Back

Cisco CCNP Security (formerly known as CCSP) FIREWALL 642-617

Deploying Cisco ASA Firewall Solutions

Michael Shannon

CBT Nuggets Trainer

"I really enjoy the way that computers can bring people together, move information quickly and empower learning. I come from three generations of teachers. My great-grandmother had a huge influenc... Read more.

Since the firewall system is usually the first solution deployed by an organizations, anyone involved in security -- from a small- or home-office to a large enterprise -- will benefit from this course in a major way. And of course, by passing the 642-617 exam, you'll be on your way to achieving CCNP Security certification!

In this course, you'll learn all about the features of the ASA for protecting your security domains and the incredible Modular Policy Framework using the Adaptive Security Appliance Device manager (ASDM). You also learn and see different ASA appliances and modular solutions in action. Other cool topics include Layer 5-7 Inspection, Transparent Firewall and ASA High-Availability solutions.

Once you finish this Nugget series, you'll have the knowledge and skills required to deploy and maintain Cisco ASA-based perimeter solutions. And, you'll be equipped to protect your IT infrastructure and applications from risks using Cisco ASA features, as well as provide thorough operational support for the Cisco Adaptive Security Appliance.
  • Videos
  • Purchase Options
Title Duration
 
Introduction to FIREWALL
This inroductory Nugget walks you through the CCNP Security path from Cisco. You will learn all about the exam as well as the general topics covered. Finally, you will learn a winning strategy for getting the most out of this FIREWALL series to prepare you for real-world application as well as exam success.
00:14:45
 
ASA Technology and Features
Here you will discover the different firewall systems and how they can be applied to security domains (also called zones). You will explore various firewall technologies as well. The features of the Adaptive Security Appliance (ASA) will be investigated. You will finish will an assortment of real-world deployment scenarios.
00:32:09
 
Security Appliance Family
This Nugget offers a comprehensive look at the appliance family from Cisco Systems. You will learn about the ASA "front-to-back" as well as various modular solutions. No discussion would be complete without the tricky topis of licensing - so that is covered here as well. This one wraps up with a discussion of basic hardware troubleshooting.
00:21:40
 
Initial Setup and Configuration
In module 4 of the Firewall Series you finally get your "virtual" hands on the actual device. This Nugget is really one long demonstration on real equipment. Topics include the ASA boot process, built-in configurations, configuration modes, the ASA file system, initial ASA setup, and ASDM basics.
00:35:09
 
Interfaces and Static Routes
Yes! The ASA is actually a switch and a router appliance and here you will discover the Adaptive Security Algorithm security levels, interface configuration, VLAN configuration, static routing, and DHCP client and server functionality.
00:34:09
 
Configuring ASA Management
The Cisco Security Professional must master device management before the firewall is deployed. In this Nugget, you will learn the management options, configure basic management settings, discover NTP v2 and v3 along with NetFlow v5 and v9, tackle file system management, and learn about software and key activation.
00:34:03
 
Basic Access Control
Who will actually be accessing your ASA to manage it and from where will they do it? Let's discover remote access protocol channels, configure remote management, control ASA authentication, and perform password recovery on the appliance.
00:40:21
 
Modular Policy Framework
In this Nugget you will move up to the big leagues by getting away from old-school access control methods to the newer and more powerful Modular Policy Framework (MPF). Topics include access rules and object grouping, planning for MPF, configuring layer 3-4 policies, configuring layer 5-7 policies, and deploying traffic management policies with MPF.
00:42:01
 
Stateful Inspection
This module is actually MPF part two. We continue the look at traffic policy as well as tuning layer 3-4 inspection. You will discover some excellent advanced connection settings along with support for dynamic protocols. Finally you will explore troubleshooting your existing layer 3-4 application inspection.
00:29:21
 
Application Layer Policy
Here you will delve deeper into Deep Packet Inspection (DPI) otherwise known as Application Inspection and Control (AIC). Protocols include HTTP, FTP, DNS, ESMTP, and others.
00:29:55
 
Advanced Access Controls
Advanced topics in this Nugget include: TCP Intercept; Botnet Traffic Filter; and Basic, Advanced, and Scanning Threat Detection.
00:29:09
 
Resource Configuration
There is only a finite amount of resources on the ASA and it is very platform and license-specific. So, let's learn about resource limits and guarantees, TCP and UDP connection limits, QoS traffic policing, traffic shaping, and priority queueing.
00:22:12
 
User-Based Policies
There are some very clever ways to allow individual users to "cut-through" the firewall on an ad-hoc basis depending on the circumstances. Here you will learn about user authentication, prompts and timeouts, user authorization, user session accounting, and troubleshooting user-based policies.
00:38:24
 
NAT and PAT
No discussion of firewall systems would be complete without a look at our old friends NAT and PAT. This Nugget explores the special relationship between NAT and the ASA, NAT Control, Dynamic NAT and PAT, Static NAT and PAT, NAT Bypass techniques, and Outside NAT scenarios.
00:40:41
 
Transparent Firewall
Transparent Firewall is another way to deploy your ASA without causing too much disruption to existing network services and topology. After an overview of transparent mode you will configure a transparent firewall. Next, you will explore layer 3-4 access control and layer 2 access control on your ASA. Finally, you will troubleshoot your transparent mode ASA.
00:26:09
 
ASA Virtualization
Virtualization is certainly a hot topic lately. Not to be left out, the Cisco ASA provides virtualization in the form of additional Security Contexts. Once we define them we will configure them. Next, we will investigate security context management and then troubleshoot multicontext mode on the ASA.
00:32:38
 
Active-Standby Failover
High-availability is a mission-critical necessity for today's SMB and enterprise organizations. In this Nugget, you will first discover the power of redundant interfaces. Then, you will learn about the ASA Active/Standby Failover model. Next, you will see the configuration of an A/S failover solution on an appliance. Finally, you will explore some important troubleshooting commands.
00:29:19
 
Active-Active Failover
So, you say that Active/Standby Failover isn't robust enough for your enterprise? Well, let's try an Active/Active Failover on for size. Here you will learn A/A Failover in a nutshell, configure Active/Active Failover, tune your A/A solution, and look at some key troubleshooting concepts.
00:32:34
 
Security Services Modules
In this Nugget of the Firewall Series you will explore the Cisco Security Services Modules (SSM) including the AIP-SSM and AIP-SSC for Intrusion Prevention and the CSC-SSM for anti-x content security.
00:33:09
 
Firewall Exam Notes
This final Nugget wraps up the series with special notes for the exam-takers. Some valuable exam strategies are provided along with key exam tips.
00:29:48
Total Series Duration: 10 hours
Which option is right for you?
Buy a Single Series
"Focus your training on one series, for one month, for one low price."
StreamOne
StreamOne SUBSCRIPTION
StreamOne is your monthly option for streaming access to Cisco CCNP Security (formerly known as CCSP) FIREWALL 642-617. One multi-user license gives you and a small team access to one full series. Cancel at any time. A StreamOne subscription gives you plenty of time to explore the benefits of CBT Nuggets, while paying for just the specific series you want.
MULTI-USER
$199
per license
$499
EDM
Download
Download Cisco CCNP Security (formerly known as CCSP) FIREWALL 642-617.
$499
DVD
DVD
Have Cisco CCNP Security (formerly known as CCSP) FIREWALL 642-617 delivered on DVD.
 
Buy a Certification Package
"Secure your future with professional recognition via industry certification. Certification Packages give you the training you need to pass those certification exams."
Get Certified. Cisco, Microsoft, CompTIA and more.
Inclusive pricing. Package includes training videos and any relevant and available exam-prep.
Image
Certification Packages
Professional Recognition from Renowned IT Organizations
CBT Nuggets offers certification packages to help you achieve valuable professional recognition. Get the most popular certifications from Cisco, Microsoft and others. IT certification after training with CBT Nuggets will help you do a lot more than put letters after your name. Begin your path to a better job and a better future today!
  • Certification Package
    $649
    4 MONTHS STREAMING
    Add to Cart
    Cisco Firewall Security Specialist
    Can’t get enough Firewall training in your life? The CBT Nuggets Firewall Security Specialist certification package gives you the in depth firewall training you desire. With this Cisco certification package, get the training to continuously develop secure network solutions and provide many levels of access to networks. Cisco’s Firewall Secu... Learn more...
Buy an Annual Subscription to Everything IT
"Eliminate your limitations. An IT Nuggets streaming subscription puts our complete IT training library at the fingertips of IT pros."
All topics. From admin to programming.
Image
IT Nuggets
Productivity for Companies and IT Advancement for Professionals
Get access to better training, and never lose it, with an IT Nuggets subscription. IT Nuggets is a multi-user product that supports all levels of your IT department, even as employees come and go. One locked-in rate gets you access to our IT training catalog, which is updated regularly and automatically at no additional charge. As long as your subscription is maintained, the rate won't change, and neither will your budget. Our full IT library is designed for Pros to keep current for career advancement and companies that want their IT Pros to reach their full potential.
YEARLY
MULTI-USER
$1999
per license
Bookmarks

No Bookmarks