|
安全分解试验分为六大部分-VPN、ASA/PIX、IOS安全、AAA+ACS和IPS和攻击防御.
进度流程:
VPN技术
六种VPN技术原理(LAN-to-LAN VPN、Remote Access VPN、DMVPN、L2TP、PPTP、WebVPN)、VPN的各种配置(包括VPN3000、PIX、ASA、Router)以及各种技术之间的区别等
PIX/ASA firewall的特性:
流量过滤(ACL、filter技术)和控制技术(NAT、QoS、application layer Inspection)、虚拟防火墙的原理和实现、transparent firewall、ARP审查、高级object groups ACL 、Cut-though Proxy、高级AAA(PIX/ASA和IOS实现的细微区别)、IDS和VPN(PIX/ASA和IOS实现的细微区别)、Failover(Active/Active和Active/Standby)、管理维护技术等。 VPN3000 的特性:
VPN 3000 Pre-Shared Keys 建立远程访问联机 、数字凭证(Digital Certificates)建立远程访问、VPN IPSec 软件客户端、VPN IPSec 硬件客户端、Cisco VPN 3000 在远程访问网络上的监测与控管 、Cisco VPN 3000 在LAN-to-LAN、数字凭证(Digital Certificates)建立LAN-to-LAN、 web VPN 技术、VPN网络上的两件监测与控管维护技术等。
IDS/IPS的特性:
入侵侦测系统(IDS)Sensor的配置、SPAN/RSPAN 技术、Cisco IDS Device Manager 和Event Viewer 的管理、attack signature 调整和自定义、报警响应方式reset和shun的调正、IDS自我保护技术、设备的联动技术(Block) Router/Switch IOS 安全特性:
AAA、高级访问控制列表、CBAC(IOS防火墙)、TCP拦截、路由协议的安全、攻击缓解技术(CAR、NBAR、black hole等)、ACS身份管理、认证代理、RADIUS and TACACS+ 、802.1X、DHCP Snooping、设备的管理安全等。
网络攻击
各种2层/3层的网络攻击的实现与防护,如:IP欺骗、ARP欺骗、DOS、DDOS、中间人攻击、DHCP攻击、碎片攻击、Smurf攻击等等;
老师会在学员每步试验做完后,针对难点向学员提出问题;通过提问的手段启发学员的主动思考能力和学习思维,从而提高试验质量,保证学员的进度含金量。
集训营机架设备清单
Cisco pix 515E(4以太口) x 2
Cisco ASA 5510(4以太口) x 1
Cisco vpn3000 x 2
Cisco IPS x 2
Cisco test_PC(IEV、Cisco VPN client 4.7)
CA server
Cisco ACS 4.1
Cisco 3640 x 4
Cisco 2600 x 18
Cisco Frame-relay switching (4700)
另有分解实验设备数套。
集训培训内容大纲
- Firewall
- PIX / ASA Firewall
- Basic Initialization
- Access Management
- Address Translation
- ACLs
- IP Routing
- Object Groups
- VLANs
- AAA
- VPNs
- Filtering
- Failover
- Layer 2 Transparent Firewall
- Security Contexts (Virtual Firewall)
- Modular Policy Framework
- Application-Aware Inspection
- High Availability Scenarios
- QoS Policies
- Other Advanced Features
- IOS Firewall
- CBAC
- Audit
- Auth Proxy
- PAM
- Access Control
- Performance Tuning
- Advanced Features
- VPN
- IPSec LAN-to-LAN
- SSL VPN
- DMVPN
- CA (PKI)
- Remote Access VPN
- VPN3000 Concentrator
- VPN3000 IP Routing
- Unity Client
- WebVPN
- EzVPN Hardware Client
- XAuth, Split-tunnel, RRI, NAT-T
- High Availability
- QoS for VPN
- GRE, mGRE
- L2TP
- PPTP
- Advanced VPN Features
- Intrusion Prevention System (IDS/IPS)
- IDS/IPS 4200 Series Sensor Appliance
- Basic Initialization
- Sensor Configuration
- Sensor Management
- Promiscuous and Inline Monitoring
- Signature Tuning
- Custom Signatures
- Blocking
- TCP Resets
- Rate Limiting
- Signature Engines
- IDM
- Event Action
- Event Monitoring
- IOS IPS
- PIX IDS
- SPAN, RSPAN
- Advanced Features
Identity Management
- Security Protocols (RADIUS and TACACS+)
- Cisco Secure ACS Configuration
- Access Management (Telnet, SSH, Pwds, Priv Levels)
- Proxy Authentication
- Service Authentication (FTP, Telnet, HTTP, other)
- Network Admission Control (NAC Framework solution)
- 802.1x
- Advanced Features
- Advanced Security
- Mitigation Techniques
- Packet Marking Techniques
- Security RFCs (RFC1918, RFC2827, RFC2401)
- Service Provider Security
- Black Holes, Sink Holes
- RTBH Filtering (Remote Triggered Black Hole)
- Traffic Filtering using Access-lists
- NAT
- TCP Intercept
- URPF
- CAR
- NBAR
- NetFlow
- Flooding
- Spoofing
- Policing
- Fragmentation
- Sniffer Traces
- Catalyst Management and Security
- Traffic Control and Congestion Management
- Catalyst Features and Advanced Configuration
- IOS Security Features
- Network Attacks
- Network Reconnaissance
- IP Spoofing Attacks
- MAC Spoofing Attacks
- ARP Spoofing Attacks
- Denial of Service (DoS)
- Distributed Denial of Service (DDoS)
- Man-in-the-Middle (MiM) Attacks
- Port Redirection Attacks
- DHCP Attacks
- DNS Attacks
- Fragment Attacks
- Smurf Attacks
- SYN Attacks
- MAC Attacks
- VLAN Hopping Attacks
- Other Layer2 and Layer3 Attacks
|