IINS - Implementing Cisco IOS Network Security (CCNA Security)

Length Price Cisco Learning Credits
5 days $3,195.00 32

In this course, you'll focus on the necessity of a comprehensive security policy and how it affects the posture of the network. You will learn to perform basic tasks to secure a small branch type office network using Cisco IOS security features available through web-based GUIs (Cisco Router and Security Device Manager [SDM]) and the command-line interface (CLI) on the Cisco routers and switches.

Prerequisites

  • ICND1 and ICND2 or CCNA Boot Camp
  • Working knowledge of the Windows operating system

What You'll Learn

  • Develop a comprehensive network security policy to counter threats against information security
  • Configure routers with Cisco IOS Software security features
  • Configure a Cisco IOS zone-based firewall to perform basic security operations on a network
  • Configure site-to-site VPNs using Cisco IOS features
  • Configure IPS on Cisco network routers
  • Configure security features on IOS switches to mitigate various Layer 2 attacks

Who Needs to Attend

  • Network Designers
  • Network Administrators
  • Network Engineers
  • Network Managers
  • Systems Engineers

Course Outline

1. Introduction to Network Security Principles

  • Network Security Fundamentals
  • Network Attack Methodologies
  • Operations Security
  • Security Policy
  • Building Cisco Self-Defending Networks
  • Cryptographic Services
  • Symmetric Encryption
  • Cryptographic Hashes and Digital Signatures
  • Asymmetric Encryption and PKI

2. Perimeter Security

  • Securing Administrative Access to Cisco Routers
  • Cisco SDM
  • Configuring AAA on a Cisco Router Using the Local Database
  • Configuring AAA on a Cisco Router to Use Cisco Secure ACS
  • Implementing Secure Management and Reporting
  • Locking Down the Router

3. Network Security Using Cisco IOS Firewalls

  • Firewall Technologies
  • Creating Static Packet Filters Using ACLs
  • Configuring Cisco IOS Zone-Based Policy Firewall

4. Site-to-Site VPNs

  • IPsec Fundamentals
  • Building a Site-to-Site IPsec VPN
  • Configuring IPsec on a Site-to-Site VPN Using Cisco SDM
  • Exclusive - IPsec over GRE

5. Network Security Using Cisco IOS IPS

  • IPS Technologies
  • Configuring Cisco IOS IPS Using Cisco SDM

6. LAN, SAN, Voice, and Endpoint Security Overview

  • Endpoint Security
  • SAN Security
  • Voice Security
  • Mitigating Layer 2 Attacks

Labs

Lab 1: Network Address Translation

  • Configure NAT
  • Test and Verify NAT
  • Verify the Configurations

Lab 2: Ethical Hacking

  • Use Nmap to Scan the Network

Lab 3: Securing IOS Administrative Access

  • Set Passwords on the Physical Lines
  • Configure Enable and Enable Secret Passwords
  • Set VTY Line Passwords
  • Use Service Password Encryption
  • Password Min-Length
  • Line Timeouts
  • Configure Banner Messages
  • Verify the IOS-FW Configuration

Lab 4: Exclusive - Preparing Cisco SDM

  • Prepare the Admin PC for SDM
  • Prepare the IOS-FW for SDM
  • Install SDM on the Admin PC
  • Launch SDM
  • Manage IOS-FW Keys and Certificates
  • Launch SDM again
  • Verify Router Configuration

Lab 5: Configuring IOS AAA with the Local Database

  • Enable AAA
  • Test AAA
  • Define and Test other Usernames
  • Configure Role-Based CLI
  • Enhanced Login Features
  • Verify the Router Configuration

Lab 6: Configuring IOS AAA with ACS

  • Connect to ACS
  • Set Up IOS-FW to ACS Communication
  • Define a New Group and User in ACS
  • Configure ACS-Based Authentication and Authorization
  • Test ACS-Based Authentication and Authorization
  • Configure ACS and Active Directory Integration
  • AAA Accounting
  • Verify the Router Configuration

Lab 7: IOS Secure Management and Reporting

  • Configure SSH Server
  • Configure NTP on the IOS-FW and Perimeter Router
  • Configure Syslog on the IOS-FW
  • Configure Syslog on the Perimeter Router
  • Verify the Router Configuration

Lab 8: Securing IOS Router Services

  • Run a Mock Security Audit
  • Run a Real Security Audit
  • Perform Configuration Adjustments
  • Verify the Router Configuration

Lab 9: Packet Filtering Using ACLs

  • Limit VTY Access
  • Filter Bogon Packets, Allow Outbound Connections
  • Allow Expected Traffic to the DMZ Server
  • Allow Other Services from the Inside
  • Test ACL Policy
  • Verify Router Configuration

Lab 10: IOS Zone-Based Firewall

  • Basic Firewall Wizard
  • Verify the Router Configuration

Lab 11: Site-to-Site VPN: Traditional IPsec

  • Verify No Tunnel/No Connectivity
  • Prepare the IOS-FW for the Tunnel
  • Use the Site to Site VPN Wizard
  • Verify VPN Status
  • Verify the Router Configuration

Lab 12: Exclusive - Site-to-Site VPN: GRE and IPsec

  • Prepare the Perimeter Router for the Tunnel
  • Use the VPN Wizard
  • Review the Updated Firewall Policy
  • Generate, Update and Apply the Mirror Configuration
  • Troubleshoot the Tunnel
  • Verify the Router Configuration

Lab 13: IOS Intrusion Prevention System

  • IOS IPS Wizard
  • Signature Definitions
  • Signature Actions
  • Verify the Router Configuration

Lab 14: Layer 2 Security

  • Configure Port Security
  • Verify the Switch Configuration

Class Dates:

Virtual
Feb 13, 2012 - Feb 17, 2012
Register Now
Virtual
Mar 19, 2012 - Mar 23, 2012
Register Now
Virtual
Apr 23, 2012 - Apr 27, 2012
Register Now
Virtual
May 21, 2012 - May 25, 2012
Register Now
Virtual
Jun 04, 2012 - Jun 08, 2012
Register Now
Virtual
Jul 16, 2012 - Jul 20, 2012
Register Now
Virtual
Aug 20, 2012 - Aug 24, 2012
Register Now
Virtual
Oct 01, 2012 - Oct 05, 2012
Register Now
Virtual
Nov 05, 2012 - Nov 09, 2012
Register Now
Virtual
Dec 17, 2012 - Dec 21, 2012
Register Now