CCIE Security
CCIE Security - Lab Preparation
|
Who Needs to Attend |
This class is designed for candidates who are within 6 months of their CCIESEC lab date. The class also covers introductory material and candidates are expected to be at a minimum CCSP level knowledge of the topics covered in order to receive full benefit of the class.
|
Prerequisites |
The skills and knowledge required for delegates to attend this course are as follows:
- At least 2 years hands-on experience with Cisco Security and SAFE Blueprint architecture.
- Students should have passed the CCIE Security Written exam and may already hold some of the security certifications such as CCSP, etc.
|
Course Description |
ASA/PIX Firewall
- Initial Configuration of PIX/ASA
- Routing
- Translations and Connections
- Access Control Lists and Object Groups
- Deep Packet Inspection
- Control URL's and FTP commands using
- MPF
- Running BGP thru the Firewall
- TCP Normalization
- Transparent Firewall
- ARP inspection on Firewall
- Virtual Firewalls (Security Contexts)
- Active/Standby Failover
- Stateful Failover
- Active/Active Failover
IPSEC/VPN
- LAN-to-LAN IPSec using NAT-T
- IPSec Hairpinning
- EZVPN in Client and Network Extension Mode
- QoS with IPSec
- DMVPN thru the Firewall
- Basic Configuration of VPN Concentrator
- Routing on the Concentrator
- Administration and Filtering on the
- Concentrator
- LAN-to-LAN Tunnel on the Concentrator
- EZVPN on the Concentrator in Client Mode
- EZVPN on the Concentrator in Network
- Extension Mode without XAUTH
- Remote Access on the Concentrator with
- RRI and Split Tunneling
IPS Sensor
- IPS in Promiscuous Mode
- SPAN/RSPAN
- Blocking Using ASA
- IPS in Inline Mode - Interface Pair and
- Inline VLAN Pair
- Signature Tuning
- Custom Stream Signatures
- Custom HTTP Signatures
- Custom Packet Signatures
Access Management
- Configuring ACS for Network Devices
- Configuring Users and Groups on ACS
- Server
- Configuring Routers, Switches and
- ASA/PIX for Management Authentication
- using ACS Server
- Configuring Command Authorization
- based on the ACS server
- Configuring Accounting based on the
- ACS Server
- Configuring Authentication Proxy on the
- ASA
- Configuring Authentication on the
- Concentrator from the ACS Server
- Configuring NAC-802.1X Authentication on the Switch
Advanced Network Security and Network Attacks
- Preventing IP Spoofing
- Configuring NAT on Routers
- Configuring IP TCP Intercept
- Blocking ICMP Attacks
- Port Security on the Switches
- DHCP Snooping
- Dynamic ARP Inspection(DAI)
- IP Source Guard
- Mitigating Attacks using CAR
- Mitigating Attacks using NBAR
- IOS Firewall
- Blocking attacks using PBR
