
Introduction to the course
Explore a real network with physical Cisco devices, connecting headquarters and branch networks, deploying Cisco RSA firewalls to protect PCs and servers on each side as you begin exploring.
Explore the LAN topology, linking headquarter and branch networks via firewalls, a layer 3 switch, and two routers, with domain controller and read-only DC plus remote admin access.
Explore the Cisco c3560 layer 3 switch hardware, including console and management ports, indicators, fans, and power options, and note optical ports require an optical model for secure networks.
Explore the Cisco 300 series router with four gigabit Ethernet ports, console and management ports, and USB options; traffic management splits user traffic with a branch router in the network.
Configure secure administrative devices and edge routers, establish secure administrative access, and enhance security for virtual options and protocol configurations, including securing OSPF routing on routers.
Secure network devices by configuring gateways, passwords, and access controls on routers and switches; enable domain-lookup, set 1024-bit RSA keys, banners, and login lockdown, and manage via a secure interface.
How to configure Routers for OSPF MD5 Authentication
How to configure Routers as NTP client.
How to configure Routers to log messages to the syslog server.
How to configure Router to support SSH connections.
Configure authentication, authorization, and accounting on routers to track who accesses devices, what commands they can use, and what they do.
How to Configure Local AAA Authentication for console access on Cisco Routers
How to Configure Local AAA Authentication for VTY access on Cisco Routers
How to Configure TACACS+ Server for Authentication
How to Configure TACACS+ Server for Authentication
How to Config, Apply and Verify numbered Access Control List (ACL) on a Router
How to Config, Apply and Verify named Access Control List (ACL) on a Router
Configure ACL on Routers
Configure IP ACLs on Routers to mitigate attacks.
Configure IPv6 ACLs
Configure Zone-based Policy Firewall
Explore ingestion prevention system, a network security tool that monitors networks for malicious activity and automatically reports, blocks, or drops threats, and read about IPRs in the PDF.
How to enable IOS IPS;
How to configure logging;
How to modify an IPS signature;
How to verify IPS.
Assign a switch as the root bridge.
Secure spanning-tree parameters to prevent STP manipulation attacks.
Mitigating MAC table attacks by using port security.
Enable port security to prevent CAM table overflow attacks.
Create a redundant link between switches.
Enable trunking and configure security on the new trunk link
Create a new management VLAN and attach a management PC to that VLAN.
Implement an ACL to prevent outside users from accessing the management VLAN.
Describe WLAN technology and standards.
Describe the components of a WLAN infrastructure.
Explain how wireless technology enables WLAN operation.
Explain how a WLC uses CAPWAP to manage multiple APs.
Describe channel management in a WLAN.
Describe threats to WLANs.
Describe WLAN security mechanisms.
In this activity, you will configure a wireless router and an access point to accept wireless clients and route IP packets. Furthermore, you will also update some of the default settings.
In this activity, you will configure a new WLAN on a wireless LAN controller (WLC), including the VLAN interface that it will use. You will configure the WLAN to use a RADIUS server and WPA2-Enterprise to authenticate users. You will also configure the WLC to use an SNMP server.
· Configure a new VLAN interface on a WLC.
· Configure a new WLAN on a WLC.
· Configure a new scope on the WLC internal DHCP server.
· Configure the WLC with SNMP settings.
· Configure the WLC to user a RADIUS server to authenticate WLAN users.
· Secure a WLAN with WPA2-Enterprise.
· Connect hosts to the new WLC.
| How to configure and verify IPSec VPN site to site on Cisco Router |
Explore the ASA on a common topology
Configure ASA settings and interface security
Configure routing, address translation, and inspection policy
Configure DHCP, AAA and SSH
Configure DMZ, static NAT and ACLs
Guide you through configure secure administrative access lab, build topology, set ip addresses from the address table, follow step-by-step instructions, and compare your answers with the answer file.
Hi,
When teaching Cisco Network Security course I've found that students often have difficulty in finding methods to troubleshoot network issues. Moreover, students have difficulty in remembering configuration commands on Cisco netwoking devices. The way to solve these issues is to practice on the network scenarios as much as possible. And this course is designed to guide students doing all the Network Security Activities on Packet Tracer simulation Software. In each video, the teacher will give the problem that need to be solved, the knowledge needs to be to applied, and the configuration commands need to be used. With the step-by-step guide video, the students can more understand the knowledge and remember the way using configuration commands.
PACKET TRACER ACTIVITIES GUIDE INCLUDE:
Explain the various types of threats and attacks.
Explain the tools and procedures to mitigate the effects of malware and common network attacks.
Configure command authorization using privilege levels and role-based CLI.
Implement the secure management and monitoring of network devices.
Configure AAA to secure a network.
Implement ACLs to filter traffic and mitigate network attacks on a network.
Implement Zone-Based Policy Firewall using the CLI.
Explain how network-based Intrusion Prevention Systems are used to help secure a network.
Explain endpoint vulnerabilities and protection methods.
Implement security measures to mitigate Layer 2 attacks.
Explain how the types of encryption, hashes, and digital signatures work together to provide
confidentiality, integrity, and authentication.
Explain how a public key infrastructure is used to ensure data confidentiality and provide authentication.
Configure a site-to-site IPsec VPN, with pre-shared key authentication, using the CLI.
Explain how the ASA operates as an advanced stateful firewall.
Implement an ASA firewall configuration.
Implement an ASA firewall configuration using ASDM (optional).
Test network security.
Happy learning!