Implementing Core Cisco ASA Security (SASAC)



Similar documents
VPN_2: Deploying Cisco ASA VPN Solutions

Deploying Cisco ASA VPN Solutions

To participate in the hands-on labs in this class, you need to bring a laptop computer with the following:

For Sales Kathy Hall

Evaluating the Cisco ASA Adaptive Security Appliance VPN Subsystem Architecture

Cisco Certified Security Professional (CCSP)

Securing Networks with Cisco Routers and Switches ( )

Implementing Cisco IOS Network Security

Cisco ASA 5500-X Series ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, and ASA 5555-X

IINS Implementing Cisco Network Security 3.0 (IINS)

Cisco Certified Network Expert (CCNE)

Managing Enterprise Security with Cisco Security Manager

SSECMGT: CManaging Enterprise Security with Cisco Security Manager v4.x

Implementing Cisco Secure AccessSolutions Exam

Securing Networks with Cisco Routers and Switches 1.0 (SECURE)

Managing Enterprise Security with Cisco Security Manager

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release

Implementing Cisco IOS Network Security v2.0 (IINS)

Securing Networks with PIX and ASA

Implementing and Administering Security in a Microsoft Windows Server 2003 Network

How To Set Up A Cisco Safesa Firewall And Security System

CCNA Security. IINS v2.0 Implementing Cisco IOS Network Security ( )

TABLE OF CONTENTS NETWORK SECURITY 2...1

Cisco ASA. Administrators

CNS-207 Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

Interconnecting Cisco Networking Devices: Accelerated (CCNAX) 2.0(80 Hs) 1-Interconnecting Cisco Networking Devices Part 1 (40 Hs)

The IINS acronym to this exam will remain but the title will change slightly, removing IOS from the title, making the new title

Cisco ASA, PIX, and FWSM Firewall Handbook

Scenario: Remote-Access VPN Configuration

"Charting the Course...

"Charting the Course... Implementing Citrix NetScaler 11 for App and Desktop Solutions CNS-207 Course Summary

TABLE OF CONTENTS NETWORK SECURITY 1...1

Cisco AnyConnect Secure Mobility Solution Guide

INTEGRATION GUIDE. DIGIPASS Authentication for Cisco ASA 5505

Workspot Configuration Guide for the Cisco Adaptive Security Appliance

ACADEMIA LOCAL CISCO UCV-MARACAY CONTENIDO DE CURSO CURRICULUM CCNA. SEGURIDAD SEGURIDAD EN REDES. NIVEL I. VERSION 2.0

Cisco ACE Application Control Engine: ACEBC Catalyst 6500 and 4710 Applicance Boot Camp

Scenario: IPsec Remote-Access VPN Configuration

CCNA Security 2.0 Scope and Sequence

Cisco Certified Network Associate - Design

Configuring SSL VPN on the Cisco ISA500 Security Appliance

(d-5273) CCIE Security v3.0 Written Exam Topics

Implementing Secured Converged Wide Area Networks (ISCW) Version 1.0

Cisco EXAM Implementing Cisco Secure Mobility Solutions (SIMOS) Buy Full Product.

Interconnecting Cisco Networking Devices Part 2

Configuring IPsec VPN with a FortiGate and a Cisco ASA

How To Configure SSL VPN in Cyberoam

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

Microsoft Administering the Web Server (IIS) Role of Windows Server

ASA 8.X: Routing SSL VPN Traffic through Tunneled Default Gateway Configuration Example

How To Learn Cisco Cisco Ios And Cisco Vlan

Cisco Virtual Office Express

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Cisco ASA

CNS-208 Citrix NetScaler 10 Essentials for ACE Migration

CCIE Security Written Exam ( ) version 4.0

ASA 8.x: VPN Access with the AnyConnect VPN Client Using Self Signed Certificate Configuration Example

Citrix NetScaler 10.5 Essentials for ACE Migration CNS208; 5 Days, Instructor-led

Cisco Discovery 3: Introducing Routing and Switching in the Enterprise hours teaching time

Citrix NetScaler 10 Essentials and Networking

Foreword Introduction Product Overview Introduction to Network Security Firewall Technologies Network Firewalls Packet-Filtering Techniques

Security Threats VPNs and IPSec AAA and Security Servers PIX and IOS Router Firewalls. Intrusion Detection Systems

SNRS. Securing Networks with Cisco Routers and Switches. Length 5 days. Format Lecture/lab

Description: Objective: Upon completing this course, the learner will be able to meet these overall objectives:

Cisco Certified Security Professional (CCSP) 50 Cragwood Rd, Suite 350 South Plainfield, NJ 07080

Configure ISE Version 1.4 Posture with Microsoft WSUS

PIX/ASA: Allow Remote Desktop Protocol Connection through the Security Appliance Configuration Example

Implementing Cisco Secure Mobility

Interconnecting Cisco Networking Devices, Part 2 Course ICND2 v2.0; 5 Days, Instructor-led

Troubleshooting and Maintaining Cisco IP Networks Volume 1

Licenses are not interchangeable between the ISRs and NGX Series ISRs.

ESET SECURE AUTHENTICATION. Cisco ASA Internet Protocol Security (IPSec) VPN Integration Guide

CCNP Security SECURE

Cisco Adaptive Security Appliance Smart Tunnels Solution Brief

ASA Remote Access VPN with OCSP Verification under Microsoft Windows 2012 and OpenSSL

ESET SECURE AUTHENTICATION. Cisco ASA SSL VPN Integration Guide

AnyConnect VPN Client FAQ

1Y0-250 Implementing Citrix NetScaler 10 for App and Desktop Solutions Practice Exam

Interconnecting Cisco Networking Devices, Part 1 (ICND1) v3.0

- Introduction to PIX/ASA Firewalls -

Cisco Application Control Engine Appliance

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP Edge Gateway for Layered Security and Acceleration Services

F5 BIG-IP: Configuring v11 Access Policy Manager APM

How To Authenticate An Ssl Vpn With Libap On A Safeprocess On A Libp Server On A Fortigate On A Pc Or Ipad On A Ipad Or Ipa On A Macbook Or Ipod On A Network

Enabling Multiple Wireless Networks on RV320 VPN Router, WAP321 Wireless-N Access Point, and Sx300 Series Switches

Table of Contents. Introduction

CNS-208 Citrix NetScaler 10.5 Essentials for ACE Migration

IOS NAT Load Balancing for Two ISP Connections

Interconnecting Cisco Network Devices 1 Course, Class Outline

SSL-TLS VPN 3.0 Certification Report. For: Array Networks, Inc.

Network Simulator Lab Study Plan

Cisco Actualtests Exam Questions & Answers

Tech-Note Bridges Vs Routers Version /06/2009. Bridges Vs Routers

How To Manage A Netscaler On A Pc Or Mac Or Mac With A Net Scaler On An Ipad Or Ipad With A Goslade On A Ggoslode On A Laptop Or Ipa On A Network With

: Interconnecting Cisco Networking Devices Part 2 v1.1

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

Cisco ASA. Implementation Guide. (Version 5.4) Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

COURSE AGENDA. Lessons - CCNA. CCNA & CCNP - Online Course Agenda. Lesson 1: Internetworking. Lesson 2: Fundamentals of Networking

Cisco ASA Adaptive Security Appliance Single Sign-On: Solution Brief

Configuring the Transparent or Routed Firewall

Cisco Adaptive Security Device Manager Version 5.2F for Cisco Firewall Services Module Software Version 3.2

Transcription:

1800 ULEARN (853 276) www.ddls.com.au Implementing Core Cisco ASA Security (SASAC) Length 5 days Price $6215.00 (inc GST) Overview Cisco ASA Core covers the Cisco ASA 9.0 / 9.1 core firewall and VPN features. This enhanced course contains added depth to the standard labs, using a topology that simulates a typical production network. You'll use ASA 5515 appliances to work through configuring access control to and from your network. Additionally, the PC systems and server systems are an integral part of the lab environment. Here you will use Windows 8, Windows Server 2012, and Kali Linux to manage, test, and even attack your lab network using real-world operating systems and applications. Skills Gained Upon completing this course, the learner will be able to meet these overall objectives: Essentials of Cisco ASA Basic connectivity and device management Network integration Configure common features of the Cisco ASA OS Cisco ASA policy control Core Cisco ASA VPN common components Main VPN components Cisco clientless VPN solutions Cisco AnyConnect full tunnel VPN solution Cisco ASA high availability and virtualization options Features of Cisco ASA 5500-X Series Next-Generation Firewalls Key Topics 1. Cisco ASA Essentials Firewall Technologies Cisco ASA Features Cisco ASA Hardware Cisco ASA Licensing Options Cisco ASA Licensing Requirements 2. Basic Connectivity and Device Management Managing the Cisco ASA Boot Process Managing the Cisco ASA Using the CLI Managing the Cisco ASA Using Cisco ASDM Navigating Basic Cisco ASDM Features Managing the Cisco ASA Basic Upgrade Managing Cisco ASA Security Levels Configuring and Verifying Basic Connectivity Parameters Configuring and Verifying Interface VLANs Configuring a Default Route Configuring and Verifying the Cisco ASA Security Appliance DHCP Server Troubleshooting Basic Connectivity

3. Network Integration NAT on Cisco ASA Security Appliances Configuring Object (Auto) NAT Configuring Manual NAT Tuning and Troubleshooting NAT on the Cisco ASA Connection Table and Local Host Table Configuring and Verifying Interface ACLs Configuring and Verifying Global ACLs Configuring and Verifying Object Groups Configuring and Verifying Public Servers Configuring and Verifying Other Basic Access Controls Troubleshooting ACLs Static Routing Dynamic Routing EIGRP Configuration and Verification Multicast Support 4. Cisco ASA Policy Control Cisco MPF Overview Configuring and Verifying Layer 3 and Layer 4 Policies Configuring and Verifying a Policy for Management Traffic Layer 5 to Layer 7 Policy Control Overview Configuring and Verifying HTTP Inspection Configuring and Verifying FTP Inspection Supporting Other Layer 5 to Layer 7 Applications Troubleshooting Application Layer Inspection 5. Cisco ASA VPN Common Components VPN Definition Key Threats to WANs and Remote Access VPN Types VPN Components Cisco ASA VPN Policy Configuration Cisco ASA Connection Profiles Cisco ASA Group Policies Cisco ASA VPN AAA and External Policy Storage Cisco ASA User Attributes Access Control Methods VPN Accounting Using External Servers Dynamic Access Policy for SSL VPN Using PKI Provisioning Server-Side Certificates on the Cisco ASA Adaptive Security Appliance CA Servers Deploying Client-Based Certificate Authentication SCEP Proxy Operations Enable Certificate Authentication in Connection Profile Configuring Certificate-to-Connection Profile Mappings 6. Cisco Clientless VPN Solution Cisco Clientless SSL VPN Cisco Clientless SSL VPN Use Cases Cisco Clientless SSL VPN Resource Access Methods Secure Sockets Layer and Transport Layer Security SSL Session Setup and Key Management SSL Server Authentication SSL Client Authentication SSL Transmission Protection Basic Cisco Clientless SSL VPN Server Authentication in Basic Clientless SSL VPN Client-side Authentication in Basic Clientless SSL VPN

Clientless SSL VPN URL Entry and Bookmarks Basic Access Control for Clientless SSL VPN Disabling Content Rewriting Basic Clientless SSL VPN Configuration Tasks Basic Clientless SSL VPN Configuration Scenario Configuring Basic Cisco Clientless SSL VPN Verify Basic Cisco Clientless SSL VPN Troubleshooting Basic Clientless SSL VPN Operations Cisco Clientless SSL VPN Application Access Overview Application Plug-Ins Configuring Application Plug-ins Verify Clientless SSL VPN Application Plug-Ins Troubleshooting Clientless SSL VPN Application Plug-Ins Smart Tunnels Configuring Smart Tunnels Verifying Smart Tunnels Troubleshoot Smart Tunnels Client-side Authentication Options Client-side Authentication and Authorization Using AAA Server Double Client-side Authentication Using AAA Servers Troubleshooting Client-side AAA Authentication 7. Cisco AnyConnect Full Tunnel VPN Solution Basic Cisco AnyConnect SSL VPN SSL VPN Clients Authentication SSL VPN Clients IP Address Assignment SSL VPN Split Tunneling Configuration Scenario Configuration Tasks Enable AnyConnect SSL VPN Define IP Address Pool Configure Identity NAT Configure Group Policy Configure Group Policy: Split Tunneling Configure Connection Profile Monitor AnyConnect VPN on Client Monitor AnyConnect VPN on Server Cisco AnyConnect SSL VPN Solution Components DTLS Overview Parallel DTLS and TLS Tunnels Configure DTLS Verify DTLS Cisco AnyConnect Client Configuration Management Managing Cisco AnyConnect Software from Cisco ASA Cisco AnyConnect Client Operating System Integration Options Deploying Cisco AnyConnect Trusted Network Detection Cisco AnyConnect Start Before Logon Deploying Cisco AnyConnect Start Before Logon Cisco AnyConnect Advanced Authentication Scenarios Certificate-Based Server Authentication Client Enrollment Methods Methods for Revoking Credentials Enable Certificate-Based Authentication Enable Two-Factor Authentication Two-Factor Authentication with Name Pre-Fill Local Authorization Overview Local Authorization Configuration Procedure Configure Local Authorization Verify Local Authorization External Authorization Scenario Configure Authorization Using LDAP/AD Verify External Authorization Troubleshooting Cisco AnyConnect VPN AnyConnect Support for IKEv2

Internet Key Exchange v1 and v2 Making IPsec the Primary Protocol for a Host Entry IKEv2 Configuration Procedure Configure a Cisco AnyConnect IPsec VPN on a Cisco ASA Verify and Troubleshoot Cisco AnyConnect IPsec VPN on Cisco ASA 8. Cisco ASA High Availability and Virtualization Labs Configuring and Verifying EtherChannel Configuring and Verifying Redundant Interfaces Troubleshooting EtherChannel and Redundant Interfaces Configuring and Verifying Redundant Interfaces Troubleshooting EtherChannel and Redundant Interfaces Multiple-Context Mode Configuring Security Contexts Verifying and Managing Security Contexts Configuring and Verifying Resource Management Troubleshooting Security Contexts Self Study (optional) Active/Active Failover Configuring and Verifying Active/Active Failover Tuning and Managing Active/Active Failover Troubleshooting Active/Active Failover Lab 1: Remote Lab Environment Lab 2: ASA Administration and Network Integration Lab 3: Network Address Translation Lab 4: Access Control and Troubleshooting Lab 5: MPF Basic Application Inspections Lab 6: MPF Advanced Application Inspections Lab 7: Basic Clientless SSL VPN Lab 8: Clientless SSL VPN Applications Lab 9: External AAA for Clientless SSL VPN Lab 10: Lab: Basic AnyConnect SSL VPN Lab 11: Advanced AnyConnect SSL VPN Lab 12: IPSec Remote Access VPN Lab 13: Active-Standby High Availability Target Audience Network engineers supporting Cisco ASA 9.x implementations Prerequisites Knowledge of the Cisco ASA IINS 2.0 - Implementing Cisco IOS Network Security The supply of this course by Dimension Data Learning Solutions Pty Ltd is governed by the booking terms and conditions. Please read the terms and conditions carefully before enrolling in this course, as enrolment in the course is conditional on acceptance of these terms and conditions.

2015 Dimension Data Learning Solutions. All Rights Reserved