
Explore the ASA firewall overview and how default traffic flow works, including through traffic versus traffic to the firewall, and how interface name and security level govern access.
Set up an ASA firewall interface from scratch, configure interface names outside, inside, and dmz, assign IP addresses with the correct masks, apply security levels, and verify with show commands.
Configure static routes on the Cisco asa with the route command, including exit interface, next hop, and a default route. Verify with show run route and show route.
Learn to configure rip version two on the asa firewall, disable auto summary, enable rip on interfaces, and implement md5 authentication per interface.
Configure eigrp on the asa alongside a router, compare interface-based authentication and masking with router keychains, and verify reachability using no auto summary and specific network statements.
Master configuring OSPF on the ASA firewall, including router-id, area-zero networks, and correct mask usage, while applying text or md5 authentication on interfaces, with global vs interface-level setup.
Configure BGP on the ASA firewall, including neighbor authentication, network advertisements, the IPv4 unicast address family, and mutual redistribution with OSPF to share internal routes in a multihomed environment.
Explore how firewall ACLs govern through traffic, including default high-to-low flow, return traffic in the connection table, same security traffic behavior, and applying explicit ACLs on the outside interface.
Control traffic destined to the firewall by per-interface services and ICMP rules, while ACLs govern through traffic. Configure remote management access per interface.
Explore remote management options for Cisco ASA firewalls, including ssh, telnet, and http/asdm. Learn per-interface access rules, authentication methods, rsa keys, and gui versus cli management.
Configure Telnet remote management on the firewall, binding access to a specific interface and source IP/mask, and enforce local database authentication with an uppercase admin username and password.
Configure remote management with ssh on a Cisco ASA by generating RSA keys, setting a domain name for the key, and enabling per-interface ssh with local or remote authentication.
Enable http/https remote management on the ASA firewall with ASDM, create a local user with privilege 15, and use the GUI to view interfaces and performance.
Translate internal private IPs to a public IP pool using dynamic NAT, maintain a translation table, and translate return traffic. Explain how source NAT differs from destination NAT on interfaces.
Learn how static NAT translates DMZ servers to public IP addresses, creates translation table entries, and enforces access with ACL, with outside-to-inside traffic checked after translation.
Explore destination nat on a Cisco ASA 9.x by translating non-routable devices to public addresses, using object networks and first/second slot interfaces for source and destination translations.
Explore dynamic PAT to let multiple internal devices share a single public IP by using unique source ports and maintaining translation and connection tables.
Configure static PAT to map a single external address to multiple internal servers using manual translation entries and port redirection for security.
Learn policy based nat, or manual nat, to translate traffic by flow with objects and translations, implement port redirection, and see policy nat precedence over auto nat on Cisco ASA.
Convert the ASA into a transparent layer two firewall by using a bridge group to join two subnets in one vlan, enabling ip routing via a BVI and acl enforcement.
Learn how to route through a transparent firewall by configuring ACLs to permit RIP multicast traffic (UDP 520) between inside and outside interfaces, enabling routing protocol updates.
Explain how ethertype ACLs control traffic on a transparent Cisco ASA firewall, distinguishing IP ethertype 800 from MPLS 8847, and applying ACLs at both interfaces.
Learn to virtualize a single Cisco ASA firewall into multiple security contexts, creating sales and marketing contexts with dedicated interfaces, startup configs, and subinterfaces for scalable topologies.
Demonstrates redundancy at the interface level on a Cisco ASA firewall, compares redundant interfaces with port channels, and guides configuring member interfaces, a virtual MAC, and an IP address.
Learn how to configure port channels on switches for Cisco ASA firewall 9.x, create a port channel with channel-group, assign VLANs, handle switch quirks manually, and verify connectivity.
Learn active/standby failover on Cisco ASA: box-level redundancy with active/standby addresses, config replication, heartbeat, and stateful vs stateless modes.
Explore active/active failover in Cisco ASA 9.x, using multi-context clustering and failover groups to enable load sharing across contexts while maintaining redundancy.
Explore how ASA clustering combines multiple firewalls into a single virtual device with redundancy and load sharing, using cluster control links, span mode, and port channels.
Configure ASA clustering in spanned mode, set the cluster interface to span, assign per-device IP addresses and priorities, then establish port channels and verify with cluster info.
Explore how the modular policy framework enables deep packet inspection at layer seven, inspecting ftp and smtp protocols to enforce default inspection and global policy.
This lecture explains how to enable ICMP inspection on a Cisco ASA by adding inspect ICMP to the global policy, turning classified ICMP into allowed return traffic.
Create a custom class map to classify port 1999 traffic as FTP, enabling deep packet inspection. Apply it in the policy to establish return entries for non standard FTP traffic.
Learn how IPsec secures LAN-to-LAN VPNs with crypto maps, covering phase one and phase two negotiations, Diffie-Hellman, pre-shared keys, transform sets, and ACL-based interesting traffic.
Set up a lan-to-lan vpn between ASA and a router, encrypting traffic with phase one and phase two using crypto map, tunnel group, and transform set on the outside interface.
Configure a lan-to-lan vpn through the firewall by pairing phase one on udp 500 with phase two esp inside udp 4500, using precise acl entries for secure nat-t.
Configure ASDM for management on the Cisco ASA firewall, generate and use the XML profile for AnyConnect VPNs, and set up GUI-based administration with HTTPS access.
Explore web vpn with ssl client, enabling browser-based remote access to internal web, ftp, and file servers via a proxy on the asa firewall; configure groups, users, and port forwarding.
Learn to deploy remote access VPNs with Cisco AnyConnect on the ASA, including SSL/IPsec, certificate setup, IP pools, XML profiles, and split tunneling.
This course teaches you how to implement the Cisco ASA Firewall from scatch. No Firewall knowledge is required. The topics covered include the following:
• Basic Configuration
• Interface configuration
• Security Levels
• Management [Telnet / SSH]
• Routing [RIPv2, EIGRP, OSPF, BGP]
• NAT [Dynamic/Static NAT, Dynamic/Static PAT, Manual NAT]
• Access Policies
• Transparent firewall
• Initialization
• Access policies
• Ethertype ACLs
• Redundancy
• Redundant Interfaces
• Port-channels
• Security Contexts
• Failover [Active/Standby & Active/Active]
• Clustering
• Deep-Packet Inspection using MPF
• Tuning the global policy
• Configuring custom L7 policy
• ASA VPNs
• Site – To – Site IPSec
• Site – To – Site – NAT – T
• Remote access
• Web VPN
• AnyConnect