Welcome!  Log in?  Create account?      Home - My account - Shoppping cart - Checkout - FAQ - Contact
 



 
About us  
Custom request form
Our services
Network Infrastructure
Unified Communications
Data Centers
Our Partners
CCIE Workbooks
CCIE bootcamps
CCIE training catalog
  3
 
advanced search
1

13














    
Course Information

Code Name
  Level  
  Price  
 
SEC-CCIE-CLASS Security Online Training

Duration: 5 days



Expert
$3,500.00    
Reviews
 
Description
Course Title
Security Online Training

Format
Online Class

Duration
5 days

Instructor
Instructor is CCIE™ Security certified

Course Content

This online class offers advanced training that helps already experienced Ciscoฎ Security engineers become even more experienced. The goal of this course is to strengthen your skills and improve competency with Ciscoฎ security products. This class is not for the beginners. It is for those who understand the technology and want to learn how to set things up quickly, efficiently, and in the right order.

The online class is structured around a small Security network packed with the utmost number of features. Your instructor will go over the recommended order of implementation; you will explore different methods for reducing configuration and troubleshooting time. The newest releases (12.4, 12.2S, 12.3T, 12.4) of IOS and VPN products are applied in the practical case studies that concentrate on individual features, so that you can adapt to any network environment you may encounter.

Target Audience

This lecture is for individuals who have worked with Ciscoฎ security products for some time already. You would want to take this class if you are looking to elevate your security knowledgebase to an expert level. Those who pursue CCIE™ Security certification will greatly benefit from this course.

Prerequisite Knowledge

• Field experience using, maintaining, and troubleshooting Ciscoฎ PIX Firewall, Ciscoฎ ACS-AAA, and VPN 3000
• Field experience using the IOS command line interface (CLI) to configure, maintain and troubleshoot Ciscoฎ IOS devices.
• Ciscoฎ Certified Security Professional (CCSPฎ) certification is preferred.

Course Objectives

• Given a large security support, identify and troubleshoot all security-related features.
• Design SAFE network with scalability, efficiency, and reliability in mind.
• Understand and implement a wide variety of security products and features in 5 days

Course Outline

1 . Foundation for Layer 2/3 Security Components

• Provisioning Layer 3 Protocols
• Provisioning VPN 3000
• Provisioning Firewalling
• Provisioning Routers
• Advanced Configuration of Attachment Circuits

2. Layer 2 Switching and Security

• Configuring VTP, VLAN, Trunk, Spanning Tree
• Names and Descriptions for Port-VLAN Assignments
• SPAN, RSPAN
• 802.1Q Tunneling
• DHCP Starvation
• Disabling Password Recovery on a Switch
• Policing on 3550/3750
• Native VLAN vs. Non-Native VLAN

3. Advanced Layer 2 Switching

• Spanning-Tree Protocol Manipulation
• BPDU Guard
• VLANs Port Security
• CAM Table Overflow
• Private VLAN Attacks
• QinQ Tunneling
• VLAN Stacking

4. Securing Layer 3 Protocols

• RIP
• EIGRP MD5
• OSPF MD5
• PIX OSPF/RIP MD5
• BGP MD5
• Secure BGP Session Using MD5
• IBGP Route Reflectors
• EBGP MultiHop over PIX Firewall
• BGP Security over Firewalling and ACL
• Filter and Summarization Routes

5. Commonly-Used of IP Security Features

• IOS SNMP Authentication Enable
• Control Privileged-Level
• PIX/IOS Banner Control
• Telnet Source
• FTP Services on IOS
• HTTP Security
• DHCP Server—Option to Ignore All BOOTP
• Configuring HTTPS Service
• Logging, CDP, NTP

6. Basic Firewalling Features

• NAT/PAT Redundancy
• Basic CBAC
• Telnet Control and ACL’s
• Anti-Spoofing
• Inspecting Traffic
• Basic PIX Firewalling and NAT
• Tunneling through the PIX
• PAM Application Control
• Common IDENT Issues

7. Advanced IP Security Features

• Distributed Time-Based Access Lists
• Controlling Access
• IOS NAT/PAT, PIX NAT/PAT
• PIX ACL’s
• PIX/IOS NTP/MD5
• IP Urlfilter PIX
• PIX FIXUP/IDENT and Object Groups
• PIX SNMP and Management SNMP Logging
• ICMP and Trace Route Filtering
• IP SSH IOS and PIX
• IOS ACL’s

8. VPN Products Provisioning

• Configuring Easy VPN on a PIX Firewall
• IPSec VPN Client to VPN 3005
• IPSec VPN 3002 to VPN 3005
• IPSec VPN 3002 to PIX and IOS
• IPSec VPN 3005 Client to PIX and IOS
• IPSec VPN Load Balancing and HA
• IPSec Split Tunneling and CRL Caching
• IPSec and Reverse Route Injection

9. Authentication Security

• Setting AAA Server for Authentication and Authorization
• RADIUS/TACACS+ PIX
• RADIUS/TACACS+ IOS
• RADIUS/TACACS+ VPN 3005
• AAA Accounting PIX/IOS/VPN3005
• Management AAA Logging
• Priv-Level Control with AAA
• 802.1X Switch
• VPN Access Control Using 802.1X Authentication
• Eazy VPN to AAA IOS/PIX/VPN3005
• PIX Termination VPDN against Tacacs+

10. Advanced VPN Features

• Full-Meshed PIX/VPN 3000/IOS/VPN-Client AES
• IPSec and CA IOS to PIX
• IPSec and CA VPN 3005
• IPSEC and DMVPN
• IPSec and NAT Transparency
• IPSEC Idle Timers
• IPSec DPD
• IPSec and DNS Resolution
• High Availability for IPSec
• Xauth
• Split-tunnel
• RRI
• NAT-T
• Other Advanced PIX Features
• Tunneling Layer 2 Services
• SSL/TLS Encryption Protocols for WebVPN
• PIX and Multicast

11. Advanced VPN and Legacy Features

• Using Dialer Profiles, ODR, DDR, Authentication
• Default Route on a PPP
• VPDN and AAA configuration and troubleshooting

12. Managing IP Security Networks

• Using AAA to Collect Login and Configuration Changes
• Securing Console for Switch and Router
• IPSec and SNMP Monitoring
• Remote Security to VPN 3000 Management
• IPSec VPN Accounting

13. Advanced Firewalling Techniques

• CBAC/ACL Bypass
• Auth Proxy
• Access control, Access lists (standard, extended, named)
• Time-Based ACL’s
• URPf
• TCP Intercept
• IP Urlfilter IOS
• Role-Based CLI Access

14. QoS and Security Integration

• PIX™ QoS/LLQ
• IOS DoS/DDoS Attacks
• Basic QoS Traffic Control and Congestion Management on a 3550 Switch
• GRE/uRPF
• CAR
• NBAR
• Netflow
• PBR
• Policing – 3550/2950/3700
• Packet Marking Techniques

15. Basic IDS Components

• Intrusion Detection System
• Initial Setup for IDS Sensor Appliance 4215
• Sensor Configuration
• Signature Tuning

16. Advanced IDS Features

• Shunning
• Attacks Flooding
• Network/Host attacks
• Attacks Spoofing
• TCP Resets
• Sensor Features
• IDS in IOS and PIX

17. Advanced Tunneling Features

• QoS for VPN over GRE Tunnel
• Rate Based Satellite Control Protocol
• L2TPv3

18. Advanced Enterprise and Service Provider Features

• MPLS-VRF/Select
• Tunneling IPv4 over IPv6
• L2TPv3 and IPSec 2650 12.3T  
Continue
8
1
5

   
9
9
11
11
5
FAQ Career Terms and Conditions Disclaimers 35 Privacy
5
1
8

Copyright ฉ ieMentor.com a division of A ieMentor Corp. All rights reserved.
Do not duplicate or redistribute in any form!
Legal Notice: Cisco, the CCVP, CCNA, CCNP, CCDA, CCDP, CCIE, Cisco Certified Design Associate, Cisco Certified Design Professional, Cisco Certified Network Associate, Cisco Certified Network Professional, Cisco Certified Internetwork Expert, Cisco Certified Internetwork Expert Routing And Switching, Cisco Certified Internetwork Expert Service Provider, Cisco Certified Internetwork Expert Storage and Cisco Certified Internetwork Expert Security are all registered trademarks of Cisco Systems Inc.    Read our Disclaimers.