
Explore key CCNP security SENSS 300-206 topics, including spoofing prevention, firewall features, VPN types (site-to-site, remote access, SSL), NAT and IPv6, and forward mirroring.
Explore the physical topology of routers, switches, and firewalls, and map their connectivity across city layouts for hands-on labs with physical devices.
Explore how a local area network groups devices into a single broadcast domain, how a switch floods broadcasts to all interfaces, and how VLANs separate broadcast domains for network segmentation.
Configure a switch to assign ports to predefined VLANs, illustrating static VLAN membership by port groups and contrasting with dynamic VLAN provisioning.
Explore dynamic VLANs and MAC-based membership managed by the VMP server, where a switch learns a device’s MAC and assigns it to VLANs like 100 or 200.
Discover how vlan tagging works by adding an extra header that contains the frame's vlan id, enabling switches to forward tagged frames between devices and across domains.
Explore the Cisco proprietary ISL protocol, its encapsulation method with 26-byte header and 4-byte trailer, dirty tagging and double tagging concepts, and how frames are carried on Cisco devices.
Explore 802.1q trunking, an open standard for smart tagging. Learn how a four-byte tag, containing protocol identifier and control information, enables VLAN tagging and QoS.
Demonstrate inter-vlan routing using router on a stick by configuring trunk links and dot1q encapsulation for VLANs 20, 30, 40, 50, and 60 to enable inter-network communication.
Configure inter-vlan routing with SVIs by creating VLANs 10, 20, 30, 40, 50, 60, assigning SVIs with IP addresses, and enabling ip routing as the gateways for each VLAN.
Explore layer 2 port security: set MAC addresses per interface, use sticky or manual entries, and enforce shutdown, restricted, or protected actions to prevent MAC spoofing and cam table overflow.
Explore layer 2 security with a port security lab, configuring switch ports, MAC addresses, sticky MAC, and violation modes (shutdown, restrict, protect) to prevent MAC spoofing and dhcp starvation.
Learn how protected ports enforce layer 2 security by preventing communication between protected hosts on the same switch. See how unprotected ports enable conversations and how to configure protected ports.
Explore layer 2 security with a protected port lab, configuring switch ports as protected to show that protected ports cannot communicate with each other on this switch, while unprotected can.
Explain MAC authentication bypass (MAB) in layer 2 security, where devices obtain IPs via DHCP and are authenticated by a RADIUS server to access network resources based on trusted MACs.
Configure layer 2 security using MAC authentication bypass (MAB) in a SENSS lab. Set up interfaces, IP addresses, IP routing, a RADIUS server, and identity binding in ICE.
Explore layer 2 security with MAB verification by configuring DHCP snooping and a DHCP server on switches, then assign IP addresses to clients and verify access bypass scenarios.
This lecture introduces 802.1x authentication for layer 2 security, showing how a supplicant on a PC presents credentials to an authenticator (switch) and an authentication server to grant access.
Configure 802.1x authentication on a lab switch with radius, set interface authentication, and add user identities with a pre-shared key, then test radius authentication.
Practice configuring 802.1x authentication verification on a switch, enable extensible authentication protocol and user authentication, and verify IP connectivity after successful authentication in a layer 2 security lab.
Learn dynamic VLAN membership that maps MAC addresses to VLAN IDs via a VMPS server for automatic assignment, and how username and password authentication guides VLAN allocation via AAA.
Learn to configure dynamic VLAN assignment for an AP using a radius server and 802.1X authenticator, including identities, groups, and policy applying VLAN 50 on the switch.
Perform a dynamic vlan verification lab to reinforce layer two security by configuring a test personal computer on port 48, enabling authentication sessions, and verifying ip address and connectivity.
Explore VLAN access control lists to secure inter-VLAN traffic on layer 2. Build an ACL to deny ICMP from 10.0.x networks while permitting other IP traffic.
In this lab, configure a vlan access list to block icmp traffic within vlan 100, create and apply an extended acl to filter traffic between hosts, and verify ping behavior.
Learn private VLANs to isolate hosts and control access without changing subnets by partitioning a VLAN into isolated, community, and promiscuous ports, with gateway communication rules.
Configure a layer 2 private VLAN lab with primary VLAN 100, secondaries 200/300 (community) and 400 (isolated), using promiscuous ports and gateway routing to control inter-host communication.
Explore a layer 2 security proxy attack, illustrating private VLANs, a promiscuous gateway, and a proxy ACL that blocks spoofed traffic between hosts.
Explore a layer 2 security proxy attack lab by isolating hosts, performing a proxy ARP attack, and configuring a gateway ACL to block proxy traffic and protect the network.
Learn how layer 2 VLAN hopping works: how untagged (native) frames and tagged frames traverse switches, and how to prevent it by configuring a consistent native VLAN on trunks.
Explore layer 2 security with a VLAN hopping lab, configuring a native VLAN, dot1Q trunks, and a separate VLAN 420 to drop untagged frames and prevent VLAN hopping.
Examine rogue DHCP attacks, how DHCP discovers and assigns IPs via the DORA sequence, and implement DHCP snooping with trusted uplink ports to block rogue servers at layer 2.
Demonstrates a rogue DHCP attack lab and DHCP snooping, showing how clients receive IP addresses and gateways and how trusted ports prevent man-in-the-middle attacks.
Explain how DHCP starvation floods the pool with requests from multiple MAC addresses to exhaust IP addresses, and how port security limits MAC addresses per port to prevent it.
Explore a layer 2 security dhcp starvation lab, showing how mac spoofing exhausts the dhcp pool and how port security with sticky mac prevents it.
Explore how IP spoofing occurs at layer 2 and how IP source binding with MAC address mappings on switches mitigates spoofed traffic.
Perform a lab on ip spoofing and learn layer 2 security with ip source guard and dhcp snooping, using binding to drop spoofed packets.
Examine a layer 2 man-in-the-middle arp poisoning attack, showing how spoofed mac and gateway ips hijack traffic and how dynamic arp inspection prevents it.
Explore dynamic ARP inspection to prevent ARP poisoning and man-in-the-middle attacks by validating ARP replies against a learned IP-to-MAC mapping, aided by DHCP snooping on the switch.
Configure dynamic arp inspection with dhcp snooping across vlan 100, building a mac-ip database and using trusted ports and static mappings on two switches.
Understand how layer 2 switches learn MAC addresses and forward frames with the CAM table, and how a macof attack causes overflow and flooding, mitigated by port security.
Demonstrate layer 2 security by simulating a CAM table overflow and applying port security with sticky MAC and max MAC address limits to prevent violations and shutdowns.
Learn how mac spoofing works at layer 2, where an attacker masks a mac address to intercept traffic, and how port security on switches prevents spoofing by limiting observed macs.
This SENSS lab demonstrates MAC spoofing using fake MAC addresses and ICMP flood attacks, showing how port security detects spoofing, catches the attacker, and disables interfaces to prevent MAC spoofing.
The lecture introduces the spanning tree protocol (STP) and how it prevents broadcast storms, MAC address instability, and multiple frame transmissions by placing interfaces in forwarding or blocking states.
Learn how spanning tree protocol tasks elect the root bridge, select the root port, and designate ports by lowest cost, using bridge IDs, priorities, and MAC address pools.
Explore STP BPDU basics, the bridge protocol data unit exchanged between switches, including hello messages every two seconds and root, non-root configuration bpdus and topology change notifications.
Explore how the stp cost acts as an implicit value for the designated port and election, and review the protocol’s default costs you can adjust.
Explore how STP selects the root bridge by the lowest priority and then the lowest MAC address, forming the bridge ID and guiding port roles.
Explain how switches elect the STP root bridge by comparing priorities and MAC addresses, with each switch initially claiming root and exchanging messages to establish the active topology.
this lecture introduces sen ss stp dp and rp, showing root bridge and port role election by cost and priority, and how forwarding and blocking ports prevent loops.
Explore stp timers introduction. Learn how hello time (2 seconds), forward delay (15 seconds), and max age (20 seconds) govern listening and learning states and bpdu handling on root port.
Explain the STP port states - disabled, blocking, listening, learning, and forwarding - and how each state affects data transmission and MAC learning.
This lecture introduces STP topology changes: direct changes occur when links go down, indirect changes involve a bridge, and insignificant changes arise from PCs turning on and off.
Learn how spanning tree protocol selects the root bridge using switch priority and MAC address, assigns root and designated ports, and blocks nonessential links to ensure loop-free networks.
Explore STP portfast introduction, detailing blocking, listening, learning, and forwarding states and the 30-second convergence. Learn how portfast forces immediate forwarding on link up and where to enable it on edge ports.
This lab demonstrates configuring spanning-tree basics on four switches, enabling portfast to move edge ports from blocking to forwarding as soon as they come up.
Explore spanning tree concepts and uplinkfast, which speeds convergence by moving an alternate port into forwarding when the root fails, while covering blocking, listening, and learning states.
configure STP uplink fast to quickly switch to forwarding on alternate paths when the root changes, adjust root priority, and observe port states from listening to forwarding.
Explore how STP backbone fast speeds convergence after a root fail via rapid port state changes and inferior BPDU handling. Enable backbone fast across switches to prevent inferior BPDU issues.
The SENSS STP backbone fast lab demonstrates enabling backbone fast on switches to prevent inferior BPDU from delaying convergence, and to rapidly elect a new root when links fail.
Explore STP root guard to prevent unintended root changes by validating BPDUs and enforcing consistent root port state on switch ports.
Explore a STP root guard lab, illustrating port blocking and unblocking in response to BPDUs to preserve topology, and show how to restore normal operation by reconfiguring switches.
Explore STP loop guard in this deep dive, learn how it silently blocks loops when BPDUs fail to arrive, prevents inconsistent states, and resumes normal operation once BPDUs return.
Explore the STP loop guard lab by enabling loop guard on designated ports, stopping BPDU exchanges, and observing ports enter a loop-inconsistent state when BPDU are not received.
Explore how STP BPDU guard blocks rogue BPDUs from attackers on access ports, forcing a port into error-disabled state to prevent rogue root transitions and protect the network.
Learn to configure and verify bpdu guard on switches, enabling it on interfaces or globally to place port 19 in disabled state when a bpdu is received.
Explore the SENSS STP BPDU filter concepts, including BPDU guard behavior on received BPDUs and how BPDU filter blocks BPDU traffic on server-connected and client-connected ports.
Learn how to configure BPDU filter to block STP BPDUs, either globally or on specific interfaces, and verify the resulting spanning tree states in a lab environment.
This lecture introduces udld, the unidirectional link detection protocol, showing how switches exchange identical messages to verify bidirectional fiber links, and explains normal and aggressive modes.
Explore the sen ss stp udld lab by enabling udld on switch interfaces and ranges, and observe automatic link detection and interface shutdown in normal and aggressive modes.
Learn how snmp lets devices such as routers, switches, and firewalls share data with an snmp manager, how agents gather data, store it in a local database, and trigger traps.
Configure snmpv1 on switches, create an access list for the snmp server, and define a read-only community for the host at 192.168.1.100.
Configure snmpv2 on the switch by defining an access list to permit hosts, creating a read-only community string, and binding the host ip to the snmp server.
Configure snmpv3 on a network device by creating an access list, defining an snmp group, and adding a user with authentication and privacy settings.
Explore span and remote span concepts by configuring a switch port analyzer to copy traffic to a network analyzer, and distinguish local and remote span use cases.
Create a monitor session to mirror traffic from source interface fast ethernet 1/0 to destination interface fast ethernet 0/48, capturing bidirectional traffic for Wireshark analysis.
Explore remote span configuration across switches, creating a relay and monitor session from source to destination, and validate with a Wireshark analyzer when hosts are in different cities.
Learn how the network time protocol enables clock synchronization across routers, switches, firewalls, and other devices using UDP port 123, with client-server interactions for accurate timekeeping.
Configure a Cisco ap server as an ntp server without authentication, assign ip addresses, synchronize router and switch clocks, and verify with show clock and ping using vm or hardware.
Configure ntp with authentication on the ap server by setting the clock, designating a master server, and applying a trusted key with md5 authentication.
This lecture introduces Cisco IOS firewall features, including network address translation, context-based access control with stateful inspection, application mapping, zone-based policies, DHCP intercept, IPsec VPN, IPS, and logging.
Explore how standard and extended access lists classify and control IP traffic. Learn about time-based, dynamic, reflexive, and named access lists for precise filtering.
Explore an IOS standard access-list lab across three switches and PCs, configure IP addresses, apply permit and deny rules with sequence numbers, and verify connectivity and restricted Telnet access.
Configure an IOS extended access-list to deny icmp traffic between specified hosts, while permitting other protocols, then verify connectivity between the PCs and FTP server to confirm the rule.
Create and apply named extended access lists on ios to permit icmp and select protocols while denying all else. Validate connectivity across hosts with pc-to-pc and ftp tests in lab.
This lab teaches creating and applying a time-based access-list on IOS, defining a time range (weekdays 9–18), setting router clocks, and validating traffic control.
Configure and test IOS dynamic extended access lists to temporarily permit traffic between hosts, applying the dynamic list to an interface and validating with telnet and show commands.
Configure and test reflexive access-list to permit return traffic, using dynamic ACLs, UDP, ICMP, and session awareness to control traffic between trusted hosts and outside networks.
Configure a Cisco ios tcp access-list to establish connections, apply reflexive and extended access rules, and verify permit and deny behavior between pcs.
Introduce zone-based firewall concepts on IOS, configure inside, outside, and DMZ zones, assign interfaces, and enable stateful packet inspection, DoS prevention, and deep packet inspection with class and policy maps.
Configure a two-zone IOS firewall with inside and outside interfaces, define zone policies, apply inspection, and verify PC reachability across trusted and untrusted networks.
Configure a three-zone iOS zone-based firewall with inside, outside, and dmz, set interfaces and IP addresses, create class-map and policy-map inspect rules, and validate with ping and Telnet tests.
Build a four-zone IOS zone-based firewall across inside, DMZ1, DMZ2, and outside interfaces; configure IP addresses, class maps, policy maps, and inspect rules to control traffic between zones.
Explore how network address translation maps private IP addresses to public IP addresses, enabling private networks to reach the internet through static, dynamic, and PAT NAT techniques.
Explain the SENSS iOS static NAT lab by configuring a one-to-one translation between inside private networks (192.168.1.x) and outside public IPs, and verify PC connectivity to internet and Google.
Learn to configure IOS dynamic nat to map multiple inside hosts to a pool of external addresses, define interfaces and an ACL, and verify translations and connectivity.
Configure and verify IOS port address translation (PAT) in a lab by setting up access lists and inside/outside interfaces, then test with PCs to validate unique port mappings.
Configure static pat to map internal private addresses to a public ip for ports 21, 23, 80, and 443, and verify translations with show ip nat translation from a pc.
Configure static NAT with nonstandard ports on the router, mapping inside networks to public IPs. Verify translations by accessing the public IP on ports 21, 22, 23, and 80.
The Implementing Cisco Edge Network Security (SENSS) (300-206) exam tests the
knowledge of a network security engineer to configure and implement security on Cisco network
perimeter edge devices such as a Cisco switch, Cisco router, and Cisco ASA firewall. This 90-minute exam
consists of 65-75 questions and focuses on the technologies used to strengthen security of a network
perimeter such as Network Address Translation (NAT), ASA policy and application inspect, and a zonebased firewall on Cisco routers. Candidates can prepare for this exam by taking the Cisco Edge Network
Security (SENSS) course.
CCNP Security 300-206 (SENSS) Module Contents in brief: