Services
Convergent Communications, Inc. - A Cisco Systems Learning Partner
Business/Enterprise Solutions Certification Packages
Cisco AS Courses
E-Learning About CCI
Consulting Home Page
Courses Schedules & Pricing Registration Contact Us
Product Training
Deploy Assure
Securing Networks with ASA Advanced (SNAA)


Course Description

Course Objectives

Intended Audience

Prerequisites

Course Outline & Labs

SCHEDULE

REGISTRATION

COURSES INDEX

Securing Networks with ASA Advanced (SNAA) - 5-day entry level course


Course Description

In this Authorized Cisco course, you will take your knowledge and skills on configuring, maintaining, and operating Cisco ASA 5500 Series Adaptive Security to the next level. Recommended training for the Cisco Certified Security Professional (CCSP) certification, SNAA takes over where SNAF leaves off, covering advanced topics of Adaptive Security.

We have added depth to the existing Cisco-developed hands-on labs for SNAA. Our advanced hands-on labs, delivered in an enhanced topology designed to simulate a typical production network, guide you through exercises such as managing digital certificates for IPSec and SSL VPNs, deep packet inspection, and using the 5505 in the SOHO environment.

Our labs utilize ASA 5520 security appliances, though this course and lab content is applicable across the ASA and PIX families of security appliances, since the command syntax is generally the same. This course covers the features and syntax of Cisco Security Appliance Software v8.0.

 

TOP


Course Objectives

  • Use advanced NAT features such as policy-based NAT
  • Use advanced modular policy framework for deep packet inspection of application protocols such as HTTP and FTP
  • How the multimedia protocols are handled and configured by the modular policy framework of the security appliance at Layer 3, 4, and 7
  • Configure the security appliance to segment traffic with VLANs
  • Configure dynamic routing capabilities of the appliance
  • Configure the security appliance to route multicast traffic
  • Use advanced IPSec VPN technologies such as peer authentication using digital certificates
  • Steps necessary to configure the ASA as a CA Server
  • Configure the IPSec VPN Client using digital certificates
  • Configure the advanced Easy VPN Server features of the ASA
  • Necessary configuration for the ASA 5505 to be a VPN hardware client
  • Steps to configure QoS for VPN traffic
  • SSL VPN features and capabilities of the security appliance
  • Enable clientless SSL VPNs with the security appliance
  • Enable AnyConnect SSL VPN Client with the security appliance
  • Enable the Cisco Secure Desktop with the security appliance to increase the security posture of SSL VPN connections
  • Enable Dynamic Access Policy with the Cisco Secure Desktop
  • Characteristics of the services modules for the ASA
  • Configure, inspect, and filter traffic with the Content Security and Control SSM
  • Configure the AIP-SSM to identify and alert for common attacks
    TOP


Intended Audience

  • Cisco customers who implement and maintain ASA and PIX Security Appliances
  • Cisco channel partners who sell, implement, and maintain ASA and PIX Security Appliances
  • Cisco systems engineers who support the sale of ASA and PIX Security Appliances

TOP

 


Prerequisites

 


Course Outline

  1. Advanced ASA NAT Configuration
    • ACLs, NAT 0, Policy NAT
  2. Advanced Protocol Handling
    • Modular Policy Framework
    • Protocol Application Inspection
    • Multimedia Protocol Handling
  3. Dynamic Routing and Switching
    • VLANs
    • Dynamic Routing
    • Multicast
  4. VPNs with IPSec
    • IPSec and Digital Certificates
    • ASA CA Server
    • LAN-to-LAN with Digital Certificates
    • IPSec VPN Client
    • Remote Access with Digital Certificates
    • Advanced Remote Access Features
    • ASA 5505 as a Hardware Client
    • VPN QoS
  5. Security Services Modules
    • ASA Services Modules
    • Content Security and Control
    • Advanced Inspection and Prevention

Course Labs

  • Lab 1: Implementing Advanced NAT
  • Lab 2: Implementing MPF for FTP
  • Lab 3: Dynamic Routing with EIGRP
  • Lab 4: LAN-to-LAN with Digital Certificates
  • Lab 5: Remote Access with Digital Certificates
  • Lab 6: ASA 5505 Hardware Client
  • Lab 7: Clientless SSL VPN
  • Lab 8: SSL VPN with AnyConnect Client
  • Lab 9: Cisco Secure Desktop and Dynamic Access Policy
  • Lab 10: Configuring AIP-SSM


TOP

 



301-565-0138 : info@ccitraning.net

Courses | Schedule | Registration | Contact Us | Homepage | Related Links
Business/Enterprise Solutions | E-Learning | Consulting | Certification Packages | CISCO AES Courses | About Us

© Convergent Communications, Inc.