The Building Enhanced Cisco Security Networks Boot Camp teaches the delegate how to create a network security policy, an often overlooked but vital part of any network security deployment, as well as deploy several emerging security technologies.
In practical labs, delegates will build a dynamic multipoint VPN (DMVPN), set up High Availability for IPSec (IPSec-HA), identify the Path MTU of a nested IPSec tunnel, configure a site-to-site IPSec VPN for split tunneling, secure network management, configure VMS 2.2 for IDS management, and set up Identity-Based Network Services (IBNS) for a wireless environment.
To test the delegates understanding of the course materials, the final phase of the class will be a network attack in which various tools will be used to attempt to gain access to their networks.
The course outline is as follows:
- Introduction
- Developing a network security policy
- Configuring site-to-site IPSec VPNs with split tunneling
- Understanding fragmentation, path MTU discovery, and recursive routing
- Deploying IPSec-HA
- Implementing DMVPN
- Deploying IBNS for a wireless network
- Securing Cisco network management
- Configuring CiscoWorks VMS 2.2 for IDS management
- Common network attack mitigation
Lab Outline:
- Developing a network security policy
- Create a threat response procedure for the network security policy
- Configure Cisco IOS Software for site-to-site VPN using IPSec
- Configure a remote office for secure split tunneling
- Identify path MTU for an established site-to-site IPSec VPN
- Configure stateless high availability between IPSec routers
- Configure connectivity to a stateful high-availability IPSec redundant pair
- Configure a NHRP spoke router to participate in a DMVPN
- Configure Cisco IOS Software for SSH Protocol
- Configure Cisco SNMP v2 and Cisco SNMP ACLs
- Configure a wireless network for 802.1X using Cisco secure ACS
- Configure Cisco secure PIX firewall, Cisco IOS Software, Cisco secure IDS, and CiscoWorks VMS 2.2 to mitigate and respond to network threats