SNAF - Securing Networks with ASA Fundamentals

Length Price Cisco Learning Credits
5 days $3,295.00 33

In this Authorized Cisco course, you will gain the knowledge and skills needed to configure, maintain, and operate Cisco ASA 5500 Series Adaptive Security.

We have enhanced our delivery of SNAF by adding depth to the existing Cisco-developed hands-on labs. In a topology designed to simulate a typical production network, our advanced hands-on labs guide you through exercises such as executing general maintenance commands, configuring ACLs, and configuring VPN on the Security Appliance.

Our labs utilize ASA 5520 security appliances, though the content in this course and our labs is applicable across the ASA and PIX families of security appliances since the command syntax is generally the same. This course has been updated to cover the features and syntax of Cisco Security Appliance Software v8.0.

Prerequisites

  • ICND2 - Interconnecting Cisco Network Devices 2
  • IINS - Implementing Cisco IOS Network Security

What You'll Learn

  • Functions of the three types of firewalls used to secure today's computer networks
  • Technology and features of Cisco security appliances
  • How Cisco Adaptive Security Appliances (ASAs) and Cisco PIX Security Appliances protect network devices from attacks and why each is an appropriate choice
  • Bootstrap the security appliance, prepare the security appliance for configuration via the Cisco Adaptive Security Device Manager (ASDM), and launch and navigate ASDM
  • Perform essential security appliance configuration using ASDM and the CLI
  • Configure dynamic and static address translations using ASDM
  • Configure switching and routing using ASDM
  • Use ASDM to configure ACLs, filter malicious active codes, and filter URLs that meet the requirements of the security policy
  • Use the packet tracer for troubleshooting
  • Use ASDM to configure object groups that meet the requirements of the security policy
  • Use ASDM to configure AAA to meet the requirements of the security policy
  • Configure a modular policy that supports the security policy using ASDM
  • Use ASDM to configure protocol inspection to meet security policy requirements
  • Configure threat detection to meet security policy requirements using ASDM and the CLI
  • Using ASDM, configure the security appliance to support a site-to-site VPN that meets policy requirements
  • Using ASDM, configure the security appliance to provide secure connectivity using remote access VPNs
  • Configure the security appliance to run in transparent firewall mode
  • Enable, configure, and manage multiple contexts to meet security policy requirements
  • Select and configure the type of failover that best suits the network topology
  • Monitor and manage an installed security appliance

Who Needs to Attend

  • Cisco customers who implement and maintain ASA and PIX Security Appliances
  • Cisco channel partners who sell, implement, and maintain ASA and PIX Security Appliances
  • Cisco systems engineers who support the sale of ASA and PIX Security Appliances

Course Outline

1. Introducing Cisco Security Appliance Technology and Features

  • Functions of the three types of firewalls that are used to secure modern computer networks
  • Technology and features of Cisco security appliances

2. Cisco Adaptive Security Appliance and PIX Security Appliance Families

  • Cisco ASA security appliance models
  • Cisco ASA security appliance licensing options

3. Getting Started with Cisco Security Appliances

  • Four main access modes
  • Security appliance file management system
  • Security appliance security levels
  • ASDM requirements and capabilities
  • Use the CLI to configure and verify basic network settings, and prepare the security appliance for configuration via ASDM
  • Verify security appliance configuration and licensing via ASDM

4. Essential Security Appliance Configuration

  • Configure a security appliance for basic network connectivity
  • Verify the initial configuration
  • Set the clock and synchronize the time on security appliances
  • Configure the security appliance to send syslog messages to a syslog server

5. Configuring Translations and Connection Limits

  • Function of TCP and UDP protocols within the security appliance
  • Function of static and dynamic translations
  • Configure dynamic address translation
  • Configure static address translation
  • Set connection limits

6. Using ACLs and Content Filtering

  • Configure the basic function of ACLs
  • Configure additional functions of ACLs
  • Configure active code filtering (ActiveX and Java applets)
  • Configure the security appliance for URL filtering
  • Use the packet tracer for troubleshooting

7. Configuring Object Grouping

  • Object grouping feature of the security appliance and its advantages
  • Configure object groups and use them in ACLs

8. Switching and Routing on Security Appliances

  • Configure logical interfaces and VLANs
  • Configure static routes and static route tracking
  • Dynamic routing capabilities of Cisco security appliances
  • Configure passive RIP routing

9. Configuring AAA for Cut-Through Proxy

  • Define and compare AAA
  • Install and configure Cisco Secure ACS
  • Configure the local user database
  • Define and configure cut-through proxy authentication
  • Define and configure user authorization using downloadable ACLs
  • Define and configure accounting

10. Configuring the Cisco Modular Policy Framework

  • Cisco Modular Policy Framework feature for security appliances
  • Functionality of class maps
  • Functionality of policy maps
  • Functionality of service policies
  • Use ASDM to configure a service policy rule

11. Configuring Advanced Protocol Handling

  • Need for advanced protocol handling
  • How the security appliance implements inspection of common network applications
  • Issues with multimedia applications and how the security appliance supports multimedia call control and audio sessions

12. Configuring Threat Detection

  • Threat detection and statistics
  • Configure basic threat detection and scanning threat detection
  • Configure and view threat detection statistics

13. Configuring Site-to-Site VPNs Using Pre-Shared Keys

  • How security appliances enable a secure VPN
  • Perform the tasks necessary to configure security appliance IPsec support
  • Commands to configure security appliance IPsec support
  • Configure a VPN between security appliances

14. Configuring Security Appliance Remote Access VPNs

  • Cisco Easy VPN
  • Cisco VPN Client
  • Configure an IPsec Remote Access VPN
  • Configure Users and Groups

15. Configuring Cisco Security Appliances for SSL VPN

  • SSL VPN and its purpose
  • Use the SSL VPN Wizard to configure a basic clientless SSL VPN connection
  • Configure SSL VPN policies
  • Verify SSL VPN operations
  • Customize the clientless SSL VPN portal

16. Configuring Transparent Firewall Mode

  • Purpose of transparent firewall mode
  • How data traverses a security appliance in transparent mode
  • Enable transparent firewall mode
  • Monitor and maintain transparent firewall mode

17. Configuring Security Contexts

  • Purpose of security contexts
  • Enable and disable multiple context mode
  • Configure a security context
  • Manage a security context

18. Configuring Failover

  • Difference between hardware and stateful failover
  • Difference between active/standby and active/active failover
  • Security appliance failover hardware requirements
  • Configure redundant interfaces
  • How active/standby failover works
  • Security appliance roles of primary, secondary, active, and standby
  • How active/active failover works
  • Configure active/standby cable-based and LAN-based failover
  • Configure active/active failover
  • Use remote command execution

19. Managing Security Appliances

  • Configure Telnet access to the security appliance
  • Configure SSH access to the security appliance
  • Configure command authorization
  • Recover security appliance passwords using general password recovery procedures
  • Use TFTP to install and upgrade the software image on the security appliance

Labs

Lab 1: Preparing the ASA for Administration

  • Access the ASA Console Port
  • Clearing an Existing Configuration
  • Taking Inventory of the ASA
  • The Setup Dialog
  • Enable SSH
  • Set Up ASDM
  • Verify the ASA Configuration

Lab 2: Essential Security Appliance Configuration

  • Execute the Startup Wizard
  • ASDM Device Setup
  • Configure Syslog
  • Test and Verify the ASA's Configuration
  • The Packet Capture Wizard
  • Verify the ASA Configuration

Lab 3: Translations and Connections

  • Understanding NAT Control and NAT 0
  • Configure PAT
  • Configure Dynamic NAT and NAT Exemption
  • Configure Static NAT
  • Verify the ASA Configuration

Lab 4: Configuring ACLs and Object Groups

  • Configure Inbound HTTP Access
  • Complete Inbound Policy using Object Groups
  • Configure Policy from the DMZ
  • Verify the ASA Configuration

Lab 5: AAA and Cut Through Proxy

  • Configure ACS and ASA Communication
  • Cut Through Authentication
  • User Authentication Timeouts
  • Virtual Telnet Server
  • Downloadable ACLs
  • Per User Override
  • AAA Accounting
  • Verify the ASA Configuration

Lab 6: Modular Policy Framework and Advanced Protocol Handling

  • Examine the Current Policy
  • FTP Protocol Inspection
  • Verify the ASA Configuration

Lab 7: Threat Detection

  • Basic Threat Detection
  • Threat Detection Statistics
  • Verify the ASA Configuration

Lab 8: Site-to-Site VPN

  • Verify Current Environment
  • ASDM VPN Wizard
  • Verify the Resulting Configuration
  • Test and Verify the VPN Tunnel
  • Verify the ASA Configuration

Lab 9: Remote Access VPN

  • Prepare the ASA for Remote Access VPN
  • Prepare the Cisco VPN Client
  • Test and Verify Remote Access VPN
  • Update the NAT Configuration
  • Verify the ASA Configuration

Lab 10: Clientless SSL VPN

  • SSL VPN Wizard
  • Test Clientless SSL VPN
  • Define a Group Policy for General Users
  • Test the Policy for General Users
  • Monitor SSL VPN Connections
  • Verify the ASA Configuration

Lab 11: Transparent Mode Firewall & Security Contexts

  • Understand the Updated Topology
  • Access the Security Appliance Console
  • Configure Transparent Firewall Mode
  • Configure Interfaces and the Management IP Address
  • Test Connectivity through the Security Appliance
  • Prepare the ASA for and Launch ASDM
  • Define and Test Inbound Policy with ASDM
  • Understand the Updated Scenario
  • Verify the ASA Configuration

Lab 12: Active/Standby Failover

  • Understand the Updated Topology
  • High Availability and Scalability Wizard
  • Verify Failover Status
  • Test Failover Operation
  • Return to a Normal State
  • Verify the ASA Configuration

Lab 13: Active/Active Failover

  • Understand the Updated Topology
  • High Availability and Scalability Wizard
  • Verify Failover Status
  • Enable Preemption
  • Test Failover Operation
  • Return to a Normal State
  • Verify the ASA Configuration

Lab 14: Managing the Security Appliance

  • Connect to the ASA via SSH
  • Configure Commands at a New Privilege Level
  • Configure Command Authorization for LOCAL Users
  • View the AAA Configuration from ASDM
  • Perform a "System Upgrade"
  • Verify the ASA Configuration

Class Dates:

Boston, MA
Aug 02, 2010 - Aug 06, 2010
Register Now
Philadelphia, PA
Aug 02, 2010 - Aug 06, 2010
Register Now
New York City, NY
Aug 09, 2010 - Aug 13, 2010
Register Now
Raleigh, NC
Aug 16, 2010 - Aug 20, 2010
Register Now
Washington, DC
Aug 16, 2010 - Aug 20, 2010
Register Now
Houston, TX
Aug 23, 2010 - Aug 27, 2010
Register Now
Chicago, IL
Aug 23, 2010 - Aug 27, 2010
Register Now
Los Angeles, CA
Aug 30, 2010 - Sep 03, 2010
Register Now
Dulles, VA
Sep 13, 2010 - Sep 17, 2010
Register Now
Morristown, NJ
Sep 20, 2010 - Sep 24, 2010
Register Now
Dallas, TX
Sep 27, 2010 - Oct 01, 2010
Register Now
Ft. Lauderdale, FL
Oct 04, 2010 - Oct 08, 2010
Register Now
Washington, DC
Oct 04, 2010 - Oct 08, 2010
Register Now
San Jose, CA
Oct 11, 2010 - Oct 15, 2010
Register Now
Atlanta, GA
Oct 11, 2010 - Oct 15, 2010
Register Now
Austin, TX
Oct 18, 2010 - Oct 22, 2010
Register Now
New York City, NY
Oct 18, 2010 - Oct 22, 2010
Register Now
Minneapolis, MN
Oct 25, 2010 - Oct 29, 2010
Register Now
Chicago, IL
Oct 25, 2010 - Oct 29, 2010
Register Now
Sacramento, CA
Nov 01, 2010 - Nov 05, 2010
Register Now
Dallas, TX
Nov 01, 2010 - Nov 05, 2010
Register Now
Baltimore, MD
Nov 08, 2010 - Nov 12, 2010
Register Now
Orlando, FL
Nov 08, 2010 - Nov 12, 2010
Register Now
Boston, MA
Nov 08, 2010 - Nov 12, 2010
Register Now
Raleigh, NC
Nov 15, 2010 - Nov 19, 2010
Register Now
Norfolk, VA
Nov 15, 2010 - Nov 19, 2010
Register Now
Los Angeles, CA
Nov 15, 2010 - Nov 19, 2010
Register Now
San Diego, CA
Nov 29, 2010 - Dec 03, 2010
Register Now
Washington, DC
Nov 29, 2010 - Dec 03, 2010
Register Now
Houston, TX
Nov 29, 2010 - Dec 03, 2010
Register Now
Rockville, MD
Dec 06, 2010 - Dec 10, 2010
Register Now
Columbus, OH
Dec 06, 2010 - Dec 10, 2010
Register Now
Morristown, NJ
Dec 13, 2010 - Dec 17, 2010
Register Now
New York City, NY
Dec 13, 2010 - Dec 17, 2010
Register Now