This class is not currently scheduled. Please see our SNAF Securing Networks with ASA Fundamentals course for equivalent content.
This comprehensive, extensively hands-on, 5-day Authorized Cisco course is designed to provide the Security Student (Security CCIE and/or CCSP Candidate), Technical CSO, Security Field Engineer, or Cisco Security Services Engineer, practical design, implementation and complete analysis of the ASA practices and components that have a large part in construction of the Cisco ‘Self-Defending Network” Solution. Experiencing the collective efforts of Cisco IOS devices, Out-of-Band Management Practices and a Heavy Focus on both the Basic and Advanced Elements of the Cisco ASA Product-line, commissioned into a ‘live’ enterprise network, each student will become intrinsically aware of how the ‘complete’ ASA solution is used to shield today’s networks against the ever-changing landscape of threats and attacks. You will also be primed to think like a hacker and be able to use many of the common methods used to compromise networks throughout the implementation of live and very realistic ASA business scenarios. As an Interface Exclusive, you will execute these advanced business scenarios using live hardware, servers and connectivity.
- Cisco Security Appliance Basics
- ASA version 8 Features Overview
- ASA Technology Semantics and Security Capabilities
- Navigation using the CLI and ASDM
- Initial Startup and Configuration of the ASA
- *ASDM File Management, Dynamic/Manual Upgrades and Hierarchical Archiving of Log Data
- *Implementation of the Out-of-Band Management Network for management of ASA/FWSM, IOS Devices, Cisco IPS, Cisco MARS, logging, authentication and network services architectures
- Collecting and Analyzing Real-Time ASDM Logs
- Configuring Access through the ASA
- Configuring Inside to Outside Traffic Flows
- Dynamic NAT and PAT, Identity NAT, Extensible NAT Combos, Static Translations
- Basic and Advanced Global Translations for NAT
- *Implementing Blended NAT and No NAT Control Scenarios based on Common Business Requirements
- *Advanced ASDM Object Naming Strategies for Object Control in Complex Environments
- Static Routes
- Configuring Outside to Inside Traffic Flows
- Advanced Static Translations, Port Redirection and NAT Scaling Techniques
- Basic Access Lists for Inbound Access
- Basic and Advanced Object Grouping
- *Configuring Advanced "Business-Class" Access through the ASA
- *Advanced Access-list Tricks Used by CCIEs in the Field
- *Using Identity NAT Exemptions and 'Dual-NAT' Options based on Uses of Common Real-Time Enterprise Applications Like OWA and Load Balanced Web Clusters
- *Delivering Dynamic Web Content by Properly Implementing Policy NAT, Content Delivery and Advanced Port Redirection Capabilities
- *Implementing TLS Proxy Options with SYN Cookies when Deploying Enterprise HTTPS Applications
- Configuring Inside to Outside Traffic Flows
- Advanced Security Appliance Operations
- Scaling the ASA Solution with Dynamic Routing, Redundant Interfaces and VLANs
- Advanced Static Routing for High-Availability and SLA Tracking
- Using Packet Tracer to Verify Optimal Data Flows Through the ASA
- Transparent Firewalls, Multiple Context Mode
- Securing Management and Service-level Access with AAA and Cut-through Proxy
- TACACS+ and RADIUS Operations
- *Complete Cisco ACS Server Implementation for Out-of-Band Management of ASA and IPS
- Advanced Protocol Inspection, Filtering and base Service Policy
- Protocol Options, Threat Detection and Malicious Protocol Filters
- Security Appliance High-Availability Solutions
- Transparent Firewalls, Multiple Context Mode, ASA Failover
- Security Appliance Maintenance, Logging and Tracing
- *Advanced management and naming practices when using the ASDM for ASA management
- Configuring secure Connectivity with VPNs on the ASA
- Configure and verify remote access VPNs using ASDM
- Configure and verify IPsec VPN clients with preshared keys using ASDM
- Configure and verify site-to-site VPNs with preshared keys using ASDM
- Verify IKE and IPsec using ASDM and CLI
- Configure and verify clientless SSL VPN using ASDM
- Configure and verify Client-based (AnyConnect) SSL VPNs using ASDM
- Configure end-point security posture with Cisco Secure Desktop
- Skills and knowledge equivalent to those learned in Interconnecting Cisco Networking Devices Part 1 (ICND1) and Interconnecting Cisco Networking Devices Part 2 (ICND2) or Attendance of the Interface CCNA220 course.
- IINS – Implementing IOS Network Security or SNRS – Securing Networks with Cisco Router and Switches are recommended but not required
- Working knowledge of the Windows operating system
- Working knowledge of Cisco IOS networking and concepts
- 6-12 months of practical working experience with access lists on Cisco IOS or PIX/ASA products
(Arrive early on Monday for Class Registration)
- Authorized Cisco SNAF courseware
- Interface CCNA Security Solutions Manual
- Interface CCNA Security Lab Evolutions Manual, Associated Diagrams, Tools DVDs
- Course Completion Certificate for Cisco SNAF


Call 1-800-264-9029