Deploying Cisco ASA VPN Solutions v2.0 (VPN)

Similar documents
Implementing Core Cisco ASA Security (SASAC)

CCNP Security VPN

ASACAMP - ASA Lab Camp (5316)

SASSL v1.0 Managing Advanced Cisco SSL VPN. 3 days lecture course and hands-on lab $2,495 USD 25 Digital Version

New Features for ASA Version 9.0(2)

Implementing CiscoWorks LMS 4.0 (CWLMS)

Cisco - ASA Lab Camp v9.0

CCNP Security VPN

Cisco Passguide Exam Questions & Answers

Cisco Virtualization Experience Media Engine Overview

Designing Windows Server 2008 Network and Applications Infrastructure

Implementing Cisco Network Security (IINS) 3.0

Prerequisites CNS-220 Citrix NetScaler Essentials and Traffic Management

Clientless SSL VPN Overview

Cisco AnyConnect Secure Mobility Client

Students interested in learning how to implement and manage the advanced NetScaler features using leading practices. Specifically:

Cisco CISCO Securing Networks with ASA Advanced. Practice Test. Version

"Charting the Course... MOC 6435 B Designing a Windows Server 2008 Network Infrastructure Course Summary

Implementing and Administering Security in a Microsoft Windows 2000 Network Course 2820 Five days Instructor-led Published: February 17, 2004

Citrix NetScaler 10.5 Essentials for ACE Migration (CNS-208)

Understanding of basic networking concepts (routing, switching, VLAN, firewall functionality)

NetScaler for Apps and Desktops CNS-222; 5 Days; Instructor-led

Citrix NetScaler Essentials and Unified Gateway

Citrix NetScaler 10.5 Essentials and Networking (CNS-205)

Interconnecting Cisco Networking Devices Part 2 v2.0 (ICND 2)

CCNA CCNA Security Official Cert Guide. Course Outline. CCNA Security Official Cert Guide.

Course Objectives In this course, students can expect to learn how to:

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

CNS-207-2I Implementing Citrix NetScaler 10.5 for App and Desktop Solutions

2554 : Administering Microsoft Windows SharePoint Services and SharePoint Portal Server 2003

Firepower Threat Defense Remote Access VPNs

Exam : Title : Security Solutions for Systems Engineers. Version : Demo

Implementing Cisco IP Routing (ROUTE)

CNS-222EA - EARLY ACCESS: NETSCALER FOR APPS AND DESKTOPS

Administering Cisco Unified Contact Center Enterprise for CVP Environments (ACCE-CVP)

Fundamentals of Windows Server 2008 Network and Applications Infrastructure

Using the Terminal Services Gateway Lesson 10

Designing and Implementing a Server 2012 Infrastructure

Introduction to 802.1X Operations for Cisco Security Professionals (802.1X)

Exam A QUESTION 1 An XYZ Corporation systems engineer, while making a sales call on the ABC Corporation headquarters, tried to access the XYZ sales de

MCSA Windows Server 2012

Exam Questions

CMB-310 Citrix Virtual Apps, Desktops and Provisioning 7.1x Administration (Fast Track)

Microsoft Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

Question: 1 An engineer is using the policy trace tool to troubleshoot a WSA. Which behavior is used?

Cisco Deploying Basic Wireless LANs

Deploying and Administering Cisco s Digital Network Architecture (DNA) and Intelligent WAN (IWAN) (DNADDC)

Expressway for Mobile and Remote Access Deployments, page 1 Cisco AnyConnect Deployments, page 9 Survivable Remote Site Telephony, page 17

Implementing Cisco Edge Network Security Solutions ( )

Exam4Tests. Latest exam questions & answers help you to pass IT exam test easily

Certified SonicWALL Security Administrator (CSSA) Instructor-led Training

Implementing Cisco Video Network Devices Part 2, v1.0 (CIVND2)

IMPLEMENTING CISCO MPLS (MPLS)

The IINS acronym to this exam will remain but the title will change slightly, removing IOS from the title, making the new title.

SASAC v1.0 Implementing Core Cisco ASA Security Cisco Training

Junos Security Bundle, JSEC & AJSEC

Cisco Exam Questions & Answers

Cisco ASA 5500 Series Adaptive Security Appliance 8.2 Software Release

70-647: Windows Server Enterprise Administration. Course Overview. Course Outline

"Charting the Course... MOC A Planning, Deploying and Managing Microsoft Forefront TMG Course Summary

ASA Clientless SSL VPN (WebVPN) Troubleshooting Tech Note

CCIE ROUTING & SWITCHING V5.0

High Availability Options

Microsoft Certified System Engineer

CISCO QUAD Cisco CCENT/CCNA/CCDA/CCNA Security (QUAD)

NE Administering Windows Server 2012

Implementing Cisco IP Switched Networks (SWITCH)

MCSA Windows Server 2012

[MS20334]: Core Solutions of Skype for Business 2015

AnyConnect HostScan. Prerequisites for HostScan

AnyConnect on Mobile Devices

Course No. MCSA Days Instructor-led, Hands-on

Connection Profiles, Group Policies, and Users

Deploying App and Desktop Solutions with Citrix XenApp and XenDesktop (CXD-300)

Implementing Desktop Application Environments

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA

[MS20743]: Upgrading Your Skills to MCSA: Windows Server 2016

Configuring Advanced Windows Server 2012 Services

Implementing and Configuring Cisco SDWAN (ICSDWAN-CT)

DESIGNING AND IMPLEMENTING A SERVER INFRASTRUCTURE

"Charting the Course... Interconnecting Cisco Networking Devices Accelerated 3.0 (CCNAX) Course Summary

Cisco Exam Questions & Answers

Deploying Cisco Unified Contact Center Express (UCCXD)

Administering Windows Server 2012

ASDM Book 3: Cisco ASA Series VPN ASDM Configuration Guide, 7.6

Course : Planning and Administering SharePoint 2016

Implementing Security in Windows 2003 Network (70-299)

[MS20347]: Enabling and Managing Office 365

A: PLANNING AND ADMINISTERING SHAREPOINT 2016

20347: Enabling and Managing Office hours

Configuring Aggregate Authentication

CNS-205 Citrix NetScaler 10.5 Essentials and Networking

Implementing and Configuring Meraki Technologies (ICMT-CT)

Core Solutions of Skype for Business 2015

CNS-220-1I: CITRIX NETSCALER TRAFFIC MANAGEMENT

CNS-220-1I: Citrix NetScaler Traffic Management Essentials

NE Designing and Deploying Microsoft Exchange Server 2016

Integrating Cisco Enterprise Chat & with UCCE (ICCE)

Upgrading your Skills to MCSA Windows Server 2012

Windows Server : Administering Windows Server 2012 R2. Upcoming Dates. Course Description. Course Outline

Transcription:

Deploying Cisco ASA VPN Solutions v2.0 (VPN) Course Overview: The Deploying Cisco ASA VPN Solutions (VPN) v2.0 course is part of the curriculum path that leads to the Cisco CCNP Security certification. This five-day instructor-led course is aimed at providing network security engineers with the knowledge and skills that they need to implement and maintain Cisco ASA adaptive security appliance-based perimeter solutions. Successful graduates will be able to use Cisco ASA features to reduce the risk to the IT infrastructure and applications and to provide detailed operations support for the Cisco ASA security appliance. Who will benefit from this course? Network Security Engineers Prerequisites: To fully benefit from this course, students should have the following prerequisite skills and knowledge: Cisco CCNA Certification Cisco CCNA Security Certification Completion of or equivalent knowledge for Deploying Cisco ASA Firewall Solutions (FIREWALL) Working knowledge of the Microsoft Windows Operating System Sunset Learning Differentiators: World Class Instruction Team o All instructors hold Certified Cisco Systems Instructor (CCSI) certification. o All instructors have a four-year technical degree or equivalent work experience. o All instructors have a minimum of either four years teaching technical networking classes or five years consulting experience. Enhanced Learning Experience o The goal of our instructors during class is ensure students understand the material, guide them through our up to date labs and encourage questions and interactive discussions. Enjoyment of the learning process is a primary objective for Sunset Learning instructors. High Quality Real World Lab Environments o Course offerings include real-time access to labs with the latest Cisco equipment o Result is real world experiences to help students prepare for actual networking environments. o Hands on experience aids in Cisco exam preparation. Outstanding Customer Service o Dedicated program manager o Quality instruction team o Creatively designed curriculum to meet your specific needs o Delivery at your location or ours

Related Courses: SECURE FIREWALL IPS Course Objectives: After completing this course, students will be able to... Describe the general properties of the Cisco ASA security appliance VPN subsystem Implement and maintain Cisco clientless remote access Secure Sockets Layer (SSL) on the Cisco ASA security appliance VPN Implement and maintain Cisco AnyConnect client-based remote access SSL on the Cisco ASA security appliance VPN, according to policies and environmental requirements Implement and maintain Cisco remote access IP Security (IPsec) on the Cisco ASA VPN, according to policies and environmental requirements Implement and maintain site-to-site VPN solutions on the Cisco ASA security appliance VPN, according to policies and environmental requirements Deploy endpoint security with Cisco Secure Desktop and dynamic access policy (DAP), and deploy and manage high-availability and high-performance features of the Cisco ASA security appliance Course Outline: Module 1: Cisco ASA Adaptive Security Appliance VPN Architecture and Common Components Lesson 1: Evaluating the Cisco ASA Adaptive Security Appliance VPN Subsystem Architecture Identify the various VPN topologies and identify the Secure Mobility Client 3.0 correct topology to use for a given scenario Identify the available VPN licensing options and Identify the Cisco ASA security appliance IPv6 VPN choose the appropriate licensing option for your capabilities network Identify the components of the Cisco AnyConnect Lesson 2: Evaluating the Cisco ASA Adaptive Security Appliance Software Architecture Describe the principles of the Cisco ASA security appliance access control model NAT features routing features AAA features Lesson 3: Implementing Profiles, Group Policies, and User Policies Describe the components of Cisco ASA security access appliance VPN policy configuration Configure Cisco ASA security appliance user Configure Cisco ASA security appliance connection attributes profiles Identify access control methods for VPN users Configure Cisco ASA security appliance group Implement VPN accounting to external RADIUS and policies TACACS+ servers Describe AAA functions that are available in remote Identify Cisco Secure Desktop and DAP features

Lesson 4: Implementing PKI Services Evaluate PKI services for IPsec and SSL VPN configurations Evaluate methods of deploying server-side certificates on the Cisco ASA security appliance Choose the appropriate CA server for your design Describe methods for deploying a client certificate to use with Cisco VPN deployments Configure and verify the local CA on the Cisco ASA security appliance and the Cisco AnyConnect client using client certificates that are provisioned by a Cisco ASA security appliance Configure and verify certificate-to-connection-profile mapping on the Cisco ASA security appliance Describe SCEP proxy operations Module 2: Cisco ASA Adaptive Security Appliance Clientless Remote Access SSL VPN Solutions Lesson 1: Deploying Basic Clientless VPN Solutions Describe the building blocks of, and use cases for, the Cisco ASA clientless SSL VPN solution Plan the configuration of a clientless SSL VPN solution Configure and verify basic Cisco ASA security appliance features and authentication for a clientless SSL VPN Configure and verify password-based local user authentication in a clientless SSL VPN Configure and verify basic access control in a clientless SSL VPN Tune and verify the content-rewriting features Troubleshoot VPN session establishment between a browser client and a Cisco ASA security appliance Lesson 2: Deploying Advanced Application Access for Clientless SSL Plan the deployment of clientless SSL VPN application-access features Troubleshoot advanced application access in Configure and verify application plug-ins clientless SSL Configure and verify smart tunnels in clientless SSL Lesson 3: Deploying Advanced Authentication and SSO for Clientless SSL Design clientless SSL VPN authentication with PKI Deploy client-side certificate-based authentication Configure and verify clientless VPN SSO methods Configure and verify multiple client authentications Troubleshoot clientless VPN SSO methods Troubleshoot the integration of a clientless SSL VPN Lesson 4: Customizing the Clientless SSL VPN User Interface and Portal Configure and verify basic customization of the VPN Configure and verify portal help customization portal navigation pages Configure and verify application-integration Configure and verify complete portal HTML customization customization Configure and verify portal localization Module 3: Cisco AnyConnect Remote Access SSL Solutions Lesson 1: Deploying a Basic Cisco AnyConnect Full-Tunnel SSL VPN Solution Describe the operation of full-tunnel SSL VPN Configure basic access control and split tunneling technology for a full-tunnel SSL VPN Plan, configure, and verify the features of Install, configure, and verify Cisco AnyConnect 3.0 the Cisco ASA security appliance for a Cisco using the predeployment method AnyConnect full-tunnel SSL VPN solution Troubleshoot VPN session establishment between a Configure and verify password-based local user Cisco AnyConnect client and a Cisco ASA security authentication and client IP address assignment for appliance a full-tunnel SSL VPN

Lesson 2: Deploying an Advanced Cisco AnyConnect Full-Tunnel SSL VPN Solution Describe the tasks that you use to configure Configure and verify Cisco AnyConnect XML profiles centrally controlled client functions in for Cisco Configure and verify the Cisco AnyConnect Trusted AnyConnect clients Network Detection, scripting, and SBL feature Deploy DTLS on the Cisco ASA security appliance Customize and verify the Cisco AnyConnect user Deploy and upgrade Cisco AnyConnect from a Cisco interface ASA Lesson 3: Deploying Advanced Authentication, Authorization, and Accounting in Cisco Full-Tunnel Choose a and user authentication method in Configure SCEP proxy for Cisco AnyConnect Cisco AnyConnect full-tunnel SSL Configure and verify integration with supporting PKI Plan the deployment of advanced client entities authentication Configure multiple client authentication Configure and verify the local CA on the Cisco ASA Troubleshoot advanced client authentication in fulltunnel SSL security appliance and the Cisco AnyConnect client with client certificates that are provisioned by the Configure and verify local and remote group policy Cisco ASA security appliance authorization in a Cisco full-tunnel SSL VPN Configure and verify the Cisco ASA security Configure and verify local and remote group policy appliance and Cisco AnyConnect client to use an accounting in a Cisco full-tunnel SSL VPN external CA and provision client certificates Module 4: Cisco ASA Adaptive Security Appliance Remote Access IPsec Lesson 1: Deploying Cisco Remote Access VPN Clients Describe the operation of IPsec VPN technology Choose the appropriate Cisco VPN Client product Install, configure, and verify the installation of the legacy Cisco IPsec VPN Client Configure and verify the legacy Cisco IPsec VPN Client profiles Configure and verify advanced the legacy Cisco IPsec VPN Client profile settings Install, configure, and verify the installation of Cisco AnyConnect 3.0 Configure and verify the auto-initiation feature of Cisco AnyConnect 3.0 Troubleshoot Cisco remote access VPN session establishment Lesson 2: Deploying Basic Cisco Remote Access IPsec VPN Solutions Plan the configuration of a Cisco remote access IPsec Configure and verify Cisco remote access VPN local VPN IP address management Configure and verify basic Cisco ASA Configure and verify Cisco remote access VPN basic features and authentication in a Cisco for access control and split tunneling remote access IPsec Configure IKEv2 support for remote access IPsec Configure and verify Cisco remote access VPN PSKbased peer authentication Troubleshoot Cisco remote access VPN session VPN solutions Configure and verify Cisco remote access VPN establishment between a Cisco VPN client and a extended authentication Cisco ASA Configure and verify Cisco remote access VPN hybrid authentication Module 5: Cisco ASA Adaptive Security Appliance Site-to-Site IPsec VPN Solutions Lesson 1: Deploying Basic Site-to-Site IPsec Plan a Cisco ASA security appliance site-to-site VPN Configure and verify basic peer authentication in a Cisco ASA security appliance site-to-site VPN Configure and verify transmission protection in a Lesson 2: Deploying Advanced Site-to-Site IPsec Plan a Cisco ASA security appliance site-to-site VPN using PKI- based authentication Configure and verify PKI-based peer authentication Cisco ASA security appliance site-to-site VPN Troubleshoot the operation of a Cisco ASA security appliance site-to-site VPN in a Cisco ASA security appliance site-to-site VPN Troubleshoot the operation of a PKI-based Cisco ASA security appliance site-to-site VPN

Module 6: Endpoint Security and High Availability for Cisco ASA Lesson 1: Implementing Cisco Secure Desktop and DAP for SSL Choose network admission features for Cisco AnyConnect full-tunnel SSL Configure and verify basic Cisco Secure Desktop Install, enable, and verify Cisco Secure Desktop on a Advanced Endpoint Assessment features on a Cisco Cisco ASA security appliance SSL VPN ASA security appliance SSL VPN Configure and verify Cisco Secure Desktop prelogin Configure and verify DAPs that are enabled for Cisco criteria on a Cisco ASA security appliance SSL VPN Secure Desktop on a Cisco ASA security appliance SSL VPN Configure and verify Cisco Secure Desktop prelogin Troubleshoot Cisco Secure Desktop operations on a policies on a Cisco ASA security appliance SSL VPN Cisco ASA security appliance SSL VPN Lesson 2: Deploying High-Availability Features in Cisco ASA Adaptive Security Appliance Choose VPN high-availability and high-performance Describe the deployment of VPN load-balancing features clusters Configure and verify redundant peering with Cisco Provide high availability and high performance using AnyConnect and IPsec client an external SLB appliance Deploy active/standby failover for SSL and IPsec Troubleshoot Cisco ASA security appliance failover and VPN clustering functions Implement dynamic routing to achieve IPsec site-tosite VPN high availability Labs: Lab 2-1: Configuring Basic Clientless VPN Access on the Cisco ASA Adaptive Security Appliance Lab 2-2: Configuring Advanced Application Access for Clientless SSL Lab 2-3: Customizing the SSL VPN Portal on the Cisco ASA Adaptive Security Appliance Lab 3-1: Configuring Basic Cisco AnyConnect Client Full-Tunnel SSL Using Local Password Authentication Lab 3-2: Deploying the Cisco AnyConnect Client with Centralized Management Lab 3-3: Configuring Basic Cisco AnyConnect Full-Tunnel SSL Using Local CA and SCEP Proxy Lab 4-1: Deploying Basic Remote Access IPsec VPN with IKEv2 Lab 5-1: Deploying a Basic Cisco ASA Security Appliance IPsec IKEv1 Site-to-Site VPN Lab 6-1: Deploying Cisco Secure Desktop in Cisco SSL Lab 6-2: Configuring a Load-Balancing SSL VPN Cluster