Cisco CCNP Security: SIMOS
Course ID
Course Description
Prerequisites
Audience
Course Content
- VPN Definition
- Key Threats to WANs and Remote Access
- Cisco Modular Network Architecture and VPNs
- VPN Types
- VPN Components
- Secure Communication and Cryptographic Services
- Cryptographic Algorithms
- Cryptography and Confidentiality
- Cryptography and Integrity
- Cryptography and Authentication
- Cryptography and Nonrepudiation
- Keys in Cryptography
- Public Key Infrastructure
- Next-Generation Encryption
- Dependencies in Cryptographic Services
- Cryptographic Controls Guidelines
- Site-to-Site VPN Topologies
- Site-to-Site VPN Technologies
- IPsec VPN Overview
- Internet Key Exchange v1 and v2
- Encapsulating Security Payload
- IPsec Virtual Tunnel Interface
- Dynamic Multipoint VPN
- Cisco IOS FlexVPN
- Overview of Point-to-Point IPsec VPNs on the Cisco ASA
- Configuration Tasks for Basic Point-to-Point Tunnels on the Cisco ASA
- Enable IKE on an Interface
- Configure IKE Policy
- Configure PSKs
- Choose Transform Set and VPN Peer
- Choose Traffic for VPN
- Configuring Site-to-Site VPN with Connection Profiles Menu
- Verify and Troubleshoot Basic Point-to-Point Tunnels on the Cisco ASA
- Overview of Cisco IOS VTIs
- Configure Static VTI Point-to-Point Tunnels
- Verify Static VTI Point-to-Point Tunnels
- Configure Dynamic VTI Point-to-Point Tunnels
- Verify Dynamic VTI Point-to-Point Tunnels
- Overview of Cisco IOS DMVPN
- DMVPN Solution Components
- GRE
- NHRP
- DMVPN Operations
- Types of Authentication
- Configure DMVPN on Hub
- Configure DMVPN on Spoke Configure Routing in DMVPN
- Verify DMVPN
- FlexVPN Overview
- Public Key Infrastructure (PKI)
- Site-to-Site VPN Topologies
- FlexVPN Architecture
- FlexVPN Configuration Overview
- FlexVPN Capabilities
- IKEv2 vs. IKEv1 Overview
- IKEv2 Message Exchange
- IKEv2 DoS Prevention
- IKEv1 and IKEv2 Comparison
- FlexVPN Use Cases
- Point-to-Point
- FlexVPN FlexVPN Configuration Blocks
- IKEv2 Profile
- Smart Defaults
- Manipulating Default Values
- Negotiating IKEv2 Proposals
- Point-to-Point VPN Scenario with IPv4 Static Routes
- Configure and Verify Point-to-Point VPN with IPv4 Static Routes
- Point-to-Point VPN Scenario with OSPFv3
- Configure and Verify Point-to-Point VPN with OSPFv3
- Enroll Devices to ECDSA PKI
- Configure Router for ECDSA
- Configure ASA for ECDSA
- Verify EC Key Pairs and Certificates
- Verify IKEv2 SA
- Verify IPsec SA
- Verify Point-to-Point FlexVPN
- Cisco IOS FlexVPN
- IKEv2 Configuration Payload
- Locally Managed Hub-and-Spoke Scenario
- Configure a Spoke in a Hub-and-Spoke Scenario
- Configure a Hub in a Hub-and-Spoke Scenario
- Configuration Exchange
- Verify and Troubleshoot Hub-and-Spoke FlexVPN
- Spoke-to-Spoke Shortcut Scenario
- NHRP in FlexVPN
- Configure and Verify a Spoke in a Spoke-to-Spoke Shortcut Scenario
- Configure and Verify a Hub in a Spoke-to-Spoke Shortcut Scenario
- RADIUS-Managed FlexVPN Scenario
- Verify Spoke-to-Spoke Shortcut Switching
- Troubleshoot Spoke-to-Spoke Shortcut Switching
- SSL VPN Components
- SSL/TLS
- Overview of group policies and connection profiles
- Basic Cisco Clientless SSL VPN
- Solution Components
- Configure ASA gateway
- Configure basic authentication
- Configure access control
- Verify basic clientless SSL VPN
- Troubleshoot basic clientless SSL VPN
- Deploying Application Access options (plug-ins, smart tunnels)
- Configure and verify plugins
- Configure and verify smart tunnels
- Troubleshoot plugins and smart tunnel
- Advanced Authentication in Cisco Clientless SSL VPN Solution Components
- Configure and verify Certificate based Authentication
- Configure and Verify External Authentication
- Troubleshoot Advanced Authentication in Clientless SSL VPN
- IP Address assignment
- Split Tunneling
- Basic Cisco AnyConnect SSL VPN
- Solution Components
- SSL VPN Server Authentication
- SSL VPN Clients Authentication
- SSL VPN Clients IP Address Assignment
- SSL VPN Split Tunneling
- Configure ASA for Basic AnyConnect SSL VPN
- Configure Basic Cisco Authentication
- Configure Access Control
- Verify and Troubleshoot Basic Cisco AnyConnect SSL VPN
- DTLS Overview
- Parallel DTLS and TLS Tunnels
- Configure DTLS
- Verify DTLS
- Cisco AnyConnect Client Configuration Management
- Cisco AnyConnect Client Operating System Integration Options
- Cisco AnyConnect Start Before Logon
- Cisco AnyConnect Trusted Network Detection
- Configure, Verify, and Troubleshoot Cisco AnyConnect Start Before Logon and Cisco AnyConnect Trusted Network Detection
- AnyConnect Support for IPSec/IKEv2
- Configure a Cisco AnyConnect IPsec/IKEv2 VPNs on a Cisco ASA Adaptive Security Appliance
- Verify and Troubleshoot Cisco AnyConnect IPsec/IKEv2 VPNs on Cisco ASA
- Cisco AnyConnect Advanced Authentication Scenarios
- External Authentication
- Certificate-Based Server Authentication
- Configure and Verify Certificate-Based Client Authentication
- SCEP Proxy Overview
- SCEP Proxy Connection Flow
- SCEP Proxy Configuration Procedure
- Configure SCEP Proxy
- Verify SCEP Proxy
- Local Authorization Overview
- Local Authorization Scenario
- Local Authorization Configuration Procedure
- Configure Local Authorization
- External Authentication and Authorization Scenario
- Configure External Authentication and Authorization
- Troubleshoot Advanced Authentication and Authorization in Cisco AnyConnect VPNs
- Accounting
- Cisco HostScan Overview
- Cisco HostScan Prelogin Assessment
- Install Cisco HostScan
- Configure Prelogin Criteria and Prelogin Policy
- Configure Host Scan Endpoint Assessment Configure Host Scan Advanced Endpoint Assessment
- DAP Overview
- Integrating DAP with Host Scan
- Configuring DAP
- Verifying and Troubleshooting DAP
For More Information
For training inquiries, call 850-308-1376
or email us at eramos@gbsi.com
Course Details
Duration - 5 days
Price - $1990.00 USD
(Discounts may apply. Call for more information.)
Acceletrain Collaborative Learning Environment (formerly know as VILT) places industry certified and expert instructors, peers, learners and multi-media components into a "borderless classroom", and interactive learning environment that can span multiple physical locations. VILT combines the benefits of the traditional brick-and-mortar classroom with innovative learning techniques and the cost savings of internet-based training.