Cisco PIX: Cisco Firewall Specialist Call: 0207 392 9696 
 
Request Brochure
 
 
Name :
Email :
Phone :
Course :
Address :
Call Now: 0207 392 9696
 

QUICK TIME TABLE
 Weekday
StartsDay(s)Time
Jul 14 2008 Mon, Wed18:30-21:30
Aug 8 2008 Friday10:00-17:00
Sep 5 2008 Friday10:00-17:00
 Weekend
StartsDay(s)Time
Jul 11 2008 Friday10:00-17:00

Cisco Firewall SPECIALS
  Cisco Firewall Specialist&
  CCNA - £1350
  You save £400        
  Cisco Firewall Specialist&
  CCNP- £3250
  You save £750        

 
 
Raves reviews responses
 

Cisco PIX
Firewall Specialist

 
  • Cisco Pix: £1000
  • Hands On Tutor Led for 4 Weeks
  • Free Books , VAT, MOCK Exam Inc.
  • Max 10 Per Class (check our facilities)
  • Re-sit Exam Fee Guarantee
  • or Call 0207 392 9696
 

Cisco PIX: Cisco Firewall Specialist


Course Explanation

With Cisco systems dominating a large chunk of the information technology industry, being a CISCO PIX firewall specialist calls for a specific skill set, unmatched by any other across the globe. Most pupils can learn Cisco IOS and CISCO PIX along with the Adaptive Security Appliance.

The course contains 16 hours of comprehensive training inclusive of physical installation, mitigation methods for common network attacks, mitigation methods for Worm, Virus, and Trojan Horse attacks, secure network lifecycle, security needs, security policy and Cisco Self Defending Network architecture all on the first day alone.

The latter half of the course holds good too, as you can enrol yourself in grasping knowledge regarding Cisco routers, with an introduction to ASA, PIX firewall and network security, modular policy framework with an advanced study of configuring PIX Security, appliance of remote access using Cisco Easy VPN and Firewall Services Module. An added advantage to this would be the free lab access after the completion of the course.

Certification Exam Code
642-552 SND Securing Cisco Network Devices
642-523 SNPA Securing Networks with PIX and ASA

 

 

 

Course Contents (16 sessions of 3hrs each)

Day 1 642-552 SND: Securing Cisco Network Devices Exam

security threats facing modern network infrastructures
• physical installation
• mitigation methods for common network attacks
• mitigation methods for Worm, Virus, and Trojan Horse attacks
• secure network lifecycle
• security needs, security policy
• Cisco Self Defending Network architecture

Secure Cisco routers
• SDM Security Audit feature
• One-Step Lockdown to secure a Cisco router
• setting strong encrypted passwords, exec timeout, login failure rate and using IOS login enhancements
• configuring multiple privilege levels
• Sconfiguring role based CLI
• Secure the Cisco IOS image and configuration file

Day 2

AAA using Cisco routers
• functions and importance of AAA
• TACACS+ and RADIUS AAA protocols
• authentication, provide access to the router (character mode)

Mitigate threats to Cisco routers and networks using ACLs
• standard, extended, and named IP ACLs used by routers to filter packets
• Configure and verify IP ACLs to mitigate given threats (filter IP traffic destined for Telnet, SNMP, and DDoS attacks) in a network using CLI
• Configure IP ACLs to prevent IP address spoofing using CLI

Secure network management and reporting
• secure management and reporting of network devices
• configure SSH on Cisco routers to enable secured management access
• configure Cisco routers to send Syslog messages to a Syslog server
• SNMPv3 and NTPv3

Day 3

Mitigate common Layer 2 attacks
• Layer 2 attacks, VLAN hopping, STP attacks, ARP spoofing, MAC spoofing, CAM overflow
• Cisco Catalyst switches (IBNS, PVLAN, SPAN port)
• common threats to WLANs
• security features of the 802.11 protocol

Cisco IOS firewall feature set using SDM
• firewall technologies
• stateful firewall operations and the function of the state table
• types of NAT that can be implemented in a firewall
• Configure and verify basic and advanced firewall on a Cisco router using SDM

Cisco IOS IPS feature set using SDM
• network based vs. host based intrusion detection and prevention
• IPS technologies, attack responses, and monitoring options
• Enable and verify Cisco IOS IPS operations using SDM

Day 5

IPsec VPN on Cisco routers using SDM
• IKE protocol functionality and phases
• IPsec and the security functions it provides
• hash-based message authentication code (HMAC) operations
• different methods of encryption
• purpose of the Diffie-Hellman key agreement protocol
• IPsec establishes origin authentication
• PKI environment at a high level
• IPsec VPN implementations
• Configure and verify an IPsec site-to-site VPN
• Cisco Easy VPN Server and Cisco Easy VPN Remote
• Configure and verify remote access VPNs using the Cisco Easy VPN Server

Day 6

642-523 SNPA: Securing Networks with PIX and ASA Exam

Install and configure a Security Appliance for basic network connectivity
• Security Appliance hardware and software architecture
• Appliance hardware and software configuration and verify if it is correct
• CLI to configure basic network settings, including interface configurations
• show commands to verify initial configurations
• Configure NAT and global addressing
• Configure DHCP client
• default route
• Configure logging, syslog files
• Configure static address translations
• Configure Network Address Translations: PAT

Configure to restrict inbound traffic from untrusted sources
• access-lists to filter traffic based on address, time, and protocols
• object-groups to optimize access-list processing
• Nat0, Policy NAT
• java/activeX filtering
• Configure URL filtering, inbound traffic restrictions
• Configure static port redirection, Configure a net static
• Set embryonic and connection limits on the Security Appliance

Configure to provide secure connectivity using site-to-site VPNs
• functionality of IPsec , Configure IKE with preshared keys
• types of encryption, IPsec parameters, crypto-maps and ACLs

Day 7

Configure to provide secure connectivity using remote access VPNs
• functions of EasyVPN
• IPsec using EasyVPN Server/Client
• Cisco Secure VPN client, SSL VPN
• WebVPN services: Server/Client, VPN operations
• SVCs, Cisco Secure Desktop

Configure transparent firewall, virtual firewall, and high availability firewall features on a Security Appliance
• Explain differences between L2 and L3 operating modes
• Transparent mode (L2)
• Virtual firewalls, Monitor and maintain virtual firewall
• Types, purpose and operation of fail-over
• Cable-based or LAN-based fail-over, Hardware, software and licensing requirements for high-availability
• Active/standby fail-over, Stateful fail-over, Active-active fail-over
• Verify fail-over operation, Recover from a fail-over, Allocate resources to virtual firewalls

Configure AAA services for the Security Appliance
• ACS for Security Appliance support, Use AAA feature
• Configure authentication using both local and external databases
• Configure authorization using an external database
• Configure the ACS server for downloadable ACLs
• Configure accounting of connection start/stop
• AAA operation

Configure routing and switching on a Security Appliance
• DHCP server and relay functionality
• VLANs, Pass multi-cast traffic

Day 8

Configure Security Appliance advanced application layer and modular policy features
• Class-map, Policy-map, Service-policy, ftp-map, http-map
• Inspection protocol, Function of protocol inspection
• DNS guard, AIP-SSM HW and SW, Load IPS SW in the AIP-SSM, AIP-SSM
• IPS modular policy, CSC-SSM HW and SW, Configure regex class maps, regular expressions
• Load CSC SW on the SSM
• CSC-SSM, Divert traffic to the CSC-SSM, Initialize the CSC-SSM

Monitor and manage an installed Security Appliance
• Obtain and apply OS updates
• Backup and restore configurations and software
• File management system
• Password/lockout recovery procedures
• Upgrade license keys
• Passwords for various access methods: Telnet, serial, enable, SSH
• Various access methods: Telnet, SSH, ASDM
• Configure command authorization and privilege levels
• Configure local username database
• Verify access control methods
• Enable ASDM functionality
• ASDM, Verify the licensing available on a Security Appliance
• Add, delete, and modify syslog messages

After Course Free Lab Access
Copyright © 2008 LSCE London (UK). All rights reserved.