Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Virtual Private Networks - Zero to Hero (VPN)
Rating: 4.6 out of 5(496 ratings)
5,083 students

Virtual Private Networks - Zero to Hero (VPN)

A comprehensive coverage of Virtual Private Networks from basic level to advanced
Last updated 1/2022
English
German [Auto],English [Auto],

What you'll learn

  • Site to Site VPNs
  • Multi Point GRE VPN
  • Advanced VPN: DMVPN
  • Advanced VPN: GETVPN
  • Advanced VPN: Remote Access VPN
  • Advanced VPN: FLEXVPN
  • Advanced VPN: IOS SSL VPN
  • IKEv1 and IKEv2 VPN

Course content

1 section31 lectures31h 19m total length
  • Introduction to the course1:59

    Explore virtual private networks from basics to real-world configuration, preparing you for CCNA Security and CCNP Security exams and enabling you to configure a remote access vpn.

  • Day 1 IPsec Exchange1:55:58

    Discover how IPsec exchanges secure VPNs, covering main mode phase one, policy negotiation, and keying material. Learn how PSK and PKI, MD5/SHA, and Diffie-Hellman ensure authentication and encryption.

  • Day 2: The First IPsec Tunnel1:32:26

    Explore how the first ipsec tunnel is negotiated on udp 500, establishing security associations and policies, selecting encryption and hashing methods, and binding a crypto map to private networks.

  • Day 3: Double Trouble IPsec1:15:24

    Explore site-to-site ipsec vpn by building and testing tunnels between R1 and R3, configuring crypto maps, transforms, and acls, and understanding main mode, quick mode, and encapsulation.

  • Day 4a: Pinning IPsec Tunnels19:50

    Build and manage IPsec tunnels using access lists and crypto maps to secure site-to-site traffic. Explore tunnel encapsulation, keepalives, scalability challenges, and multicast limitations.

  • Day 4b: Nat Traversal (NAT-T)42:45

    Demonstrates nat traversal for a VPN between R4 and R1, detailing ACL policies, NAT, UDP 4500 encapsulation, and static port bindings for tunnel establishment.

  • DAY 5 GRE over IPSec and SVTI1:05:31

    Learn how GRE over IPsec creates encrypted tunnels for private networks over the public internet, using SVTI and IPsec profiles to secure traffic.

  • DAY 6 DMVPN Phase 1 Part11:24:14

    Learn how Dmvpn phase 1 enables scalable multipoint tunnels with a hub-and-spoke topology, using Nhrp dynamic mapping and registration to resolve destinations.

  • DAY 6 DMVPN Phase 1 Part218:47

    Explain how dmvpn phase 1 uses hub-and-spoke tunnels with static neighbors and dynamic mappings, routing multicast hello traffic through the hub to spokes.

  • DAY 7 DMVPN Phase 2, 323:19

    Explore dual-hub DMVPN design with active-active hubs to ensure spoke communication when a hub fails, maintain dynamic mappings and multicast to multiple hubs, and enable load-balanced path selection.

  • DAY 7 DMVPN Phase 3 Dual Hub1:23:26

    Explore DMVPN phase 3 dual-hub design that enables direct spoke-to-spoke communication through dynamic registrations, resolution requests, and redirect shortcuts, improving scalability and hub efficiency.

  • DAY 8 DMVPN Phase 1,2,3 with OSPF Dual hub59:53

    Master DMVPN day 8: implement phase 1 and 3 with OSPF in a dual-hub hub-and-spoke network, using multipoint tunnel types, point-to-point links, and redirects for spoke-to-spoke routing.

  • Day 9: GETVPN Single Hub TEK1:23:36

    Get VPN in a multi-site private WAN, detailing how a key server manages IPsec tunnels, group member registration, session keys, and push-down policies to achieve scalable VPN with gdoi.

  • DAY 10: GETVPN Dual Hub KEK and TEK1:29:07

    Learn how getvpn uses kek and tek with dual key servers, primary-secondary roles, and gdoi key exchange to secure tunnels, with unicast/multicast rekey and time-based anti-replay.

  • DAY 11: VPN with CA Server1:28:18

    Explore how public key infrastructure and certificate authorities secure site-to-site and SSL VPN tunnels by issuing and signing identity certificates, enabling enrollment and trusted RSA-based keys.

  • DAY 12: EzVPN Client1:22:04

    Configure remote access vpn with ezvpn client, including group name, password, and address pools. Understand how dynamic crypto maps push policies, transform sets, and split-tunnel traffic for secure connectivity.

  • DAY 13: EzVPN Router as a Client, NEM, NEM-Plus1:24:21

    Discover how ezvpn router acts as a client, configuring ipsec, dynamic maps, and inside/outside interfaces. Learn network extension modes (including network extension plus) and extended authentication for flexible site connectivity.

  • Day 14: EzVPN Enhanced1:38:50

    Explore EzVPN enhanced with dynamic virtual tunnel interfaces and unnumbered IP addresses, enabling template-driven, scalable VPN deployments with reverse route injection and static routing.

  • DAY 15: IKEv2 Site to Site VPN1:14:46

    Ikev2 site-to-site vpn fundamentals, including a streamlined four-packet exchange, nat-t handling, and create child essays, with traffic selector and authentication options.

  • DAY 16 IOS SSL VPN Part 11:17:11

    Explore how ssl vpn encrypts traffic at layer seven using an ssl handshake, certificates, and port 443 to secure remote access, unlike IPsec’s layer three approach.

  • DAY 16 IOS SSL VPN Part 225:45

    Explore ssl vpn gateway configuration, creating port forwards like R1 and R2, using a thin client and java to tunnel traffic through 127.0.0.1, within admin and sales contexts.

  • DAY 17: SSL VPN on ASA1:36:52

    Configure SSL VPN on an ASA with AnyConnect thick client, enable web VPN on the outside, and enforce group policies and web-type ACLs for controlled http access and split tunneling.

  • DAY 18: Site to Site VPN on ASA20:52

    Explore how to set up a site-to-site IPsec VPN on an ASA firewall, detailing interfaces, crypto maps, tunnel groups, and the differences from iOS-based routers.

  • Day 18: VRF aware VPN54:33

    Explore vrf aware vpn architectures in mpls networks by creating separate vrfs with distinct routing tables, route distinguishers, and interfaces, enabling isolated site a and site b traffic.

  • Day 19: EzVPN on the ASA34:32

    EzVPN on the ASA is explained through remote access vpn configuration using dynamic crypto maps, tunnel groups, and group policies, including split tunneling and network extension mode.

  • Day 19: IKEv1 and IkEv2 on the ASA33:49

    Explore configuring IKEv1 and IKEv2 on the ASA, including setting tunnel groups, IPsec L2/L, crypto ikev2/IPsec proposals, pre-shared keys, and matching policies, and applying crypto maps on the outside interface.

  • DAY 20: FLEX VPN Site to Site1:12:47

    Master flex vpn site-to-site in a hub-and-spoke topology with spoke-to-spoke tunnels. Configure ikev2 ipsec, static tunnels, virtual templates, and resolution via redirects to enable direct communication between spokes.

  • DAY 20 DVTI52:29
  • DAY 21: FLEX VPN53:15

    Learn flex vpn fundamentals by configuring a flex vpn server and client, comparing with easy vpn, and understanding manual tunnel, routes, and ikev2 ipsec setups.

  • DAY 22: VPN High Availability59:07

    This lecture explains vpn high availability using standby groups and a virtual ip to keep the vpn active, with ipsec tunnels, pre-empt, and tracking to ensure seamless failover.

  • DAY 2314:04

    Explore how to prioritize and police vpn traffic through ipsec tunnels using class maps, policy maps, ip precedence, and group or crypto profiles, ensuring dedicated bandwidth and reliable delivery.

Requirements

  • Basic networking knowledge is needed

Description

In this course you will learn how to configure and manage Virtual Private Networks using all but GNS3. We will start from understanding basic concepts of VPNs such as packet exchange and configuring Site to Site VPNs. We will  then move on to advanced VPNs such as DMVPN, GETVPN and FLEXVPN. You can reach out to me with any questions while you go through this course. I commit to responding within 24-48 hours of the query.


Before you join:

*Verify audio quality from sample videos to validate if it works for you

*Verify the length of the videos to validate if it works for you


Please note: This is a recorded class with students. The audio quality at times may not be optimal. Although the feedback from most students is that it is bearable, I would request you to go through some of the videos before subscribing to be sure that it is going to work for you.


Happy Learning!

Who this course is for:

  • Beginners in Network Security