SNAA - Securing Networks with ASA Advanced

Length Price Cisco Learning Credits
5 days $3,295.00 33

In this Authorized Cisco course, you will take your knowledge and skills on configuring, maintaining, and operating Cisco ASA 5500 Series Adaptive Security Appliance to the next level. Recommended training for the Cisco Certified Security Professional (CCSP) certification, SNAA takes over where SNAF leaves off, covering advanced topics of the Adaptive Security Appliance.

Prerequisites

  • SNAF - Securing Networks with ASA Fundamentals

What You'll Learn

  • Use advanced NAT features such as policy-based NAT
  • Use advanced modular policy framework for deep packet inspection of application protocols such as HTTP and FTP
  • How the multimedia protocols are handled and configured by the modular policy framework of the security appliance at Layer 3, 4, and 7
  • Configure the security appliance to support multiple VLANs on a single physical interface
  • Configure dynamic routing capabilities of the appliance
  • Use advanced IPSec VPN technologies including peer authentication using digital certificates
  • Steps necessary to configure the ASA as a CA Server
  • Configure the IPSec VPN Client using digital certificates
  • Configure the advanced Easy VPN Server features of the ASA
  • Necessary configuration for the ASA 5505 to be a VPN hardware client
  • Steps to configure QoS for VPN traffic
  • SSL VPN features and capabilities of the security appliance
  • Enable clientless SSL VPNs with the security appliance
  • Enable AnyConnect SSL VPN Client with the security appliance
  • Enable the Cisco Secure Desktop with the security appliance to increase the security posture of SSL VPN connections
  • Enable Dynamic Access Policy for remote access IPsec or SSL VPN
  • Characteristics of the security services modules for the ASA
  • Configure, inspect, and filter traffic with the Content Security and Control SSM
  • Configure the AIP-SSM to identify and alert for common attacks

Who Needs to Attend

  • Cisco customers who implement and maintain ASA and PIX Security Appliances
  • Cisco channel partners who sell, implement, and maintain ASA and PIX Security Appliances
  • Cisco systems engineers who support the sale of ASA and PIX Security Appliances

Course Outline

1. Advanced ASA NAT

  • Applying NAT 0 and Policy NAT
    • ACLs
    • NAT
    • Translation Behavior
    • NAT Exemption
    • Policy NAT
    • Verify and Troubleshoot

2. Advanced Protocol Handling

  • Applying the Cisco Modular Policy Framework
    • Modular Policy Framework Overview
    • Configuring the Modular Policy Framework
    • Configuring a Layer 7 Class Map
    • Configuring a REGEX Class Map
    • Configuring a Layer 7 Policy Map
    • Verifying the Modular Policy Framework Configuration
  • Handling Advanced Protocol
    • Protocol Inspection Overview
    • FTP Inspection
    • HTTP Inspection
    • Instant Messaging Inspection
    • ESMTP Inspection
    • DNS Inspection
    • ICMP Inspection
    • Verifying Protocol Inspection

3. Dynamic Routing and Switching

  • Switching with VLANs
    • ASA VLAN Operations
    • VLAN Configuration
    • Configuring VLANs on the ASA 5505
    • Verify VLANs
  • Routing with Dynamic Protocols
    • Dynamic vs. Static Routing
    • RIP
    • OSPF
    • EIGRP
    • Redistribution
    • Verification and Troubleshooting

4. IPsec VPNs

  • Understanding IPsec and Digital Certificates
    • What IPsec Is
    • IPsec Operation
    • Digital Certificates and Public Key Cryptography
    • Certificates and Scalability
    • Certificate Enrollment Process
    • Validating the Certificate
    • Certificate Revocation Lists
    • Security Appliance Certificate Enrollment Support
    • Key Pairs and Trustpoints
  • Implementing Site-to-Site VPNs with Digital Certificates
    • Site-to-Site VPNs
    • Configuring CA Certificates
    • Site-to-Site IPsec Connection Profiles
    • Modifying Certificate to Connection Mapping
    • Hub and Spoke
    • Site-to-Site Redundancy
    • Verifying Site-to-Site VPNs
    • Troubleshooting Site-to-Site VPNs
  • Configuring the Cisco VPN Client
    • Cisco VPN Client
    • Client Installation
    • Digital Certificates with Cisco VPN Client
    • Connection Entry
    • Advanced Options
    • Verify and Troubleshoot Client Configuration
  • Implementing Remote Access VPNs with Digital Certificates
    • Remote Access VPNs
    • Configuring an ASA for Remote Access
    • Installing ASA Certificates
    • Defining a Remote Access Address Pool
    • User Policy Attribute Inheritance
    • Configuring an IPSec Connection Profile
    • Configuring the Certificate to Connection Profile Policy
    • Verifying Remote Access VPNs
    • Troubleshooting Remote Access VPNs
  • Configuring Advanced Remote Access Features and Policy
    • Load Balancing
    • Reverse Route Injection
    • Backup Servers
    • Intra-Interface VPN Traffic
    • NAT Transparency
    • Client Update
    • Split Tunneling
    • Personal Firewalls
  • Configuring the ASA 5505 as an Easy VPN Hardware Client
    • Introduction to Cisco Easy VPN
    • Cisco Easy VPN Server Policy
    • Easy VPN Hardware Client
  • IPsec VPNs and QoS
    • QoS Overview
    • ASA QoS
    • Configuring QoS for VPNs

5. SSL VPNs

  • SSL VPN Technology Overview
    • SSL Overview
    • Clientless SSL VPN
    • Cisco Secure Desktop (CSD)
  • Configuring Clientless SSL VPNs
    • Configuring Clientless SSL VPN
    • Verifying Clientless SSL VPN Operation
    • Configuring Port-Forwarding SSL VPN
    • Verifying Port-Forwarding SSL VPN
    • Configuring Additional SSL VPN Features
    • Troubleshooting Clientless and Port-Forwarding SSL VPNs
  • Configuring Full Network Access SSL VPNs
    • Cisco Full Network Access SSL VPN Overview
    • Configuring Cisco AnyConnect SSL VPN
    • Verifying Cisco AnyConnect SSL VPN Operation
    • Configuring Advanced Features for the Cisco AnyConnect SSL VPN Client
    • Configuring Certificate-Based Authentication for AnyConnect SSL VPN
    • Troubleshooting Cisco AnyConnect SSL VPN Client Operation
  • Cisco Secure Desktop
    • Cisco Secure Desktop Overview
    • Cisco Secure Desktop Interoperability
    • Preparing the ASA for Cisco Secure Desktop
  • Securing the Desktop with CSD and DAP
    • CSD Workflow
    • Pre-Login Assessment
    • Secure Session
    • Cache Cleaner
    • Host Emulation and Keystroke Logger Detection
    • Host Scan
    • Dynamic Access Policy
    • DAP Testing

6. Security Services Modules

  • Examining the SSMs
    • Business Challenges
    • SSMs
    • CSC-SSM
    • AIP-SSM
    • AIP-SSM or CSC-SSM
  • CSC-SSM: Getting Started
    • CSC-SSM Overview
    • CSC-SSM SW Loading
    • Initial CLI CSC Configuration
    • Initial Configuration of the CSC-SSM using CSC Setup Wizard from ASDM
  • AIP-SSM: Getting Started
    • AIP-SSM Overview
    • AIP-SSM SW Loading
    • Initial IPS ASDM Configuration
    • Configure an IPS Security Policy

Labs

Lab 1: Advanced NAT

  • Verify Existing NAT Configuration
  • Configure Outbound Policy NAT
  • Configure Inbound Policy NAT
  • Verify the ASA Configuration

Lab 2: Modular Policy Framework: FTP and HTTP

  • Advanced Inspection: FTP Command Enforcement
  • Advanced Inspection: HTTP Content Enforcement
  • Verify the ASA Configuration

Lab 3: Dynamic Routing: EIGRP and OSPF

  • Configure Non-ASA Devices for EIGRP and OSPF
  • Modify the ASA in preparation for Dynamic Routing
  • Configure OSPF On The ASA
  • Configure EIGRP On The ASA
  • Verify the Results
  • Enable Route Redistribution and Verify the Results
  • Verify the ASA Configuration

Lab 4: Site-to-Site VPN with Digital Certificates

  • Examine Current SSL Identity Certificate
  • Authenticate the External CA
  • Enroll with the External CA via SCEP
  • Configure Site-to-Site VPN
  • Verify Site-to-Site VPN
  • Verify the ASA Configuration

Lab 5: Remote Access VPN with Digital Certificates

  • Configure a Tunnel Group for CA Access
  • Install and Configure the Cisco Easy VPN Client
  • Enroll the VPN Client with the Internal CA Server
  • Configure a Tunnel Group for Full Network Access
  • Monitor Remote Access VPN Activity
  • Verify the ASA Configuration

Lab 6: ASA 5505 Hardware Client

  • Initial Configuration of Easy VPN Server
  • Enroll the 5505 with the Services-R-Us CA
  • Easy VPN Remote on the 5505
  • Verify the ASA Configuration

Lab 7: SSL VPN: Clientless and Thin Client

  • Enable Basic Clientless SSL VPN Access
  • Test Basic Clientless SSL VPN Access
  • Verify the ASA Configuration

Lab 8: SSL VPN: AnyConnect Client

  • Local CA on the ASA
  • Configure AnyConnect Client Support
  • Enroll with the ASA Local CA
  • Install the Stand Alone AnyConnect Client
  • Configure and Verify the Web Launch AnyConnect Client
  • Verify the ASA Configuration

Lab 9: Cisco Secure Desktop and Dynamic Access Policies

  • Enable the Cisco Secure Desktop
  • Configure Policies for the CSD
  • Verify the Cisco Secure Desktop Operation
  • Configure a Dynamic Access Policy
  • Verify the DAP Operation
  • Verify the ASA Configuration

Lab 10: The AIP-SSM

  • Recover the AIP-SSM Image
  • Initial Setup of the AIP-SSM
  • AIP-SSM Management Connection Options
  • Configure the ASA's MPF to use the AIP-SSM Inline
  • Verify the ASA and AIP-SSM Configurations

Class Dates:

Washington, DC
Aug 09, 2010 - Aug 13, 2010
Register Now
Dallas, TX
Aug 09, 2010 - Aug 13, 2010
Register Now
Denver, CO
Aug 16, 2010 - Aug 20, 2010
Register Now
Orlando, FL
Aug 23, 2010 - Aug 27, 2010
Register Now
New York City, NY
Aug 30, 2010 - Sep 03, 2010
Register Now
Raleigh, NC
Sep 13, 2010 - Sep 17, 2010
Register Now
San Jose, CA
Sep 13, 2010 - Sep 17, 2010
Register Now
Austin, TX
Sep 20, 2010 - Sep 24, 2010
Register Now
Chicago, IL
Sep 27, 2010 - Oct 01, 2010
Register Now
Morristown, NJ
Oct 04, 2010 - Oct 08, 2010
Register Now
Houston, TX
Oct 18, 2010 - Oct 22, 2010
Register Now
Atlanta, GA
Nov 01, 2010 - Nov 05, 2010
Register Now
Washington, DC
Nov 08, 2010 - Nov 12, 2010
Register Now
Dallas, TX
Nov 15, 2010 - Nov 19, 2010
Register Now
Boston, MA
Nov 29, 2010 - Dec 03, 2010
Register Now
Philadelphia, PA
Nov 29, 2010 - Dec 03, 2010
Register Now
Chicago, IL
Dec 13, 2010 - Dec 17, 2010
Register Now