
Deploying Cisco ASA Firewall Solutions (FIREWALL)
Overview
Learn the skills needed to configure, maintain, and operate the firewall features of the Cisco ASA 5500 Series Adaptive Security Appliances (ASAs). We have enhanced this Cisco ASA Firewall course and added depth to the standard labs, using a topology that simulates a typical production network. You'll use ASA 5520 appliances to work through configuring access control to and from your network. You will also examine the PIX firewall and the Firewall Services Module (FWSM).
Skills Learned
- Bootstrap the security appliance
- How ASAs and Cisco PIX Security Appliances protect network devices from attacks
- Use object groups to simplify ACL complexity and maintenance
- Prepare the security appliance for configuration via the Cisco Adaptive Security Device Manager (ASDM)
- Launch and navigate ASDM
- Perform essential security appliance configuration using ASDM and the CLI
- Configure dynamic and static address translations
- Configure access policy based on Access Control Lists (ACLs)
- Troubleshoot with Syslog, Packet Tracer, and packet capture
- Use the Modular Policy Framework to provide unique policies to specific data flows
- Handle advanced protocols with application inspection
- Deep packet inspection of application layer traffic
- Select and configure the type of failover that best suits the network topology
- Configure access-control based on authenticated users
- Configure threat detection to meet security policy requirements
- Technology and features of the Cisco ASA
- Cisco ASA product family
- Enable, configure, and manage multiple contexts to meet security policy requirements
- Configure the security appliance to run in transparent firewall mode
- Monitor and manage an installed security appliance
- Initialize ASA Security Service Modules including the AIP-SSM and CSC-SSM
Who Should Attend This Course?
Anyone who implements and maintains Cisco ASA firewalls. Network security specialists and technicians. Candidates seeking CCNP Security certification.
Prerequisites
It is recommended you attend the following Cisco courses: IINS (Implementing Cisco IOS Network Security) and ICND2 (Interconnecting Cisco Network Devices 2).
Course Outline
Module 1: Cisco ASA Adaptive Security Appliance
Technology and Features ASA Family
Module 2: Basic Connectivity and Device Management
Cisco ASA and Cisco ASDM Interfaces and Static Routing Basic Device Management Features Management Access
Module 3: Cisco ASA Access Control Features
Basic Access Control Modular Policy Framework Basic Stateful Inspection Features Application-Layer Policies Advanced Access Controls Resource Limits and Guarantees User-Based Policies
Module 4: Cisco ASA Network Integration Features
Network Address Translation Transparent Firewall Operations
Module 5: Cisco ASA Virtualization and High Availability Features
Virtualization Features Redundant Interfaces Active/Standby High Availability Failover Active/Active High Availability Failover
Module 6: Cisco ASA Security Service Modules
AIP-SSM and AIP-AIP-SSC Module Integration CSC-SSM Module Integration
Interested in this course? Contact us online or call 800-850-9932 for more information, pricing, class schedules and to register.
| Upcoming Classes | Start Date |
|---|---|
| FIREWALL | Jul 29 |
Live Labs with Real Cisco Gear
Get hands on practice with real world scenarios just like a traditional class. This course includes the following hands on labs.
1. Basic Firewall Configuration
2. Configuring Network Address Translation
3. Using Access Control Lists (ACL)
4. Configuring Modular Policy Framework
5. Configuring Management Features
6. Configuring Basic Access Control
7. Tuning Basic Cisco ASA Adaptive Security Appliance Stateful Inspection features
8. Configuring Application-Layer Polices
9. Configuring User-Based Policies (Cut Through Proxy)
10. Configuring Cisco ASA Adaptive Security Appliance NAT
11. Configuring Transparent Firewall Mode
12. Deploying a Cisco ASA Adaptive Security Appliance Active/Standby Failover
13. Deploying a Cisco ASA Adaptive Security Appliance Active/Active Failover




