SNRS - Securing Networks with Cisco Routers and Switches v3.0

Length Price Cisco Learning Credits
5 days $3,195.00 32

Discover advanced concepts in IOS router and switch security in this course that starts where IINS v1.0, core training for the CCNA Security Associate certification, stops. In SNRS v3.0, a component in the Cisco Certified Security Professional certification, you will take your IOS router and switch security skills to the professional level.

You'll cover switch topics, including advanced Layer 2 security and Identity-Based Networking Services (IBNS) based on IEEE 802.1x, and you'll cover router topics, including network platform security, VPN, firewall, and IPS. Learn how to secure a router's control plane, data plane, and management plane. You will spend a large portion of the class covering advanced VPN topics, including using digital certificates for VPN authentication, GRE over IPsec, Dynamic Virtual Trunk Interfaces, Dynamic Multipoint VPN (DMVPN), Group Encryption Transport VPN (GET VPN), remote access IPsec VPN with the Easy VPN Server, Cisco VPN Client and Easy VPN Remote (hardware client), and SSL VPN. Examine both the newer Zone-Based Policy Firewall (ZFW) as well as the traditional Context-Based Access Control (now referred to as IOS Classic Firewall). You'll cover advanced IPS topics as well, including event action overrides, event action filters, signature tuning, and custom signature creation.

Prerequisites

  • ICND1 - Interconnecting Cisco Network Devices 1
  • ICND2 - Interconnecting Cisco Network Devices 2
  • IINS - Implementing Cisco IOS Network Security

What You'll Learn

  • Layer 2 Security: Attack methods and techniques to mitigate the attacks
  • Identity Based Networking Services: 802.1x authentication and authorization with Cisco switches
  • Network Foundation Protection: Secure an IOS router's control plane, management plane, and data plane
  • VPN Connectivity:
    • IPsec overview
    • Site-to-site IPsec VPN using public key infrastructure and digital certificates for authentication
    • Virtual tunnel interfaces
    • GRE over IPsec
    • High-availability VPN options
    • Dynamic Multipoint VPN
    • Group Encryption Transport VPN
    • Cisco IOS SSL VPN (WebVPN)
    • Easy VPN Server, Remote, and Client for Remote Access IPsec VPN
  • Protect your network with Cisco IOS Classic Firewall and Cisco IOS Zone-Based Policy Firewall
  • Defend against threats on your network using IOS Intrusion Prevention Systems

Who Needs to Attend

  • Internetwork professionals who want to ensure security of their network using IOS devices that are already common in their network
  • Internetwork professionals who seek Cisco Certified Security Professional (CCSP) certification

Course Outline

1. Network Platform Security with Switches

  • Configuring Advanced Layer 2 Security
  • Introducing Cisco IBNS
  • Implementing Basic 802.1x Authentication
  • Configuring Advanced 802.1x Authentication and Authorization

2. Network Platform Security with Routers

  • Examining the Cisco Network Foundation Protection Strategy
  • Securing the Control Plane
  • Securing the Management Plane
  • Securing the Data Plane

3. Secure Site-to-Site Communications

  • Examining VPN and IPsec Fundamentals
  • Implementing IPsec VPNs with PKI
  • Implementing GRE over IPsec
  • Configuring High-Availability VPNs and VTI
  • Implementing DMVPN
  • Implementing GET VPN

4. Secure Remote Access Communications

  • Implementing Cisco IOS Remote Access using Cisco Easy VPN
  • Examining a Cisco IOS SSL VPN

5. Threat Control and Containment

  • Configuring NAT and PAT
  • Configuring a Cisco IOS Classic Firewall
  • Configuring a Cisco IOS Zone-Based Policy Firewall
  • Configuring Cisco IOS IPS

Labs

Lab 1: Advanced Layer 2 Security

  • Configure and Verify Private VLAN Edge
  • Mitigate Private VLAN Edge Router Proxy Attacks
  • Configure and Verify DHCP Snooping

Lab 2: Layer 2 AAA with 802.1x

  • Configure RADIUS between the L3-Switch and ACS
  • Configure and Test Basic 802.1x Authentication
  • Configure and Test 802.1x Restricted VLAN
  • Configure and Test 802.1x Guest VLAN
  • Configure and Test 802.1x MAC Authentication Bypass
  • Install and Configure the Cisco Secure Services Client
  • Configure and Test 802.1x Dynamic VLAN Assignment

Lab 3: Cisco Network Foundation Protection

  • OSPF with Authentication
  • Configure SNMP Version 3
  • Configure and Monitor NetFlow with SDM

Lab 4: Site-To-Site VPN with PKI

  • Assign the SSL Trustpoint for SDM
  • Enroll the IOS-FW with the CA Server via SDM
  • Configure the IOS-FW for the VPN via SDM
  • Test and Verify the VPN

Lab 5: IPsec Redundancy using GRE

  • Understand the Scenario
  • Configure IPsec over GRE via SDM on the IOS-FW

Lab 6: DMVPN

  • Prepare Site1
  • Test Connectivity and Adjust the Configuration

Lab 7: GET VPN

  • Configure and Verify the First Group Member
  • Verify GETVPN Traffic

Lab 8: Cisco Easy VPN

  • Easy VPN Server Wizard
  • Examine the Configuration
  • Prepare the VPN Client
  • Test the Remote Access VPN
  • Easy VPN Remote Hardware Client
  • Monitor Remote Access VPN Connections with SDM

Lab 9: IOS SSL VPN

  • Configure RADIUS Support
  • Configure Clientless SSL VPN Access
  • Configure and Test Port Forwarding
  • Configure and Test the Full Tunnel SSL VPN Client
  • Configure and Test the Cisco Secure Desktop

Lab 10: IOS Classic Firewall

  • Prepare the IOS-FW for IOS Classic Firewall
  • Execute the SDM Advanced Firewall Wizard
  • Verify Expected Connectivity
  • Verify Expected Protections

Lab 11: IOS Zone-Based Policy Firewall

  • Basic Firewall Wizard
  • Implement the DMZ Inbound
  • Implement the DMZ to Inside
  • Static URL Filtering
  • HTTP Application Inspection

Lab 12: IOS IPS

  • IOS IPS Wizard
  • Signature Definitions
  • IPS Manager Express
  • Event Action Filters

Class Dates:

San Jose, CA
Aug 16, 2010 - Aug 20, 2010
Register Now
Dallas, TX
Aug 23, 2010 - Aug 27, 2010
Register Now
Washington, DC
Aug 30, 2010 - Sep 03, 2010
Register Now
New York City, NY
Sep 13, 2010 - Sep 17, 2010
Register Now
Chicago, IL
Sep 20, 2010 - Sep 24, 2010
Register Now
Morristown, NJ
Sep 27, 2010 - Oct 01, 2010
Register Now
Houston, TX
Oct 04, 2010 - Oct 08, 2010
Register Now
Atlanta, GA
Oct 25, 2010 - Oct 29, 2010
Register Now
Raleigh, NC
Nov 01, 2010 - Nov 05, 2010
Register Now
Washington, DC
Nov 15, 2010 - Nov 19, 2010
Register Now
Dallas, TX
Nov 29, 2010 - Dec 03, 2010
Register Now
Chicago, IL
Dec 06, 2010 - Dec 10, 2010
Register Now