𝔖 Scriptorium
✦   LIBER   ✦

πŸ“

Ccsp Cisco Secure VPN Exam Certification Guide (Ccsp Self-Study) [With CDROM]

✍ Scribed by Roland, John;Newcomb, Mark


Publisher
Cisco Press
Year
2003
Tongue
English
Leaves
593
Series
CCSP Self-Study
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Official self-study test preparation guide for the Cisco 9E0-121 and 642-511 CSVPN examsCoverage of the CSVPN topics enables you to identify and fill your knowledge gaps before the exam date. You'll learn about: Configuring Cisco VPN 3000 concentrators and VPN 3002 Hardware Clients for remote access Enabling secure VPNs using IPSec technologies Peer authentication using preshared keys and digital certificates Using Network Address Translation (NAT) and Port Address Translation (PAT) over VPNs Administering and monitoring VPN concentrators in remote-access and LAN-to-LAN networks Utilizing IPSec protocols and features Configuring VPN Client personal firewall support through the VPN concentrator Integrated unit and interactive user authentication through the Cisco VPN 3002 Hardware ClientBecoming a CCSP distinguishes you as part of an exclusive group of experts, ready to take on today's most challenging security tasks. Installation and configuration of Cisco VPN 3000 Series concentrators and Cisco VPN 3002 Hardware Clients are critical tasks in today's network environments, especially as reliance on the public Internet as an extension of business networks increases. Whether you are seeking a Cisco VPN Specialist Certification or the full-fledged CCSP Certification, learning what you need to know to pass the CSVPN (Cisco Secure Virtual Private Networks) exam qualifies you to keep your company's network safe while meeting its business needs."CCSP Cisco Secure VPN Exam Certification Guide" is a comprehensive study tool that enables you to master the concepts and technologies required for success on the CSVPN exam. Each chapter of the "CCSP Cisco Secure VPN Exam Certification Guide" tests your knowledge of the exam subjects through sections that detail exam topics to master and areas that highlight essential subjects for quick reference and review. Challenging chapter-ending review questions and exercises test your knowledge of the subject matter, reinforce key concepts, and provide you with the opportunity to apply what you've learned in the chapter. In addition, a final chapter of scenarios pulls together concepts from all the chapters to ensure you can apply your knowledge in a real-world environment. The companion CD-ROM testing engine enables you to take practice exams that mimic the real testing environment, focus on particular topic areas, and refer to the electronic text for review.This book is part of a recommended learning path from Cisco Systems that can include simulation and hands-on training from authorized Cisco Learning Partners and self-study products from Cisco Press. To find out more about instructor-led training, e-learning, and hands-on instruction offered by authorized Cisco Learning Partners worldwide, please visitwww.cisco.com/go/authorizedtraining.Companion CD-ROMThis companion CD-ROM contains a test bank with more than 200 practice exam questions.

✦ Table of Contents


Cover......Page 1
Contents......Page 9
Introduction......Page 18
Chapter 1 All About the Cisco Certified Security Professional......Page 26
Overview of CCSP Certification and Required Exams......Page 28
The Cisco Secure VPN Exam......Page 29
Topics on the Cisco Secure VPN Exam......Page 31
Recommended Training Path for the CCSP Certification......Page 33
Final Exam Preparation Tips......Page 34
How to Best Use This Chapter......Page 38
"Do I Know This Already?" Quiz......Page 39
Typical VPN Applications......Page 44
Using Cisco VPN Products......Page 49
An Overview of IPSec Protocols......Page 59
The IPSec Protocols......Page 62
Security Associations......Page 69
Existing Protocols Used in the IPSec Process......Page 70
Combining Protocols into Transform Sets......Page 77
Establishing VPNs with IPSec......Page 80
Step 1: Interesting Traffic Triggers IPSec Process......Page 82
Step 4: Allow Secured Communications......Page 84
Step 5: Terminate VPN......Page 85
Table of Protocols Used with IPSec......Page 86
Creating VPNs with IPSec......Page 88
How to Best Use This Chapter......Page 102
"Do I Know This Already?" Quiz......Page 103
Major Advantages of Cisco VPN 3000 Series Concentrators......Page 108
Performance and Scalability......Page 110
Security......Page 113
Management Interface......Page 117
Ease of Upgrades......Page 122
Cisco Secure VPN Concentrators: Comparison and Features......Page 123
Cisco VPN 3005 Concentrator......Page 124
Cisco VPN 3015 Concentrator......Page 125
Cisco VPN 3030 Concentrator......Page 126
Cisco VPN 3080 Concentrator......Page 127
Cisco VPN 3000 Concentrator Series LED Indicators......Page 128
Cisco VPN 3002 Hardware Client......Page 131
Cisco VPN Client......Page 132
Table of Cisco VPN 3000 Concentrators......Page 134
Table of Cisco VPN 3000 Concentrator Capabilities......Page 135
How to Best Use This Chapter......Page 148
"Do I Know This Already?" Quiz......Page 149
Unique Preshared Keys......Page 155
Wildcard Preshared Keys......Page 156
VPN Concentrator Configuration......Page 157
Cisco VPN 3000 Concentrator Configuration Requirements......Page 158
Cisco VPN 3000 Concentrator Initial Configuration......Page 159
Configuring IPSec with Preshared Keys Through the VPN 3000 Concentrator Series Manager......Page 175
Advanced Configuration of the VPN Concentrator......Page 192
Overview of the VPN Client......Page 197
VPN Client Features......Page 198
VPN Client Installation......Page 200
VPN Client Configuration......Page 204
VPN 3000 Concentrator CLI Quick Configuration Steps......Page 209
VPN Client Installation Steps......Page 210
VPN Client Program Options......Page 211
Complete Configuration Table of Contents......Page 212
Complete Administration Table of Contents......Page 215
Complete Monitoring Table of Contents......Page 216
Scenario 4-1......Page 230
Scenario 4-2......Page 231
Scenario 4-1 Answers......Page 233
Scenario 4-2 Answers......Page 234
Chapter 5 Configuring Cisco VPN 3000 for Remote Access Using Digital Certificates......Page 238
How to Best Use This Chapter......Page 239
"Do I Know This Already?" Quiz......Page 240
The CA Architecture......Page 244
Simple Certificate Enrollment Process Authentication Methods......Page 251
CA Vendors and Products that Support Cisco VPN Products......Page 254
Certificate Generation and Enrollment......Page 255
Certificate Revocation Lists......Page 260
IKE Configuration......Page 262
Configuring the VPN Client for CA Support......Page 264
X.509 Identity Certificate Fields......Page 268
Certificate Validation and Authentication Process......Page 269
Certificate Management Applications......Page 270
Scenario 5-2......Page 278
Scenario 5-1 Answers......Page 279
Scenario 5-2 Answers......Page 280
How to Best Use This Chapter......Page 282
"Do I Know This Already?" Quiz......Page 283
Cisco VPN Client Firewall Feature Overview......Page 288
The Stateful Firewall (Always On) Feature......Page 290
Configuring Firewall Filter Rules......Page 292
Protocol and TCP Connection......Page 296
TCP/UDP Source and Destination Ports......Page 297
Configuring the Stateful Firewall......Page 299
Configuring the VPN Concentrator for Firewall Usage......Page 300
Firewall Setting......Page 301
Custom Firewall......Page 302
Firewall Policy......Page 303
Monitoring VPN Client Firewall Statistics......Page 304
Enabling Automatic Client Update Through the Cisco VPN 3000 Concentrator Series Manager......Page 306
Cisco VPN Client Firewall Feature Overview......Page 308
Stateful Firewall (Always On) Feature......Page 310
Configuring Firewall Filter Rules......Page 311
Action......Page 312
Configuring the VPN Concentrator for Firewall Usage......Page 313
Monitoring VPN Client Firewall Statistics......Page 314
Scenario 6-1 Answers......Page 322
How Best to Use This Chapter......Page 326
"Do I Know This Already?" Quiz......Page 327
Administering the Cisco VPN 3000 Series Concentrator......Page 330
Software Update......Page 333
System Reboot......Page 336
Monitoring Refresh......Page 338
Access Rights......Page 339
File Management......Page 345
Certificate Manager......Page 346
Monitoring the Cisco VPN 3000 Series Concentrator......Page 347
Event Log Screen......Page 349
System Status......Page 350
Sessions......Page 351
Statistics......Page 353
Administering the Cisco VPN 3000 Series Concentrator......Page 361
Administer Sessions......Page 363
Software Update......Page 364
Clients......Page 365
System Reboot......Page 366
Monitoring Refresh......Page 367
Administrators......Page 368
Access Control List......Page 369
Certificate Manager......Page 370
Monitoring the Cisco VPN 3000 Series Concentrator......Page 371
Sessions......Page 372
Top Ten Lists......Page 373
Statistics......Page 374
MIB II Statistics......Page 375
Chapter 8 Configuring Cisco 3002 Hardware Client for Remote Access......Page 382
How to Best Use This Chapter......Page 383
Do I Know This Already? Quiz......Page 384
Configure Preshared Keys......Page 389
Verify IKE and IPSec Configuration......Page 391
Setting debug Levels......Page 392
Configuring VPN 3002 Hardware Client and LAN Extension Modes......Page 394
Split Tunneling......Page 397
Unit and User Authentication for the VPN 3002 Hardware Client......Page 398
Configuring the Head-End VPN Concentrator......Page 399
Configuring Unit and User Authentication......Page 403
Interactive Hardware Client and Individual User Authentication......Page 404
Troubleshooting IPSec......Page 409
Split Tunnel......Page 410
Configuring Individual User Authentication on the VPN 3000 Concentrator......Page 411
Scenario 8-1......Page 418
Scenario 8-2......Page 419
Scenario 8-2 Answers......Page 420
How to Best Use This Chapter......Page 422
"Do I Know This Already?" Quiz......Page 423
Setting Up the VPN Concentrator Using RIPv2......Page 430
Setting Up the VPN Concentrator Using OSPF......Page 431
Configuring VPN 3002 Hardware Client Reverse Route Injection......Page 432
VPN 3002 Hardware Client Backup Servers......Page 435
VPN 3002 Hardware Client Load Balancing......Page 437
Overview of Port Address Translation......Page 439
IPSec Over TCP/IP......Page 441
UDP NAT Transparent IPSec (IPSec Over UDP)......Page 442
Troubleshooting a VPN 3002 Hardware Client IPSec Connection......Page 443
Configuring Auto-Update for the VPN 3002 Hardware Client......Page 446
Monitoring Auto-Update Events......Page 449
Backup Servers......Page 452
IPSec Over TCP/IP......Page 453
Auto-Update......Page 454
Scenario 9-1......Page 463
Scenario 9-1 Answers......Page 464
Chapter 10 Cisco VPN 3000 LAN-to-LAN with Preshared Keys......Page 466
How to Best Use This Chapter......Page 467
"Do I Know This Already?" Quiz......Page 468
Configuring Network Lists......Page 472
Creating a Tunnel with the LAN-to-LAN Wizard......Page 474
Certificate Management......Page 477
Root Certificate Installation via SCEP......Page 478
Enrollment Variables......Page 487
Example Corporation......Page 496
Memphis......Page 497
IKE Policy......Page 498
Scenario 11-4β€”Memphis......Page 499
Scenario 11-6β€”Terry and Carol......Page 500
IKE Policy......Page 501
Detroit VPN 3030 Concentrator and Router (Generic for All)......Page 502
Detroit VPN 3030 Concentrator for Portland......Page 503
Portland VPN 3002 Hardware Client......Page 504
Seattle VPN 3002 Hardware Client......Page 505
Memphis VPN 3005 Concentrator and Router......Page 506
Scenario 11-6 Answers......Page 507
Detroit VPN 3030 Concentrator for Carol and Similar Users......Page 508
Carol VPN Client and Browser......Page 509
Appendix A: Answers to the "Do I Know This Already?" Quizzes and Q&A Sections......Page 512
B......Page 574
C......Page 575
D......Page 577
F......Page 578
I......Page 579
M......Page 580
R......Page 581
S......Page 582
U......Page 583
V......Page 584
W-Z......Page 585


πŸ“œ SIMILAR VOLUMES


CCSP SECUR exam certification guide: CCS
✍ Bastien, Greg;Degu, Christian πŸ“‚ Library πŸ“… 2005;2006 πŸ› Cisco Press 🌐 English

Official self-study test preparation guide for the Cisco SNRS exam 642-502Attack threatsRouter management and administrationAuthentication, Authorization, and Accounting (AAA) and Cisco Secure Access Control ServerRADIUS and TACACS+Cisco IOS(R) Firewall feature setSecuring networks with Cisco router

CCSP Cisco Secure VPN exam certification
✍ John Roland, Mark Newcomb πŸ“‚ Library πŸ“… 2003 πŸ› Cisco Press 🌐 English

The primary goal of this book is to help you prepare to pass either the 9E0-121 or 642-511 Cisco Secure VPN (CSVPN) exams as you strive to attain the CCSP certification or a focused VPN certification. Adhering to the premise that, as individuals, we each retain information better through different m

CCSP Cisco Secure VPN exam certification
✍ John Roland, Mark Newcomb πŸ“‚ Library πŸ“… 2003 πŸ› Cisco Press 🌐 English

The official study guide for the Cisco Secure VPN exam #9E0-121* The only Cisco authorized exam certification guide for the new CSVPN exam* Pre- and post-chapter quizzes help assess knowledge and identify areas of weakness* Overviews and Foundation Summaries present complete and quick review of all

CCSP Cisco Secure VPN exam certification
✍ John Roland, Mark Newcomb πŸ“‚ Library πŸ“… 2003 πŸ› Cisco Press 🌐 English

<p>Official self-study test preparation guide for the Cisco 9E0-121 and 642-511 CSVPN exams</p><p>Coverage of the CSVPN topics enables you to identify and fill your knowledge gaps before the exam date. You'll learn about: <ul><li>Configuring Cisco VPN 3000 concentrators and VPN 3002 Hardware Clients

CCSP Cisco Secure PIX firewall advanced
✍ Christian Degu, Greg Bastien πŸ“‚ Library πŸ“… 2003 πŸ› Cisco Press 🌐 English

Good information in here. It's good if you're looking for a cheap way to study. When you upgrade to Pix OS 8 some of the commands are the same, but you implement them at different config levels. You will conf t and then int ethernet0 to configure the interfaces for example. With the older OS it'