
Compare symmetric encryption, using a single key for encryption and decryption, with asymmetric encryption, using a public key to encrypt and a private key to decrypt, noting symmetric is faster.
Explore how hashing produces a fixed-size digest from data, a one-way function for integrity and authentication, and how MD5, SHA, and HMAC verify data integrity.
Learn how Ike negotiates IPsec security associations between IPsec peers via phase one and phase two, comparing Ike v1 and v2, including main and aggressive modes and quick mode.
Explore how virtual private networks create secure tunnels over the internet using IPsec and SSL, ensuring privacy and data integrity for site-to-site and remote access, with client-based and clientless options.
Download and import the dmvpn labs, workbook, and topology resources for eve-ng, then follow the step-by-step lab workbook to practice main mode and aggressive mode configurations.
Demonstrates site-to-site IPsec using ESP and AH, compares tunnel and transport modes, explains encryption, authentication, and anti-replay, and verifies policies with a hands-on lab topology.
Configure site-to-site ipsec vpn ikev1 with nat between two private subnets (192.168.1.0/24 and 192.168.2.0/24), implement nat exemption, and verify with show commands and pings.
Configure a site-to-site ipsec vpn between a Cisco router and RSA using ikev1, implementing phase 1 and 2, crypto maps, and testing with PC one and PC two.
Configure a full mesh ipsec vpn using ikev1 with esp between three routers, building two tunnels per device, using public ips 1.1.1.1, 2.2.2.2, 3.3.3.3 and subnets 192.168.1.0/24, 192.168.2.0/24, 192.168.3.0/24.
Discover how generic routing encapsulation, a Cisco tunneling protocol, creates a layer 3 tunnel to carry multicast traffic, not encrypted by default, with a secure site-to-site VPN added.
Explore DMVPN deployment across three methods: phase one hub-to-spoke, and phases two and three with spoke-to-spoke tunnels using Mgr on both sides.
Describe dmvpn terminologies including NBMA addresses, NHS and NHC roles, and tunnel IP addresses used to map private and public addresses.
Dmvpn uses multipoint tunnels and point-to-point tunnels for hub-to-spoke and spoke-to-spoke connectivity. It relies on nhrp to map nbma addresses to logical tunnel addresses via a hub and spokes.
Learn to configure site-to-site ipsec vpn using ikev2 between r1 and r2 with isp, using private subnets 192.168.1.0/24 and 192.168.2.0/24, with pre-shared keys, proposals, policies, and acl-based traffic.
A Virtual Private Network (VPN) is a network that uses the Internet, to provide remote offices or individual users with secure access to their organization's network. In this course you will learn how to configure and manage Virtual Private Networks. We will start from understanding basic concepts of VPNs such as Cryptography, Symmetric & Asymmetric Encryption, Cryptography Hash, Diffie-Hellman, IPsec Protocols, packet exchange and configuring Site to Site VPNs. We will then move on to advanced VPNs such as DMVPN. This is the first part of the 2 Parts for new CCNP SECURITY Concentration Exam SPVN-300-730 covers topics in 2 Parts. Whether you are a beginner or already have some experience in Networking & Security the course will be really beneficial for you.
Overview:
This exam tests your knowledge of implementing secure remote communications with Virtual Private Network (VPN) solutions, including Secure communications, Architectures and Troubleshooting.
Topics to Cover:
Concept of Cryptography & Terminologies.
Concept of Symmetric & Asymmetric Encryption.
Concept of Cryptography Hash (SHA and MD5).
Concept of Diffie-Hellman (DH) Group.
Concept of IPsec Protocols Features.
Concept of IKE, IKE Versions and Modes.
Concept of SSL/TLS and Hands-shake.
Concept of Virtual Private Network VPN.
Policy-Based and Route-Based VPNs Theory.
Site-to-Site VPN on Router with ESP & AH.
Site to Site VPN On Cisco Router IKEv1.
Site-to-Site IPsec VPN Verification.
Site-to-Site VPN Troubleshooting Phase 1.
Site-to-Site VPN Troubleshooting Phase 2.
Site-to-Site VPN with Overlapping Subnet.
Site-to-Site IPsec VPN IKEv1 with NAT.
Site-to-Site IPsec VPN with Dynamic IP.
Site-to-Site VPN On Router & ASA IKEv1.
Site-to-Site VPN On Cisco ASA IKEv1.
Site-to-Site VPN Main & Aggressive Mode.
IPsec VPN Site to Multisite using IKEv1.
IPsec VPN Site to Full Mesh using IKEv1.
Concept of Generic Routing Encapsulation.
Configure and Verify GRE with IPsec Lab.
Concept of Dynamic Multipoint VPN DMVPN.
Theory of Three Different DMVPN Deployment.
Dynamic Multipoint VPN DMVPN Terminologies.
Dynamic Multipoint VPN DMVPN Components.
DMVPN Network Designs Three Different Phases.
Configure Dynamic Multipoint VPN Phase 1.
DMVPN Phase 1 command Explanation & Routing.
Configure Dynamic Multipoint VPN Phase 2.
Configure Dynamic Multipoint VPN Phase 3.
Concept of IPsec Configuration on DMVPN.
Configure & Verify DMVPN Phase 3 with IPsec.
DMVPN Troubleshooting and verification.
Site to Site VPN On Cisco Router IKEv2.
Site-to-Site VPN On Cisco ASA IKEv2.