
Learn how a firewall regulates traffic between two or more networks, blocks unauthorized access, and enforces security policies to protect LANs, DMZs, and servers from threats.
Deploy a firewall to monitor and control internet traffic, enforce security policies, prevent unauthorized access, and mitigate denial-of-service and data modification risks for the internal network and DMZ.
Explore three-tier firewall design with internal LAN, a DMZ hosting servers, and the Internet edge, explaining why placing services in the DMZ protects the LAN from external attacks.
Explore how stateful packet filtering enhances firewall security by tracking traffic with a state table, inspecting packets against rules, and differentiating initiated requests from replies to allow or drop traffic.
Compare stateful and stateless packet filtering, showing how a state table tracks sessions to enforce firewall rules and filter traffic at different interfaces.
Explore application level gateways and proxy servers, explaining how proxies cache web content to reduce internet traffic and how they filter or block certain sites.
Discover next-generation firewall capabilities, including traffic filtering from the local network to the internet, cloud and content filtering, identity-based access, per-user policies, application controls, and intrusion prevention with antivirus-like protection.
Compare firewall options to match network requirements and explore vendor offerings across basic and next generation firewalls, including stateful and stateless filtering, proxies, and application gateways.
Explore Cisco stateful firewalls with IOS-ASA, including dedicated appliances, policy-based configurations, and context-based access control and zombie's policy firewall.
Discover Cisco ASA features, including platform-based services, traffic inspection, application identification, and VPN options for site-to-site and remote access.
Learn how ASA-supported features enable a single physical appliance to host multiple virtual firewalls (contexts) with isolated security policies, high availability, and scalable clustering, plus management via CLI.
Compare asa firewall models across small office home office deployments, detailing base and advanced licenses, platform differences, and features for site-to-site vpn and protection.
Manage Cisco ASA with both CLI and GUI using ASDM, and perform basic configurations from the console. Explore secure CRT or HyperTerminal as setup tools and prepare for lab configurations.
Explore ASA basic cli modes and commands, including enable versus enable secret passwords, global configuration and interface modes, use of short commands and autocomplete, and how to exit the CLI.
Explore how ASA security levels govern traffic between land, DMZ, and internet. Learn default allow/deny rules, interface naming, and ACL-based refinements for secure network access.
Configure ASA interfaces to establish inside, outside, and DMZ segments, including naming interfaces and setting trust levels for secure service hosting.
Configure ASA security policies by applying a default global policy and policy maps to inspect traffic, log sessions, and manage icmp testing, with optional rate limiting and preconfigured inspections.
Explore how the ASA routes traffic across head and branch offices by configuring firewalls, specifying subnet masks and next-hop IDs, and validating connectivity with verification commands and logging.
Explore how access control lists regulate traffic between interfaces by matching entries to permit or deny packets in top-to-bottom order, with implicit deny for unmatched traffic.
Learn how to configure a basic acl on a Cisco asa firewall, including default deny, permit rules, and applying access-group to control traffic between outside and inside interfaces.
Explore how traffic between the same security level is blocked by default on a firewall and how to enable targeted traffic, including cases involving DMZ and VPN scenarios.
Group servers, services, sources, and destinations into acl object groups to minimize access control entries, reduce processing overhead, and simplify configuration and maintenance of firewall rules.
Master ACL object groups to control access to multiple services on three servers in a DMZ, using server and service objects to build scalable permit and deny rules.
Explore the difference between private and public IP addresses, where private IPs stay inside the organization and traffic translates to public IPs to reach the Internet, which are globally unique.
Learn how to translate private ip addresses to public ones using nat, configuring routers or firewalls to enable internet access while private addresses remain internal.
Explore nat types including static mapping for hosted services, dynamic nat with address pools, and pat overload that uses port translation to map private ip addresses to public ip addresses.
Configure dynamic nat on asa by using an object network and a public address pool to translate inside private ips to public ips for inside-to-outside traffic, with lookback testing.
Showcases dynamic pat on the firewall, translating private ip addresses to a single public ip, configuring and clearing objects, and testing traffic to validate the setup.
Learn dynamic pat using exit interface to translate inside addresses to a single public ip on the outside, accommodating changing ips.
Explore dynamic nat and pat configurations by defining a public pool and a private subnet, translating inside to outside traffic with an exit interface, and verifying with sample traffic.
Configure static nat on the ASA to map three DMZ hosts to public IPs, create object networks for each host, and apply an access list to allow internet access.
Configure static PAT on ASA to map multiple private IPs to a single public IP using different ports. Learn object networks, private IP ranges, port-based translation, and basic ACLs.
Understand zone-based firewall concepts on iOS, defining land, internet, and DMZ zones, and applying deep packet inspection with policies and ACLs to control interzone traffic.
Configure a zone-based firewall by creating zones (land, internet, DMZ), assigning interfaces, and enforcing default deny between zones; define class maps and policy maps, then apply actions to interfaces.
Learn to configure zbf security zones, including user defined and system predefined zones like inside, outside, and dmz, and to apply traffic policies.
Configure firewall security zones by creating LAN and Internet zones and binding them to interfaces. Enforce default denial between zones and prepare to classify traffic and apply policies.
Zbf default traffic flow across security zones; by default interzone traffic and internet-to-lan traffic is dropped, requiring explicit policies to allow or deny traffic.
Classify traffic with class-maps in a zbf framework to define what to allow or deny by default, then apply policy maps to inspect and permit specific protocols.
Configure zbf class-map for traffic classification and inspection. Use a type inspect class-map to match traffic between specific hosts on land and internet, with named objects and sequence syntax.
Configure zone-based firewall rules by building policy maps and class maps to inspect or drop traffic between zones, using default actions and logs to manage matched or unmatched traffic.
This Course is designed to prepare CCNA Security candidates for the exam topics covered by the 210-260 IINS exam.
This is Fourth of 6 parts of the Complete CCNA Security 210-260 Exam..
This course allows learners to understand common security concepts, and deploy basic security techniques utilizing a variety of popular security appliances within a "real-life" network infrastructure. It focuses on security principles and technologies, using Cisco security products to provide hands-on examples.
This Cisco self-paced course is designed to be as effective as classroom training.
Course content is presented in easily-consumable segments via both Instructor Video and text. Makes the learning experience hands-on, increasing course effectiveness
The revised CCNA Security (IINS v3.0) curriculum is designed to bring data, device, and administration together to have better network security, which is more relevant and valuable than ever. It is destined to meet the current business demand so that the network security professionals are able to acquire new knowledge, training and vital skills to be successful in evolving job roles.
1. Security Concepts – This section includes security principles, threats, cryptography, and network topologies. It constitutes 12% of the questions asked in the exam.
2. Secure Access – This section deals with secure management, AAA concepts, 802.1X authentication, and BYOD. It makes 14% of the exam.
3. VPN (Virtual Private Networks) – This focuses on VPN concepts, remote access VPNs, and site-to-site VPNs. It is 17% of the exam.
4. Secure Routing & Switching – This section concentrates on VLAN security, mitigation techniques, layer 2 attacks, routing protocols, and overall security of Cisco routers. That is 18% of the exam.
5. Cisco Firewall Technologies – This section is 18% of the exam and focuses on stateful and stateless firewalls, proxy firewalls, application, and personal firewalls. Additionally, it concentrates on Network Address Translation (NAT) and other features of Cisco ASA 9.x.
6. IPS – It is 9% of the exam and this portion focuses on network-based and host-based IPS, deployment, and IPS technologies.
7. Content and Endpoint Security –Constituting 12% of the exam, this section checks your understanding on the endpoint, web-based, and email-based threats. Later it leads to apt and effective mitigation technology and techniques to counter those threats.