IINS - Implementing Cisco IOS Network Security (CCNA Security)

Length Price Cisco Learning Credits
5 days $3,195.00 32

In this course, you'll focus on the necessity of a comprehensive security policy and how it affects the posture of the network. You will learn to perform basic tasks to secure a small branch type office network using Cisco IOS security features available through web-based GUIs (Cisco Router and Security Device Manager [SDM]) and the command-line interface (CLI) on the Cisco routers and switches.

Prerequisites

  • ICND1 and ICND2 or CCNA Boot Camp
  • Working knowledge of the Windows operating system

What You'll Learn

  • Develop a comprehensive network security policy to counter threats against information security
  • Configure routers with Cisco IOS Software security features
  • Configure a Cisco IOS zone-based firewall to perform basic security operations on a network
  • Configure site-to-site VPNs using Cisco IOS features
  • Configure IPS on Cisco network routers
  • Configure security features on IOS switches to mitigate various Layer 2 attacks

Who Needs to Attend

  • Network Designers
  • Network Administrators
  • Network Engineers
  • Network Managers
  • Systems Engineers

Course Outline

1. Introduction to Network Security Principles

  • Network Security Fundamentals
  • Network Attack Methodologies
  • Operations Security
  • Security Policy
  • Building Cisco Self-Defending Networks
  • Cryptographic Services
  • Symmetric Encryption
  • Cryptographic Hashes and Digital Signatures
  • Asymmetric Encryption and PKI

2. Perimeter Security

  • Securing Administrative Access to Cisco Routers
  • Cisco SDM
  • Configuring AAA on a Cisco Router Using the Local Database
  • Configuring AAA on a Cisco Router to Use Cisco Secure ACS
  • Implementing Secure Management and Reporting
  • Locking Down the Router

3. Network Security Using Cisco IOS Firewalls

  • Firewall Technologies
  • Creating Static Packet Filters Using ACLs
  • Configuring Cisco IOS Zone-Based Policy Firewall

4. Site-to-Site VPNs

  • IPsec Fundamentals
  • Building a Site-to-Site IPsec VPN
  • Configuring IPsec on a Site-to-Site VPN Using Cisco SDM
  • Exclusive - IPsec over GRE

5. Network Security Using Cisco IOS IPS

  • IPS Technologies
  • Configuring Cisco IOS IPS Using Cisco SDM

6. LAN, SAN, Voice, and Endpoint Security Overview

  • Endpoint Security
  • SAN Security
  • Voice Security
  • Mitigating Layer 2 Attacks

Labs

Lab 1: Network Address Translation

  • Configure NAT
  • Test and Verify NAT
  • Verify the Configurations

Lab 2: Ethical Hacking

  • Use Nmap to Scan the Network

Lab 3: Securing IOS Administrative Access

  • Set Passwords on the Physical Lines
  • Configure Enable and Enable Secret Passwords
  • Set VTY Line Passwords
  • Use Service Password Encryption
  • Password Min-Length
  • Line Timeouts
  • Configure Banner Messages
  • Verify the IOS-FW Configuration

Lab 4: Exclusive - Preparing Cisco SDM

  • Prepare the Admin PC for SDM
  • Prepare the IOS-FW for SDM
  • Install SDM on the Admin PC
  • Launch SDM
  • Manage IOS-FW Keys and Certificates
  • Launch SDM again
  • Verify Router Configuration

Lab 5: Configuring IOS AAA with the Local Database

  • Enable AAA
  • Test AAA
  • Define and Test other Usernames
  • Configure Role-Based CLI
  • Enhanced Login Features
  • Verify the Router Configuration

Lab 6: Configuring IOS AAA with ACS

  • Connect to ACS
  • Set Up IOS-FW to ACS Communication
  • Define a New Group and User in ACS
  • Configure ACS-Based Authentication and Authorization
  • Test ACS-Based Authentication and Authorization
  • Configure ACS and Active Directory Integration
  • AAA Accounting
  • Verify the Router Configuration

Lab 7: IOS Secure Management and Reporting

  • Configure SSH Server
  • Configure NTP on the IOS-FW and Perimeter Router
  • Configure Syslog on the IOS-FW
  • Configure Syslog on the Perimeter Router
  • Verify the Router Configuration

Lab 8: Securing IOS Router Services

  • Run a Mock Security Audit
  • Run a Real Security Audit
  • Perform Configuration Adjustments
  • Verify the Router Configuration

Lab 9: Packet Filtering Using ACLs

  • Limit VTY Access
  • Filter Bogon Packets, Allow Outbound Connections
  • Allow Expected Traffic to the DMZ Server
  • Allow Other Services from the Inside
  • Test ACL Policy
  • Verify Router Configuration

Lab 10: IOS Zone-Based Firewall

  • Basic Firewall Wizard
  • Verify the Router Configuration

Lab 11: Site-to-Site VPN: Traditional IPsec

  • Verify No Tunnel/No Connectivity
  • Prepare the IOS-FW for the Tunnel
  • Use the Site to Site VPN Wizard
  • Verify VPN Status
  • Verify the Router Configuration

Lab 12: Exclusive - Site-to-Site VPN: GRE and IPsec

  • Prepare the Perimeter Router for the Tunnel
  • Use the VPN Wizard
  • Review the Updated Firewall Policy
  • Generate, Update and Apply the Mirror Configuration
  • Troubleshoot the Tunnel
  • Verify the Router Configuration

Lab 13: IOS Intrusion Prevention System

  • IOS IPS Wizard
  • Signature Definitions
  • Signature Actions
  • Verify the Router Configuration

Lab 14: Layer 2 Security

  • Configure Port Security
  • Verify the Switch Configuration

Class Dates:

Washington, DC
Aug 02, 2010 - Aug 06, 2010
Register Now
Morristown, NJ
Aug 09, 2010 - Aug 13, 2010
Register Now
Denver, CO
Aug 09, 2010 - Aug 13, 2010
Register Now
Dallas, TX
Aug 16, 2010 - Aug 20, 2010
Register Now
Atlanta, GA
Aug 23, 2010 12:01 AM -
Aug 27, 2010 12:00 AM
Register Now
San Jose, CA
Aug 23, 2010 12:01 AM -
Aug 27, 2010 12:00 AM
Register Now
Los Angeles, CA
Aug 30, 2010 - Sep 03, 2010
Register Now
Chicago, IL
Sep 13, 2010 - Sep 17, 2010
Register Now
Raleigh, NC
Sep 20, 2010 - Sep 24, 2010
Register Now
Phoenix, AZ
Sep 27, 2010 - Oct 01, 2010
Register Now
Washington, DC
Oct 04, 2010 - Oct 08, 2010
Register Now
New York City, NY
Oct 11, 2010 - Oct 15, 2010
Register Now
Boston, MA
Oct 18, 2010 - Oct 22, 2010
Register Now
Dallas, TX
Oct 25, 2010 - Oct 29, 2010
Register Now
Chicago, IL
Nov 01, 2010 - Nov 05, 2010
Register Now
Rockville, MD
Nov 08, 2010 - Nov 12, 2010
Register Now
Morristown, NJ
Nov 15, 2010 - Nov 19, 2010
Register Now
San Jose, CA
Nov 29, 2010 - Dec 03, 2010
Register Now
Atlanta, GA
Dec 06, 2010 - Dec 10, 2010
Register Now
Washington, DC
Dec 13, 2010 - Dec 17, 2010
Register Now