Implementing Core Cisco ASA Security SASAC
Implementing Core Cisco ASA Security SASAC
Implementing Core Cisco ASA Security SASAC
www.ddls.com.au
Price
5 days
Overview
Cisco ASA Core covers the Cisco ASA 9.0 / 9.1 core firewall and VPN features. This enhanced course contains added depth
to the standard labs, using a topology that simulates a typical production network. You'll use ASA 5515 appliances to work
through configuring access control to and from your network.
Additionally, the PC systems and server systems are an integral part of the lab environment. Here you will use Windows 8,
Windows Server 2012, and Kali Linux to manage, test, and even attack your lab network using real-world operating
systems and applications.
Skills Gained
Upon completing this course, the learner will be able to meet these overall objectives:
Essentials of Cisco ASA
Basic connectivity and device management
Network integration
Configure common features of the Cisco ASA OS
Cisco ASA policy control
Core Cisco ASA VPN common components
Main VPN components
Cisco clientless VPN solutions
Cisco AnyConnect full tunnel VPN solution
Cisco ASA high availability and virtualization options
Features of Cisco ASA 5500-X Series Next-Generation Firewalls
Key Topics
1. Cisco ASA Essentials
Firewall Technologies
Cisco ASA Features
Cisco ASA Hardware
Cisco ASA Licensing Options
Cisco ASA Licensing Requirements
2. Basic Connectivity and Device Management
Managing the Cisco ASA Boot Process
Managing the Cisco ASA Using the CLI
Managing the Cisco ASA Using Cisco ASDM
Navigating Basic Cisco ASDM Features
Managing the Cisco ASA Basic Upgrade
Managing Cisco ASA Security Levels
Configuring and Verifying Basic Connectivity Parameters
Configuring and Verifying Interface VLANs
Configuring a Default Route
Configuring and Verifying the Cisco ASA Security Appliance DHCP Server
Troubleshooting Basic Connectivity
3. Network Integration
NAT on Cisco ASA Security Appliances
Configuring Object (Auto) NAT
Configuring Manual NAT
Tuning and Troubleshooting NAT on the Cisco ASA
Connection Table and Local Host Table
Configuring and Verifying Interface ACLs
Configuring and Verifying Global ACLs
Configuring and Verifying Object Groups
Configuring and Verifying Public Servers
Configuring and Verifying Other Basic Access Controls
Troubleshooting ACLs
Static Routing
Dynamic Routing
EIGRP Configuration and Verification
Multicast Support
4. Cisco ASA Policy Control
Cisco MPF Overview
Configuring and Verifying Layer 3 and Layer 4 Policies
Configuring and Verifying a Policy for Management Traffic
Layer 5 to Layer 7 Policy Control Overview
Configuring and Verifying HTTP Inspection
Configuring and Verifying FTP Inspection
Supporting Other Layer 5 to Layer 7 Applications
Troubleshooting Application Layer Inspection
5. Cisco ASA VPN Common Components
VPN Definition
Key Threats to WANs and Remote Access
VPN Types
VPN Components
Cisco ASA VPN Policy Configuration
Cisco ASA Connection Profiles
Cisco ASA Group Policies
Cisco ASA VPN AAA and External Policy Storage
Cisco ASA User Attributes
Access Control Methods
VPN Accounting Using External Servers
Dynamic Access Policy for SSL VPN
Using PKI Provisioning Server-Side Certificates on the Cisco ASA Adaptive Security
Appliance
CA Servers
Deploying Client-Based Certificate Authentication
SCEP Proxy Operations
Enable Certificate Authentication in Connection Profile
Configuring Certificate-to-Connection Profile Mappings
6. Cisco Clientless VPN Solution
Cisco Clientless SSL VPN
Cisco Clientless SSL VPN Use Cases
Cisco Clientless SSL VPN Resource Access Methods
Secure Sockets Layer and Transport Layer Security
SSL Session Setup and Key Management
SSL Server Authentication
SSL Client Authentication
SSL Transmission Protection
Basic Cisco Clientless SSL VPN
Server Authentication in Basic Clientless SSL VPN
Client-side Authentication in Basic Clientless SSL VPN
Target Audience
Network engineers supporting Cisco ASA 9.x implementations
We can also deliver and customise this training course for larger groups saving your organisation time, money and resources. For
more information, please contact us on 1800 853 276.
Prerequisites
Knowledge of the Cisco ASA
IINS 2.0 - Implementing Cisco IOS Network Security
The supply of this course by Dimension Data Learning Solutions Pty Ltd is governed by the booking terms and conditions. Please read the terms and conditions carefully before enrolling in this
course, as enrolment in the course is conditional on acceptance of these terms and conditions.