SMN - Implementing Security Manager for Cisco Networks v1.1

Length Price Cisco Learning Credits
3 days $2,895.00 29

Cisco Security Manager is an enterprise-class management application designed to configure firewall, VPN, and intrusion prevention (IPS) security services on Cisco network and security devices. Cisco Security Manager can be used in networks of all sizes-from small networks to large networks consisting of thousands of devices-by using policy-based management techniques. Cisco Security Manager works in conjunction with the Cisco Security Monitoring, Analysis, and Response System (MARS). Training on these core management systems is a vital part of any Security Operations Center.

  • Firewall Management: Device-agnostic, unified interface for managing firewall rules across different Cisco devices supporting the firewall feature set; flexible rule specification methods for improved productivity and organization of rules; powerful toolset to identify configuration errors and optimize firewall rules
  • VPN Management: VPN Wizard for rapid, simple definition of site-to-site and remote access VPNs
  • IPS Management: Comprehensive solution for configuration management of all Cisco IPS technologies and automation of signature updates
  • Policy-Based Management: Ability to define aspects of a device's configuration into a named, shareable policy, which can be re-used across multiple devices; support for policy hierarchies to allow logical structuring and maximum re-usability
  • Rich-Client Graphical User Interface: Integrated, easy-to-use interface providing multiple views optimized around specific configuration tasks; device-centric view, map-centric view, and policy-centric view
  • Workflow: Provides an approval framework, whereby proposed configuration changes and deployments can be reviewed and approved
  • Role-Based Access Control: Integration with Cisco ACS for granular, role-based access control to devices and management functions
  • Flexible Deployment Options: Support for various methods of deploying configuration changes such as direct to device, to file, or using call-home based techniques
  • Integration with Cisco Security MARS: Cross-correlation between firewall rules and related events and between IPS signatures and related events

Prerequisites

  • CCNA for Security certification or the equivalent knowledge
  • Passing score on any Cisco CCSP Security exam
  • At least six months of practical experience configuring Cisco Security products
  • Familiarity with implementing network security policies and the following networking components and concepts:
    • Security Technologies: NAT, PAT, ASA, VPN, IPS, CSA, ACS, MARS, PIX, IOS integrated router and switch security, and security management software
    • Security Protocols: AAA, IPSec, IKE, and various tunneling protocols
    • Application Protocols: HTTP, HTTPS, ICMP, SSH, SSL, NTP, FTP, TFTP, DNS, etc

What You'll Learn

  • CSM overview; Define your expectations and investigate real-world deployment scenarios
  • How to manage devices in CSM
  • Policy inheritance and policy sharing features in CSM; Create policies and learn how to manage them
  • Concept of objects in Cisco Security Manager and how to use and manage them
  • Use of Map View; Link maps together to give your security team a "drill-down" action map
  • Use Map View to create site-to-site VPNs and remote access VPNs, including SSL VPNs with the use of the Cisco AnyConnect client
  • Various firewall services and objects that are used to manage firewall-related policies
  • How to configure platform policies on firewall devices
  • How to configure platform-specific services and policies on Cisco IPS sensors and Cisco IOS IPS devices
  • Tight integration and cross-launch functionality of the Cisco MARS to CSM by use of an IPS event
  • How to configure platform policies and interface policies on Cisco IOS routers including routing and security-related tasks
  • How to configure platform-specific services and policies on Catalyst 6500 Series Switches and Cisco 7600 Series Routers
  • FlexConfig and how to best use its features
  • How to manage deployments and configuration changes by using Workflow and Non-Workflow mode; View e-mails that management will review and take action on
  • Monitoring, troubleshooting, and diagnostic tools available in Cisco Security Manager

Who Needs to Attend

 

  • Channel Partner/Reseller
  • Anyone interested in managing a Data Loss Prevention (DLP) environment
  • Customer
  • Employee

Course Outline

1. Cisco Security Manager Overview

  • Introducing the Cisco Security Manager
  • Managing Devices in CSM
  • Policy Management in CSM
  • Managing Objects
  • Using Map View

2. Provisioning Cisco Security Devices

  • Managing Virtual Private Networks
  • Managing Firewall Services
  • Managing Firewall Devices
  • Managing SSL VPNs
  • Managing IPS Services and Devices
  • Managing Routers
  • Managing Catalyst 6500 Switch Series and Cisco 7600 Router Series Devices

3. Managing FlexConfigs, Deployment, and Administration in Cisco Security Manager

  • Managing FlexConfigs
  • Managing Deployment and Workflow Activities
  • Using Tools

Labs

Lab 1: Bootstrapping Network Devices

Lab 2: Device Import

Lab 3: Creating Policy Objects

Lab 4: Managing Policies

Lab 5: Authentication and Locking

Lab 6: Discovering Map View

Lab 7: Exploring VPNs in CSM

Lab 8: Configuring SSL VPNs in CSM

Lab 9: CSM, IPS, and MARS

Lab 10: ACL Policy Investigation

Lab 11: Workflow and Administrative Tasks

Class Dates:

San Jose, CA
Oct 11, 2010 - Oct 13, 2010
Register Now
Dallas, TX
Nov 01, 2010 - Nov 03, 2010
Register Now
New York City, NY
Dec 13, 2010 - Dec 15, 2010
Register Now