SASSL v1.0 Managing Advanced Cisco SSL VPN. 3 days lecture course and hands-on lab $2,495 USD 25 Digital Version

Size: px
Start display at page:

Download "SASSL v1.0 Managing Advanced Cisco SSL VPN. 3 days lecture course and hands-on lab $2,495 USD 25 Digital Version"

Transcription

1 Course: Duration: Fees: Cisco Learning Credits: Kit: 3 days lecture course and hands-on lab $2,495 USD 25 Digital Version Course Overview Managing Advanced Cisco SSL VPN (SASSL) v1.0 is an instructor-led three-day course focused on providing advanced knowledge and features of Secure Sockets Layer (SSL) VPNs on the Cisco Adaptive Security Appliance (ASA). Students will be able to evaluate various deployment options for SSL VPNs and configure advanced features using the Cisco Advanced Security Device Manager (ASDM) GUI. Objective Students will learn and able to meet following objectives: Describe client-based and clientless VPN solutions Explain the relationship between tunnel groups, group and user policies, connection profiles, and dynamic access policies Describe basic and advanced features of the clientless WebVPN solution, including smart tunnels, web ACLs, plug-ins, auto-signon, bookmarks, and portal customization Describe basic and advanced features within Cisco AnyConnect client version 3.0, including firewall policy push, Trusted Network Detection (TND), login scripts and profile editor Describe the features and benefits of Cisco Secure Desktop and understand the differences between the prelogin policies and Host Scan; use Cisco Secure Desktop to integrate Endpoint Assessment and Advanced Endpoint Assessment (AEA) Configure dynamic access policies (DAPs) Describe the process required to enroll the Cisco ASA appliance with a third-party certificate authority (CA) and how to enroll and retrieve user-based certificates to provide mutual authentication Explain how the username credential can be automatically populated and how the connection profile can be chosen automatically using the prefill and certificate mapping features in the Cisco ASA appliance December 30, / 8

2 Prerequisite Skills and Knowledge The knowledge and skills that a learner must have before attending this course are as follows: Skills and knowledge equivalent to those learned in Securing Networks with ASA Fundamentals (SNAF) Working knowledge of the Microsoft Windows operating system, including Microsoft Internet Explorer Understanding of SSL and certificate fundamentals It is recommended that a learner have the following knowledge and skills before attending this course: Skills and knowledge equivalent to those learned in Securing Networks with ASA Advanced (SNAA) -OR- Skills and knowledge equivalent to those learned in Virtual Private Networks (VPN) Laptop requirements Students registering for this course will be receive digital format course kit. To be able to view digital kit students will need to bring a laptop. The recommended system requirements are as under; Windows 7 or 8.1 or 10 is recommended. Mac OSX 10.6 or greater is supported as well. Intel Celeron or better processors are preferred. 1 GB or more of RAM Browser requirement: Internet Explorer 10 or Mozilla Firefox. (Safari, Mozilla Firefox for Mac OSX) Note: Our labs currently cannot run on Microsoft Edge (Windows 10) due to it not supporting Extensions/Add-ons or Google Chrome due to Java being removed from the platform itself. All students are required to have administrator rights to their PCs and cannot be logged in to a domain using any Group Policies that will limit their machine's capabilities. If you do not have administrator rights to your PC, you at least need permissions to download, install, and run Cisco Any Connect Client and Java. All PCs require the latest Java Runtime Environment, which can be downloaded from Course Outline Course Introduction The Course Introduction provides learners with the course objectives and prerequisite learner skills and knowledge. The Course Introduction presents the course flow diagram and the icons that are used in the course illustrations and figures. This course component also describes the curriculum for this course, providing learners with the information that they need to make decisions regarding their specific learning path. Overview Learner Prerequisite Skills and Knowledge Course Goal and Objectives Course Flow Additional References Lab Exercise Scenario Your Training Curriculum December 30, / 8

3 Module 1: Feature Mapping and Scenario Discussion This module provides an understanding of SSL technology and an overall understanding of which SSL VPN solution to implement given a set of requirements. Upon completing this module, the learner will be able to meet these objectives: Describe SSL technology Describe clientless SSL VPN features Describe AnyConnect features Design SSL VPN solution Select SSL VPN solution according to user access needs 1. SSL Technology Overview 2. Clientless SSL Feature Overview 3. AnyConnect Feature Overview 4. Group Deployment Type (Clientless versus AnyConnect) 5. License Requirements for Suggested Solution Module 2: Initializing ASA and Preparing for PKI and AAA Support This module provides an understanding of the ASA basic configuration required to allow the ASDM access to the ASA. The module also provides an understanding of enrolling with a third-party certificate authority and using self-signed and default certificates. RADIUS and LDAP authentication are discussed. Upon completing this module, the learner will be able to meet these objectives: Initialize ASA and enable ASDM Generate a self-signed persistent certificate Enroll a certificate from the CA server Integrate with the AAA server Monitoring 1. Basic ASA Configuration 2. Validating Licenses 3. Generating Self-Signed Certificate to Be Used with ASDM 4. Enrolling Digital Certificate from CA Server to Be Used for SSL VPN Access 5. Configuring Integration with AAA Servers (RADIUS, LDAP) 6. Review of Logging December 30, / 8

4 Module 3: Connection Profile and Group Policy Configuration This module provides an understanding of the fundamental policy assignments applied by the ASA when a remote user connects to the VPN. The module investigates the use of group policies by configuring bookmarks that will be used for clientless WebVPN users. Upon completing this module, the learner will be able to meet these objectives: Create a new connection profile and group policies for supporting clientless and AnyConnect remote VPN users Restrict tunneling protocols Create bookmarks using plug-ins, CIFS, HTTP and HTTPS links 1. Creating Connection Profiles and Group Policies 2. Configuring Group Policy 3. Creating Bookmarks Module 4: Enhanced Clientless WebVPN Features This module provides an understanding of enhanced features for clientless VPN access. Building on the basic bookmarks covered in the previous module, this module investigates the use of plug-ins and the use of Smart Tunnels and auto-signon for single-signon access. Kerberos Constrained Delegation, as it applies to VPN authentication, is discussed. Portal customization is discussed with simple examples. Upon completing this module, the learner will be able to meet these objectives: Configure Smart Tunnels Configure Auto-Signon Configure Auto-Signon with forms-based authentication Describe Kerberos Constrained Delegation Describe portal customization options 1. Plug-ins 2. Uploading the RDP Plug-in 3. Configuring Smart Tunnels 4. Auto-signon for HTTP/S resources 5. Auto-signon for forms-based authentication 6. Kerberos Constrained Delegation 7. Microsoft extensions to KCD for VPN authentication 8. Portal customization December 30, / 8

5 Module 5: Enhanced Cisco AnyConnect Client Features This module provides an understanding of the latest Cisco AnyConnect 3.0 features including login scripts, secure mobility, trusted network detection, and always-on. The module investigates AnyConnect customization by using the profile editor in ASDM to edit and deploy policies to remote users. Upon completing this module, the learner will be able to meet these objectives: Describe the new features of the AnyConnect 3.0 Configure some of the AC 3.0 features 1. AnyConnect 3.0 Features 2. AnyConnect Secure Mobility 3. Trusted Network Detection 4. Always-on VPN 5. Login Script 6. AnyConnect Client Profile configuration 7. AnyConnect diagnostics Module 6: Cisco Secure Desktop Deployment and Prelogin Assessment This module provides an understanding of Cisco Secure Desktop and the use of Cisco Secure Desktop with dynamic access policies (DAPs). Upon completing this module, the learner will be able to meet these objectives: Install and configure Cisco Secure Desktop Configure and manage: Keystroke Logger Detection Host emulator Cache cleaner Test and troubleshoot Cisco Secure Desktop issues Install and configure Cisco Secure Desktop Cisco Secure Desktop Overview Installing and configuring Cisco Secure Desktop Configure and Manage Keystroke Logger Detection Host Emulator Cache cleaner Test and troubleshoot Cisco Secure Desktop issues December 30, / 8

6 Module 7: Dynamic Access Policies This module covers the use of dynamic access policies (DAPs) with SSL VPNs. The module defines the basic operation of DAPs and investigates Endpoint Assessment watermark checks with DAPs, by using a detailed example. Upon completing this module, the learner will be able to meet these objectives: Configure DAP Use Endpoint Assessment Policies with DAP Work with policy objects 1. Describing DAP Attributes 2. Configuring DAP 3. Using Endpoint Assessment Policies with DAP 4. Working with Policy Objects Module 8: Securing Resources with Webtype and Network ACLs This module provides an understanding of the use of Webtype ACLs and network-based ACLs. The module investigates use cases of when one would use each technology. Upon completing this module, the learner will be able to meet these objectives: Describe Webtype ACLs Configure Webtype ACLs Apply Webtype ACLs Describe Network-Based ACLs Configure Network-Based ACLs Apply Network-Based ACLs 1. Feature Overview 2. Configuring and Applying Webtype ACLs 3. Configuring and Applying Network-Based ACLs Module 9: Cisco Secure Desktop Endpoint Assessment This module provides an understanding of the distinctions between Host Scan, and the Host Scan Extensions Endpoint Assessment and Advanced Endpoint Assessment (AEA) with DAPs. The module investigates the use of watermarking using AEA and providing remediation for Anti-virus/Anti-spyware services. The module also includes a discussion surrounding firewall checks and firewall rule policy configurations. Upon completing this module, the learner will be able to meet these objectives: December 30, / 8

7 Describe the difference between the Host Scan and the Advanced Host Scan Configure the Host Scan and the Advanced Host Scan features Use these features with the Dynamic Access Policy Troubleshoot DAP-related issues 1. Configuring Cisco Secure Desktop for Advanced Host Scan 2. Configuring DAP Policy to Utilize Advanced Host Scan 3. Testing and Troubleshooting the Configuration Module 10: Certificate-Based Authentication This module covers detailed certificate authentication options for the SSL VPN. The module defines how to obtain manual user certificates using a Microsoft CA and investigates certificate templates on the CA. The module also covers the various methods of mapping remote users to connection profiles including the use of the group alias, group URL access, and certificate profile mapping. There is a review of methods of Connection Profile selection, and Group Policy selection. The module then moves from Certificate Mapping to LDAP Attribute mapping. Finally, after enumerating all these configuration options, two variations on two-factor authentication are presented. Upon completing this module, the learner will be able to meet this objective: Configure client authentication and authorization using digital certificates 1. Obtain a User Certificate 2. Configure VPN authentication with client certificates 3. Configure Connection Profile selection 4. Configure Group Policy selection 5. Configure LDAP Attribute maps for Authorization settings 6. Two-Factor Authentication Module 11: Advanced Troubleshooting This module provides the tools to allow thorough troubleshooting for clientless and client-based SSL VPNs. Upon completing this module, the learner will be able to meet this objective: Use troubleshooting tools and techniques to overcome SSL VPN problems 1. SSL VPN Troubleshooting 2. AnyConnect Troubleshooting December 30, / 8

8 3. Clientless SSL VPN Troubleshooting Module 12: Scaling SSL VPN This module provides an understanding of VPN load balancing between several ASAs. The section describes the configuration and monitoring of the load-balanced sessions. Upon completing this module, the learner will be able to meet these objectives: Configure load balancing Configure shared license 1. Introduction 2. Configuring Load Balancing 3. Monitoring 4. Verifying and Troubleshooting 5. Configuring a Shared License Lab Overview Students will work on the following labs in course. 1. Lab 1: Accessing the Lab Machines 2. Lab 2: Initializing the Cisco ASA Appliance and Preparing for PKI and AAA Support 3. Lab 3: Configuring Basic Clientless and Client-Based SSL VPNs 4. Lab 4: Enhanced Clientless WebVPN Features 5. Lab 5: Enhanced Cisco AnyConnect Client Features 6. Lab 6: Cisco Secure Desktop Deployment and Prelogin Assessment 7. Lab 7: Host Scan and DAPs 8. Lab 8: Securing Resources with Webtype ACLs 9. Lab 9: Cisco Secure Desktop Endpoint Assessment 10. Lab 10: Certificate-Based Authentication 11. Lab 11: Advanced Troubleshooting 12. Configuration Files Summary 13. Teardown and Restoration December 30, / 8

Deploying Cisco ASA VPN Solutions v2.0 (VPN)

Deploying Cisco ASA VPN Solutions v2.0 (VPN) Deploying Cisco ASA VPN Solutions v2.0 (VPN) Course Overview: The Deploying Cisco ASA VPN Solutions (VPN) v2.0 course is part of the curriculum path that leads to the Cisco CCNP Security certification.

More information

CCNP Security VPN

CCNP Security VPN CCNP Security VPN 642-647 Official Cert Guide Howard Hooper, CCIE No. 23470 Cisco Press 800 East 96th Street Indianapolis, IN 46240 Contents Introduction xxiv Part I ASA Architecture and Technologies Overview

More information

ASACAMP - ASA Lab Camp (5316)

ASACAMP - ASA Lab Camp (5316) ASACAMP - ASA Lab Camp (5316) Price: $4,595 Cisco Course v1.0 Cisco Security Appliance Software v8.0 Based on our enhanced FIREWALL and VPN courses, this exclusive, lab-based course is designed to provide

More information

5 days lecture course and hands-on lab $3,295 USD 33 Digital Version

5 days lecture course and hands-on lab $3,295 USD 33 Digital Version Course: Duration: Fees: Cisco Learning Credits: Kit: DCAC9K v1.1 Cisco Data Center Application Centric Infrastructure 5 days lecture course and hands-on lab $3,295 USD 33 Digital Version Course Details

More information

Implementing Core Cisco ASA Security (SASAC)

Implementing Core Cisco ASA Security (SASAC) 1800 ULEARN (853 276) www.ddls.com.au Implementing Core Cisco ASA Security (SASAC) Length 5 days Price $6215.00 (inc GST) Overview Cisco ASA Core covers the Cisco ASA 9.0 / 9.1 core firewall and VPN features.

More information

Create and Apply Clientless SSL VPN Policies for Accessing. Connection Profile Attributes for Clientless SSL VPN

Create and Apply Clientless SSL VPN Policies for Accessing. Connection Profile Attributes for Clientless SSL VPN Create and Apply Clientless SSL VPN Policies for Accessing Resources, page 1 Connection Profile Attributes for Clientless SSL VPN, page 1 Group Policy and User Attributes for Clientless SSL VPN, page 3

More information

Cisco Passguide Exam Questions & Answers

Cisco Passguide Exam Questions & Answers Cisco Passguide 642-648 Exam Questions & Answers Number: 642-648 Passing Score: 800 Time Limit: 120 min File Version: 61.8 http://www.gratisexam.com/ Cisco 642-648 Exam Questions & Answers Exam Name: Deploying

More information

Exam A QUESTION 1 An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters, tried to access the XYZ sales de

Exam A QUESTION 1 An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters, tried to access the XYZ sales de Cisco 642-647 Deploying Cisco ASA VPN Solutions (VPN v1.0) Version: Demo https://.com Exam A QUESTION 1 An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters,

More information

For Sales Kathy Hall

For Sales Kathy Hall IT4E Schedule 13939 Gold Circle Omaha NE 68144 402-431-5432 Course Number Course Name Course Description For Sales Chris Reynolds 402-963-4465 creynolds@it4e.com www.it4e.com SISE v1.1 SKY For Sales Kathy

More information

Contents. Introduction. Prerequisites. Requirements. Components Used

Contents. Introduction. Prerequisites. Requirements. Components Used Contents Introduction Prerequisites Requirements Components Used Topology and flow Configure ASA Step1. Basic SSL VPN configuration Step2. CSD installation Step3. DAP policies ISE Verify CSD and AnyConnect

More information

ASA 8.0: How to Change the WebVPN Logo

ASA 8.0: How to Change the WebVPN Logo ASA 8.0: How to Change the WebVPN Logo Contents Introduction Prerequisites Requirements Components Used Conventions Change the WebVPN Logo Upload and Configure the Logo Apply the Customization Customize

More information

Cisco - ASA Lab Camp v9.0

Cisco - ASA Lab Camp v9.0 Cisco - ASA Lab Camp v9.0 Code: 0007 Lengt h: 5 days URL: View Online Based on our enhanced SASAC v1.0 and SASAA v1.2 courses, this exclusive, lab-based course, provides you with your own set of equipment

More information

Cisco Secure Desktop (CSD) on IOS Configuration Example using SDM

Cisco Secure Desktop (CSD) on IOS Configuration Example using SDM Cisco Secure Desktop (CSD) on IOS Configuration Example using SDM Document ID: 70791 Contents Introduction Prerequisites Requirements Components Used Network Diagram Related Products Conventions Configure

More information

New Features for ASA Version 9.0(2)

New Features for ASA Version 9.0(2) FIREWALL Features New Features for ASA Version 9.0(2) Cisco Adaptive Security Appliance (ASA) Software Release 9.0 is the latest release of the software that powers the Cisco ASA family. The same core

More information

Implementing Cisco Network Security (IINS) 3.0

Implementing Cisco Network Security (IINS) 3.0 Implementing Cisco Network Security (IINS) 3.0 COURSE OVERVIEW: Implementing Cisco Network Security (IINS) v3.0 is a 5-day instructor-led course focusing on security principles and technologies, using

More information

ASA Clientless SSL VPN (WebVPN) Troubleshooting Tech Note

ASA Clientless SSL VPN (WebVPN) Troubleshooting Tech Note ASA Clientless SSL VPN (WebVPN) Troubleshooting Tech Note Document ID: 104298 Contents Introduction Prerequisites Requirements Components Used Conventions Troubleshooting ASA Version 7.1/7.2 Clientless

More information

AnyConnect HostScan. Prerequisites for HostScan

AnyConnect HostScan. Prerequisites for HostScan The AnyConnect Posture Module provides the AnyConnect Secure Mobility Client the ability to identify the operating system, anti-virus, anti-spyware, and firewall software installed on the host. The HostScan

More information

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

Exam4Tests.   Latest exam questions & answers help you to pass IT exam test easily Exam4Tests http://www.exam4tests.com Latest exam questions & answers help you to pass IT exam test easily Exam : 642-647 Title : Deploying Cisco ASA VPN Solutions (VPN v1.0) Vendors : Cisco Version : DEMO

More information

Administering the Web Server (IIS) Role of Windows Server (10972)

Administering the Web Server (IIS) Role of Windows Server (10972) Administering the Web Server (IIS) Role of Windows Server (10972) Duration: 5 Days Price: $895 Delivery Option: Attend via MOC On-Demand Students Will Learn Installing IIS Configuring the default web site

More information

Cisco AnyConnect Secure Mobility Client

Cisco AnyConnect Secure Mobility Client To provide secure VPN connections, the Cisco VXC 6215 supports the Cisco AnyConnect Secure Mobility Client, Release 3.1. The Cisco AnyConnect Secure Mobility client provides remote users with secure VPN

More information

Clientless SSL VPN Overview

Clientless SSL VPN Overview Introduction to Clientless SSL VPN, page 1 Prerequisites for Clientless SSL VPN, page 2 Guidelines and Limitations for Clientless SSL VPN, page 2 Licensing for Clientless SSL VPN, page 3 Introduction to

More information

Clientless SSL VPN. Security Precautions CHAPTER

Clientless SSL VPN. Security Precautions CHAPTER CHAPTER 68 lets users establish a secure, remote-access VPN tunnel to the adaptive security appliance using a web browser. There is no need for either a software or hardware client. Clientless SSL VPN

More information

Cisco CISCO Securing Networks with ASA Advanced. Practice Test. Version

Cisco CISCO Securing Networks with ASA Advanced. Practice Test. Version Cisco 642-515 CISCO 642-515 Securing Networks with ASA Advanced Practice Test Version 3.1 QUESTION NO: 1 Cisco 642-515: Practice Exam Which two statements correctly describe configuring active/active failover?

More information

CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions 1800 ULEARN (853 276) www.ddls.com.au CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions Length 5 days Price $5500.00 (inc GST) Overview The objective of Implementing Citrix NetScaler

More information

Firepower Threat Defense Remote Access VPNs

Firepower Threat Defense Remote Access VPNs About, page 1 Firepower Threat Defense Remote Access VPN Features, page 3 Firepower Threat Defense Remote Access VPN Guidelines and Limitations, page 4 Managing, page 6 Editing Firepower Threat Defense

More information

Cisco Virtualization Experience Media Engine Overview

Cisco Virtualization Experience Media Engine Overview Cisco Virtualization Experience Media Engine Overview Purpose of This Guide, page 1 About Cisco Virtualization Experience Media Engine, page 1 Cisco AnyConnect Feature Support, page 4 Purpose of This Guide

More information

Using the Terminal Services Gateway Lesson 10

Using the Terminal Services Gateway Lesson 10 Using the Terminal Services Gateway Lesson 10 Skills Matrix Technology Skill Objective Domain Objective # Deploying a TS Gateway Server Configure Terminal Services Gateway 2.2 Terminal Services (TS) Web

More information

ASDM Book 3: Cisco ASA Series VPN ASDM Configuration Guide, 7.6

ASDM Book 3: Cisco ASA Series VPN ASDM Configuration Guide, 7.6 ASDM Book 3: Cisco ASA Series VPN ASDM Configuration Guide, 7.6 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS

More information

Implementing and Administering Security in a Microsoft Windows 2000 Network Course 2820 Five days Instructor-led Published: February 17, 2004

Implementing and Administering Security in a Microsoft Windows 2000 Network Course 2820 Five days Instructor-led Published: February 17, 2004 Implementing and Administering Security in a Microsoft Windows 2000 Network Course 2820 Five days Instructor-led Published: February 17, 2004 Introduction This five-day instructor-led course provides students

More information

Contents. Introduction. Prerequisites. Requirements. Components Used

Contents. Introduction. Prerequisites. Requirements. Components Used Contents Introduction Prerequisites Requirements Components Used Configure Network Diagram ASA ISE Step 1. Configure Network Device Step 2. Configure Posture conditions and policies Step 3. Configure Client

More information

Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN. VMware Workspace ONE UEM 1810

Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN. VMware Workspace ONE UEM 1810 Workspace ONE UEM Certificate Authentication for Cisco IPSec VPN VMware Workspace ONE UEM 1810 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

VMware AirWatch Certificate Authentication for Cisco IPSec VPN

VMware AirWatch Certificate Authentication for Cisco IPSec VPN VMware AirWatch Certificate Authentication for Cisco IPSec VPN For VMware AirWatch Have documentation feedback? Submit a Documentation Feedback support ticket using the Support Wizard on support.air-watch.com.

More information

Clientless SSL VPN Users

Clientless SSL VPN Users Manage Passwords, page 1 Use Single Sign-On with Clientless SSL VPN, page 3 Username and Password Requirements, page 18 Communicate Security Tips, page 19 Configure Remote Systems to Use Clientless SSL

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 642-648 Exam Questions & Answers Number: 642-648 Passing Score: 800 Time Limit: 120 min File Version: 22.3 http://www.gratisexam.com/ Cisco 642-648 Exam Questions & Answers Exam Name: Deploying Cisco

More information

ASA 8.x Dynamic Access Policies (DAP) Deployment Guide

ASA 8.x Dynamic Access Policies (DAP) Deployment Guide ASA 8.x Dynamic Access Policies (DAP) Deployment Guide Contents Introduction DAP and AAA Attributes DAP and Endpoint Security Attributes Default Dynamic Access Policy Configuring Dynamic Access Policies

More information

Introduction to 802.1X Operations for Cisco Security Professionals (802.1X)

Introduction to 802.1X Operations for Cisco Security Professionals (802.1X) Introduction to 802.1X Operations for Cisco Security Professionals (802.1X) The goal of the course is to provide students with foundational knowledge in the capabilities and functions of the IEEE 802.1x

More information

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA SafeNet Authentication Manager Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1 Document Information

More information

Citrix NetScaler Essentials and Unified Gateway

Citrix NetScaler Essentials and Unified Gateway Course Code: CNS2221 Vendor: Citrix Course Overview Duration: 5 RRP: 2,690 Citrix NetScaler Essentials and Unified Gateway Overview Designed for students with little or no previous NetScaler, NetScaler

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 300-209 Exam Questions & Answers Number: 300-209 Passing Score: 800 Time Limit: 120 min File Version: 35.4 http://www.gratisexam.com/ Exam Code: 300-209 Exam Name: Implementing Cisco Secure Mobility

More information

Students interested in learning how to implement and manage the advanced NetScaler features using leading practices. Specifically:

Students interested in learning how to implement and manage the advanced NetScaler features using leading practices. Specifically: Citrix NetScaler Essentials and Unified Gateway About this course Course type: Specialist Course code: CNS2221 Duration: 5 Days Special Notices Designed for students with little or no previous NetScaler,

More information

Exam Questions

Exam Questions Exam Questions 300-209 SIMOS Implementing Cisco Secure Mobility Solutions (SIMOS) https://www.2passeasy.com/dumps/300-209/ 1. Refer to the exhibit. Which VPN solution does this configuration represent?

More information

10972: ADMINISTERING THE WEB SERVER (IIS) ROLE OF WINDOWS SERVER

10972: ADMINISTERING THE WEB SERVER (IIS) ROLE OF WINDOWS SERVER ABOUT THIS COURSE This course provides students with the fundamental knowledge and skills to configure and manage Internet Information Services. This course is intended to help provide pre-requisite skills

More information

Prerequisites CNS-220 Citrix NetScaler Essentials and Traffic Management

Prerequisites CNS-220 Citrix NetScaler Essentials and Traffic Management CNS-221 Citrix NetScaler Unified Gateway Learn the skills required to configure and manage NetScaler Gateway and Unified Gateway features, including how to implement Gateway components including NetScaler

More information

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release :: Seite 1 von 5 :: Datenblatt zum Produkt Cisco ANYCONNECT ESSENTIALS VPN mit DC# 554678 :: Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release PB526545 Cisco ASA Software Release 8.2

More information

Cisco s AnyConnect VPN Client (version 2.4)

Cisco s AnyConnect VPN Client (version 2.4) Table of Contents [TOC]: Introduction Getting Started Installation Overview Using the Softphone System Requirements Introduction: Valley City State University is deploying Cisco s AnyConnect Virtual Private

More information

Table of Contents HOL-1757-MBL-6

Table of Contents HOL-1757-MBL-6 Table of Contents Lab Overview - - VMware AirWatch: Technology Partner Integration... 2 Lab Guidance... 3 Module 1 - F5 Integration with AirWatch (30 min)... 8 Getting Started... 9 F5 BigIP Configuration...

More information

Administering System Center Configuration Manager ( A)

Administering System Center Configuration Manager ( A) Administering System Center Configuration Manager (20703-1A) Duration: 5 Days Price: $895 Delivery Option: Attend via MOC On-Demand Students Will Learn Describing the features Configuration Manager and

More information

CCNP Security VPN

CCNP Security VPN Table of Contents Chapter 1 Evaluating the Cisco ASA VPN Subsystem...4 CCNP Security VPN 642-647 Quick Reference Cristian Matei Chapter 2 Deploying Cisco ASA IPsec VPN Solutions... 36 Chapter 3 Deploying

More information

6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure

6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure www.peaksolutions.com 6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure Course 6421A: Five days; Instructor-Led Introduction This five-day instructor-led course provides

More information

Table of Contents 1 Cisco AnyConnect...1

Table of Contents 1 Cisco AnyConnect...1 Table of Contents 1 Cisco AnyConnect...1 2 Introduction...2 3 Cisco AnyConnect Integration...3 4 Cisco AnyConnect Client Integration...4 4.1 Configure the Cisco ASA...4 4.2 Install the Cisco AnyConnect

More information

Basic Clientless SSL VPN Configuration

Basic Clientless SSL VPN Configuration Rewrite Each URL, page 1 Switch Off URL Entry on the Portal Page, page 2 Trusted Certificate Pools, page 2 Configure Browser Access to Plug-ins, page 4 Configure Port Forwarding, page 9 Configure File

More information

Clientless SSL VPN Remote Users

Clientless SSL VPN Remote Users This chapter summarizes configuration requirements and tasks for the user remote system. It also helps users get started with Clientless SSL VPN. It includes the following sections: Make sure that the

More information

Remote Access VPN. Remote Access VPN Overview. Licensing Requirements for Remote Access VPN

Remote Access VPN. Remote Access VPN Overview. Licensing Requirements for Remote Access VPN Remote Access virtual private network (VPN) allows individual users to connect to your network from a remote location using a laptop or desktop computer connected to the Internet. This allows mobile workers

More information

A: Administering System Center Configuration Manager

A: Administering System Center Configuration Manager 20703-1A: Administering System Center Configuration Manager Duration: 5 days; Instructor-led WHAT YOU WILL LEARN This five-day course describes how to use Configuration Manager and its associated site

More information

Implementing Security in Windows 2003 Network (70-299)

Implementing Security in Windows 2003 Network (70-299) Implementing Security in Windows 2003 Network (70-299) Level 1 Authorization & Authentication 2h 20m 20s 1.1 Group Strategy 1.2 Group Scopes 1.3 Built-in Groups 1.4 System or Special Groups 1.5 Administrating

More information

Configure an External AAA Server for VPN

Configure an External AAA Server for VPN About External AAA Servers, page 1 Guidelines For Using External AAA Servers, page 2 Configure Multiple Certificate Authentication, page 2 Active Directory/LDAP VPN Remote Access Authorization Examples,

More information

DevNet Sandbox Collaboration 11.5

DevNet Sandbox Collaboration 11.5 DevNet Sandbox Collaboration 11.5 Lab User Guide Joseph Kearns Cisco DevNet Sandbox Contents 1 Introduction... 3 2 Reserving the lab... 3 3 Connecting to your Sandbox Servers... 4 4 Main Topology Page...

More information

Establishing two-factor authentication with Cisco and HOTPin authentication server from Celestix Networks

Establishing two-factor authentication with Cisco and HOTPin authentication server from Celestix Networks Establishing two-factor authentication with Cisco and HOTPin authentication server from Celestix Networks Contact Information www.celestix.com Celestix Networks USA Celestix Networks EMEA Celestix Networks

More information

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. Cisco Adaptive Security Appliance 9.5(2)

<Partner Name> <Partner Product> RSA SECURID ACCESS Implementation Guide. Cisco Adaptive Security Appliance 9.5(2) RSA SECURID ACCESS Implementation Guide Cisco Peter Waranowski, RSA Partner Engineering Last Modified: January 9 th, 2018 Solution Summary Cisco Adaptive Security Appliance

More information

Guide to Deploying VMware Workspace ONE. VMware Identity Manager VMware AirWatch 9.1

Guide to Deploying VMware Workspace ONE. VMware Identity Manager VMware AirWatch 9.1 Guide to Deploying VMware Workspace ONE VMware Identity Manager 2.9.1 VMware AirWatch 9.1 Guide to Deploying VMware Workspace ONE You can find the most up-to-date technical documentation on the VMware

More information

Module 1: Understanding and Installing Internet Information Services

Module 1: Understanding and Installing Internet Information Services Course Outline Module 1: Understanding and Installing Internet Information Services In this module, you will learn about the infrastructure prerequisites for using Microsoft Internet Information Services

More information

This document describes the configuration of Secure Sockets Layer (SSL) decryption on the FirePOWER Module using ASDM (On-Box Management).

This document describes the configuration of Secure Sockets Layer (SSL) decryption on the FirePOWER Module using ASDM (On-Box Management). Contents Introduction Prerequisites Requirements Components Used Background Information Outbound SSL Decryption Inbound SSL Decryption Configuration for SSL Decryption Outbound SSL decryption (Decrypt

More information

Clientless SSL VPN Users

Clientless SSL VPN Users Manage Passwords Manage Passwords, on page 1 Use Single Sign-On with Clientless SSL VPN, on page 3 Username and Password Requirements, on page 19 Communicate Security Tips, on page 20 Configure Remote

More information

Advanced Clientless SSL VPN Configuration

Advanced Clientless SSL VPN Configuration Microsoft Kerberos Constrained Delegation Solution, page 1 Configure Application Profile Customization Framework, page 7 Encoding, page 11 Use Email over Clientless SSL VPN, page 13 Microsoft Kerberos

More information

NetScaler for Apps and Desktops CNS-222; 5 Days; Instructor-led

NetScaler for Apps and Desktops CNS-222; 5 Days; Instructor-led NetScaler for Apps and Desktops CNS-222; 5 Days; Instructor-led Course Description Designed for students with little or no previous NetScaler, NetScaler Gateway or Unified Gateway experience, this course

More information

CCNA CCNA Security Official Cert Guide. Course Outline. CCNA Security Official Cert Guide.

CCNA CCNA Security Official Cert Guide. Course Outline. CCNA Security Official Cert Guide. Course Outline CCNA Security 210-260 Official Cert 23 Apr 2018 Contents 1. Course Objective 2. Pre-Assessment 3. Exercises, Quizzes, Flashcards & Glossary Number of Questions 4. Expert Instructor-Led Training

More information

WebVPN. WebVPN Security Precautions CHAPTER

WebVPN. WebVPN Security Precautions CHAPTER CHAPTER 28 lets users establish a secure, remote-access VPN tunnel to the security appliance using a web browser. There is no need for either a software or hardware client. provides easy access to a broad

More information

Pulse Secure Client for Chrome OS

Pulse Secure Client for Chrome OS Pulse Secure Client for Chrome OS Quick Start Guide Published March, 2018 Release 5.2r1 Version 1.6 2018 by Pulse Secure, LLC. All rights reserved 1 Pulse Secure, LLC 2700 Zanker Road, Suite 200 San Jose,

More information

Identity Services Engine Guest Portal Local Web Authentication Configuration Example

Identity Services Engine Guest Portal Local Web Authentication Configuration Example Identity Services Engine Guest Portal Local Web Authentication Configuration Example Document ID: 116217 Contributed by Marcin Latosiewicz, Cisco TAC Engineer. Jun 21, 2013 Contents Introduction Prerequisites

More information

NetScaler Gateway 10.5

NetScaler Gateway 10.5 NetScaler Gateway 10.5 Jun 26, 2014 About This Release Key Features What's New Known Issues Compatibility with Citrix Products System Requirements NetScaler Gateway Plug-in System Requirements Endpoint

More information

Basic Clientless SSL VPN Configuration

Basic Clientless SSL VPN Configuration Rewrite Each URL, page 1 Switch Off URL Entry on the Portal Page, page 2 Trusted Certificate Pools, page 2 Configure Browser Access to Plug-ins, page 3 Configure Port Forwarding, page 8 Configure File

More information

2554 : Administering Microsoft Windows SharePoint Services and SharePoint Portal Server 2003

2554 : Administering Microsoft Windows SharePoint Services and SharePoint Portal Server 2003 2554 : Administering Microsoft Windows SharePoint Services and SharePoint Portal Server 2003 Introduction Elements of this syllabus are subject to change. This five-day instructor-led course provides students

More information

Cisco Unified Serviceability

Cisco Unified Serviceability Cisco Unified Serviceability Introduction, page 1 Installation, page 5 Introduction This document uses the following abbreviations to identify administration differences for these Cisco products: Unified

More information

AnyConnect on Mobile Devices

AnyConnect on Mobile Devices AnyConnect on mobile devices is similar to AnyConnect on Windows, Mac and Linux platforms. This chapter provides device information, configuration information, support information, as well as other administrative

More information

CISSP - Certified Information Systems Security Professional

CISSP - Certified Information Systems Security Professional CISSP - Certified Information Systems Lab Outline The CISSP Practice Lab will provide you with the necessary platform to gain hands on skills in security. By completing the lab tasks you will improve your

More information

"Charting the Course... MOC A Planning, Deploying and Managing Microsoft Forefront TMG Course Summary

Charting the Course... MOC A Planning, Deploying and Managing Microsoft Forefront TMG Course Summary Description Course Summary The goal of this three-day instructor-led course is to provide students with the knowledge and skills necessary to effectively plan, deploy and manage Microsoft Forefront Threat

More information

Configure HTTPS Support for ISE SCEP Integration

Configure HTTPS Support for ISE SCEP Integration Configure HTTPS Support for ISE SCEP Integration Document ID: 116238 Contributed by Todd Pula and Sylvain Levesque, Cisco TAC Engineers. Jul 31, 2013 Contents Introduction Prerequisites Requirements Components

More information

Chapter 10 Configure AnyConnect Remote Access SSL VPN Using ASDM

Chapter 10 Configure AnyConnect Remote Access SSL VPN Using ASDM Chapter 10 Configure AnyConnect Remote Access SSL VPN Using ASDM Topology Note: ISR G1 devices use FastEthernet interfaces instead of GigabitEthernet interfaces. 2015 Cisco and/or its affiliates. All rights

More information

Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers

Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers Configuring, Managing, and Maintaining Windows Server 2008 R2 Servers Course 6419B - Five Days - Instructor-led - Hands on Introduction This five-day instructor-led course provides students with the knowledge

More information

Guide to Deploying VMware Workspace ONE. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager 3.1

Guide to Deploying VMware Workspace ONE. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager 3.1 Guide to Deploying VMware Workspace ONE DEC 2017 VMware AirWatch 9.2 VMware Identity Manager 3.1 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Course: Duration: Fees: Cisco Learning Credits: Kit:

Course: Duration: Fees: Cisco Learning Credits: Kit: Course: Duration: Fees: Cisco Learning Credits: Kit: DCNX7K v3.0 - Configuring Cisco Nexus 7000 Series Switch 5 days lecture course and hands-on lab $3,395 USD 34 Digital Version Course Details The Configuring

More information

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training McAfee Web Gateway Administration Intel Security Education Services Administration Course Training The McAfee Web Gateway Administration course from Education Services provides an in-depth introduction

More information

Configuring the Cisco VPN 3000 Concentrator 4.7.x to Get a Digital Certificate and a SSL Certificate

Configuring the Cisco VPN 3000 Concentrator 4.7.x to Get a Digital Certificate and a SSL Certificate Configuring the Cisco VPN 3000 Concentrator 4.7.x to Get a Digital Certificate and a SSL Certificate Document ID: 4123 Contents Introduction Prerequisites Requirements Components Used Conventions Install

More information

Secure Mobility. Klaus Lenssen Senior Business Development Manager Security

Secure Mobility. Klaus Lenssen Senior Business Development Manager Security Secure Mobility Klaus Lenssen Senior Business Development Manager Security KL Secure Mobility 2008 Cisco Systems, Inc. All rights reserved. Cisco public 1 Complete Your Online Session Evaluation Please

More information

The Rockefeller University I NFORMATION T ECHNOLOGY E DUCATION & T RAINING. VPN Web Portal Usage Guide

The Rockefeller University I NFORMATION T ECHNOLOGY E DUCATION & T RAINING. VPN Web Portal Usage Guide The Rockefeller University I NFORMATION T ECHNOLOGY E DUCATION & T RAINING VPN Web Portal Usage Guide Table of Contents WHAT IS VPN WEB CLIENT 4 SUPPORTED WEB BROWSERS 4 LOGGING INTO VPN WEB CLIENT 5 ESTABLISHING

More information

CCNP Security: Securing Networks with ASA VPNs

CCNP Security: Securing Networks with ASA VPNs CCNP Security: Securing Networks with ASA VPNs Rob Settle Security Specialist, CCIE #23633 (Security, Routing and Switching) BRKCRT-1160 1 Rejoice, Security Folks VPNs are enablers! 2 Rejoice VPNs are

More information

Chapter 10 Configure Clientless Remote Access SSL VPNs Using ASDM

Chapter 10 Configure Clientless Remote Access SSL VPNs Using ASDM Chapter 10 Configure Clientless Remote Access SSL VPNs Using ASDM This lab has been updated for use on NETLAB+ Topology Note: ISR G1 devices use FastEthernet interfaces instead of GigabitEthernet Interfaces.

More information

Contents. Introduction

Contents. Introduction Contents Introduction Prerequisites Requirements Components Used Background Information Cisco Anyconnect Secure Mobility Client Internet Protocol Flow Information Export (IPFIX) IPFIX Collector Splunk

More information

The VPN menu and its options are not available in the U.S. export unrestricted version of Cisco Unified Communications Manager.

The VPN menu and its options are not available in the U.S. export unrestricted version of Cisco Unified Communications Manager. Overview, page 1 Prerequisites, page 1 Configuration Task Flow, page 1 Overview The Cisco for Cisco Unified IP Phones creates a secure VPN connection for employees who telecommute. All settings of the

More information

Administering System Center 2012 Configuration Manager

Administering System Center 2012 Configuration Manager Course 10747: Administering System Center 2012 Configuration Manager Page 1 of 8 Administering System Center 2012 Configuration Manager Course 10747: 4 days; Instructor-Led Introduction This four-day instructor-led

More information

Five9 Plus Adapter for Agent Desktop Toolkit

Five9 Plus Adapter for Agent Desktop Toolkit Cloud Contact Center Software Five9 Plus Adapter for Agent Desktop Toolkit Administrator s Guide September 2017 The Five9 Plus Adapter for Agent Desktop Toolkit integrates the Five9 Cloud Contact Center

More information

Exam : Title : Security Solutions for Systems Engineers. Version : Demo

Exam : Title : Security Solutions for Systems Engineers. Version : Demo Exam : 642-566 Title : Security Solutions for Systems Engineers Version : Demo 1. Which one of the following elements is essential to perform events analysis and correlation? A. implementation of a centralized

More information

Clientless SSL VPN End User Set-up

Clientless SSL VPN End User Set-up 71 CHAPTER This section is for the system administrator who sets up Clientless (browser-based) SSL VPN for end users. It summarizes configuration requirements and tasks for the user remote system. It also

More information

Implementing Microsoft Azure Infrastructure Solutions (20533)

Implementing Microsoft Azure Infrastructure Solutions (20533) Implementing Microsoft Azure Infrastructure Solutions (20533) Duration: 5 Days Price: $895 Delivery Option: Attend via MOC On-Demand Students Will Learn Describing Azure architecture components, including

More information

Evangel euniversity [ANGEL ACCESS AND HELP GUIDE]

Evangel euniversity [ANGEL ACCESS AND HELP GUIDE] Evangel euniversity [ANGEL ACCESS AND HELP GUIDE] How to access your ANGEL account, what your computer needs to run ANGEL, and how to get ANGEL Technical and User support. Table of Contents How to Access

More information

VMware Identity Manager Cloud Deployment. Modified on 01 OCT 2017 VMware Identity Manager

VMware Identity Manager Cloud Deployment. Modified on 01 OCT 2017 VMware Identity Manager VMware Identity Manager Cloud Deployment Modified on 01 OCT 2017 VMware Identity Manager You can find the most up-to-date technical documentation on the VMware Web site at: https://docs.vmware.com/ The

More information

VMware Identity Manager Cloud Deployment. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager

VMware Identity Manager Cloud Deployment. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager VMware Identity Manager Cloud Deployment DEC 2017 VMware AirWatch 9.2 VMware Identity Manager You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

CISCO EXAM QUESTIONS & ANSWERS

CISCO EXAM QUESTIONS & ANSWERS CISCO 300-206 EXAM QUESTIONS & ANSWERS Number: 300-206 Passing Score: 800 Time Limit: 120 min File Version: 35.2 http://www.gratisexam.com/ Exam Code: 300-206 Exam Name: Implementing Cisco Edge Network

More information

GLOBALPROTECT. Key Usage Scenarios and Benefits. Remote Access VPN Provides secure access to internal and cloud-based business applications

GLOBALPROTECT. Key Usage Scenarios and Benefits. Remote Access VPN Provides secure access to internal and cloud-based business applications GLOBALPROTECT Prevent Breaches and Secure the Mobile Workforce GlobalProtect extends the protection of Palo Alto Networks Next-Generation Security Platform to the members of your mobile workforce, no matter

More information

ASA Remote Access VPN IKE/SSL Password Expiry and Change for RADIUS, TACACS, and LDAP Configuration Example

ASA Remote Access VPN IKE/SSL Password Expiry and Change for RADIUS, TACACS, and LDAP Configuration Example ASA Remote Access VPN IKE/SSL Password Expiry and Change for RADIUS, TACACS, and LDAP Configuration Example Document ID: 116757 Contributed by Michal Garcarz, Cisco TAC Engineer. Nov 25, 2013 Contents

More information