Saturday, 7 March 2009

Cisco CCNA Security 640-553 Training by TrainSignal


In as Little as 13 Hours, You'll Learn How To Identify, Lockdown, & Secure Vulnerabilities in a Small to Medium Enterprise Branch Network...And Have the Knowledge Necessary to Pass the Cisco CCNA Security/IINS 640-553 Exam...Guaranteed!

A Letter From Chris Bryant
CCIE #12933, CCNA, CCNP

You cannot be a Cisco Network Administrator without knowing Cisco Security. Today, security knowledge is no longer a luxury, it is a necessity in nearly any IT position.

Any job applicant, from the most experienced network admin to the entry level junior admin will be required to demonstrate a substantial amount of knowledge concerning security elements.

Passing the CCNA Security exam and proving your security knowledge is difficult. That's why I have created this comprehensive course that shows you how to tackle the diverse security issues that you will face on the exam and in the real world.

As with all Train Signal courses, this CCNA Security course presents the same combination of clearly explained theory and an abundance of "real world" lab examples using the new Security Device Manager (SDM) and the Command Line. This exciting course contains over 13 hours of video instruction where I break down network security theory as you work hands on with real Cisco routers & switches... and secure your own network!
Cisco CCNA Security Training Course FAQs
"Am I qualified to take this course?"

YES! If you are a network administrator, an aspiring network administrator, or have on-the-job security experience, this course will build a stronger foundation of advanced security concepts.

YES! If you have Cisco CCNA Certification or a basic understanding of Cisco Routers and Switches (without certification), this course is for you.

Note: The prerequisite to take the Cisco CCNA Security exam is Cisco CCNA certification.

Note: If you plan to continue on to the CCSP certification, the Cisco CCNA Security certification is the prerequisite.
"Do I need Cisco equipment to complete this training course?"

NO You do not need any Cisco equipment to watch the videos or to pass the Cisco CCNA Security/IINS 640-553 exam; however, working hands-on with Cisco equipment may enhance your training experience.
"I already have my CCNA. Do I need my Cisco CCNA Security certification?"

YES! The ability to secure a Cisco network is one of the most marketable skills for any Cisco professional and network security has never been more important.

Cisco CCNA Security Course Outline
"Everyone has a different method/style of learning best.
If learning via self-paced method, then I would highly recommend Train Signal’s Cisco CCNA materials..."
- Marlon Deerr, Train Signal Student


Introduction - Welcome to Your CCNA Security Video Course!

Meet your instructor Chris Bryant and get started right way with exam preparation tips.

* About Your Instructor
* Exam Prep Tips
Video 1
Hackers – Their Motives and Methods

Learn about Hacker Roles and why they hack. Discover what your Network Security Goals should be, and how to implement Network Security Best Practices to achieve those goals to keep from suffering the consequences of ineffective network security.

* Why Do Hackers Hack?
* General Network Security Goals
* The Consequences of Ineffective Network Security
* Where Network Attacks Originate From
* Social Engineering Attacks
* Trojan Horses and Privilege Escalation Attacks
* Using Ping Sweeps and Port Scans on Your Own Network
* Best Practices
Video 2
Introduction to SDM (Security Device Manager)

Improve productivity, simplify router deployments, and troubleshoot complex connectivity issues using the Security Device Manager. Plus, launch, login, and tour SDM and discover some Real World SDM issues as you learn to manage your router away from the Command Line.

* Cisco's Security Device Manager (SDM)
* Pre-installation Configuration
* Installing SDM
* Launching and Loading SDM
* SDM Settings - User Preferences
* SDM Configure Window
* Additional Tasks Tab
* SDM Monitor Window
* SDM in Internet Explorer Problem
Video 3
Authentication, Authorization, and Accounting (AAA)

Learn how Authentication works in AAA, what happens when you specify different devices used for Authentication, and discover commands used in Authentication, Authorization, and Accounting that will be useful in the real world and on the exam. Plus, configure TACAS+ and RADIUS security protocols.

* What is AAA?
* TACAS+ vs. RADIUS
* TACAS+ and RADIUS Configuration
* Authentication Configuration
* No Authentication Option
* Telnet Login Problem
* Real World Not About AAA Lists
* Using AAA for Privileged EXEC Mode and PPP
* Accounting
* Authorization
* Configuring AAA with SDM
Video 4
Layer 2 Security

Learn how to prevent security threats like CAM Overflow attacks by configuring and implementing Port Security, Sticky Addresses, Lightweight Extensible Authentication Protocol (LEAP), and SPAN. Plus, discover the relationship between DHCP Snooping, Dynamic ARP Inspection, and IP Source Guard and learn to configure and operate Root Guard and BPDU Guard.

* Basic L2 Security Features
* Cisco Password Rules Review
* Preventing CAM Overflow Attacks with Port Security
* Port Security
* Configuring Port Security
* Misconfiguring Port Security
* Aging Time for Secure Addresses
* Sticky Addresses
* Configuring MAC Table Event Notification
* Dot1x Port-Based Authentication
* Cisco Lightweight Extensible Authentication Protocol (LEAP)
* Extensible Authentiaction Protocol-Flexible Authentication via Secure Tunneling (EAP-FAST)
* Local SPAN Configuration
* Remote SPAN Configuration
* Filtering Intra-VLAN Traffic
* VLAN Access List (VACL)
* Private VLAN
* DHCP Snooping
* Dynamic ARP Inspection
* IP Source Guard
* MAC Address Flooding Attacks
* VLAN Hopping
* Root Guard
* BPDU Guard
Video 5
Layer 3 Security

This is one of the most important videos in the course because of the volume of detailed information that you will use on the exam and in the real world. Learn about "Salting" your MD5 to make an encrypted password even stronger and discover how Network Time Protocol (NTP) will be important in your security deployment. Plus, learn to configure and use Superviews, Autosecure, Security Audits, and One-Step Lockdown via SDM to thwart ICMP based attacks, IP Spoofing, and Recon Attacks.

* Configuring Enable Password
* Privileged Level Password vs. Privleged Level Secret
* Encrypting Passwords
* Strong Passwords vs. Weak Passwords
* Creating and Testing Minimum Length Password Policy
* ”Salting” your MD5
* Network Time Protocol (NTP)
* Configuring NTP Master Time Source
* Synchronizing System Clocks
* Configuring Peering with NTP Peers Command
* Other Clock Commands
* Telnet and SSH
* Creating Banners
* Different Types of Network Attacks
* Denial of Services (DoS) Attack and SYN Flooding Attack
* TCP Intercept Defense
* ICMP (Ping) Sweep, Port Scan and Port Sweep
* Ping of Death vs. Invite of Death and Ping Floods
* Smurf Attacks
* Availability Attacks: Don't Forget the Physical Layer!
* IP Spoofing
* IP Source Routing
* Packet Sniffers and Queries
* Other Confidentiality Attacks
* Password Attacks
* Salami Attack
* Other Network Attacks Types - Trust Exploitation
* Superviews - Role-Based CLI Views
* AutoSecure
* One-Step Lockdown
* Security Audit
* NTP and SSH in SDM
* Differences Between SDM and AutoSecure
* SNMP
* Logging
* Viruses and Worms
* Cisco IOS Logging Enhancements
* Buffer Overflow
* Cisco IOS Resilient Conofiguration and Login Enhancements
* exec-timeout Command
Video 6
The Intrusion Prevention System (IPS)

Learn the differences between Intrusion Detection (IDS) and Intrusion Prevention (IPS) and how they operate. Plus, discover the different approaches to identifying malicious traffic and learn to use NIPS, HIPS and Honeypots to stop it. We'll also configure your Intrusion Prevention System using the Security Device Manager (SDM) and we'll use the Command Line to verify this IPS configuration.

* Intrusion Detection (IDS) vs. Intrusion Prevention (IPS)
* Signatures and Signature Types
* NIPS and HIPS
* Honeypots
* Configuring IPS in SDM
* Editing IPS Rules
* Editing Global Settings
* SDEE Message Logs
* Viewing Signatures
* Editing and Deleting Signatures
* Verifying Your IPS Configuration
Video 7
Firewalls

Learn to enable a Cisco router to act as a firewall using the Cisco IOS Firewall Set. Plus, discover concepts relatively new to Cisco like Zone-based Firewalls that are meant to phase out CBAC and the “ip inspect” command. We'll also configure and edit a firewall using the Security Device Manager's (SDM) Basic Firewall Wizard and we'll draw distinctions between the Basic Firewall Wizard and SDM's Advanced Firewall Wizard.

* Firewall Basics
* Stateless and Stateful Firewalls
* Application Layer Gateway (ALG)
* The Cisco IOS Firewall Feature Set Components
* Authentication Proxy
* Plan for Firewall Success Then Succeed!
* ACL Review
* Extended ACL Review
* Extended Access Control Lists
* Real-World ACL Success Tips
* Introduction to Turbo ACLs
* CBAC and “ip inspect” command
* Real-World Tips and Best Practices
* TCP and UDP Generic Inspection
* Deep Pocket Inspection (DPI)
* Zone-Based Firewall Configuration
* Class Maps and Policy Maps
* Basic Zone Commands
* Configuring Zone Pairs
* Configuring Firewall with SDM's Basic Firewall Wizard
* Editing Firewall with SDM
* SDM's Advanced Firewall Wizard
* Watch Your Directions - More Tips
* ICMP Inspection
* Final Note
Video 8
Cryptography and Virtual Private Networks (VPNs)

Learn how Asymetric and Symetric Algorithms can be used to implement Cryptography Techniques that help encrypt clear text passwords. Plus, configure your own IKE policy using the Command Line and get your hands dirty by using the Security Device Manager (SDM) to configure Site-to-Site VPN and Generic Routing Encapsulation (GRE) over IPsec.

* Cryptography Techniques
* Asymmetric and Symmetric Algorithms
* RSA Algorithm
* Diffie-Hellman (DH)
* A Word or Two About SHA
* What is VPN?
* VPN Terminology and Theory
* Introduction to PKI and the Certificate of Authority
* Public Key Cryptography Standards (PKCS)
* Internet Key Exchange (IKE)
* Steps to Configure Site-to-Site VPN
* Configuring IKE Policy Using Command Line
* Policy Match Criteria
* Crypto ACLs
* Mirror Configuration
* Creating Crypto Map
* Using SDM to Configure Site-to-Site VPN
* Generating Mirror in SDM
* Testing Our Configuration
* Verifying SDM Configuration Using Command Line
* The Return of Generic Routing Encapsulation (GRE) Over IPSec
* Using SDM to Configure GRE over IPSec
Video 9
Introduction to Voice and SAN Security

You do not need to be an expert in Voice Networking or Storage Area Networking (SAN) to learn how to keep these types of networks secure. Learn the differences between FCAP and FCPAP, discover the details of LUN and LUN Masking, and delve deeper into VoIP (Voice Over IP). Whatever your experience level may be, this detailed overview of Voice and SAN Networking will provide you the insight you need to get into one of the fastest growing areas in the IT field.

* Voice Over IP Overview
* Gateways and Gatekeepers
* VoIP Protocols
* Typical VoIP Attacks and Precautions
* Introduction to Storage Area Networking (SAN)
* SAN Transport Technologies and Protocols
* SAN Security - LUNS and LUN Masking
* SAN Zones
* Virtual SANs (VSANs)
* FCAP and FCPAP
Video 10
Introduction to Cisco Network Solutions

This video will introduce you to Cisco Network Solutions including: ASA 5500, Cisco Self-Defending Network, Cisco Security Management Suite, and Cisco Security Agent. Plus, learn about the five phases of the Cisco SDLC (System Development Life Cycle) and discover the differences between Quantitative Risk Analysis and Qualitative Risk Analysis.

* System Development Life Cycle
* Cisco SDLC Phase 1 - Initiation
* Cisco SDLC Phase 2 - Acquisition and Development
* Cisco SDLC Phase 3 - Implementation
* Cisco SDLC Phase 4 - Operation and Maintenance
* Cisco SDLC Final Phase - Disposition
* Disaster Recover - Hot, Warm and Cold Sites
* Risk Analysis - Quantitative and Qualitative
* Cisco Self-Defending Network
* Cisco Security Management Suite
* IronPort
* Cisco Security Agent
* Cisco Security Agent Interceptors
* Cisco ACS
* “in-band” and “out of band”

Sunday, 11 January 2009

Cisco IOS images to use with GNS3






The original cisco IOS image files of routers, switches, and firewalls, which can be used to create a network with gns3 and get the feel of working with real router. for more information for how to use and install visit gns3

once it is installed all you need is the ios files which are original cisco ios here to work on without setting up a costly lab for ccna, ccnp, ccsp, ccvp, ccie.


Network Security Fundamentals






Product Description:

An introduction to the key tools and technologies used to secure network access

* Examine common security vulnerabilities and the defenses used to protect network resources
* Learn about cryptography, including modern-day techniques like 3DES, RSA, hashing, and the use of certificates
* Learn how to design, adopt, and enforce security policies
* Evaluate the nuances of secure network design
* Secure HTTP traffic by hardening operating systems, servers, and browsers
* Protect routers through administrative access policies and services
* Understand what firewalls do and how to implement them to maximum effect
* Inspect and monitor network activity with IDS
* Utilize VPNs for secure remote access
* Learn about PKI technologies
* Examine secure wireless design techniques
* Use logging and auditing tools, such as syslog, SNMP, RMON, and SAA, to manage network traffic

Companies have long been struggling with threats from the hacking community. Keeping pace with the rapid evolution of security technology and the growing complexity of threats is a challenge even in the best of times. The increased focus on security has sent IT managers and engineers scrambling to acquire the proper expertise to implement complex, multilayered solutions.

Network Security Fundamentals introduces the topic of network security in an easy-to-understand and comprehensive manner. This book is designed to provide a fundamental understanding of the various components of a network security architecture and to demonstrate how each component can be implemented to achieve best results. The book uses straightforward language to introduce topics and to show the features, mechanics, and functionality of various network security devices. A series of case studies helps illuminate concepts and shows how you can apply the concepts to solve real-world problems.

Divided into four parts, Network Security Fundamentals takes you on a tour of all the essential technologies and modern defenses at your disposal to help you maintain network uptime and data integrity. Part I covers the basics, introducing terms and concepts and laying the foundation of a solid security structure. The discussion focuses on weaknesses and vulnerabilities along with an overview of the traditional defenses used to thwart attacks. Part II examines two components of security-cryptography and security policies. Part III looks at the various security components. Separate chapters cover web security, router security, firewalls, intrusion detection systems (IDS), remote access security, virtual private networks (VPN), Public Key Infrastructure (PKI), wireless security, and logging and auditing. Each chapter in this section is a self-contained tutorial, allowing you to skip to those topics of greatest interest or primary concern. Part IV includes several reference appendixes, including the Cisco SAFE Blueprint, NSA guidelines, and SANS policies.

Whether you are looking for an introduction to network security principles and practices or a security configuration reference, this book provides you with the invaluable insight you need to protect valuable company resources.



Saturday, 10 January 2009

CiscoPress CCNA Security IINS 640-553



CCNA Security Official Exam Certification Guide is a best of breed Cisco® exam study guide that focuses specifically on the objectives for the CCNA® Security IINS exam. Senior security instructors Michael Watkins and Kevin Wallace share preparation hints and test-taking tips, helping you identify areas of weakness and improve both your conceptual knowledge and hands-on skills. Material is presented in a concise manner, focusing on increasing your understanding and retention of exam topics.

CCNA Security Certification meets the needs of IT professionals who are responsible for network security. It confirms an individual's skills for job roles such as Network Security Specialists, Security Administrators, and Network Security Support Engineers. This certification validates skills including installation, troubleshooting and monitoring of network devices to maintain integrity, confidentiality and availability of data and devices and develops competency in the technologies that Cisco uses in its security structure.

Students completing the recommended Cisco training will gain an introduction to core security technologies as well as how to develop security policies and mitigate risks. IT organizations that employ CCNA Security-holders will have IT staff that can develop a security infrastructure, recognize threats and vulnerabilities to networks, and mitigate security threats.

The official study guide helps you master all the topics on the IINS exam, including
Network security threats
-Security policies
-Network perimeter defense
-AAA configuration
-Router security
-Switch security
-Endpoint security
-SAN security
-VoIP security
-IOS firewalls
-Cisco IOS® IPS
-Cryptography
-Digital signatures
-PKI and asymmetric encryption
-IPsec VPNs










CCNA Security 640-553 IINS CBT Nuggets



Are you an IT Pro responsible for network security? Do you have CCNA certification and want to take the next step in network security? Are you working towards CCSP certification? If any of these are you, this is the training you’re looking for.

Jump into security with Jeremy Cioara’s Cisco CCNA Security video series. Jeremy puts you in the mind of hackers and intruders and shows you how to defeat these black hats. Soon you’ll be recognizing different types of attackers and threats and eliminating the damage that can follows security breaches.

You’ll learn all about your security enemies --whether they’re hackers, phreakers, hacktivists, hobby hackers or script kiddies. And you’ll learn how these bad guys:

  • Investigate your network
  • Identify and target your operating system and applications
  • Break into your system
  • Steal logins, user names and passwords
  • Create network backdoors so they can mount future attacks

Cisco Security gives you lots of great tools for discovering and defeating attackers. Self-Defending Network (SDN) helps you automatically identify threats, both internal and external. MARS (Monitoring Analysis & Response System) analyzes threats and identifies false alarms. In fact, Cisco Security provides you with tons of network protection, but doesn’t bury you with security alerts.

Jeremy’s videos move from one "cool topic" to the next -- showing you the big picture involved in securing your network. By the time you’ve finished watching the full series, you’ll have a terrific foundation in Cisco security. And you’ll be respected for the confidentiality, integrity and availability that you bring to your organization’s network data.

This training is mapped to Cisco CCNA Security exam 640-533 IINS, so you’ll be ready to pass the certification test.

By the time you're done you'll thoroughly understand the following topics about Cisco CCNA Security Exam-Pack 640-553: IINS Series:

  • Welcome to CCNA Security: Cisco Certification and Getting the Most from This Series
  • Welcome to CCNA Security: Understanding the Threats
  • Welcome to CCNA Security: Understanding the Threats, Part 2
  • Foundation Router Security: Using SDM to Lock Down Your Router
  • Foundation Router Security: Implementing Secure Router Management
  • Foundation Router Security: Understanding and Implementing AAA
  • Foundation Router Security: Using IOS-based Tools for Administrative Access
  • Foundation Router Security: Becoming an ACL Wizard
  • Foundation Switch Security: Locking Down the Catalyst Switch
  • Foundation Switch Security: Locking Down the Catalyst Switch, Part 2
  • Foundation Switch Security: Understanding NAC, Cisco CSA. and VoIP Security
  • Security Services: Implementing Router-Based Firewalls
  • Security Services: Implementing Router-Based Firewalls, Part 2
  • Security Services: Implementing Router-Based IPS
  • Security Services: Understanding VPN Components - IPSec and Encryption
  • Security Services: Understanding VPN Components - Digital Signatures and PKI
  • Security Services: Understanding VPN Architecture
  • Security Services: Implementing Site-to-Site VPNs via Command Line
  • Security Services: Implementing Site-to-Site VPNs via SDM
  • A Final Word to CCNA Security Test Takers

Prerequisite
CCNA certification

Here's what you'll learn in each video of the Cisco CCNA Security - Exam-Pack 640-553: IINS Series:

Video 1 - "Welcome to CCNA Security: Cisco Certification and Getting the Most from This Series" - With every new program, there is typically an included "Read Me First" text file. In the same sense, consider this nugget the "Watch Me First" of the series. This nugget presents the strategies you can use for getting the most from the series, changes to the Cisco certification program, and the ideal CCNA Security lab environment.

Video 2 - "Welcome to CCNA Security: Understanding the Threats" - It's impossible to defend against something you don't understand. In this nugget, Jeremy defines the goal behind having a secure network and the categories of intruders and attacks.

Video 3 - "Welcome to CCNA Security: Understanding the Threats, Part 2" - Jeremy continues defining the properties of a secure network by discussing many of the network attacks you can face and a general mitigation strategy. In addition, Jeremy discusses the components behind the Cisco Self-Defending Network system.

Video 4 - "Foundation Router Security: Using SDM to Lock Down Your Router" - The Cisco Security Device Manager (SDM) is a powerful graphic interface you can use to manage your router and perform complex tasks with the click of a mouse button. This nugget walks through the process of configuring your router to support Cisco SDM and using the SDM to perform a security audit or one-step lockdown of your device.

Video 5 - "Foundation Router Security: Implementing Secure Router Management" - One of the first areas of security you should consider is the management traffic between you and the network devices. In this nugget, Jeremy describes creating an Out Of Band (OOB) management network and three areas of network management: syslog, SNMP, and SSH.

Video 6 - "Foundation Router Security: Understanding and Implementing AAA" - AAA is more than just roadside assistance; it represents authentication, authorization, and accounting (AAA) methods you can use on a Cisco device. This nugget describes the concepts behind AAA and walks through the setup of a AAA device and the Cisco ACS TACACS+ server.

Video 7 - "Foundation Router Security: Using IOS-based Tools for Administrative Access" - While server security is essential, network security is of the utmost importance. One of the first network areas requiring more security is the area of administrative access. By default Cisco switches and routers will allow someone to attempt to logon to the device infinitely. This nugget focuses on locking down this logon prompt, configuring role-based access (sub-administrators), and securing the IOS and configuration files on your devices.

Video 8 - "Foundation Router Security: Becoming an ACL Wizard" - Understanding the implementation of Access Control Lists (ACLs) is critical for any Cisco environment, however, you can apply ACLs in more ways than one. In this nugget, Jeremy walks through guidelines for using ACLs followed by four practical scenarios of ACL implementation.

Video 9 - "Foundation Switch Security: Locking Down the Catalyst Switch" - In this nugget, all eyes turn to the internal network as Jeremy discusses Layer 2 security for your network. This initial nugget explores the reasons for L2 security, common attacks at L2, and concludes with one of the core mitigation techniques: port security.

Video 10 - "Foundation Switch Security: Locking Down the Catalyst Switch, Part 2" - Layer 2 security continues as Jeremy builds multiple layers of security at the switch level including Spanning Tree Protocol (STP) protection, Rogue DHCP server control, Storm Control, SPAN, and Private VLANs.

Video 11 - "Foundation Switch Security: Understanding NAC, Cisco CSA and VoIP Security" - The evolution of network attacks have dictated an entire new generation of Layer 2 security methods. In this nugget, Jeremy discusses these newer forms of security such as Network Admission Control (NAC), 802.1x, the Cisco Security Agent (CSA), and VoIP security.

Video 12 - "Security Services: Implementing Router-Based Firewalls" - The security focus moves from the switch environment to the routed network. This initial nugget discusses Cisco's two firewall strategies: The Cisco IOS Classic Firewall and the Zone-based Firewall.

Video 13 - "Security Services: Implementing Router-Based Firewalls, Part 2" - Cisco's Zone-based Firewall strategy is a completely new style of firewall for IOS routers. This nugget walks through the implementation of the new Zone-based Firewall on live Cisco gear.

Video 14 - "Security Services: Implementing Router-Based IPS" - The Cisco Integrated Service Router (ISR) product line was designed to implement many traditionally separate network functions into a single device. This made the implementation of Intrusion Prevention System (IPS) a natural one. In this nugget, Jeremy discusses the place and configuration of Cisco IPS on an ISR device.

Video 15 - "Security Services: Understanding VPN Components - IPSec and Encryption Virtual Private Networks" - (VPNs) have become a commonplace technology to allow remote users to access a network and bridge multiple offices connected to the Internet into a seamless network fabric. The architecture behind VPN technology is anything but commonplace. In this nugget, Jeremy discusses the IP Security (IPSec) protocol used to create VPN connections, focusing specifically on the encryption capabilities.

Video 16 - "Security Services: Understanding VPN Components - Digital Signatures and PKI" - The VPN discussion continues as Jeremy explains the ideas behind the Public Key Infrastructure (PKI) and certificate-based authentication.

Video 17 - "Security Services: Understanding VPN Architecture" - This final, conceptual nugget on VPN technology focuses on the process devices go through when establishing a VPN connection. Special attention is given to the important concepts of identifying interesting traffic and the Internet Key Exchange (IKE) phases.

Video 18 - "Security Services: Implementing Site-to-Site VPNs via Command Line" - It's time to put the VPN concepts into action! In this nugget, Jeremy walks through the step-by-step process to configure a site-to-site VPN using the command line interface.

Video 19 - "Security Services: Implementing Site-to-Site VPNs via SDM" - Once you have seen the command-line configuration of a site-to-site VPN, this nugget shows you the "easy configuration method" by setting up the same VPN using the Cisco Security Device Manager (SDM) graphic interface.

Video 20 - "A Final Word to CCNA Security Test Takers" - To conclude the CCNA Security series, Jeremy gives some final tips to those focused on the certification exam.