Anda di halaman 1dari 2

CCNP Security

ASA 9.x

- Basic Configuration
- Routing on the Firewall
- Traffic Flow thru the Firewall
- NAT on the Firewall [Dynamic NAT & PAT, Static NAT & PAT]
- High Availability [Redundancy/Failover]
-------------------------------------------------------------
Intrusion Prevention Systems [IPS/SourceFire/Firepower]

- Allows you to check the packet for well-known network attacks


- It also creates a baseline for your network.
- IPS can also detect uncharacteristic behaviour in your network based on the
baseline that is created.
- Checks for Network Traffic that might be an attack against the network
- Basic Configuration
- Tuning existing signatures
- Create Custom signatures
-------------------------------------------------------------
Advanced Malware Protection [AMP]

- It is a product that allows you to check the files that are being sent over the
network for the existence of Malware within the File
- Basic Configuration
- Policy Control
-------------------------------------------------------------
Firepower Threat Defence [FTD]

- Combines the Firewalling, IPS and AMP capabilities into a single device [Physical
or virtual]
- Basic Configuration
- Firewalling
- IPS Policies
- AMP Policies
-------------------------------------------------------------
Firesight Management Console [FMC]

- It is an appliance [Physical or Virtual] that will manage all the devices from a
single Console.
-------------------------------------------------------------
VPNs

- LAN to LAN VPNs Using IPSec


- LAN to LAN VPNs Using GRE/IPSec
- DMVPN
- GET VPN
- Flex VPN
- Remote Access VPNs
-------------------------------------------------------------
Content Filtering

- Web Security Appliance [WSA]


- Web Filtering based on Categories
- Basic Configuration
- Configure Filtering Policies
- Email security Appliance [ESA]
- E-mail filtering / SPAM filtering
- Basic Configuration
- Configure Filtering Policies
-------------------------------------------------------------
Identity Management/Authentication

- Access Control Server [ACS] - Device Administration


- Basic Configuration
- Authentication
- Authorization
- Identity Services Engine [ISE] - End User Authentication
- Basic Configuration
- Dot1x Authentication
- Downloadable ACL
-------------------------------------------------------------
Router/Switch Security

- Router
- Zone-based Firewall
- Time-based ACLs
- IPV6 Unicast Routing
- Switch
- Port-Security
- DHCP Snooping
- ARP Inspection
- Dynamic ARP Inspection
- Private VLAns
-------------------------------------------------------------

Anda mungkin juga menyukai