課堂由導師以講座形式教授課程理論及進行眾多的商業實習,而實習時段由學員親自進行商業實習。
1 Introduction of ASA
1.1 Configuration File Management
2 Configure ASA Interfaces
2.1 Security Level Overview
2.2 實習: Configure hostname and “inside” interface with static IP address 10.0.0.15/8
2.3 實習: Configure “outside” interface with DHCP client feature
2.4 實習: Configure IPv6 on the ASA
2.5 實習: Configure “outside” interface with PPPoE client feature
2.6 DHCP Server
2.7 實習: Configure DHCP Server
2.8 實習: Study the meaning of security-level
3 ASA Management Access Configuration
3.1 Enable Password
3.2 實習: Configure Enable password
3.3 Telnet Access
3.4 實習: Configure telnet access in ASA - part 1
3.5 實習: Configure telnet access in ASA - part 2
3.6 SSH (Secure Shell) Access
3.7 實習: Configure SSH Access in ASA
3.8 ASDM (Adaptive Security Device Manager)
3.9 實習: Configure ASDM
4 System Monitoring in ASA
4.1 實習: Configure NTP Client with authentication in ASA
4.2 System Message Severity Levels
4.3 實習: Enable and Configure General Properties of System Logging
4.4 實習: Enable Console Logging
4.5 Terminal Logging
4.6 實習: Termial Logging
4.7 實習: Configure Syslog
4.8 實習: Configure SNMP Trap
4.9 實習: ASDM Logging
4.10 實習: Buffer Logging
4.11 實習: Buffer Logging – Manual Flash Logging.
4.12 實習: Buffer Logging – Automatic Flash Logging
4.13 實習: Buffer Logging – Automatic save log to FTP
4.14 Advanced ASA Logging
5 IP and IP Mutlicast Routing in ASA
5.1 Basic Routing Concepts
5.2 Static Routing
5.3 實習: ASA Static Routing
5.4 實習: Simple Load Balancing by Static Route
5.5 Service Level Agreement (SLA) in ASA
5.6 實習: Static Routing with SLA
5.7 RIP
5.8 實習: RIPv1 in ASA
5.9 事後驗證: RIPv1 in ASA
5.10 實習: RIPv2 in ASA
5.11 實習: default gateway advertisement by RIP in ASA
5.12 實習: RIPv1 and RIPv2 coexist in ASA
5.13 實習: RIP plain text authentication in ASA
5.14 實習: RIP MD5 authentication in ASA
5.15 OSPF (Open Shortest Path First)
5.16 實習: Single Area OSPF
5.17 實習: Multi-Area OSPF
5.18 實習: Advertise default gateway via OSPF in ASA
5.19 Special OSPF Network Type in ASA
5.20 實習:OSPF Point-to-Point Non-Broadcast network type in ASA
5.21 Virtual Link:
5.22 實習: Virtual Link in ASA
5.23 OSPF Authentication
5.24 實習: OSPF Plain Text authentication
5.25 實習: OSPF MD5 authentication
5.26 EIGRP
5.27 實習: Configure EIGRP in ASA
5.28 EIGRP Authentication:
5.29 實習: Enable EIGRP Authentication in ASA
5.30 IP Mutlicast in ASA
5.31 實習: Multicast in ASA
6 Network Access Control
6.1 Access List Types
6.2 Access Control Entry Order
6.3 Extended Access List
6.4 實習: Basic Extended Access List
6.5 實習: Add an ACE to an existing Extended Access List
6.6 Standard Access List
6.7 實習: Basic Redistribution between OSPF and EIGRP in ASA
6.8 實習: Using Standard Access List to perform route filtering in ASA
6.9 IPv6 Access List
6.10 實習: Configure IPv6 Access List
6.11 Advanced Access Control List Topics
6.12 Object Grouping
6.12.1 Object Grouping: Protocol
6.12.2 Object Grouping: Network
6.12.3 Object Grouping: Service
6.12.4 Object Grouping: ICMP Type
6.13 實習: ACL with object grouping
6.14 Time-based ACL
6.15 實習: Time-Base ACL
6.16 ICMP Filtering
6.17 實習: Configure ICMP Access in ASA
6.18 Application Layer Filtering
6.19 Content Filtering
6.20 實習: Filter Java in ASA
6.21 URL Filtering
7 Packet Monitoring in ASA
7.1 實習: Capture all traffic in the outside interface
8 NAT (Network Address Translation)
8.1 Basic NAT Concepts
8.1.1 Dynamic NAT Concept
8.2 Dynamic NAT with overlaod Concept
8.3 Static NAT Concept
8.4 實習: Configure Static NAT
8.5 實習: Static NAT with PAT
8.6 實習: Dynamic NAT with overload
8.7 實習: Dynamic NAT with public ip pool
8.8 實習: Dynamic NAT with public ip pool with interface ip address for last resort
8.9 Advance NAT Topics – Twice NAT
8.10 實習: Twice NAT 1
8.11 實習: Twice NAT 2
8.12 實習: Twice NAT 3
8.13 DNS and NAT
8.14 實習: NAT with DNS 1
8.15 實習: NAT with DNS 2
9 AAA (Authentication, Authorization, Accounting)
9.1 AAA Components
9.2 AAA Protocols
9.3 實習: Local AAA for telnet authentication
9.4 實習: Local AAA for SSH authentication
9.5 實習: Local AAA for ASDM authentication
9.6 實習: Local AAA for Console authentication
9.7 實習: Local AAA for Enable authentication
9.8 實習: AAA authentication for telnet authentication by using Cisco ACS
9.9 實習: AAA authentication for SSH authentication by using Cisco ACS
9.10 實習: AAA authentication for ASDM authentication by using Cisco ACS
9.11 Advanced AAA Topics – Cut Through Proxy
9.12 實習: Cut-Through Proxy
10 Quality of Service (QoS)
10.1 QoS Support in ASA
10.2 Configuration Logics in ASA
10.3 實習: QoS Policing in ASA
10.4 實習: QoS Policing in Router2
10.5 實習: QoS Shaping in ASA1
10.6 實習: QoS Priority Queue in ASA
11 IPSec Site-to-Site VPN (Virtual Private Network)
11.1 Review of IPSec VPN
11.2 IPSec VPN Life Cycle
11.3 Configuration Logics of IPSec VPN in ASA
11.4 實習: Configure Site-toSite IPSec VPN between ASA and IOS Router
12 EasyVPN (IPSec Remote Access VPN)
12.1 實習: IPSec Remote Access VPN |