- Delegates should be familiar with network technologies and have a good understanding of TCP/IP.
- Previous experience of Cisco IOS would be an advantage.
A 4 day instructor-led practical course designed to familiarise delegates with the Cisco ASA Firewall CLI and ASDM. The course details the key commands used to configure and secure networks using the ASA Firewall with v8 of the operating system and version 6 of the ASDM.
Delegates will configure the ASA using the console port, TFTP server, telnet and SSH using local and RADIUS authentication. The device will be configured to utilise Syslog and SNMP.
ASA Firewalls will also be configured to use Access-Lists, Network Address Translation and VPN's utilising IPSec protocols. The course will cover the theory of Public/Private Keys, shared secret keys and their use in forming Site to site VPN's between ASA Firewalls using IKE and IPSec. Students will configure the units to create site to site VPN's, remote access VPN's using the Cisco Secure VPN Client and Web VPN's. The course will cover the theory of failover and delegates will configure Active/Standby failover on the ASA.
Privileged commands and protocol analyser traces will be used, where necessary, to debug protocols and ensure proper operation of the ASA Firewall. Students will also perform password recovery operations.
This course will involve interfacing the ASA with other network equipment, such as routers and switches, as would be expected in a network environment.
Audience:
Course is suitable for anyone involved in ASA firewall configuration and network security
Course is approximately 50% practical
Objectives:
At the end of this course the student will be able to configure ASA Firewalls to:
- Allow configuration via console port, telnet and SSH
- Copy configurations and upgrade OS image.
- Authenticate users using RADIUS and local authentication.
- Act as a DHCP Server, Client and Relay.
- Operate as a Routed or Transparent Firewall.
- Operate in Failover mode.
- Support VLANs.
- Run routing protocols (OSPF and RIP) and exchange routing information with Cisco routers.
- Support Access Control Lists and content filtering.
- Support Object Grouping.
- Establish Internet connections using NAT and PAT.
- Setup site to site VPN's using IKE and IPSec.
- Setup Remote Access VPN's using Cisco secure VPN client.
- Setup Web VPN's
- Log access-list activity using a syslog server.
- Send traps to an SNMP Server.
- Password recovery
Practical Exercises
- Lab Exercise 1: Basic Configuration of Cisco ASA.
- Lab Exercise 2: Configure support for VLANs on ASA.
- Lab Exercise 3: Connectivity via Telnet and Local/RADIUS authentication.
- Lab Exercise 4: Configure Static and Dynamic routing on ASA.
- Lab Exercise 5: Filter traffic using Access Control Lists.
- Lab Exercise 6: Configure NAT on ASA.
- Lab Exercise 7: Configure VPN's on ASA.
- Lab Exercise 8: Configure Active/Standby Failover on ASA/Pix.
- Lab Exercise 9: Password Recovery on Cisco ASA.
Equipment Used in Practical Exercises:
- 4 Cisco ASA 5505 Firewalls running v8 of the CLI and capable of Active/Standby Failover. Pix 515E firewalls running v8 of the CLI, Cisco routers, switches and hubs as required.
Qatar - Cisco ASA/Pix Operation
Egypt - Cisco ASA/Pix Operation
Saudi Arabia - Cisco ASA/Pix Operation
South Africa - Cisco ASA/Pix Operation
Brasil - Operação em Cisco ASA/Pix
Canada - Cisco ASA/Pix Operation
Österreich - Cisco ASA/Pix Operation
Schweiz - Cisco ASA/Pix Operation
Deutschland - Cisco ASA/Pix Operation
Czech Republic - Cisco ASA/Pix Operation
Denmark - Cisco ASA/Pix Operation
Estonia - Cisco ASA/Pix Operation
Finland - Cisco ASA/Pix Operation
Greece - Cisco ASA/Pix Operation
Magyarország - Cisco ASA/Pix Operation
Ireland - Cisco ASA/Pix Operation
Luxembourg - Cisco ASA/Pix Operation
Latvia - Cisco ASA/Pix Operation
España - Funcionamiento de Cisco ASA / Pix
Italia - Cisco ASA/Pix Operation
Lithuania - Cisco ASA/Pix Operation
Nederland - Cisco ASA/Pix Operation
Norway - Cisco ASA/Pix Operation
Portugal - Operação em Cisco ASA/Pix
România - Cisco ASA/Pix Operation
Sverige - Cisco ASA/Pix Operation
Türkiye - Cisco ASA/Pix Operation
Malta - Cisco ASA/Pix Operation
Belgique - Cisco ASA/Pix Operation
France - Cisco ASA/Pix Operation
Australia - Cisco ASA/Pix Operation
Malaysia - Cisco ASA/Pix Operation
New Zealand - Cisco ASA/Pix Operation
Philippines - Cisco ASA/Pix Operation
Singapore - Cisco ASA/Pix Operation
Thailand - Cisco ASA/Pix Operation
Vietnam - Cisco ASA/Pix Operation
India - Cisco ASA/Pix Operation
Argentina - Funcionamiento de Cisco ASA / Pix
Chile - Funcionamiento de Cisco ASA / Pix
Costa Rica - Funcionamiento de Cisco ASA / Pix
Ecuador - Funcionamiento de Cisco ASA / Pix
Guatemala - Funcionamiento de Cisco ASA / Pix
Colombia - Funcionamiento de Cisco ASA / Pix
México - Funcionamiento de Cisco ASA / Pix
Panama - Funcionamiento de Cisco ASA / Pix
Peru - Funcionamiento de Cisco ASA / Pix
Uruguay - Funcionamiento de Cisco ASA / Pix
Venezuela - Funcionamiento de Cisco ASA / Pix
Polska - Cisco ASA/Pix Operation
United Kingdom - Cisco ASA/Pix Operation
South Korea - Cisco ASA/Pix Operation
Pakistan - Cisco ASA/Pix Operation
Sri Lanka - Cisco ASA/Pix Operation
Bulgaria - Cisco ASA/Pix Operation
Bolivia - Funcionamiento de Cisco ASA / Pix
Indonesia - Cisco ASA/Pix Operation
Kazakhstan - Cisco ASA/Pix Operation
Moldova - Cisco ASA/Pix Operation
Morocco - Cisco ASA/Pix Operation
Tunisia - Cisco ASA/Pix Operation
Kuwait - Cisco ASA/Pix Operation
Oman - Cisco ASA/Pix Operation
Slovakia - Cisco ASA/Pix Operation
Kenya - Cisco ASA/Pix Operation
Nigeria - Cisco ASA/Pix Operation
Botswana - Cisco ASA/Pix Operation
Slovenia - Cisco ASA/Pix Operation
Croatia - Cisco ASA/Pix Operation
Serbia - Cisco ASA/Pix Operation
Bhutan - Cisco ASA/Pix Operation