Cisco Training - HD TelePresence // S-VPN

Deploying Cisco ASA VPN Solutions v1.0

Remote access and site-to-site VPN features to reduce risk to IT infrastructure and its applications

Course Description

The Deploying Cisco ASA VPN Solutions (VPN) 1.0 course is an instructor-led course that is presented by Cisco Learning Partners to their end-user customers. This five-day course aims at choosing, configuring, and troubleshooting the majority of Cisco ASA adaptive security appliance remote access and site-to-site VPN features to reduce risk to IT infrastructure and its applications.

Audience

This course is designed for Network Security Engineers and anyone with their CCNA Security Certification and/or working towards CCNP Security Certification.

Prerequisites

​Before taking this course, students should have working knowledge of the Microsoft Windows operating system and successfully completed the following courses:
 
IINS: CCNA Security - Implementing Network Security with IOS Devices 
SECURE: Securing Networks with Cisco Routers and Switches

What You Will Learn

After completing this course, you will be able to:
  • Evaluate the Cisco ASA adaptive security appliance VPN subsystem
  • Deploy Cisco ASA adaptive security appliance IPsec VPN solutions
  • Deploy Cisco ASA adaptive security appliance Cisco AnyConnect remote access VPN solutions
  • Deploy Cisco ASA adaptive security appliance clientless remote access VPN solutions
  • Deploy advanced Cisco ASA adaptive security appliance VPN solutions​

Course Outline

1. Evaluation of the Cisco ASA Adaptive Security Appliance VPN Subsystem
Evaluating the Cisco ASA Adaptive Security Appliance Software Architecture
  • Cisco ASA Adaptive Security Appliance Access Control Model Refresher
  • Cisco ASA Adaptive Security Appliance Packet Routing Refresher
  • Cisco ASA Adaptive Security Appliance NAT Refresher
  • Cisco ASA Adaptive Security Appliance AAA Refresher
Evaluating the Cisco ASA Adaptive Security Appliance VPN Subsystem Architecture
  • PKI Technology
  • Comparison of Cisco ASA Adaptive Security Appliance VPN Technologies
  • VPN Termination on Cisco ASA Adaptive Security Appliance Network Interfaces
  • Packet Flow in Cisco ASA Adaptive Security Appliance VPN Functions
  • Cisco ASA Adaptive Security Appliance VPN Access Control Model
  • Cisco ASA Adaptive Security Appliance VPN Licensing
Applying Common Cisco ASA Adaptive Security Appliance Remote Access VPN Configuration Concepts
  • Cisco ASA Adaptive Security Appliance VPN Policy Configuration
  • Connection Profiles
  • Group Policies
  • External Policy Storage

2. Deployment of Cisco ASA Adaptive Security Appliance IPsec VPN Solutions
Deploying Basic Site-to-Site IPsec VPNs
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Configuring Basic Peer Authentication
  • Configuring Transmission Protection
  • Troubleshooting a Cisco ASA Adaptive Security Appliance Site-to-Site VPN
Deploying Certificate Authentication in Site-to-Site IPsec VPNs
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying Certificate-Based Authentication
  • Configuring PKI-Based Peer Authentication
Deploying the Cisco VPN Client
  • Evaluating Cisco VPN Client Features
  • Installing Cisco VPN Client Software
  • Configuring Cisco VPN Client Profiles
  • Configuring Advanced Profile Settings
Deploying Basic Cisco Easy VPN Solutions
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Configuring Basic Cisco ASA Adaptive Security Appliance Cisco Easy VPN Server Features
  • Configuring Group PSK Authentication
  • Configuring Extended User Authentication
  • Configuring Client Network Settings
  • Configuring Basic Access Control and Split Tunneling
  • Configuring the Cisco VPN Client
  • Troubleshooting Basic Cisco Easy VPN Operation
Deploying Advanced Authentication in Cisco Easy VPN Solutions
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying Cisco VPN Client Certificate Authentication
  • Configuring Hybrid Authentication
  • Deploying Advanced PKI Integration
  • Troubleshooting PKI Integration
Deploying the Cisco ASA 5505 Adaptive Security Appliance as Cisco Easy VPN Remote
  • Choosing Cisco Easy VPN Remote Modes
  • Deploying a Basic Cisco Easy VPN Remote Profile
  • Configuring Advanced Cisco Easy VPN Remote Features
  • Troubleshooting the Cisco Easy VPN Remote
  
3. Deployment of Cisco ASA Adaptive Security Appliance Cisco AnyConnect Remote Access VPN Solutions
Deploying a Basic Cisco AnyConnect Full Tunnel SSL VPN Solution
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Configuring Basic Cisco ASA Adaptive Security Appliance SSL VPN Gateway Features
  • Configuring Local Password-Based User Authentication
  • Configuring Client IP Address Management, Basic Access Control, and Split Tunneling
  • Installing and Configuring the Cisco AnyConnect Client
  • Troubleshooting Basic Full Tunnel SSL VPN Operation
Deploying Advanced Cisco AnyConnect VPN Client
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying DTLS
  • Managing Cisco AnyConnect Software
  • Configuring Cisco AnyConnect Client Profiles
  • Deploying Advanced Cisco AnyConnect Operating System Integration Options
  • Customizing the Cisco AnyConnect User Interface
Deploying Advanced Authentication in Cisco AnyConnect Full Tunnel SSL VPNs
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying External AAA Authentication
  • Deploying Certificate-Based Client Authentication Using the Cisco ASA Adaptive Security Appliance Local CA
  • Deploying Advanced PKI Integration
  • Deploying Multiple Client Authentication
4. Deployment of Cisco ASA Adaptive Security Appliance Clientless Remote Access VPN Solutions
Deploying a Basic Clientless VPN Solution
  • Configuration Choices, Basic Procedure, and Required Input Parameters
  • Configuring Basic Cisco ASA Adaptive Security Appliance SSL VPN Gateway Features
  • Configuring Local Password-Based User Authentication
  • Configuring Basic Portal Features and Access Control
  • Troubleshooting Clientless SSL VPNs
Lesson 2: Deploying Advanced Application Access for Clientless SSL VPN
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Configuring Application Plug-Ins
  • Configuring Smart Tunnels
  • Configuring Port Forwarding
  • Troubleshooting Advanced Application Access
3. Deploying Advanced Authentication and SSO in a Clientless SSL VPN
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying Client Certificate-Based Authentication
  • Deploying Advanced Gateway PKI Integration, External Certificate Authorization, and Double Authentication
  • Troubleshooting PKI Integration
  • Deploying Clientless SSL VPN SSO
Customizing the Clientless SSL VPN User Interface and Portal
  • Deploying Basic Navigation Customization
  • Deploying Full Portal Customization
  • Deploying Portal Localization
  • Deploying Portal Help Customization
  • Cisco AnyConnect Portal Integration
5. Deployment of Advanced Cisco ASA Adaptive Security Appliance VPN Solutions
Deploying VPN Authorization, Access Control, and Accounting
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying Local Authorization
  • Deploying External Authorization
  • Configuring Session Accounting
  • Troubleshooting Authorization and Accounting of a Clientless SSL VPN
Deploying Cisco Secure Desktop in SSL VPNs
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Installing, Enabling, and Customizing Cisco Secure Desktop
  • Configuring Prelogin Criteria
  • Configuring Prelogin Policies
  • Configuring Advanced Endpoint Assessment
  • Troubleshooting Cisco Secure Desktop Operation for Clientless Connections
Deploying Dynamic Access Policies
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Configuring DAP
  • Aggregating DAP Records
  • Integrating Cisco Secure Desktop with DAP
  • Using LUA Expressions in Dynamic Access Policies
  • Troubleshoot DAP
Deploying High Availability and High Performance in SSL and IPsec VPNs
  • Configuration Choices, Basic Procedures, and Required Input Parameters
  • Deploying Redundant Peering
  • Deploying Cisco ASA Adaptive Security Appliance Active/Standby Failover
  • Deploying Dynamic-Routing-Based VPN Failover
  • Deploying Cisco ASA Adaptive Security Appliance VPN Clustering
  • Deploying High Availability and High Performance Using Network Server Load Balancing
  • Deploying VPN QoS
  • Troubleshooting Cisco ASA Adaptive Security Appliance VPN Failover and Clustering