
Learn to set up a Cisco web security lab by building a topology, installing and configuring the WSA, applying initial configuration and licensing, and configuring hostname, gateway, and DNS.
Explore the topology introduction for Cisco WSA 9.2.0, including ip addressing schemes, dhcp, dns servers, and lab devices connected to the internet and lan.
Configure Cisco WSC for initial setup, including router and switch interfaces, NAT with an access-list, and inside and outside interfaces, then verify internet connectivity and DNS reachability from the LAN.
Learn to install WSA 9.2.0 via OVF on VMware Workstation, import the OVF file, configure the VM (IP 192.168.1.1), and verify internet and LAN reachability.
Set up the vWSA initial configuration by configuring the management IP, default admin credentials, hostname, and enabling essential services, then commit and save.
Learn to install a Cisco WSA license on a vWSA, including login, pasting the license, and verifying a 45-day license in system storage.
Learn to run the system setup wizard on WSC, configure hostname and DNS, set management IP and gateway, and enable default actions before verifying and installing the configuration.
Verify the web proxy settings on WSC by navigating to security services, selecting web proxy, and confirming the proxy is enabled and listening on port 128.
Configure explicit proxy configuration on client devices by setting a proxy address in the browser’s lan settings, then verify access to websites through the proxy.
Verify that client traffic is routed through the WSA by configuring explicit proxy settings, monitoring proxy logs, and confirming requests to destinations like google.com are forwarded by the WSA.
Take snapshots of the vWSA labs topology VMs to preserve working lab states, rename and save snapshots after verifying device connectivity, and prepare multiple VM snapshots for future lab reversion.
Block poker.com with a custom URL configuration in the web security manager by creating an identification profile, adding the domain, applying a block policy, and verifying access.
Demonstrates blocking poker.com using custom URL verification in the WSA 9.2.0 deep dive labs, navigating system administration policies and identification profile to enforce the block.
Block google.com with a custom URL configuration in the Web Security Manager by creating identification profiles and a policy that blocks sites in access policies.
Block google.com using custom url verification in the web security manager. Trace policies, adjust blocking rules in policy trace, verify logs, and commit changes to enforce the block.
Block bing.com with a custom url configuration on the WSA, using the identification profile and global policy, then submit, commit, and verify the block.
Explore how to block bing.com using custom URL verification in the WSA 9.2.0 deep dive labs, by configuring policies, testing access, and deleting blocks via SSL sessions and policy changes.
Configure blocking yahoo.com with custom URL configuration in WSA 9.2.0 using web security manager identification profiles and PC global policies to enforce a blocked sites rule.
Verify blocking of yahoo.com using custom URL verification in WSA 9.2.0 by inspecting the system administration policy in WSC, noting SSL session blocked and denied access.
learn to block ask.com using custom url configuration on the wsa 9.2.0, configure identification profiles and a block sites policy, monitor activity, and verify changes.
Verify blocking of a target domain using a custom url verification policy in the wsa 9.2.0 lab, perform policy trace, paste addresses, commit changes, and confirm session denial.
Block aol.com using a custom url configuration by configuring identification profiles in the web security manager and applying an access policy to enforce the block.
Demonstrate blocking aol.com using custom url verification on the WSA, tracing policies, applying an identification profile and access policy, reviewing SSL logs, and committing changes to enforce the block.
Block baidu.com using custom URL configuration in WSA 9.2.0, configuring identification profiles and policy to monitor and enforce blocked sites across client devices.
Block baidu.com using custom URL verification in the WSA 9.2.0 lab, using policy trace, identification profile, and logs to verify the block.
block wolframalpha.com using custom url configuration in wsa 9.2.0, configuring identification profiles and access policy to enforce the block and verify the change.
Learn to block wolframalpha.com using a custom URL verification policy in the WSC, verify the block, and remove the policy to restore access, with attention to categories and identification profiles.
Learn to block archive.org using a custom URL configuration in the WSA 9.2.0 environment by configuring identification profiles, custom categories, and access policies in the web security manager.
Block archive.org by applying a custom url verification policy, verify the denial, and later confirm access is restored after policy updates.
Block twitter.com with a custom URL configuration in the WSA 9.2.0 by creating an identification profile, applying a block policy, and validating access via the Web Security Manager.
Block Twitter.com using custom URL verification in the CCIE Security WSA 9.2.0 lab, verify the policy and SSL session, and adjust custom categories and identity profiles to control access.
Block facebook.com using a custom URL configuration in the web security manager. Define a policy, select identification profiles, configure the block categories, submit the policy, and verify the result.
Block facebook.com with WSA 9.2.0 using custom URL verification; verify via policy trace in the WSC, apply and delete changes, then commit and refresh to confirm.
Block youtube.com using custom URL configuration in WSA 9.2.0 labs by creating an identification profile for pc one, applying a block sites policy, and verifying access through the WSC.
Demonstrates blocking YouTube.com with a custom URL verification in WSA 9.2.0, using the WSC quota system administration policy and validating outbound access denial.
Block skype.com using a custom url configuration in WSA 9.2.0 by creating an identification profile for pc one and applying a Web security manager policy to block the site.
Learn to block skype.com on Cisco WSA 9.2.0 by using custom URL verification, verify with policy trace, apply denial, and test access to confirm the block while allowing other sites.
Block poker dot com using the WSA 9.2.0 global policy by creating an identification profile for the gambling category and applying it to the access policy.
Verify poker.com blocking using a global policy by tracing policy logs, identifying denied connections, and applying changes to restore client functionality.
Learn to block google dot com using global policy configuration in WSA 9.2.0 by configuring identification profiles, selecting search engine and portals policies, and applying the global policy.
Verify google.com is blocked by a global policy on the WSA, review access logs to confirm the block, then delete the PC policy and commit to regain access.
Block bing.com using the global policy in WSA 9.2.0 by creating an identification profile for PC1 and applying it to block the domain under search engines and portals.
Verify blocking of pink dot com using the global policy in WSA 9.2.0, inspect the policy tree and logs, and confirm access is denied.
Block yahoo dot com using a global policy configuration in WSA, through system administration policy trees, selecting the identification profile PC1 and applying policy PC policy under the global policy.
Verify Yahoo.com blocking using the global policy in the WSA, then configure and test the block in the WSC system administration and confirm access is denied or restored.
Block access to ask.com using a global policy in WSA 9.2.0, configure identification profiles, and apply search engine and portal filtering, then commit the policy.
Block Ask.com using the global policy and verify denial through the WSC and the system administration policy tree, refreshing the page to confirm access is blocked.
Block aol.com using global policy configuration in the web security manager within WSA-9.2.0, by setting identification profiles, applying access policies, and committing changes for later verification.
Verify blocking of aol.com using global policy by tracing policy access in the WSC, adjusting security manager policies, and confirming denied access to the target domain.
Block access to archive.org by configuring a global policy in WSA 9.2.0, selecting identification profiles and applying a P7 policy to PC one.
Verify blocking of a site using global policy verification by tracing policy for the site and IP, confirming access denial, and committing changes in the web security manager access policies.
Block twitter.com using a global policy in the web security manager by creating a social networking policy, applying it to the pc policy, and verifying the block.
Verify and enforce twitter.com blocking using the global policy in WSA 9.2.0, navigate policy trees, update access policies, modify identification profiles, commit changes, and test access.
Block facebook.com using the WSA 9.2.0 global policy configuration with web security manager identification profiles and social networking filters. Apply across 80 PCs and verify via the management portal.
Verify blocking of facebook.com using global policy through the wsc system administration policy trace, then modify and commit changes in the web security manager to test access.
Block youtube.com using the global policy in WSA 9.2.0; trace the www.youtube.com entry, apply a PC policy via web security manager identification profiles, and commit changes for verification.
Verify youtube.com is blocked using global policy verification, trace policy events, check logs in the web security manager, and confirm denial across the client session.
Block skype.com using global policy configuration in the web security appliance, configure identification profiles to block internet telephony, apply and commit the policy, then verify.
Verify Skype.com is blocked using the global policy in WSC, inspect policy trees and identification profiles, commit changes, and review logs and SSL session entries to confirm denial.
Block pornography sites by configuring a global policy on the web security appliance, set up identification profiles, create the bc1 policy, apply the category block, and commit changes for verification.
Learn how to block and verify pornography sites using global policy verification on the WSA 9.2.0, by testing with URLs, adjusting system administration policies, and observing blocked and permitted results.
Configure a download limit in WSA 9.2.0 by creating a policy, setting a custom UDP blocking rule for 100 MB, and committing the changes.
Verify the download limit for SCDP STDs and FTB by testing PC-to-PC transfers; show that source IP addresses exceeding 100 MB are blocked and smaller downloads proceed.
Configure ip-based http url blocking in wsa 9.2.0 by creating a web security manager category with a regular expression, applying an identification profile, and committing the policy to block sites.
Demonstrates IP-based blocking of HTTP traffic and verifies it through system administration policy trace, showing how to apply the block and confirm egress is restricted.
Learn to configure WSA 9.2.0 to block IP-based and URL-based HTTPS access using the Web Security Manager, create a custom category, apply the policy, and verify.
Learn to configure IP-based URL blocking and HTTPS verification in the WSA 9.2.0 lab by applying access policies, testing blocked sites, and validating client restrictions.
Block ip base url ftp sites by configuring the web security manager. Create a custom category with a regular expression and apply identification profiles to block the ftp site.
Verify ip-based url blocking for ftp with a wsa 9.2.0 policy, showing pc1 blocked and pc2 allowed, and confirm ssl session results across the blocking rules.
demonstrates configuring a redirection policy in the web security appliance 9.2.0 to redirect bing to google dot com, using web security manager identification profiles and a new PC policy.
Verify the redirection from Bing to Google within the WSA 9.2.0 labs, examining how requests are blocked or redirected by policies and observing page refresh behavior.
Configure a warning for social sites in the web security manager by selecting identification profiles and applying the social networking global policy, then commit the changes.
Navigate WSA 9.2.0 social site verification warnings by tracing system administration policies, accessing Facebook, and reviewing policy matches before accepting the warning statement.
Configure a proxy bypass on the WSA by selecting the identification profile, applying a custom bypass for google.com, and committing changes in the web security manager to verify access.
Verify proxy bypass on WSA 9.2.0 by reviewing identification profiles and bypass settings for destinations like youtube.com and google.com, and note bypass works with a transparent proxy, not forward proxies.
Join Microsoft Active Directory on WSC by configuring network authentication and entering the domain name and admin credentials.
Verify Microsoft Active Directory integration by joining computers, confirming the hostname and its fully qualified name, and diagnosing icon visibility to ensure successful Active Directory enrollment.
Configure proxy authentication on the WSA 9.2.0 by creating identification and authentication profiles, joining the WSC to a domain, and validating DNS reachability.
Verify proxy authentication by entering credentials on PC1 and refreshing google.com; PC1 gains access while PC2 remains authenticated from the prior session.
Learn to upgrade WSA to version 9.2.0 via the system administration upgrade flow, monitor download progress, and reboot the system after installation to complete the vWSA configuration.
Verify the WSC upgrade process, including reboot prompts and accessing the WSC portal to confirm upgrade status and completion of the Cisco WSC upgrade.
Restore a Cisco WSC to factory defaults using the CLI reset config command. Reconfigure the management IP, hostname, and essential services to restore normal operation.
Configure the management IP on the WSA via CLI using ifconfig, set the IP address, hostname, and proxy settings, then verify connectivity with ping and save the configuration.
Learn to set a device hostname via the cli with the sethostname command and commit the changes, then verify the new hostname is applied.
Use the setgateway CLI to configure the gateway IP on Cisco devices, choose an appropriate IP such as 192.168.1.1, save the config, and verify connectivity with a ping.
Learn to set DNS IP addresses via CLI on the WSA, choosing between local and public DNS, adding and prioritizing servers, saving configuration, and deleting entries.
Learn how to flush the dns cache on Cisco WSA, verify dns configuration, test domain reachability with ping, and apply the dns flush command to clear all dns caches.
Learn how to check Cisco WSA 9.2.0 configuration from the CLI with showconfig, view and save session logs, and interpret the resulting WSC configuration.
Learn to configure the time zone on Cisco WSA via the settz CLI. Select continent and country, apply DST, and set the date, then commit the changes.
Learn how to configure time via the CLI using settime, enter date and time in the required format, and verify the updated clock on Cisco WSC devices.
Change the admin password on Cisco devices via the CLI using the passwd command, handling old and new password prompts, system generated passwords, and committing the change.
Learn to check the WSA version via CLI by accessing the WSC, logging in with credentials, and viewing version details and device information.
Discover how to upgrade the WSA via CLI, verify the current version and upgrade to 9.2.0.0809, perform the reboot, and re-login to confirm the updated system.
Learn to revert a WSA appliance to a prior 9.2.x version using the command-line interface, selecting the target build, confirming prompts, and rebooting the device.
Discover how to back up the wsa configuration in 9.2.0 by exporting the configuration file from the system administration page after applying policy blocks and identification profiles.
Load a configuration file via the CLI using loadconfig, by opening the backup file, copying its contents, and pasting into the session, then committing changes to apply the config.
Learn to display the current date and time via the cli date command, and configure time by selecting continent, country, and city on a device during admin setup.
Learn to display alerts from the appliance using the cli command display alerts. See alert logs, check license status on Cisco WSC, and notice proxy key expiry in 15 days.
Learn to flush entries from the proxy authentication cache (authcache) on the WSA by configuring authentication profiles and using a flush command.
Learn how to create a new user via the cli using userconfig, assign to administrator, operator, or guest groups, and manage password prompts, including system-generated passwords.
Advanced threats can hide even on legitimate websites. Users may inadvertently put your organization at risk by clicking where they shouldn't. Cisco Secure Web Appliance protects your organization by automatically blocking risky sites and testing unknown sites before allowing users to click on them. Using TLS 1.3 and high-performance capabilities, Cisco Secure Web Appliance keeps your users safe.
This course will help candidates learn and master Cisco Web Security Appliance Solution Overview version 9.2.0. The course includes intensive labs up to advanced level.
CCIE Security WSA 9.2.0 Labs Contents in brief: (Update in Progress)
WSA-9.2.0 Topology Introduction
WSA-9.2.0 Topology Initial Configuration
WSA-9.2.0 Installation using OVF on VMware Workstation
WSA-9.2.0 Initial Configuration on WSA
WSA-9.2.0 Install License on WSA
WSA-9.2.0 Run System Setup Wizard
WSA-9.2.0 Verify Web Proxy Settings on WSA
WSA-9.2.0 Explicit Proxy Configuration on Client
WSA-9.2.0 Check That Traffic is Hitting to WSA or not
WSA-9.2.0 Search Engines and Portals Blocking
WSA-9.2.0 Social Site Blocking
WSA-9.2.0 References Sites Blocking
WSA-9.2.0 Internet Telephony Site Blocking
WSA-9.2.0 HTTP/HTTPS/FTP Download Limit Configuration
WSA-9.2.0 HTTP/HTTPS/FTP Download Limit Verification
WSA-9.2.0 IP Base URL Blocking of HTTP Configuration
WSA-9.2.0 IP Base URL Blocking of HTTP Verification
WSA-9.2.0 IP Base URL Blocking of HTTPS Configuration
WSA-9.2.0 IP Base URL Blocking of HTTPS Verification
WSA-9.2.0 IP Base URL Blocking of FTP Configuration
WSA-9.2.0 IP Base URL Blocking of FTP Verification
WSA-9.2.0 Redirection bing to google Configuration
WSA-9.2.0 Redirection bing to google Verification
WSA-9.2.0 Warning For Social Site Configuration
WSA-9.2.0 Warning For Social Site Verification
WSA-9.2.0 Proxy Bypass on WSA Configuration
WSA-9.2.0 Proxy Bypass on WSA Verification
WSA-9.2.0 Microsoft Active Directory Integration Configuration
WSA-9.2.0 Microsoft Active Directory Integration Verification
WSA-9.2.0 Proxy Authentication Configuration
WSA-9.2.0 Proxy Authentication Verification
WSA-9.2.0 How to Upgrade WSA Configuration
WSA-9.2.0 How to Verifiy WSA Upgrade
WSA-9.2.0 How to Restore the factory defaults via CLI "resetconfig"
WSA-9.2.0 How to Set Management IP via CLI "ifconfig"
WSA-9.2.0 How to Set Hostname via CLI "sethostname"
WSA-9.2.0 How to Set Gateway IP via CLI "setgateway"
WSA-9.2.0 How to Set DNS Server IP via CLI "dnsconfig
WSA-9.2.0 How to Flush DNS Cache "dnsflush"
WSA-9.2.0 How to Check Configuration via CLI "showconfig"
WSA-9.2.0 How to Configure Time Zone via CLI "settz"
WSA-9.2.0 How to Configure Time via CLI "settime"
WSA-9.2.0 How to Change Admin Password via CLI "passwd"
WSA-9.2.0 How to Check WSA version via CLI "version"
WSA-9.2.0 How to Upgrade WSA version via CLI "upgrade"
WSA-9.2.0 How to Revert WSA version via CLI "revert"
WSA-9.2.0 How to Take Backup of WSA Configuration
WSA-9.2.0 How to Load a configuration file via CLI "loadconfig"
WSA-9.2.0 How to Display the current date and time via CLI "date"
WSA-9.2.0 How to Display alerts sent by the appliance via CLI "displayalerts"
WSA-9.2.0 How to Flush entries from proxy authentication cache "authcache"
WSA-9.2.0 How to Create user via CLI "userconfig"
WSA-9.2.0 How to Configure Failover via CLI "failoverconfig"
WSA-9.2.0 How to Configure Failover via GUI
WSA-9.2.0 How to Load PAC File on WSA
WSA-9.2.0 How to Configure PAC File URL on Client For High availability or Failover
WSA-9.2.0 How to Enable HTTPS Proxy on WSA
WSA-9.2.0 How to Load WSA Certificate on Client
WSA-9.2.0 Block Social Networking during Peak Business Hours (otherwise Warn)
WSA-9.2.0 How to Set Volume Quotas on WSA for YouTube
WSA-9.2.0 How to Configure Application Visibility and Control (AVC) on WSA
WSA-9.2.0 How to Configure Web Reputation on WSA