Career Training >> Information Technology Training >> Cisco Training >> SNPA (Securing Networks with PIX and ASA) Training Seminar
Course ID: 12154 | Course Duration: 5 Days
Course Dates: 
 
Career Training
 

SNPA (Securing Networks with PIX and ASA) Training Class

Course ID: 12154
 
 
Course Snapshot View Dates Add To My Courses Get More Information About This Course Register Online Register By Fax On-Site Training View Printer Friendly Version
 
     
 

SNPA (Securing Networks with PIX and ASA) Training Seminar


This Authorized Cisco course teaches the knowledge and skills needed to
configure, maintain, and operate Cisco PIX 500 Series Security Appliances and
Cisco ASA 5500 Series Adaptive Security Appliances. SNPA is recommended training
for the Cisco Certified Security Professional (CCSP) certification.
We have enhanced our 5-day hands-on delivery of SNPA by adding extra depth to
the existing Cisco-developed hands-on labs. Twenty advanced hands-on labs guide
you through configuring the Security Appliance and executing general maintenance
commands, and configuring ACLs on the Security Appliance. Since all labs are
performed on PIX 515 Security Appliances, those features unique to the 5500
Series Adaptive Security Appliances are discussed but are not covered in
hands-on labs.
We have also included coverage of new version 7.0(4) features like syslog
rate-limiting and cascading ACLs. Other course exclusives are use of the capture
and management-access commands, stateful ICMP inspection, TCP Intercept, digital
certificates, and a full lab on configuring a Modular Policy Framework.
All labs are based on our enhanced topology, which simulates a typical
production network instead of one designed only for a classroom environment.
 
     
     
  Course Details  
     
     
  Agenda  
 


1. Cisco Security Appliance Technology and Features



Introduction to the general functionality provided by firewalls and Security
Appliances.


  • Firewall Technologies

  • Security Appliance Features Overview


2. Cisco PIX Security Appliance and ASA Adaptive Security Appliance Families



Introduction to the Cisco PIX 500 Series Security Appliance family, Cisco ASA
5500 Series Adaptive Security Appliance family, and Firewall Services Module (FWSM).


  • Models and Features of Cisco Security Appliances

  • PIX Security Appliance Licensing

  • ASA Adaptive Security Appliance Licensing

  • Cisco Firewall Services Module


3. Getting Started with Cisco Security Appliances



Learn to configure a Security Appliance.


  • User Interface

  • File Management

  • Security Appliance Security Levels

  • Basic Security Appliance Configuration

  • Examining Security Appliance Status

  • Time Setting and NTP Support

  • Syslog Configuration


4. Translations and Connections



Discussion of Security Appliance translations and connections, how the Security
Appliance processes TCP and User Datagram Protocol (UDP) traffic, and how to
configure dynamic and static address translations in a Security Appliance.


  • Transport Protocols

  • Network Address Translation

  • Port Address Translation

  • Identity NAT (NAT 0)

  • Static Command

  • Port Redirection with the Static Command

  • TCP Intercept and Connection Limits

  • Connections and Translations

  • Configuring Multiple Interfaces


5. Access Control Lists (ACLs) and Content Filtering



Discuss how to control access through the Security Appliance using ACLs. Learn how to configure the Security Appliance to filter
malicious active code and how to configure URL filtering.


  • ACLs

  • Time-Based ACLs

  • Editing Existing ACLs

  • The ICMP Command

  • Other ACL Uses

  • Malicious Active Code Filtering

  • URL Filtering


6. Object Grouping



Learn object grouping concepts and how to use the object-group command to
configure object grouping. The various types of object groups are explained, and
the use and configuration of nested object groups are covered.


  • Configuring Object Groups

  • Nested Object Groups

  • Applying Object Groups to ACLs


7. Authentication, Authorization, and Accounting (AAA)



Learn Security Appliance AAA and
how to configure AAA.


  • Introduction to AAA

  • Installation of Cisco Secure ACS for Windows 2000

  • Security Appliance Access Authentication Configuration

  • Using the Local User Database

  • Changing Authentication Timeouts

  • Security Appliance Cut-Through Authentication Configuration

  • Virtual Telnet and Virtual HTTP

  • Tunnel Access Authentication Configuration

  • Authorization Configuration

  • Downloadable ACLs

  • Per-User Override

  • Accounting Configuration


8. Switching and Routing



Explanation of the virtual local area network (VLAN) capabilities of the
Security Appliance and the routing capabilities of the Security Appliance.
Discussion of Routing Information Protocol (RIP) and the Open Shortest Path
First (OSPF) algorithm in detail and configuration of the Security Appliance to
allow multicast traffic.


  • VLANs

  • Static and Dynamic Routing

  • OSPF

  • Multicasting


9. Modular Policy Framework



Introduction of modular policy framework and explanation of how to configure a
modular policy.


  • Modular Policy Overview

  • Configuring a Class Map

  • Configuring a Policy Map

  • Configuring a Service Policy


10. Advanced Protocol Handling



Introduction to Security Appliance advanced protocol handling. Learn to
configure protocol inspection, including configuring an inspection modular
policy, defining an FTP map, defining an HTTP map, and describing a number of
the inspection protocols supported by the Security Appliance.


  • Advanced Protocol Handling

  • FTP, HTTP, and Protocol Application Inspection

  • Configuring Deep Packet Inspection

  • Multimedia Support


11. VPN Configuration



Learn the basics of IPSec and Security Appliance virtual private networks (VPNs),
with a focus on communications between Security Appliance gateways for
site-to-site secure connectivity. Discuss how VPNs function and the tasks
necessary to configure VPN connection parameters on the Security Appliance.


  • Secure VPNs

  • How IPSec Works

  • Configure VPN Connection Parameters

  • Configuring IKE Parameters

  • Configuring Tunnel Groups

  • Configuring IPSec Parameters

  • Scale Security Appliance VPNs with Digital Certificates


12. Configuring Security Appliance Remote Access Using Cisco Easy VPN



Discuss the Cisco Easy VPN and its two components and modes of operation.


  • Introduction to Cisco Easy VPN

  • How Cisco Easy VPN Works

  • Configuring Users and Groups

  • Configuring IKE Mode Config Parameters

  • Configuring Dynamic Crypto Maps

  • Configuring the Easy VPN Server for Extended Authentication

  • Configure Security Appliance Hub-and-Spoke VPNs

  • Cisco VPN Client Manual Configuration Tasks

  • Working with the Cisco VPN Client


13. Configuring ASA for WebVPN



Define the characteristics of WebVPN and how it compares with traditional VPNs.
Discuss the end-user interface and the steps and commands necessary to configure
the ASA for WebVPN. As this is a feature unique to the ASA 5500 Series, it is
not covered in a hands-on lab.


  • WebVPN End-User Interface

  • Configure WebVPN General Parameters, Servers, URLs, and Port Forwarding

  • Define Email Proxy Servers

  • Configure WebVPN Content Filters and ACLs


14. Configuring Transparent Firewall



Overview and explanation of transparent firewall mode. Enabling transparent
firewall and monitoring and maintenance commands specific to the transparent
firewall mode are also detailed.


  • Transparent Firewall Mode Overview

  • Enabling Transparent Firewall Mode

  • EtherType ACLs

  • ARP Inspection

  • Monitoring and Maintaining Transparent Firewall Mode


15. Configuring Security Contexts



Learn the purpose of security contexts and how to enable, configure, and manage
multiple contexts.


  • Security Context Overview

  • Enabling Multiple Context Mode

  • Configuring a Security Context

  • Managing Security Contexts


16. Failover



Introduction to the Security Appliance failover options and how to configure
them. Describe the types of failover supported by the Security Appliance and
learn to configure active/standby, active/active, and stateful failover.


  • Understanding Failover

  • Serial Cable-Based Failover Configuration

  • Acti
 
     
     
  Audience  
 


Cisco customers who implement and maintain PIX and ASA Security Appliances;
Cisco channel part

 
     
  Pre-requisites  
  PreReqs  
     
  Comments  
  For all course dates held in Canada, please add 5% GST to the course price. Canadian residents will need to add an additional 7% PST to the course price.  
     
     
 
On-Site Training Bring this SNPA (Securing Networks with PIX and ASA) training class in-house at your facility. Request More Information Request More Information On SNPA (Securing Networks with PIX and ASA)
 
Career Training
 
 
Career Training
  SNPA (Securing Networks with PIX and ASA) Training Course Dates and Locations  
     
  Course ID: 12154 | Course Duration: 5 Days  
     
  Locations:  
     
   User Incentive For Registering on TrainUp.com! Gift card when you register today!  
     
 
Start Date Price      Location/Event Details Register Online Request
More Info
  Print/Fax
Register
10/13/2008 $3,095.00    King Of Prussia, PA Register Online For The 10/13/2008 Event Request More Information   Register By Fax For The 10/13/2008 Event
10/20/2008 $3,095.00    Minneapolis, MN Register Online For The 10/20/2008 Event Request More Information   Register By Fax For The 10/20/2008 Event
10/20/2008 $3,095.00    ARLINGTON, VA Register Online For The 10/20/2008 Event Request More Information   Register By Fax For The 10/20/2008 Event
10/27/2008 $3,095.00    Cary, NC Register Online For The 10/27/2008 Event Request More Information   Register By Fax For The 10/27/2008 Event
10/27/2008 $3,095.00    Schaumburg, IL Register Online For The 10/27/2008 Event Request More Information   Register By Fax For The 10/27/2008 Event
10/27/2008 $3,686.19    Vancouver, BC Register Online For The 10/27/2008 Event Request More Information   Register By Fax For The 10/27/2008 Event
11/03/2008 $3,095.00    Phoenix, AZ Register Online For The 11/03/2008 Event Request More Information   Register By Fax For The 11/03/2008 Event
11/03/2008 $3,095.00    Burlington, MA Register Online For The 11/03/2008 Event Request More Information   Register By Fax For The 11/03/2008 Event
11/03/2008 $3,095.00    Irving, TX Register Online For The 11/03/2008 Event Request More Information   Register By Fax For The 11/03/2008 Event
11/10/2008 $3,095.00    New York, NY Register Online For The 11/10/2008 Event Request More Information   Register By Fax For The 11/10/2008 Event
11/10/2008 $3,095.00    ORLANDO, FL Register Online For The 11/10/2008 Event Request More Information   Register By Fax For The 11/10/2008 Event
11/17/2008 $3,095.00    Irvine, CA Register Online For The 11/17/2008 Event Request More Information   Register By Fax For The 11/17/2008 Event
11/17/2008 $3,095.00    Houston, TX Register Online For The 11/17/2008 Event Request More Information   Register By Fax For The 11/17/2008 Event
12/01/2008 $3,095.00    Dublin, OH Register Online For The 12/01/2008 Event Request More Information   Register By Fax For The 12/01/2008 Event
12/01/2008 $3,095.00    Rancho Cordova, CA Register Online For The 12/01/2008 Event Request More Information   Register By Fax For The 12/01/2008 Event
12/01/2008 $3,686.19    Toronto, ON Register Online For The 12/01/2008 Event Request More Information   Register By Fax For The 12/01/2008 Event
12/01/2008 $3,095.00    ST. LOUIS, MO Register Online For The 12/01/2008 Event Request More Information   Register By Fax For The 12/01/2008 Event
12/08/2008 $3,095.00    Santa Clara, CA Register Online For The 12/08/2008 Event Request More Information   Register By Fax For The 12/08/2008 Event
12/08/2008 $3,095.00    Cary, NC Register Online For The 12/08/2008 Event Request More Information   Register By Fax For The 12/08/2008 Event
12/08/2008 $3,095.00    ARLINGTON, VA Register Online For The 12/08/2008 Event Request More Information   Register By Fax For The 12/08/2008 Event
12/15/2008 $3,095.00    Irving, TX Register Online For The 12/15/2008 Event Request More Information   Register By Fax For The 12/15/2008 Event
12/15/2008 $3,095.00    El Segundo, CA Register Online For The 12/15/2008 Event Request More Information   Register By Fax For The 12/15/2008 Event
12/15/2008 $3,095.00    MORRISTOWN, NJ Register Online For The 12/15/2008 Event Request More Information   Register By Fax For The 12/15/2008 Event
12/15/2008 $3,924.40    Kanata, ON Register Online For The 12/15/2008 Event Request More Information   Register By Fax For The 12/15/2008 Event
 
     
 
On-Site Training Bring this SNPA (Securing Networks with PIX and ASA) training class in-house at your facility. Request More Information Request More Information On SNPA (Securing Networks with PIX and ASA)
 
Career Training
 
 
Career Training
  Browse Our Catalog  
     
  Select a market segment to view more courses

 
     
  Or, select a category to view more Information Technology courses

 
     
  Browse By Category Browse By Category

Browse By Location Browse By Location

Browse New Courses Browse New Courses

 
     
Career Training
 
   
 
 
Career Training
   
Career Training
 
 
 
 






Site Map -- Top Training Courses -- Request On-Site Training

Find Jobs -- Degree Programs -- Training Providers -- Resource Center -- About Us -- Contact us

TrainUp.com Your Career Training Marketplace