The Implementing Secure Converged Wide Area Networks (ISCW) is an advanced instructor-led course that introduces techniques and features enabling or enhancing WAN and remote access solutions. This five-day course focuses on using one or more of the available WAN connection technologies for remote access between enterprise sites.
This course includes cable-modems and Digital Subscriber Line (DSL) with Network Address Translation (NAT), Multi Protocol Label Switching (MPLS) virtual private networks (VPNs), and network security using VPNs with IPsec encryption and Internet Key Exchange (IKE) keys. Successful graduates will be able to secure the network environment using existing Cisco IOS security features, and configure the three primary components of the Cisco IOS Firewall Feature set (Firewall, Intrusion Prevention System [IPS], and Authentication, Authorization, and Accounting [AAA]). This task-oriented course teaches the knowledge and skills needed to secure Cisco IOS router networks using features and commands in Cisco IOS software, and using a router configuration application. ISCW is part of the recommended learning path for students seeking the Cisco Certified Network Professional (CCNP).
Implementing Secure Converged Wide Area Networks (ISCW) is part of the recommended learning path for students seeking the Cisco Certified Internetworking Professional (CCIP), Cisco Certified Network Professional (CCNP), Cisco Certified Design Professional (CCDP), and Cisco Certified Internetwork Expert (CCIE) certifications.
Prerequisites
To fully benefit from this course, it is recommended that you have the following prerequisite skills and knowledge:
- Networking terms, numbering schemes, and topologies
- Open System Interconnection (OSI) reference model
- Operating and configuring a Cisco switch and router
- TCP/IP stack and configuring IP addresses
- IP subnetting
- Routing protocol operation
- Using, implementing, and configuring static and default routes
- Interpreting the contents, entries, and indicators from a Cisco routing table
- Filtering traffic with standard and extended access lists
- Verifying basic router configurations using show and debug command output
- Verifying basic switch configurations using show command output Enter prerequisites here
- Completion of Introduction to Cisco Networking Technologies (INTRO) is recommended
- Completion of Interconnecting Cisco Network Devices (ICND) is recommended
Associated Certifications
- Cisco Certified Network Professional (CCNP)
Who Should Attend
This course is intended for the following audience:
- Network Designers
- Network Administrators
- Network Engineers
- Network Managers
- Systems Engineers
- Sales Support Engineers
- Network technicians who are responsible for implementing and troubleshooting complex network environments.
- Cisco Channel Partner/Resellers
- CCIP, CCNP and CCDP candidates
- CCIE Routing and Switching candidates
Course Objectives
After completing this course, the student will be able to:
- Describe the remote connectivity requirements for secured access and explain the alignment of these requirements with Cisco network architectures
- Describe and implement teleworker broadband connectivity
- Implement and verify frame mode MPLS
- Describe and configure a site-to-site IPsec VPN
- Describe and configure Cisco device hardening
- Describe and configure IOS firewall features
Course Outline
- Network Connectivity Requirements
- Describing Network Requirements
- Teleworker Connectivity
- Describing Topologies for Facilitating Remote Connections
- Describing Cable Technology
- Describing DSL Technology
- Configuring the CPE as the PPPoE or PPPoA Client
- Verifying Broadband ADSL Configurations
- Frame Mode MPLS Implementation
- Introducing MPLS Networks
- Assigning MPLS Labels to Packets
- Implementing Frame Mode MPLS
- Describing MPLS VPN Technology
- IPsec VPNs
- Understanding IPsec Components and IPsec VPN Features
- Implementing Site-to-Site IPsec VPN Operations
- Configuring IPsec Site-to-Site VPN Using SDM
- Configuring GRE Tunnels over IPsec
- Configuring High-Availability Options
- Configuring Cisco Easy VPN and Easy VPN Server Using SDM
- Implementing the Cisco VPN Client
- Cisco Device Hardening
- Mitigating Network Attacks
- Disabling Unused Cisco Router Network Services and Interfaces
- Securing Cisco Router Installations and Administrative Access
- Mitigating Threats and Attacks with Access Lists
- Configuring AAA on Cisco Routers
- Cisco IOS Threat Defense Features
- Introducing the Cisco IOS Firewall
- Implementing Cisco IOS Firewalls
- Introducing Cisco IOS IPS
- Configuring Cisco IOS IPS