IPS - Implementing Cisco Intrusion Prevention System v 6.0

Length Price Cisco Learning Credits
4 days $3,095.00 31

In this course, you will gain the skills required to deploy Cisco's recently updated version 6.0 network-based Intrusion Prevention System (IPS). New features added to version 6.0 include virtual sensor support, passive OS fingerprinting, and anomaly detection. The course introduces you to Cisco IPS platforms, including the 4200 Series Sensors, the Catalyst 6000 Series Intrusion Detection Module 2 (IDSM2), the Advanced Inspection, and Prevention Security Services Module (AIP-SSM). The command line and the IPS Device Manager GUI are used to configure the sensor.

Prerequisites

  • ICND2 - Interconnecting Cisco Network Devices 2
  • IINS - Implementing Cisco IOS Network Security

What You'll Learn

  • How Cisco IPS protects network devices from attacks
  • Basic intrusion prevention terminology
  • Different intrusion prevention technologies and evasive techniques
  • Cisco IPS Sensor platforms and their features
  • Install and configure basic settings on a Cisco IPS 4200 Series Sensor
  • Use the Cisco IPS Device Manager (IDM) to configure built-in signatures to meet the requirements of a given security policy
  • Create and implement customized intrusion prevention signatures
  • Create alarm filters to reduce alarms and possible false positives
  • Configure IPS protective reactions such as TCP reset and deny attacker inline
  • Configure a Cisco IPS Sensor to perform blocking on IOS routers and Adaptive Security Appliances (ASAs) or PIX firewalls
  • Perform maintenance operations such as signature updates
  • Configure and monitor anomaly detection, passive OS fingerprinting, and virtual sensors
  • Initialize and install remaining Cisco IPS family of products
  • Use the CLI and Cisco IDM to obtain system information
  • Configure the Cisco IPS sensor to allow a SNMP NMS to monitor the Cisco IPS sensor

Who Needs to Attend

  • Internetwork professionals who want to ensure security on their network or who seek Cisco certification.

Course Outline

1. Intrusion Prevention Overview

  • Explanation of Intrusion Prevention
  • Cisco IPS Products
  • Cisco IPS Sensor Software Solutions
  • Evasive Techniques

2. Installation of a Cisco IPS 4200 Series Sensor

  • Installing an IPS Sensor Using the CLI
  • Using the Cisco IDM
  • Configuring Basic Sensor Settings

3. Cisco IPS Signatures

  • Configuring Cisco IPS Signatures and Alarms
  • Signature Engines
  • Customizing Signatures

4. Advanced Cisco IPS Configuration

  • Advanced Tuning of Cisco IPS Sensors
  • Monitoring and Managing Alarms
  • Configuring a Virtual Sensor
  • Configuring Advanced Features
  • Configuring Blocking

5. Additional Cisco IPS Devices

  • Cisco IDS Module
  • Cisco ASA AIP-SSM

6. Cisco IPS Sensor Maintenance

  • Maintaining Cisco IPS Sensors
  • Managing Cisco IPS Sensors

Labs

 

Lab 1: Cisco IPS Sensor CLI

  • Reimage the sensor from the recovery partition
  • Initial login to the sensor
  • Initial set up of the sensor
  • Configure the sensor via the CLI
  • Manage user accounts
  • Back up the sensor's configuration

Lab 2: IPS Device Manager

  • Launch IDM and login
  • Configure the sensor using IDM, including sensing interfaces, allowed hosts, user accounts, and NTP
  • Manage user accounts with IDM
  • Monitor events on the sensor using IDM
  • Experiment with the sensor's Software Bypass feature

Lab 3: IPS Event Viewer

  • Install and Configure IEV
  • Create various alert conditions
  • IEV Default Views
  • IEV Filters
  • IEV Custom Views
  • Real-Time Dashboard
  • IEV Reports

Lab 4: Working with Signatures

  • Test a Reference Signature
  • Investigate the Deny Packet Inline Action
  • Investigate the Deny Attacker Inline Action

Lab 5: Signature Configuration

  • Configure and test the HTTP application firewall
  • Create and test a Meta event
  • Create a signature using the Signature Wizard
  • Create a signature with the Signature Wizard, defining the signature engine first

Lab 6: Sensor Tuning

  • Understand Fragment Reassembly and Stream Reassembly options
  • Configure and use event variables
  • Understand Risk Rating
  • Configure Event Action Overrides
  • Configure Event Action Filters

Lab 7: Virtual Sensors

  • Implement a second Virtual Sensor
  • Remove the second Virtual Sensor

Lab 8: Anomaly Detection and OS Fingerprinting

  • Examine Anomaly Detection Status
  • Configure Anomaly Detection
  • Test Anomaly Detection
  • Configure a manual OS mapping

Lab 9: Monitoring and Maintaining the Sensor

  • Update the sensor via IDM
  • Troubleshooting via IDM

Class Dates:

Washington, DC
Aug 03, 2010 - Aug 06, 2010
Register Now
Houston, TX
Aug 10, 2010 - Aug 13, 2010
Register Now
Norfolk, VA
Aug 24, 2010 - Aug 27, 2010
Register Now
Dallas, TX
Aug 31, 2010 - Sep 03, 2010
Register Now
Chicago, IL
Sep 07, 2010 - Sep 10, 2010
Register Now
Boston, MA
Sep 14, 2010 - Sep 17, 2010
Register Now
San Jose, CA
Sep 21, 2010 - Sep 24, 2010
Register Now
Raleigh, NC
Sep 28, 2010 - Oct 01, 2010
Register Now
New York City, NY
Oct 05, 2010 - Oct 08, 2010
Register Now
Morristown, NJ
Oct 12, 2010 - Oct 15, 2010
Register Now
Orlando, FL
Oct 26, 2010 - Oct 29, 2010
Register Now
Washington, DC
Nov 02, 2010 - Nov 05, 2010
Register Now
Los Angeles, CA
Nov 09, 2010 - Nov 12, 2010
Register Now
Dallas, TX
Nov 16, 2010 - Nov 19, 2010
Register Now
Chicago, IL
Nov 30, 2010 - Dec 03, 2010
Register Now