SNAA

Securing Networks with ASA Advance v1.0

You are in: Home > Cisco > Courses > Current Page

Course Content

Securing Networks with ASA Advanced (SNAA) v1.0 is a new five-day course to replace the Cisco Secure Virtual Private networks (CSVPN) & Securing Networks with PIX and ASA (SNPA) courses. Recommended training for the Cisco Certified Security Professional (CCSP) certification, SNAA takes over where SNAF leaves off, covering advanced topics of Adaptive Security. In order to cover new features in ASA software version 8.0 and to fully cover the VPN features of the ASA, the content of SNPA was split into two courses, one that covers the fundamentals and one that covers more advanced topics. The SNAA 1.0 course takes a task-oriented approach to teaching the skills to deploy, configure and administer the Cisco ASA using a fictional company's deployment of an ASA which is based on real world scenarios. We have added depth to the existing Cisco-developed hands-on labs for SNAA. Our advanced hands-on labs, delivered in an enhanced topology designed to simulate a typical production network, guide you through exercises such as managing digital certificates for IPSec and SSL VPNs, deep packet inspection, and using the 5505 in the SOHO environment. Our labs utilize ASA 5520 security appliances, though this course and lab content is applicable across the ASA and PIX families of security appliances, since the command syntax is generally the same.

Course Objectives

After completing this course the student should be able to:

  • Use advanced NAT features such as policy-based NAT
  • Use advanced modular policy framework for deep packet inspection of application protocols such as HTTP and FTP
  • How the multimedia protocols are handled and configured by the modular policy framework of the security appliance at Layer 3, 4, and 7
  • Configure the security appliance to segment traffic with VLANs
  • Configure dynamic routing capabilities of the appliance
  • Configure the security appliance to route multicast traffic
  • Use advanced IPSec VPN technologies such as peer authentication using digital certificates
  • Steps necessary to configure the ASA as a CA Server
  • Configure the IPSec VPN Client using digital certificates
  • Configure the advanced Easy VPN Server features of the ASA
  • Necessary configuration for the ASA 5505 to be a VPN hardware client
  • Steps to configure QoS for VPN traffic
  • SSL VPN features and capabilities of the security appliance
  • Enable clientless SSL VPNs with the security appliance
  • Enable AnyConnect SSL VPN Client with the security appliance
  • Enable the Cisco Secure Desktop with the security appliance to increase the security posture of SSL VPN connections
  • Enable Dynamic Access Policy with the Cisco Secure Desktop
  • Understand characteristics of the services modules for the ASA

Prerequisites

Course Outline

The course includes these topics:

Advanced ASA NAT Configuration

  • ACLs, NAT 0, Policy NAT

Advanced Protocol Handling

  • Modular Policy Framework
  • Protocol Application Inspection
  • Multimedia Protocol Handling

Dynamic Routing and Switching

  • VLANs
  • Dynamic Routing
  • Multicast

VPNs with IPSec

  • IPSec and Digital Certificates
  • ASA CA Server
  • LAN-to-LAN with Digital Certificates
  • IPSec VPN Client
  • Remote Access with Digital Certificates
  • Advanced Remote Access Features
  • ASA 5505 as a Hardware Client
  • VPN QoS

Security Services Modules

  • ASA Services Modules
  • Content Security and Control
  • Advanced Inspection and Prevention

Course Details

Duration: 5 days
Time: 9:00 am - 5:00 pm
Fee: $3,295 USD
CLCs: 33

Upcoming Classes

No classes scheduled.

» View Entire Schedule
» Additional Information

Delivery Locations

Denver, CO
Remote Class

Reston, VA
Chicago, IL
Sunnyvale, CA
The Americas
New York, NY

Redeem Cisco Learning Credits

Copyright 2009 Advanced Network Information. All rights reserved. Terms & Conditions | Privacy | ANI Training