but SD when with strong filters and then some some other tools tacked on. And it just made more sense. I did take some semesters of computer science. I've got basic programming skills in the sense that I know enough to be dangerous. I'm not interested in being a programmer. The cloud. I have mixed feelings about the cloud. I'm a big proponent of that old t-shirt says the clouds just someone else's computer. So I don't know it's and they keep changing how things set up every time I study something. I don't use it. And then six months later, it's semi obsolete, whatever I learn, like it's just a bad experience. I'll stick with security. I was just going to say I feel whole everything changing every few months is I feel like even
the cloud hosted networking platforms, I feel like, you know, every few weeks I log in and something is completely moved or a new features there that I don't know anything about or how you configure something is non-existent or moved or requires a new license now. So that's just a pain point I think we're all living with. Yeah. And then there's three major clouds too. So you're like, okay, which one? Oh, all of them. Oh, man. I guess. So I want to pull on that thread. You mentioned about the pipeline getting a little smaller. Do you feel like that's because what do you think is driving that? Is it automation? Is it cloud adoption? Why do you feel like that sort of traditional CLI knowledge is less in demand? Well, I think it's just a continuation of the trend we've seen in other areas of IT and computing. I remember, so I mentioned a couple or three semesters of computer science. That was in the early aughts after I actually had my bachelor's. I was like, well, maybe I go back and study something I can use. Right?
So, and I remember one of my professors saying we were learning VSC plus plus. That's how it has hold on. But it's a standard template library was booming already back then. So it was just based, it's just what it sounds like. You know, you don't write a module to do this or a function to do something. You just call one that's already there. And he said right off the bat, he's like, don't rewrite these. But you know, just approve yourself or or, you know, because you think it's cheating or something, these are battle tested. Just call the library. And he said at the time, something, I think, universalizes out to everything in our lives. People are scared of calling these library or these functions because they think that their skills will atrophy and they won't be good programmers anymore because they're relying on this other tool.
So what we're doing now is we're abstracting away the necessity to type conf.t, router, OSPF, etc., etc. Or we're just doing away with a lot of those, those lower level skills. Nobody codes an assembly anymore. Use higher level languages and then you move up the chain so you don't have to manage memory and everything. Well, now networking, which is I, I think along with databases, guys, we're the very conservative ones. But working, don't change anything because if you hit enter on one wrong command, everything stops. So we're behind, we're behind the curve, but we're finally getting there. They're abstracting out a lot of the minutia that I was supposed to be doing. And frankly, still am. I've recently troubleshot multiple spanning tree. I mean, talk about a blast from the past. I didn't even think anyone ever used it. But still there. Yeah.
Well, some environments, like you just, you can't, you can't go and dork around with them. They have to just stay up. Okay. That makes sense. But bringing it back to, okay, so you had good reasons for going to security. You had some experience there. You felt like there was also demand there. How did you choose, I think specifically was the 350 701 S Quar exam. How did you decide that was the one you were going to go for? Same way I screwed up with the CWNA. I thought, except this time I thought, okay, I don't have to start at the bottom. I'll start at the mid tier. So the CCNP. I didn't realize that it doubled as the CCE written. So I accidentally started studying for the CCE written. I'm not proud of it. But once I realized, I mean, it didn't take more than a minute when I got the book. I'm like, oh, oh, oh, okay. I'm like, okay, well, let's just give this a shot. I got six months.
And then I opened the book and started reading. And I was like, oh, man, I don't know about any of this stuff. I know the big picture stuff, the CIA, Triad, etc. Difference between worm, virus, Georgia. Okay, yeah, I got all that. But beyond the firewalls, ice, and some basic end user level experience with any connect stuff like that, I didn't do anything about any of that. So I kind of had to make a choice. And the choice was, it wasn't really a choice. It was like, okay, well, yeah, I don't know any of this. That's what the book is for. So just as the Brits like to say crack on, right? But the only problem is there was a time limit. And I didn't know, you know, it's been a long time since I studied anything at the level. The CWNA is no joke, but it's nothing like the CCIE. Like this is, this is a brutal, even before I went, I went, I went, I went, I went, a meritus on the route switch one after the 10 year mark because it used to take me three
months of study to pass it, even after passing the lab. So if you, if you're listening to this and you know, like, well, it's just a written exam. Yeah, technically, but it's no joke. It's no joke at all. Okay. And Keith, for those of us who aren't as entrenched in the Cisco certification portfolio, my understanding at least the last time I looked at this is like the CCIE has the written component and then like a hands-on component to it. Is it still like that or is it like one type of regular test, like multiple choice and then a written one that's a little bit more in depth? What is, what comprises it now? Okay. So you test, you take the written one and then that gives you a three year window if you assuming you pass it where you can schedule and then go take the lab exam. I haven't looked into the details of the logistics now, but in 2008 and I believe it's the same, you flew it to Cisco headquarters one of a half dozen or so locations where you
took a proctored lab. So you sat at a desk, they handed you a binder, well, at least in me, it back in 2008 they handed me two binders. One had a bunch of lab diagrams and information on how the network was configured. This is what you have and then they gave you a second binder with a bunch of requirements. This is what you need to accomplish and you got about, it's an eight hour exam, but you really have about five hours, tops, you have six to get that lab done because then you need to go for a small walk, come back and start it all over again. And I found two different mistakes that I made on that one that I know, I know I had done wrong. So I have no idea if I would have passed if I had needed the entire eight hours to go one one round through. So okay, you got the book and you started going through it.
Did you do other things to prepare for the written exam? Yeah, before I got it, I actually have access to Cisco's fire jumper videos and training that's kind of the pre-sale stuff. So I went through that, I got to level two, which is you can just do on their site. It's fairly low intensity, but it does tell you like, okay, these are the verticals, these are the product names, et cetera. This is what each one does. So you're not a babe in the woods anymore. You're still a little more like a toddler. And see, then to get to level three, you have to take at least one class and I did that. I took a, I got a two day class and Cisco secure access, you know, they end client that kind of ties a lot of things together on the end machine. Okay, so fire jumper is like, here's a crash course in how Cisco does. So client remote access. Yeah, okay. All their product suites, it's actually pretty valuable because if you have access, you
can just kind of go every time you have a slow afternoon, you can go take like a 20 minute course or something. Okay. And it is structured like a course in that they'll ask you questions at the end as they are ready. Yeah, I mean, they're easy. They're not geared. You know, that's one thing with the CCIE that you have to be ready for if you're not familiar with it. If you're good at taking tests, you can pass a lot of certification exams without knowing the material all that well. You could be sum up familiar. You could do that with the fire jumper stuff. You cannot do that with the CCIE level written stuff. They, they fair it you out. They find you and that that's that was me on that test. I'm pretty good at taking tests. If I know the material decent, I can usually pass the test. Not this one. Now they killed me. I was guessing on a lot of them. Like I mentioned in one of those blog posts, I can use basic logic and what I do know
on to get five question, or five answers to a question down to two. But I could never figure out which of the following two or the remaining two were correct. And I think they did that on purpose. I think they know what they're doing. Those test writers. That was good. They structured the exam. If you are like you said, you can sort of use logic and general experience to puzzle it out to two possible answers. There are two possible answers, but only one of them is right. Yeah. Or more more likely, both are right, but one is right. Yeah. Yeah. I called them a devious lot in one of those posts. They are. They are a devious law bravo. I got to say. Okay. So you had the book you were doing the fire jumpers. Did you do any like exam labs or anything or practice exams? Oh. Yeah. Well, I kind of a little more hands-on work via a partner company.
I don't know if I'm allowed to name them. So I guess I won't. But they have some hands-on labs so I could get in and kind of drill on FTDs, you know, the newer firewalls, things like that. But mostly it was reading and then I would take a practice exam and then I would go and I would jump on to Google Gemini and I would look up the answers and then I would retype them into my own little word doc in my own words. So AI is, I kind of used it as a glorified search engine, but I made sure that I understood the answer versus because I think one of the dangers of, you know, those practice exams is most of them only have about 300 or so questions. And if you're sitting for the CCIE, you're probably going to be at least capable enough. I'm trying to dance around calling us smart. You're probably going to be capable enough when you're reading these questions by the
third or fourth walkthrough of this practice exam. You read the third word in the question and you already know which answer it is. So you just accidentally memorize it. And so at that point, it almost loses all value. So you're like, this isn't helping anymore. I mean, I guess it's okay to drill it in, you know, drill in the knowledge every now and then. But if you're trying to use it as a study aid, it is very limited value. So I did four different vendors, a practice exams from four different companies. Yeah. Yeah. I went on, as again, I mentioned in one of those articles, I went on Reddit, which I frankly can't stand for a number of reasons. But I was desperate and I was like, okay, this is a $400 test. Am I ready? So I went on, you know, logged in and started looking around. No one knows. And that's one of the, that was one of my only beef with this, with this test and with the study material is, okay, I get wanting it to be difficult.
But at the same time, you can't, you can't set people up to fail by giving them a practice exam from Cisco, for example. And you know, I think I got like 94% on the last one. And I understood all the answers that I was giving. And then I go in and fail the test. That's not, that's not helpful. It's not good feedback if you're trying to, you know, match your performance on a practice exam to the actual exam itself. Correct. And the one that I, oh boy, I forgot the name, I'm bad with names, but I forgot. There's one specific vendor that I kept hearing was kind of the, the, the Cadillac, if you will, of, of these CCIE written exams and a bunch of other ones. And if you're routinely passing those, and again, you're not just memorizing, you'll be fine. It was not fine. So. And let me ask you this, Keith.
So I feel like, because we talked about like in your blog post, you talk about like, the trickery of words, right, wordplay and them, you know, trying to catch that. Those people in between, I'm good at taking tests and I've studied versus I can actually apply it. I kind of, so I have a big beef with a lot of certification programs, but I think the reason distills down to, there's, especially when you get into vendor certifications, there's this component of almost a pre sales. Do you understand how we position this product and the technical capabilities of the product? And there's the, can you configure this and to what degree and integrate with other things? But then the third piece that I feel like is missing a lot is the architecture, which transcends and has nothing to do with the specific vendor necessarily. But it's, you know, can you design and build something from scratch with or without the knowledge of the other two things, right? So, so you can do architecture without having vendor specific stuff, but you can also
do all of the nitty gritty configuration. I know how this thing works and the buttons to tap if you tell me exactly what you want. And you can do that without understanding the full picture of the architecture. So, and I'm sure in organizations you've worked with, there's, you know, sometimes there's architects who do the kind of high level planning and then there's the actual people that do the implementation and the configuration and the management. So my question for you and the whole like things are tricky and it's challenging and your comments around, you know, there's a difference between reading a bunch of stuff and actually getting to configure it and work through it. Where, where, you know, five or six dots get connected instead of just one data point. Where do you feel like in the whole understanding the portfolio, kind of as like almost pre sales, configuring it as an asset manager or owner and then architecting? Where did you feel the CCIE security sat in terms of, you know, was it a third, a third, a third? Was it more in the architecture space or was it super nitty gritty with the product config?
I'm going to have to give you a very unsatisfying, a lot of, a lot of every one of those because granted, I have not obviously taken the lab so I can't speak to that. You're expected to have a depth of knowledge across a wide breadth of solutions. So I would say they expect you to be able to configure them as a standalone and then integrate things. And that's actually probably the biggest thing that I face planted on when I was studying is by not building labs on my own. And I don't mean full CCIE labs. I mean, get an old server with a ton of cores and a ton of RAM, throw a hypervisor on there
and untangle whatever licensing and image, you know, requisitioning problems you've got to deal with. Get them on there, get two FTDs to start and build an IP sac tunnel between them. And then then build like a get VPN tunnel and then, you know, just work through all the technology so that you understand the FTD then add ice, you know, then add email filtering, which is going to be a whole mess because now you have to send emails. So it's like they're definitely expecting you to know each component in depth and then how they integrate and work with each other. And I just, it's too chaotic to try and learn that from a book. You have to read the book and, you know, on a lot of I don't think I'm saying anything revolutionary here. You have to read about it, then do it, then read about it some more, then do it.
And you just have to flip back and forth because if you just try to do it with your, you know, typing commands in whatever you can memorize how to get things done without understanding why they work. And then of course, if you like what I was doing was far too heavy on reading and far too light on doing. So I could, I could explain, you know, protocol interactions, but so what? You can't actually get the job done. So I was not you, I was not more useful to the end client. After six months, then I was before with some caveats that now I can participate more intelligently in some discussions, but so what? Were you able to use any of the like virtual lab platforms like even G or G and S three? There's another one that's popped up recently. I've seen some blog posts on.
Yeah. No, I just, I didn't get into that. I didn't have time because I looked it in. I was like, okay, first step. What are the server specs? Oh, man, this is, I mean, it's just once you walk down the path of building the lab, it's like you, you'd have to stop your study. Of the security material and start studying how to build a lab. Exactly. Which is absolutely worthwhile and everyone should do it, but you shouldn't do it when the clock is ticking. Yeah. Like, you know, if you have, say about two months, I think last, when I realized I am not ready for this at all. I really need to lab this stuff. Okay, that's too late. I only have two months. So it's, it's one of those, those, those forks in the road at which point I just say, I'm going to plow ahead on the reading. And that's why I don't begrudge those, those test writers at all for adding something that I just could not pass.
Because the CCE has a reputation, a good one, a great one. And if I had passed, I don't know. I think it would have punished the reputation because I don't think I deserve to. I just kind of, I was like, all right, well, I studied. Let's see how I do. And I feel like from a difficulty standpoint, there's a difference between asking a complicated question, like asking a question that you really need to know three or four things, even if it's a short question, to be able to answer. I think that's reasonably complex versus some of the weird twisty language, like I saw in your, you know, your other blog posts where they're trying to get you on wording, which is one of the things I hated about the early CISP exams. Where I feel like it was a, it was a language test, not a technical test. And I'm trying to trick you. I could test. Yeah. That's what yeah, because they're throwing triple negatives at you. Right. And, and you have 90 minutes or whatever to untangle what they're doing. And you're like, guys, does this, does this have anything to do with Infosack? Or you just, you just try to kick me in the shins.
Okay. So we know you didn't pass. You mentioned labbing is one thing that you would have done differently. Are there other things that you would do differently if you were going to approach this again? I think that was the main one. Just take your time. I didn't, again, I didn't realize when I bought that book, I was like, oh, six months. So then, you know, first off, the test was that much harder because they're double dipping into the CCI. Second, that's six months later. Again, it's a fork in the road. What do you do? Just go, just go. And, you know, it's, it's difficult to regret. Studying, you know, so I'm glad I did what I did. But in hindsight, I think I wouldn't have pressured myself to try and get through this material and pass a test. I think I would have gotten the book, start a bot. And then immediately bought the lab mocks, like started studying that and then set that up. And I think the, you know, going one product at a time, it's kind of the way Narbick,
if it goes to circle back to him, his CCI boot camps are structured differently than others. I took a different one as well back in 2008. And most of them were, hey, here's a bunch of labs and it's every technology. And they're almost together like the real lab, which is fine. Right. It's not a bad setup. And we're going to go through how, how to set these up. One lab per day will dissect it. Narbick, you know, you start off with back then frame relay was there underlying WAN technology to force you to really dig into the nuts and bolts of OSPF. And we're going to do that. And then only when we're conquered, we've conquered the frame, are we going to get into the spanning tree? And then we're going to build on top of that. And so I think I would have done that. Take it piece by piece and just heavy notes, maybe even blog postworthy detail,
because one thing that I really learned when I took over Ethan's old blog was, you know, you take notes. And then the next day you go back and read them and there's some things that even one day later don't make sense. Really, if you're, if you're going to polish it up for, to make sense to someone who wasn't there, you have to re-experience the pain. And you just got to, you just got to relearn it again. And it, it really did help. So I think I would do that. I would also advocate for that as, you know, not a network engineer, but I take a lot of briefings from vendors and we get into technical detail. And in the moment, I feel like, yeah, I got this. And then when I try to write a follow on blog about it, I'm like, ooh, okay, no, I need to dig in a little deeper and take a little more time and really get my thoughts together and figure out, do it. Did I really understand it? And sometimes go back and ask questions and so on. I think that which is why blogging your, your journey is can be so valuable because it does really force you
to confront yourself with, did I understand this? Because writing it down for somebody else to read really makes you question that and have to address it. And hopefully answer yes, I did understand this. Well, yeah, it also, it puts you in the hot seat to be correct. He goes, I can talk to you right now and talk about OSPF areas or whatnot. And, you know, it's verbal, it's, it's fleeting. Yeah. On site, put it down in writing and put my name on it. Oh, man, I better be right from the real embarrass. That's my reputation right there in 10 years from now, people can look that up and go, wow, I'm not hiring this guy. Or you just get a lot of well actually comments. Oh, yeah, yeah, exactly. After the first one, I just go, okay, point conceited. All right, you guys just stop hating me. Right. Yes. So, you know, given your exposure to the exam topics and the technologies, do you see this
exam is actually having practical value if people are looking to advance their networking or their cyber set career or is it more like if I'm going to run a Cisco shop, I should do it. I think it's, it's incredibly valuable. The reason that I picked Cisco for starters is they're the 800 pound gorilla. I mean, there's no, I mean, that's the biggest reason. Let's get that out of the way. It's the old nobody ever got fired for buying Cisco. You know, that's, I think they repurpose that for my BM. They did. But, but beyond that, Cisco actually has a full suite that integrates, not necessarily gracefully and not clearly because I mean, honestly, I'm not a violent man, but the amount of renaming and rebranding of their products is just infuriating. It's like, I have a diagram. I actually busted out of Visio and and, and, well, okay, here's, here's this name and, and then an arrow to the new one. And I got, I got something like 30 products.
It's, it's, it's infuriating. Some of them have been renamed like their firewalls. They've been renamed like four times. That's a big, own blog post and cheat sheet, by the way. Yeah. Yeah. It's, it's, it's, it's infuriating because a lot of the times it tests, especially if the training material isn't updated, then they're talking about a product that, that doesn't exist anymore. It's been renamed. In one case, I can't remember what it was. I had a, I had a test question that, that asked about it, something that I'd never heard of and it's because Cisco retired it or like a year or two ago. And it's like, man, it's, it's, it's a distraction. You're really trying to learn the technology and be useful. I mean, it's all about solving problems at the end of the day. And the, the problem I'm not trying to solve is, is Cisco's marketing strategy. So is there's a little bit of frustration there, but that said, they do have a full soup to not sweet. And I'm not, because I'm not enmeshed in that world yet.
I can't say which pieces of it are, are best of breed. But they are there. And one thing that Cisco, I think, does that pretty well is they, they, obviously they don't develop anything in house anymore. That's, that's really worth using. I actually, I think one of the four people in the world that, that worked on their, their early SD WAN CLI based solution, I forgot what he was called. It was, oh, God, it was atrocious. Yeah. Read a 700 page book on that and then threw it away because they, they threw it away. They did. But what they do is they buy something. They, they mess with it and irritate everybody who was already using it. But then they stick with it for a good 10 years. I remember when they did that with snort and I actually wrote the snort configuration guide for free. BSD back in, I want to say 2002, I maintained that for maybe a year or so. And I remember when the Cisco bought snort and everybody was super angry because they were turned it into like a,
a four U, seller on box for $20,000 or something. And, but what they've done since is they stick with it and they end up making a pretty good product. So the fact that they have an A to Z suite means that I'm going to have to learn A to Z. If I just follow their curriculum and that's what the, that's what the cert was for. I just wanted the curriculum. I don't, I already have a CC. I don't need another one. My employer's not going to give me a raise on the, my, the, the clients that I work on probably won't even know what I'm talking about. If I mention it, I wanted the curriculum and also the light at the end of the tunnel. You know, you, you, you, you put your head down and you start working on this stuff. There's a, to borrow from economists and there's an opportunity cost. Yeah. I have other books that I want to be reading that hack. How honestly have nothing to do with tech. That you put that whole shelf back there. There's one tech book on it. I like other things too. And I have to stop so I can really head down, barrel forward, learn the stuff.
I want a finish line. So I can, I mean, I'm not going to finish for good. I'll come back in six months, but I want to do other stuff. And that's what I think that the certs in general give you a curriculum and a finish line. And then the Cisco one specifically gives you that breath of the product suite that really does everything. Even if it's not the greatest at the moment, you know, can, can you learn Cisco secure access and then move to Nesco? Of course you can. You know, I got the route switch CCI, but then I was working on Junipers. And though if you're familiar with Juniper CLI, it's wildly different. I actually preferred it for complex tasks, but it's wildly different from Cisco. But I already knew a BGP bid. I knew how to configure it. All I had to do was translate. So I've seen the accusation that it's just a Cisco training tool. I would argue with the word just.
It is a Cisco product training tool. Absolutely. But okay, so I know I know how to use Cisco ice. Now that means I had to get into the nitty gritty of radius attributes. I had to tie it into duo, but can I tie it into a different identity manager? Of course I can. All I got to do is look up a how to. I understand exactly how the technology works. Yeah, there is a lot of value to that actually. The hard part was Cisco though is sometimes they teach very Cisco specific language. And I went into people that like if only done a Cisco, only touch Cisco and only done Cisco training and don't know the context of that thing outside of the way Cisco implements it. And it's the name with the trademark at the end instead of an IEEE term for something. So I think, but if you understand the concepts, then it's yeah, it's a language problem of what does somebody else call this? And that's easier than I don't know what this is or what it's supposed to do.
Right. You don't have to explain to somebody with the CCIE or even a CCNA that routing and switching are different. So they may have only learned it via a Cisco book, but they know. So you just go, okay, well, what we use, we use Juniper's here. Well, they still know that routing and switching are different. This is it's they're far further down the path. Yeah. So in the second post you wrote, you mentioned wanting to spin up a lab and actually work on things. So you can learn to solve cybersecurity problems, which sounds to me like a different golden getting assert. So that I've got kind of two questions off of that thought. Well, I guess we sort of answered this first one. Do you see an overlap in training to pass a cert and actually learning to solve problems? Or are they separate things? I think you would probably say that's a deep but there's still value. Yeah, that's that's actually I would say that's probably the underlying question.
We all need to answer when we look at a certification because the you go deeper down underneath that question. There's there's a really interesting one. You keep going. I like to think of it as trying to find the bottom turtle. And the bottom turtle in this this scenario is human nature. Humans are lazy. We will we will take the shortest path between two points. So what what's the problem you're trying to solve? And you got to make sure that the problem you're trying to solve is aligned with the the the subject matter on the test. The methodology of that the test is using to measure that. And the difficulty level. So I'm going to stop babbling and abstracts here. If you can pass a test and still not know how to do the the job that the test was testing you for it's a crappy test. And that's why I think the CCIE is still retaining its value 30 some odd whatever years
down the line is they don't let you take shortcuts. So if there's a way I can type a few commands and get a job done without understanding what those commands are actually accomplishing then I'll do it. And not because I'm lazy but because I'm human. Everybody does that. You see it in college is nowadays. The students just use AI. Why? Because they're not interested in the knowledge. They're not interested in learning to solve any of the problems that the knowledge reports to help them solve. So why not just cheat? Right? Just get the AI to do the work for you. And then they come out with they've got the credential. They got the piece of paper, the certificate. And they're better off for it because reasons. I don't want to get into that but. But the CCIE on the flip side. I want to just kind of pitch this at you and play devil's advocate for a second. Kind of the way if you were saying well I'd like to spin up a lab but I don't want to get
derailed with spinning the lab up when my goal is really this other thing over here. I do feel like there's this middle ground of if there's a faster path to offload certain things. I've gotten lazy over the years. You know I spent a long time hands on keyboard. And after a while it's just like I don't want to have to remember every CLI command and whether I have to do this command before that command. I want to be able to get to a point where we have like full intent based networking where it's like here's how this should work. You should auto configure yourself to do that once I've once I've explained to you how I want the architecture right. So I kind of feel like both of these on the flip on the flip side of that is. You can't architect if you don't understand how all the pieces work independently end together and you don't understand the protocols and you you'll never be able to architect and troubleshoot. But I do think there's a place in the middle where people can be lazy and say okay somebody else is doing the the architecting somehow and somebody else is responsible for troubleshooting.
But let me lazily do this thing because my goal is not learning this thing. My goal is this other in state over here. Yes. So that's that's adding abstraction layers. And that yeah that's just like standard template library did right. You just I don't want to have to remember how to code an assembly. I don't want to have to climb the ladder every single time. You know it's the old cliche of reinventing the wheel. At some point you just have to buy a wheel and use it because you have other things that you need to get done. And that's fine. We're not there yet. And I think that that it was analogized as to a ladder because at some point because that every layer of abstraction is a wrong on the ladder and you climb higher and higher. And eventually you get to if you remember the old movie Logan's run. Did you ever see that? Oh yeah. Yeah. So you have a bunch of people sitting in a city, a domed city that every all of their environmental controls, all their needs are being met by machines. And no one has any idea how the machines work. Yeah. Yeah. With that's great.
Until the machine stops working. So there's always going to be the need for us gear heads running around. It's just there's so much to know now that that we have to cordone smaller and smaller slices of knowledge. So I don't know where that leaves us. And maybe Uncle Elon is going to augment our brains or something so we can all keep up. But yeah, it's overwhelming. So what are you doing next with this specifically? And then let's broaden that a little bit. Well, for the last three weeks, I've been reading happily every morning books that have nothing to do with Cisco or security. Just all the time that I was taking, I'm reading, I'm writing other things. But after a few months of that, I'm going to ignore the actual study material, study how to
build a lab, do that. And then I'm just going to play in the mud like a happy little boy. And I'm going to learn how to do the things that I was reading about because it's actually, it's a lot more satisfying as well to get those FTDs up even if they're just virtualized on one box in the other room and build that IP-Sack tunnel. And then I don't know how many people remember the first time they messed around with two Cisco routers and configured loop back addresses on two routers and then advertise them into a protocol. And then you could ping across the direct connection and it was like, oh, I did something, right? It was more exciting than reading the book saying, and here's how you redistribute this interface or static router, whatever it might be into a EIGRP. Like, no, you actually do that. So that's what I want to do. And I actually get there.
And I think that that's at the end of the day, you're going to keep asking yourself, because you get on, you drift. So you got to jerk yourself back on course, go, what's the problem I'm trying to solve? Well, not to sound too meta. It's the ability to solve problems. I want to solve problems. And it gives me a genuine visceral satisfaction to solve problems. And so reading about them allows me to talk about solving problems. I don't want to do that. I want to solve them. So that's what I want to do. I'm going to take that time and I'm going to build that box and I'm going to get in there. And at the end of the day, like I mentioned, I don't need a CCI. I don't even need the NP. I mean, it's nice. And I think my bosses will appreciate it. And it might even help if we need to, I don't know, do some pricing negotiations for security goods. That's fine. I'll do it. I don't mind. But that's not my end goal. My end goal is, okay, a client has a need.
And they need to, for example, tie, I should say move to zero touch or zero trust. To trust. Access. And they need an endpoint client. They need to integrate multi-factor authentication. And they want to avoid dragging all their traffic back to a data center. I need to know how to do that. Yeah. So I wanted to make sure we mentioned this in terms of lab options. There's also container lab and net lab, net lab from Avon Peppelnyak. So something to think about for folks who are thinking about labs. That's a big name. Yeah. Yeah. I'm not sure how, I think they might be better suited to your use case. Keith, in terms of, I just need to learn how to do stuff. I don't know if you want to use them necessarily for a specific certification, but certainly for folks listening worth looking into their capabilities. Yeah. Thanks. I'll actually look into that. Yeah. Please too. All right. Well, we'll come into the end of this conversation. Keith, but again,
really appreciate you taking the time to share your experience and to write to really good blog posts, which we'll link to in the show notes, but you can also find them at packappurchase.net. But I just wanted to leave folks with maybe a couple of takeaways in terms of one. Don't be afraid of trying and failing. Like, it's okay. And there is value in it. But that's just me saying, do you feel like this process was still valuable to you, even though it didn't work out? Absolutely. Like I said, I can't solve problems. I can talk about them now. But I'm a lot closer to solving problems than I was before I started. And that's one thing I, I'm going to tie this back into something a little as a tariff. I did you did too for years. And every single night, you step on that mat, you lose every single night. Unless you are the top guy in the gym, in which case, you still sometimes lose, but every single time you lose. And yeah, after a while, you build up
calluses, you go, I don't know, the care. I'm going to crush this. I'm going to crush this. Whatever it is in front of me, I'm going to, and sometimes you don't, sometimes I crushed you. So you get back up and you just do it again. Who cares? Yeah, love it. And second thing, any advice for folks who are considering certifications or other mechanisms for career advancement? Oh, yeah, sure. If you again, go back to what's the problem you're trying to solve in my Reddit minutes that I spent on Reddit. Somebody asked whether or not he should, he should try a CCE or a computer science degree. And my answer was the same. What's the problem you're trying to solve? If you want to computer science is not vocational training. It's, it's the study of what can be computed. If that's, if that's your drive, then go do it. But if you're looking for a job, do the CCE. It's task oriented. It's vocational training. It's intense. But if you're new, don't, don't try to jump rungs and just jump to this. It's not worth it. It's not worth it.
You're going to have to go back. You're going to have to start over. Take your time. Focus on actually understanding the material. As I mentioned, one of those posts, the CCE is, is so tricky because they want to make sure you cannot be tricked. I had a coworker who immediately after getting a CCE back, maybe about 15 years ago, got the Juniper version, the JNCIE. He said, it was a lot easier. Now part of that was he was already a CCE. So again, he knew, he knew how to redistribute protocols without causing a loop, all that stuff. But he said, they just asked you the question. They didn't, and again, this was, I don't know if they changed it. It was like 2009 or something. They didn't try and trick you. So I don't know. There's merit to both. But who cares? Just go. Just start pounding it out and just keep going. I think I guess wrapping up, I would just
reiterate what Drew said about. Don't be afraid of failing an exam, especially a professional exam. I think there's this weird taboo, both in any technology curriculum and cybersecurity, where people feel like we need to have all of the answers and be, you know, meet some bar that we've set for ourselves. And this industry, the velocity of the change of the industry, the solutions of technology and how they work is too fast for anybody to keep up with. Unless you have such a narrow scope and you do it all day every day. And I kind of think it's, it makes more sense when I manage an engineer and engineering team, one of the things I would tell people is like, don't stress and study for weeks and weeks and months and months. Now CCI is a little different. But in general, don't you will stress. You will stress. The diminishing returns after a while. That is just this thing that you dread. So like, study a little bit. Go take it. Expect to fail it. And that's fine. But now you understand two things. It is what do you need to study and to what depth? What more hands on do you need? Because now,
do we need to get lab equipment, etc. for you? And or if this is an optional exam, because sometimes you have to do them and sometimes they're, they're the engineer is selected to do it. Is this still, does this get you to Keyes Point where you wanted to go? Or is this so off the rails to the side that it's not, it's not in line with your objectives? So figure that out before you spend a lot of time and energy. And if you failed the exam the first time, so what? Now you know what to study for. You've made the best use of your time. And then you'll go back if it makes sense and take it again. And you certainly won't be the first person ever who failed to see you or any other exam. Yeah, that's fine. And you know, to Keyes Point about, you know, trying to trick so that you can't be tricked. I think in dance, we used to say, practice and don't practice until you get it right. Practice until you can't get it wrong. And I think that's the tone probably they're looking for. I think a lot of the exams I've seen recently get so twisty with the language it defeats the
purpose. And you lose the technical component of the technical evaluation in that because now you're can you handle double negatives and triple negatives? So yeah, it's just an IQ test. Yeah, it's not an IQ test. But some of the tests will give that to you and just know that that's part of the crappy part of the game that we play and do it that what you will. So Keith, I mentioned the blog post you wrote will have links to the show notes. Are you elsewhere online? You mentioned some books you wrote where can folks find you? Oh, yeah. Well, I read under a pen name because yeah, but the two that I wrote under my own name are actually first person satire is based on the Iliad in the Odyssey. Oh, well, okay. Because I told you I have other interests very timely. Yeah, I don't care enough to even push them anymore. It was like five, eight years ago or something. But yeah, you can find them on Amazon. Okay, I'll have that link in the show notes. And I said from that I try and I don't tell people where I work anymore. I don't tell people
where I live, even the city or state. I don't tell people anything anymore. It's a really shame. I really like people. And I used to kind of like, you know, that cheesy banner in your high school that said, uh, strangers are only friends you've never met. I actually lived like that. And then I was forced on multiple occasions to stop. Okay. Well, I think you're on LinkedIn though. So are you at least accepting folks on LinkedIn or I'm accepting folks on LinkedIn. I do not share where I work. That's fine. Totally. Yeah. You're welcome to have some privacy. We all need more of it, I think. Yeah. Well, Keith, thank you so much. One for writing the posts for sharing your experience. And then two for giving us even more time to talk about it to dig into it. Really appreciate it. I love this episode. I hope other folks get something out of it. So thank you so much for that. And of course, to the people listening, thank you for being here for this episode of Pack of Protector. If there are things you want us to cover or if you've got a comment to correction or a question about anything you just heard, you can reach out to us at packupwishers.net slash FU. The FU is for follow up and we do love one listeners reach out. And just to let you know,
Pack of Protector is part of the larger Pack of Pushers podcast network. We've got podcasts on networking IPv6 DevOps, professional development leadership and more. We also have a Slack group you can join for free. Our YouTube channel, we can watch us if you don't just want to listen. We even have an IRC group plus two industry newsletters. All at Pack of Pushers are that and always free no login required. Thanks for listening.
More episodes
More from Packet Protector

PP125: News Roundup—Cyberattack Impacts Pacemakers, OpenAI Publishes Eye-Opening...
Packet Protector

PP124: How Coruna, DarkSword, and Other Exploits Slice Up Apple iPhones
Packet Protector

PP123: Using Gridctl to Keep MCP Configs From Leaking Secrets
Packet Protector

PP122: Using Burp Suite to Understand How Apps Collect and Share Our Data
Packet Protector