Networkers Home - Best Cisco Certification Training Institute in Bangalore, Delhi, India for CCIE Security, CCIE Voice, CCNA Training Courses  
  Home   About us   Cisco Certification   NH YouTube Channel   Blog   Contact us
devider BOOTCAMP SCHEDULE cisco certification Delhi cisco programs Delhi
 
   

Content on this page requires a newer version of Adobe Flash Player.

Get Adobe Flash player

CCIE Security and CCIE Voice Certification Training Programs from Networkers Home - Largest CCIE Security Institute in The World
ccie security boot camp Bangalore Financing your training need
 
  Home  | CCIE Security  
  Networkers Home Solution CCIE Security (3.0) Lab Preparation Boot Camp  
 
Networkers Home CCIE Security Instructor Led Boot Camp is designed for CCIE Security candidates ready for an intense seven day course designed to be challenged and immersed in the knowledge needed to attain to achieve the CCIE Security certification. Over seven lengthy days, your existing knowledge will be solidified, any weaknesses exposed and you will gain vital test-taking strategies.

In Networkers Home’s popular Boot Camp, you will receive many hours of in depth lecture for seven days from our world renowned instructors, who will provide detailed explanation and facilitate group discussion. You will also have access to individual attention from the Instructor when you need personal mentoring. After each day’s lectures, you will be challenged with many hours of extremely complex lab scenarios that run late into the evening, reinforcing the material you have covered earlier in the day. On day seven, you will be work through a difficult full-scale super lab that will put your ability to the test.

Throughout the course you will have unlimited access to your own personal rack of equipment matching the CCIE Security Lab blueprint. By immersing yourself in an environment without the distraction of work and personal obligations, you will maintain the undisrupted focus required to benefit from the volume of material concentrated into one week.
 
HIGHLIGHTS OF THE BOOT CAMP
The course length is seven days, Monday through Sunday
The course starts at 10 AM (boot camp location time) and typically runs for 10+ hours per day
The course is a combination of lecture, hands-on lab and unique mock labs
A completely unique proprietary lab workbook worth 500 USD included in the price
Participants get access to a dedicated vRack of complete Cisco CCIE equipment used in the Lab Exam
Extremely comfortable venue with modern presentation facilities
Help desk assistance to arrange Visa, accommodation, and other required facilities
Course labs & lectures have been written specifically for this intense boot camp
Course Outline
Implementing Secure Networks Using Cisco ASA Firewalls
Configuring and Troubleshooting Cisco ASA Firewalls
Initializing the Basic Cisco ASA Firewall (IP Address, Mask, Default Route, etc.)
Understanding Security Levels (Same Security Interface)
Understanding Single vs. Multimode
Understanding Firewall vs. Transparent Mode
Understanding Multiple Security Contexts
Understanding Shared Resources for Multiple Contexts
Understanding Packet Classification in Multiple-Contexts Mode
VLAN Subinterfaces Using 802.1Q Trunking
Multiple-Mode Firewall with Outside Access
Single-Mode Firewall Using the Same Security Level
Multiple-Mode, Transparent Firewall
Single-Mode, Transparent Firewall with NAT
ACLs in Transparent Firewall (for Pass-Through Traffic)
Understanding How Routing Behaves on the Adaptive Security Appliance (Egress and Next-Hop Selection Process)
Understanding Static vs. Dynamic Routing
Static Routes
RIP with Authentication
OSPF with Authentication
EIGRP with Authentication
Managing Multiple Routing Instances
Redistribution Between Protocols
Route Summarization
Route Filtering
Static Route Tracking Using an SLA
Dual ISP Support Using Static Route Tracking
Redundant Interface Pair
LAN-Based Active/Standby Failover (Routed Mode)
LAN-Based Active/Active Failover (Routed Mode)
LAN-Based Active/Standby Failover (Transparent Mode)
LAN-Based Active/Active Failover (Transparent Mode)
Stateful Failover Link
Device Access Management
Enabling Telnet
Enabling SSH
The nat-control Command vs. no nat-control Command
Enabling Address Translation (NAT, Global, and Static)
Dynamic NAT
Dynamic PAT
Static NAT
Static PAT
Policy NAT
Destination NAT
Bypassing NAT When NAT Control Is Enabled Using Identity NAT
Bypassing NAT When NAT Control Is Enabled Using NAT Exemption
Port Redirection Using NAT
Tuning Default Connection Limits and Timeouts
Basic Interface Access Lists and Access Group (Inbound and Outbound)
Time-Based Access Lists
ICMP Commands
Enabling Syslog and Parameters
NTP with Authentication
Object Groups (Network, Protocol, ICMP, and Services)
Nested Object Groups
URL Filtering
Java Filtering
ActiveX Filtering
ARP Inspection
Modular Policy Framework (MPF)
Application-Aware Inspection
Identifying Injected Errors in Troubleshooting Scenarios
Understanding and Interpreting Adaptive Security Appliance show and debug Outputs
Understanding and Interpreting the packet-tracer and capture Commands
 
Implementing Secure Networks Using Cisco IOS Firewalls
Configuring and Troubleshooting Cisco IOS Firewalls
Zone-Based Policy Firewall Using Multiple-Zone Scenarios
Transparent Cisco IOS Firewall (Layer 2)
Context-Based Access Control (CBAC)
Proxy Authentication (Auth Proxy)
Port-to-Application Mapping (PAM) Usage with ACLs
Use of PAM to Change System Default Ports
PAM Custom Ports for Specific Applications
Mapping Nonstandard Ports to Standard Applications
Performance Tuning
Tuning Half-Open Connections
Understanding and Interpreting the show ip port-map Commands
Understanding and Interpreting the show ip inspect Commands
Understanding and Interpreting the debug ip inspect Commands
Understanding and Interpreting the show zone|zone-pair Commands
Understanding and Interpreting the debug zone Commands
 
Implementing Secure Networks Using Cisco VPN Solutions
Configuring and Troubleshooting Cisco VPN Solutions
Understanding Cryptographic Protocols (ISAKMP, IKE, ESP, Authentication Header, CA)
IPsec VPN Architecture on Cisco IOS Software and Cisco ASA Security Appliance
Configuring VPNs Using ISAKMP Profiles
Configuring VPNs Using IPsec Profiles
GRE over IPsec Using IPsec Profiles
Router-to-Router Site-to-Site IPsec Using the Classical Command Set (Using Preshared Keys and Certificates)
Router-to-Router Site-to-Site IPsec Using the New VTI Command Set (Using Preshared Keys and Certificates)
Router-to-ASA Site-to-Site IPsec (Using Preshared Keys and Certificates)
Understanding DMVPN architecture (NHRP, mGRE, IPsec, Routing)
DMVPN Using NHRP and mGRE (Hub-and-Spoke)
DMVPN Using NHRP and mGRE (Full-Mesh)
DMVPN Through Firewalls and NAT Devices
Understanding GET VPN Architecture (GDOI, Key Server, Group Member, Header Preservation, Policy, Rekey, KEK, TEK, and COOP)
Implementing GET VPN (Using Preshared Keys and Certificates)
GET VPN Unicast Rekey
GET VPN Multicast Rekey
GET VPN Group Member Authorization List
GET VPN Key Server Redundancy
GET VPN Through Firewalls and NAT Devices
Integrating GET VPN with a DMVPN Solution
Basic VRF-Aware IPsec
Enabling the CA (PKI) Server (on the Router and Cisco ASA Security Appliance)
CA Enrollment Process on a Router Client
CA Enrollment Process on a Cisco ASA Security Appliance Client
CA Enrollment Process on a PC Client
Clientless SSL VPN (Cisco IOS WebVPN) on the Cisco ASA Security Appliance (URLs)
AnyConnect VPN Client on Cisco IOS Software
AnyConnect VPN Client on the Cisco ASA Security Appliance
Remote Access Using a Traditional Cisco VPN Client – on a Cisco IOS Router
Remote Access Using a Traditional Cisco VPN Client – on a Cisco ASA Security Appliance
Cisco Easy VPN – Router Server and Router Client (Using DVTI)
Cisco Easy VPN – Router Server and Router Client (Using Classical Style)
Cisco Easy VPN – Cisco ASA Server and Router Client
Cisco Easy VPN Remote Connection Modes (Client, Network, Network+)
Enabling Extended Authentication (XAUTH) on Cisco IOS Software and the Cisco ASA Security Appliance
Enabling Split Tunneling on Cisco IOS Software and the Cisco ASA Security Appliance
Enabling Reverse Route Injection (RRI) on Cisco IOS Software and the Cisco ASA Security Appliance
Enabling NAT-T on Cisco IOS Software and the Cisco ASA Security Appliance
High-Availability Stateful Failover for IPsec with Stateful Switchover (SSO) and Hot Standby Router Protocol (HSRP)
High Availability Using Link Resiliency (with Loopback Interface for Peering)
High Availability Using IPsec Backup Peers
High Availability Using GRE over IPsec (Dynamic Routing)
Basic QoS Features for VPN Traffic on Cisco IOS Software and the Cisco ASA Security Appliance
Identifying Injected Errors in Troubleshooting Scenarios (for Site-to-Site, DMVPN, GET VPN, and Cisco Easy VPN)
Understanding and Interpreting the show crypto Commands
Understanding and Interpreting the debug crypto Commands
 
Configuring Cisco IPS to Mitigate Network Threats
Configuring and Troubleshooting Cisco IPS
Understanding Cisco IPS System Architecture (System Design, MainApp, SensorApp, EventStore)
Understanding Cisco IPS User Roles (Administrator, Operator, Viewer, Service)
Understanding Cisco IPS Command Modes (Privileged, Global, Service, Multi-Instance)
Understanding Cisco IPS Interfaces (Command and Control, Sensing, Alternate TCP Reset)
Understanding Promiscuous (IDS) vs. Inline (IPS) Monitoring
Initialization Basic Sensor (IP Address, Mask, Default Route, etc.)
Troubleshooting Basic Connectivity Issues
Managing Sensor ACLs
Allowing Services Ping and Telnet from/to Cisco IPS
Enabling Physical Interfaces
Promiscuous Mode
Inline Interface Mode
Inline VLAN Pair Mode
VLAN Group Mode
Inline Bypass Mode
Interface Notifications
Understanding the Analysis Engine
Creating Multiple Security Policies and Applying Them to Individual Virtual Sensors
Understanding and Configuring Virtual Sensors (vs0, vs1)
Assigning Interfaces to the Virtual Sensor
Understanding and Configuring Event Action Rules (rules0, rules1)
Understanding and Configuring Signatures (sig0, sig1)
Adding Signatures to Multiple Virtual Sensors
Understanding and Configuring Anomaly Detection (ad0, ad1)
Using the Cisco IDM (IPS Device Manager)
Using Cisco IDM Event Monitoring
Displaying Events Triggered Using the Cisco IPS Console
Troubleshooting Events Not Triggering
Displaying and Capturing Live Traffic on the Cisco IPS Console (Packet Display and Packet Capture)
SPAN and RSPAN
Rate Limiting
Configuring Event Action Variables
Target Value Ratings
Event Action Overrides
Event Action Filters
Configuring General Settings
General Signature Parameters
Alert Frequency
Alert Severity
Event Counter
Signature Fidelity Rating
Signature Status
Assigning Actions to Signatures
AIC Signatures
IP Fragment Reassembly
TCP Stream Reassembly
IP Logging
Configuring SNMP
Signature Tuning (Severity Levels, Throttle Parameters, Event Actions)
Creating Custom Signatures (Using the CLI and Cisco IDM)
Understanding Various Types of Signature Engines
Understanding Various Types of Signature Variables
Understanding Various Types of Event Actions
Understanding New Cisco IPS 6.0 Features (e.g., Deny Packets for High-Risk Events by Default)
Creating a Custom String TCP Signature
Creating a Custom Flood Engine Signature
Creating a Custom AIC MIME-Type Engine Signature
Creating a Custom Service HTTP Signature
Creating a Custom Service FTP Signature
Creating a Custom ATOMIC.ARP Engine Signature
Creating a Custom ATOMIC.IP Engine Signature
Creating a Custom TCP Sweep Signature
Creating a Custom ICMP Sweep Signature
Creating a Custom Trojan Engine Signature
Enabling Shunning and Blocking (Enabling Blocking Properties)
Shunning on a Router
Shunning on the Cisco ASA Security Appliance
Enabling the TCP Reset Function
Cisco IOS IPS on a Router Using Version 5.x Format Signatures
Loading a Version 5.x Signature File onto the Router
Understanding the Signature Engines for Cisco IOS IPS
Transparent Cisco IOS IPS
 
Implementing Identity Management
Configuring and Troubleshooting Identity Management
Understanding the AAA Framework
Understanding the RADIUS Protocol
Understanding RADIUS Attributes (Cisco AV-PAIRS)
Understanding the TACACS+ Protocol
Understanding TACACS+ Attributes
Comparison of RADIUS and TACACS+
Configuring Basic LDAP Support
Overview of Cisco Secure ACS
How to Navigate Cisco Secure ACS
Cisco Secure ACS – Network Settings Parameters
Cisco Secure ACS – User Settings Parameters
Cisco Secure ACS – Group Settings Parameters
Cisco Secure ACS – Shared Profiles Components (802.1X, NAF, NAR, Command Author, Downloadable ACL, etc.)
Cisco Secure ACS – Shell Command Authorization Sets Using Both Per-Group Setup and Shared Profiles
Cisco Secure ACS – System Configuration Parameters
Cisco Secure ACS – Posture Validation Policies for NAC Setup
Cisco Secure ACS – Using Network Access Profiles (NAPs)
Cisco Secure ACS – MAC Authentication Bypass (MAB) Using NAP
Enabling AAA on a Router for vty Lines
Enabling AAA on a Switch for vty Lines
Enabling AAA on a Router for HTTP
Enabling AAA on the Cisco ASA Security Appliance for Telnet and SSH Protocols
Using Default vs. Named Method Lists
Complex Command Authorization and Privilege Levels, and Relevant Cisco Secure ACS Profiles
Proxy Service Authentication and Authorization on the Cisco ASA Security Appliance for Pass-Through Traffic (FTP, Telnet, and HTTP), and Relevant Cisco Secure ACS Profiles
Using Virtual Telnet on the Cisco ASA Security Appliance
Using Virtual HTTP on the Cisco ASA Security Appliance
Downloadable ACLs
AAA 802.1X Authentication Using RADIUS on a Switch
NAC-L2-802.1X on a Switch
NAC-L2-IP on a Switch
Troubleshooting Failed AAA Authentication or Authorization
Troubleshooting Using Cisco Secure ACS Logs
Using the test aaa Command on the Router, Switch, or Cisco ASA Security Appliance
Understanding and Interpreting the debug radius Command
Understanding and Interpreting the debug tacacs+ Command
Understanding and Interpreting the debug aaa authentication Command
Understanding and Interpreting the debug aaa authorization Command
Understanding and Interpreting the debug aaa accounting Command
Implementing Control Plane and Management Plane Security Configuring and Troubleshooting Router Traffic Plane Security
Understanding Four Types of Traffic Planes on a Cisco Router (Control, Management, Data, and Services)
Understanding Control Plane Security Technologies and Core Concepts Covering Security Features Available to Protect the Control Plane
Understanding Management Plane Security Technologies and Core Concepts Covering Security Features Available to Protect the Management Plane
Configuring Control Plane Policing (CoPP)
Control Plane Rate Limiting
Disabling Unused Control Plane Services (IP Source Routing, Proxy ARP, Gratuitous ARP, etc.)
Disabling Unused Management Plane Services (Finger, BOOTP, DHCP, Cisco Discovery Protocol, etc.)
MPP (Management Plane Protection) and Understanding OOB (Out-of-Band) Management Interfaces
Configuring Protocol Authentication
Route Filtering and Protocol-Specific Filters
ICMP Techniques to Reduce the Risk of ICMP-Related DoS Attacks (IP Unreachable, IP Redirect, IP Mask Reply, etc.)
Selective Packet Discard (SPD)
MQC and FPM Types of Service Policy on the CoPP Interface
Broadcast Control on a Switch
Catalyst Switch Port Security
Cisco IOS Software-Based CPU Protection Mechanisms (Options Drop, Logging Interval, CPU Threshold)
The Generalized TTL Security Mechanism Known as “BGP TTL Security Hack” (BTSH)
Device Access Control (vty ACL, HTTP ACL, SSH Access, Privilege Levels)
SNMP Security
System Banners
Secure Cisco IOS File Systems
Understanding and Enabling Syslog
NTP with Authentication
Role-Based CLI Views and Cisco Secure ACS Setup
Service Authentication on Cisco IOS Software (FTP, Telnet, HTTP)
Network Telemetry Identification and Classification of Security Events (IP Traffic Flow, NetFlow, SNMP, Syslog, RMON)
 
Configuring Advanced Security
Configuring and Troubleshooting Advanced Security Features
Implementing RFC 1918 Antispoofing Filtering
Implementing RFC 2827 Antispoofing Filtering
Implementing RFC 2401 Antispoofing Filtering
Marking Packets Using DSCP and IP Precedence and Other Values
Unicast RPF (uRPF) With or Without an ACL (Strict and Loose Mode)
RTBH Filtering (Remote Triggered Black Hole)
Basic Traffic Filtering Using Access Lists: SYN Flags, Established, etc. (Named vs. Numbered ACLs)
Managing Time-Based Access Lists
Enabling NAT and PAT on a Router
Conditional NAT on a Router
Multihome NAT on a Router
Enabling a TCP Intercept on a Router
Enabling a TCP Intercept on the Cisco ASA Security Appliance
FPM (Flexible Packet Matching) and Protocol Header Definition File (PHDF) Files and Configuration of Nested Policy Maps
CAR Rate Limiting with Traffic Classification Using ACLs
PBR (Policy-Based Routing) and Use of Route Maps
Advanced MQC (Modular QoS CLI) on a Router
Advanced Modular Policy Framework (MPF) on the Cisco ASA Security Appliance
Classification Using NBAR
Understanding and Enabling NetFlow on a Router
Traffic Policing on a Router
Port Security on a Switch
Storm Control on a Switch
Private VLAN (PVLAN) on a Switch
Port Blocking on a Switch
Port ACL on a Switch
MAC ACL on a Switch
VLAN ACL on a Switch
Spanning Tree Protocol (STP) Protection Using BPDU Guard and Loop Guard on a Switch
DHCP Snooping on a Switch
IP Source Guard on a Switch
Dynamic ARP Inspection (DAI) on a Switch
Disabling DTP on All Nontrunking Access Ports
 
Identifying and Mitigating Network Attacks
Configuring and Troubleshooting Network Attacks
Note: This section uses the same products and technologies discussed in all the previous sections above particularly the “Configuring Advanced Security” section, but with greater focus and emphasis on reactive measures and attack mitigation
Concept of Proactive vs. Reactive Measures
Knowledge of Protocols: TCP, UDP, HTTP, SMTP, ICMP, FTP
Knowledge of Common Attacks: Network Reconnaissance, IP Spoofing, DHCP Snooping, DNS Spoofing, MAC Spoofing, ARP Snooping, Fragment Attack, Smurf Attack, TCP SYN Attack
Understanding and Interpreting ARP Header Structure
Understanding and Interpreting IP Header Structure
Understanding and Interpreting TCP Header Structure
Understanding and Interpreting UDP Header Structure
Understanding and Interpreting HTTP Header Structure
Understanding and Interpreting ICMP Header structure
Understanding and Interpreting ICMP Type Name and Codes
Understanding and Interpreting Syslog Messages
Understanding and Interpreting Packet Capture Outputs (Sniffer, Ethereal, Wireshark, TCPDump)
Understanding Different Types of Attack Vectors
Interpreting Various show and debug Outputs
Traffic Characterization
Packet Classification
Packet-Marking Techniques
Classifying Attack Patterns Using FPM
Memorizing Common Protocol and Port Numbers
Preventing an ICMP Attack Using ACLs
Preventing an ICMP Attack Using NBAR
Preventing an ICMP Attack Using Policing
Preventing an ICMP Attack Using the Modular Policy Framework (MPF) on the Cisco ASA Security Appliance
Preventing a SYN Attack Using ACLs
Preventing a SYN Attack Using NBAR
Preventing a SYN Attack Using Policing
Preventing a SYN Attack Using CBAC
Preventing a SYN Attack Using CAR
Preventing a SYN Attack Using a TCP Intercept
Preventing a SYN Attack Using the Modular Policy Framework (MPF) on the Cisco ASA Security Appliance
Preventing Application Protocol–Specific Attacks Using FPM (e.g., HTTP, SMTP)
Preventing Application Protocol–Specific Attacks Using NBAR (e.g., HTTP, SMTP)
Preventing Application Protocol–Specific Attacks Using the Modular Policy Framework (MPF) on the Cisco ASA Security Appliance (e.g., HTTP, SMTP)
Preventing IP Spoofing Attacks Using Antispoofing ACLs
Preventing IP Spoofing Attacks Using uRPF
Preventing IP Spoofing Attacks Using IP Source Guard
Preventing Fragment Attacks Using ACLs
Preventing MAC Spoofing Attacks Using Port Security
Preventing ARP Spoofing Attacks Using DAI
Preventing VLAN Hopping Attacks Using the switchport mode access Command
Preventing STP Attacks Using the Root Guard or BPDU Guard
Preventing DHCP Spoofing Attacks Using Port Security
Preventing DHCP Spoofing Attacks Using DAI
Preventing Port Redirection Attacks Using ACLs
 
 
    E-Mail This Page   Add This Page    
 
 
 
NH Programs
  Cisco Programs
  CCIE Programs
 
 
ccie security boot camp Delhi
 
 
ccie security boot camp training
 
 
 
 
 
 
 
About NH
About Us
Vision & Mission
Management Team
Technical Team
Contact Us
Blog
Sitemap
Training offered
For Indian Students
For Foreign Students
Bootcamps
Bootcamp Tips
Support
Why Networkers Home
Advantage India
CISCO Exams
CCIE Exams
Careers
FAQ
Enquiry
New Delhi Janakpuri : +91- 99710 77882
+91 (11) 40531905 / 6 / 7
Bangalore : +91 (80) 32025523
  +91 (80) 49014701 / 2 / 3 / 4
info@networkershome.com
© 2009, Networkers Home - All rights reserved.
Powered by Bangalore VFX