Associated Certifications
CCNP Security
Required Exam(s)
300-206
Instructorctclc admin
TypeOnsite Course
Duration
5 Days
Methods of Delivery
ILT, WEBEX, VIRTUAL
Price$3495.00
Buy NowBook Now

This course is part of the curriculum path leading to the Cisco Certified Network Professional Security (CCNP Security) certification. Additionally, it is designed to prepare security engineers with the knowledge and hands-on experience to prepare them to configure Cisco perimeter edge security solutions utilizing Cisco Switches, Cisco Routers, and Cisco Adaptive Security Appliance (ASA) Firewalls.
The goal of the course is to provide students with foundational knowledge and the capabilities to implement and managed security on Cisco ASA firewalls, Cisco Routers with the firewall feature set, and Cisco Switches. The student will gain hands-on experience with configuring various perimeter security solutions for mitigating outside threats and securing network zones. At the end of the course,
students will be able to reduce the risk to their IT infrastructures and applications using Cisco Switches, Cisco ASA, and Router security appliance feature and provide detailed operations support for these products.

Course Objectives

Who Should Attend

Perquisites

Course Outline

Download Outline

Upon completing this course, the student will be able to meet these objectives:

  •  Understand Cisco modular Network Security Architectures such as SecureX and TrustSec
  •  Implement data, control and management plane security controls
  •  Configure, verify, and troubleshoot NAT features on Cisco ASA and on Cisco IOS Software routers
  •  Configure, verify, and troubleshoot threat controls on Cisco ASA

The primary audience for this course is as follows:

  •  Network Security Engineers

  •  CCNA Security or valid CCSP or any CCIE certification can act as a prerequisite

 

Course Introduction
Module 1: Cisco Secure Design Principles

  •  Network Security Zoning
  •  Cisco Modular Network Architecture
  •  Cisco SecureX Architecture
  •  Cisco TrustSec Solution

Module 2: Network Infrastructure Protection Deployment

  •  Introducing Cisco Network Infrastructure Protection
  •  Deploying Cisco IOS Control Plane Security Controls
  •  Deploying Cisco IOS Management Plane Security Controls
  •  Deploying Cisco ASA Management Plane Security Controls
  •  Deploying Cisco Traffic Telemetry Methods
  •  Deploying Cisco IOS Layer 2 Data Plane Security Controls
  •  Deploying Cisco Layer 3 Data Plane Security Controls

Module 3: NAT Deployment on Cisco IOS and Cisco ASA

  •  Introducing Network Address Translation
  •  Deploying Cisco ASA Network Address Translation
  •  Deploying Cisco IOS Software Network Address Translation

Module 4: Threat Controls Deployment on Cisco ASA

  •  Introducing Cisco Firewall Threat Controls
  •  Deploying Basic Cisco ASA Access Policies
  •  Deploying Advanced Cisco ASA Access Policies
  •  Deploying Reputation-Based Cisco ASA Access Policies
  •  Deploying Identity-Based Cisco ASA Access Policies

Module 5: Threat Controls Deployment on Cisco IOS Software

  •  Deploying Basic Cisco IOS Zone-Based Policy Firewall Access Policies
  •  Deploying Advanced Cisco IOS Zone-Based Policy Firewall Access Policies

Labs

  •  Configure Control and Management Plane Security Controls
  •  Configure Traffic Telemetry Methods
  •  Configure Layer 2 Data Plane Security Controls
  •  Configure Layer 3 Data Plane Security Controls
  •  Configure Cisco ASA NAT
  •  Configure Cisco IOS Software NAT
  •  Configure Basic Cisco ASA Access Policies
  •  Configure Advanced Cisco ASA Access Policies
  •  Configure Cisco ASA Botnet Traffic Filter
  •  Configure Cisco ASA Identity Firewall
  •  Configure Basic Cisco IOS Zone-Based Policy Firewall Access Policies
  •  Configure Advanced Cisco IOS Zone-Based Policy Firewall Access Policies