Cisco Security Career Certifications
And Validate Your Areas of Expertise Cisco Firewall, VPN, and IDS Specialists Recommended Training through Cisco Learning Partners Pre-requisite Valid CCNA certification Cisco Secure PIX Firewall Advanced 3.1 Recommended Training through Cisco Learning Partners Pre-requisite Valid CCNA certification Cisco Secure Virtual Private Networks 3.1 Recommended Training through Cisco Learning Partners Pre-requisite Valid CCNA certification Cisco Secure Intrusion Detection System 3.0 Cisco Secure...
Mode Config via AAA
The second step is to optimize the configuration of IP parameters by storing them on central servers. Extremely large remote access VPNs may have a large number of VPN servers and it makes sense to offload the IP parameters to one or two central AAA servers. Second optimization approach moves most IP related client configuration to a central AAA server 2003, Cisco Systems, Inc. All rights reserved. This figure illustrates how mode config parameters are stored on a central AAA server....
- AAA and Preshared Secrets
- Access Control
- Access Server Guidelines
- Adjusting the Peer Response Timeout Value
- Advanced PKI Features in Cisco IOS
- AES Candidates
- AES vs 3DES
- Aggressive Mode
- Aggressive Mode Summary
- AH Header Structure
- An organization needs to transport voice and data over its sitetos ite VPN
- Analysis of G729 over ADSL
- Analysis of G729 over PPP
- Analyze the Current Situation
- Analyze the Current Situation Cont
- Analyzing Dial Security Requirements
- Answers
- Anti Replay Protection
- Anti Spoofing Prevention - 2
- Application Examples
- Applications of GRE Tunnels in Enterprise Networks
- Applications of GRE Tunnels in ISP Networks
- Applications of PPTP and L2TP
- Asymmetric Algorithms Revisited
- Asymmetric Encryption Algorithms
- Authenticating IKE Peers
- Authentication
- Authentication Header
- Authentication Method
- Authentication of IKE Peers
- Authentication Strength and Infrastructure Trust - 2
- Authorization Guidelines
- Authorization of Network Access
- Automated Random Key Generation
- Automatic Key Revocation Procedures
- Backup with Cisco VPN Client
- Bandwidth Availability
- Based on existing hash functions keyed MD5 keyed SHA1
- Because it uses simple logical operations it is easily implementeble in hardware
- Block Ciphers
- Both are simple to describe and implement
- Breaking Encryption
- Callback
- Callback Guidelines
- Caller ID Restrictions
- Campus VPN
- Centralized Configuration of VPN Clients
- Centralizing Configuration of Remote Devices
- Certificate Authentication Process
- Certificate Authority CA
- Certificate Generation Process
- Certificate Revocation
- Certificate Revocation List CRL
- Certificates are public ie not secret information
- Characteristics of Mpls Vpns
- Chinese Wall
- Choice of Algorithms
- Choosing an Algorithm
- Choosing the Tunnel Endpoint Address
- Cisco Eappeap Features and Limitations
- Cisco IOS aa the terminating peer
- Cisco IOS Advanced PKIEnabled Features Configuration
- Cisco IOS Configuration Example - 2
- Cisco IOS Configuration of DPD
- Cisco Ios Pki Enrollment
- Cisco Ios Pki Revocation Procedures Cont
- Cisco IOS routers can be used for complex topologies use sitetosite design guidelines
- Cisco PIX as the terminating peer - 2
- Cisco Secure ACS Guidelines
- Classification and Marking in VPNs
- Cluster Configuration
- Combining GRE with IPSec
- Commonly used CA identities
- Complexity of Management
- Conclusion
- Configuration Example
- Configured IKE Policies and Keys Example
- Configuring a Trustpoint in IOS
- Configuring Auto Enrollment
- Configuring CA Authentication
- Configuring Manual Enrollment
- Content Switches
- Converting Enterprise Networks into ISPs
- Cost and Time to Break 3DES
- Countermeasures
- Countermeasures Distrust signaling use endtoend protection mechanisms under your control IPSec
- Course Agenda
- Course Objectives
- Course Objectives cont
- Cracker Tools
- CRL repository directory should be reachable redundant servers
- Crosscertified CAs
- Crypto Map Sets
- Crypto Maps
- Crypto Maps and Interfaces
- Cryptography and Performance Impact
- Current and Future Integrity Solutions
- Current Situation
- Data is XORed with the pseudorandom stream for encryption and decryption
- Dedicated bridging protocols are recommended
- Definition
- Definition and Protocols
- Delay
- Demand for Stronger Authentication
- DES Description
- DES in Action
- DES Modes of Operation
- Design Decisions for Dial Backup
- Design Decisions for the Dialin POP
- Design Limitations
- Desirable Algorithm Features
- Devices poll the CA for a new CRL when old CRL expires
- Diffie Hellman Group
- Diffie Hellman Groups
- Digital Certificate
- Digital Certificates - 2
- Digital Signature Properties
- Digital Signature Standard DSS
- Digital Signatures in Action
- Dmvpn
- DMVPN Advantages
- DMVPN Configuration Example
- DMVPN Features
- DMVPN Mechanisms
- DMVPN Summary
- DMVPN with EIGRP
- DMVPN with OSPF
- DMVPN with RIP
- DNBased Crypto Maps
- DNS Server Assignment
- Do Not Trust WEP in Secure Environments
- Does not provide confidentiality has to be combined with IPSec
- Does not require ISPs assistance in setting up the VPNs
- DoS Considerations
- Dscp
- Dual DMZ Design
- Dynamic Crypto Map Operation
- Dynamic Retrieval of Certificates
- Dynamic TED Command Cisco IOS
- EAPs Authentication Helpers
- Easy Solutions
- Easy VPN
- Enabling Address Assignment on a Crypto
- Encapsulating Security Payload
- Encryption Algorithm
- Encryption Algorithms and Their Keys
- Encryption and Decryption
- End user validates all keys dangerous
- Enrollment Guidelines
- Equipment deficiencies routing other nonIP protocols QoS resilience etc
- ESP Header Structure
- ESP Modes Example - 2
- Example - 2 3 4
- Example Cisco Eappeap Wlan Scenario
- Example Cont - 2 3 4 5 6 5 6 7 8 9 10 11 12 13 14
- Example Scenario - 2
- Example Scenario 1 3
- Example Scenario 2 Solution
- Example Scenario Cont 4
- Example Scenario QoS Interface Design
- Example Scenario Voice Call Bandwidth Cont 5
- Example Scenarios and Environments
- Example Scenario Solution 15 16 17
- Example Using RSA Encrypted Nonces 18 19
- Example Link Failure Scenario 1Solution 1 Cont - 2
- Example Link Failure Scenario 1Solution
- Example Link Failure Scenario 1Solution 2 Cont
- Example Local VPN Device Failure
- Example Local VPN Device Failure Cont - 2
- Example Remote VPD Device Failure
- Example Remote VPN Device Failure Cont - 2
- Examples
- ExampleVPN Device Failure Cont
- ExampleVPN Path Failure Scenario
- ExampleVPN Path Failure Scenario 3 Cont
- Extended Authentication Xauth Cont
- Facts - 2
- Facts Cont 3 4
- Failure Detection Options
- Failure Scenarios
- Features - 2
- Features and Limitations of Aggressive Mode
- Features and Limitations of GRE 3
- Features of GRE 4
- Filtering Granularity
- Fragmentation and IPSec
- Fragmentation Issue Example
- Fragmentation with GRE and IPSec
- Frame Details
- General Cisco Wireless Product Guidelines
- General Procedure
- Graphical Topology editor
- GRE Feature Matrix
- GRE Tunnels - 2
- GRE tunnels should be added to provide support for multicastbroadcasts and other protocols
- Guidelines - 2 3 4 5 6
- Guidelines for Confidentiality and Integrity 7 8 9 10 11 12 13
- Hash Algorithm
- Hash Functions
- Hashing - 2
- Hashing Algorithms
- Hashing in Action
- Hhiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii
- High end routers on larger sites 2 Mbps
- HMACs in Action
- Hot Standby Routing Protocol
- How to Attack the Shared Key Authentication
- How to prove that you are the original author of a document
- Huband Spoke Characteristics
- Huband Spoke Characteristics using IPSec
- Human Factor Analysis
- Identify Basic Security Leaks
- Identifying the Need for Dial Technology
- If addressing is not enforced the user can choose own IP address bypass of firewall rules impersonation
- IKE and Certificates
- IKE Authentication
- IKE Authentication Guidelines
- IKE Complexity
- IKE Description
- IKE Features - 2
- IKE Identity
- IKE Lifetime
- IKE Modes Overview
- IKE Phases
- IKE Policy Configuration
- IKE Process
- IKE Protection Guidelines
- IKE Session Protection
- Implementing Load Balancing
- Implementing Static Load Balancing
- Incoming Dynamic Crypto Map Overview
- Infrastructure Guidelines
- Initial Sequence Numbers
- InstaM firewaN software for toe WLAN client for protection while IPsec is down
- Instructions
- Integration with Perimeter Devices Cont
- Inter Client Communication
- Interclient Communication Example Scenario
- Interdependence of Key Exchange and Bulk Protection Mechanisms
- Internet Key Exchange
- Introduction - 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32
- IOS Mode Configuration Commands
- IOS Mode Configuration Commands Cont
- IPSec and Mpls Vpn Integration
- IPSec ESP provides
- IPSec established between client and gateway
- Psec Fragmentation with PMTUD
- Psec over ADSL
- Psec over ADSL Cont
- IPSec SA Creation
- IPSec Security Features
- IPSec Transform Negotiation
- IPSec Transport Mode
- IPSec Tunnel Mode
- IPSec Tunnel Transport Mode Usage Guidelines
- Isolated VPNs can have access to VPNs with central servers
- ISPs can provide VPN functionality over IPonly networks
- K1K3 yields 168bit key length
- Key Exchange Choice
- Key Generation
- Key LEAP Devices
- Key length and Key spaces
- Key Length Issues
- Key management can be a big problem
- Key Management Components
- Key Recovery and Key Escrow
- Key Refresh Definition
- Key Revocation
- Key Storage in Memory
- Key Storage in Non Volatile Memory
- Key VPN Devices
- Keystream Collisions
- L2TP and IPSec
- L2TP Security
- L2TP Tunnel Building Process
- Limitations
- Linear Operations
- Load Balancing
- Load Balancing Cont
- Load Balancing in Remote Access VPNs
- Local Registration Authorities
- Lookahead Fragmentation
- LRAs minimize CA exposure to the network
- M
- Main Mode
- Managed CPEBased IPSec VPNs
- Management Center for PIX Firewalls
- Management Center for VPN Routers
- Manual Generation of Keys
- Manual IPsec Configuration Example
- Manual Key Exchange Procedures
- Manual Key Revocation Methods
- Manual SA Configuration
- Markers IP precedence Dscp Fr De Atm Clp 8021q COS etc
- Marking and IPsec VPNs
- Mass Encryption
- MD5 Example
- MD5 Used as a HMAC
- Mechanism used to perform per user authentication for remote clients
- Microsoft PPTP terminology
- Mode Config
- Mode Config Example
- Mode Config Features
- Mode Configuration Overview DNS Server Assignment Challenge
- Monitoring PKI
- MPLS Definitions and Protocols
- Mpls Vpn Applications
- Mpls Vpn Guidelines
- Mpls Vpn Limitations
- Multimedia Requirements
- Multiple DMVPNs Across a Large WAN
- Multiple RSA Key Pair Support
- Multiprotocol GRE Operation
- Natural Sources
- Next Hop Resolution Protocol
- No automated procedurescompare sent and received fingerprints
- Objective - 2 3
- Objectives
- One Dmvpn Across a Large WAN
- One Dmvpn Across the Internet
- One tunnel per user is required Client to LAC
- Online Certificate Status Protocol OCSP servers
- Only Cisco Express Forwarding CEF and process switching are supported regular fast switching is not supported
- Operation of NHRP
- Operation of TED
- Optimization Rules
- Optimized Authentication of Peers - 2
- Optimizing Peer Configuration
- Other Management Products - 2
- Other TED limitations
- Outline
- Overview - 2 3 4 5 6
- Passing Tunnels Traffic Directly to the Protected Network
- Peers exchange public values
- Perfect Forward Secrecy - 2
- Performance Matrix Client VPN Devices
- Performance Matrix Highend Hub VPN Devices
- Performance Matrix Lowend Spoke VPN Devices
- Performance Matrix VPN Concentrators
- Perimeter Topology - 2
- Periodic Burdens
- PFS Example
- Physical Security of Dial Networks
- PIX Device Manager
- Pkcs
- Pkcs10
- PKI Applications
- PKI Deployment Issues
- PKI Enrollment
- PKI Features for PIX and VPN 3000
- PKI Terminology
- PKI Topologies Hierarchical CAs
- PKI Topologies SingleRoot CA
- Placement of VPN Systems - 2
- Pmtud
- PMTUD and ICMP Filters
- PMTUD Guidelines
- Pptp
- PPTP can only be used for dialin L2TP can also be used for dialout
- PPTP Security - 2
- Pptpmppe Performance
- Practice - 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39
- Processing Challenges
- Product Guidelines - 2
- Provides framework for the authenticating and securing of data
- QoS Guarantees
- Quick Mode
- Quick Mode Summary
- Random and Pseudorandom Numbers
- RC Algorithms
- Rc4
- Received PK is verified with CAs PK
- References - 2 3
- Refined Questions
- Remember that any method requires twoway authentication
- Remote Access and Multimedia Applications
- Requesting a Certificate Revocation List
- Require Data Encryption MPPE
- Requirements and Reality
- Requires interoperability with other technologiesstandards PKCS X500 LDAP
- Requires ISPs assistance in setting up the VPNs
- Researching an Organizations Dial Security Requirements Cont
- Restrictions
- Roaming
- Router Architecture - 2
- Routing in DMVPNs - 2
- Routing Protocols
- RSA Digital Signatures
- RSA Digital Signatures in Detail
- RSA Encryption
- RSA Key Exchange for Encryption
- RSA Signature Overview
- RSAEncrypted IKE Authentication
- RSAEncrypted Nonces
- Scep Pkcs Example
- Secret Key Exchange Using Public Key Cryptography Cont
- Secure Hash Algorithm 1 SHA1 with 160bit hashes
- Securing GRE - 2
- Security Associations
- Security between Mpls Vpns
- Security Guidelines for Native Wireless Networks Cont
- Sequence of IKE Operations
- Setting Manual Keys with securityassociation Commands
- SHA1 Example
- SHA1 is preferred for highest security
- SHA1 Used As a HMAC
- Shared Key Authentication
- Signing Process in Detail
- Simple Certificate Enrollment Protocol SCEP
- Single DMZ with private interface protection
- Single DMZ with public interface protection firewall bypass or onastick design inside the network
- Siteto Site and Remote Access VPNs
- Sitetosite VPN
- Smart Card Standards
- Smart Cards
- Solution - 2
- Solution 1 3 4
- Solution Guidelines 5
- Sometimes manual verification of keys is required to avoid maninthemiddle attacks
- Specific Peer Authentication Guidelines in Siteto Site VPNs
- Spoke devices
- Spoofing Issue with GRE
- Stateless historyless MPPE is only supported in recent versions of Dial Up Networking DUN13
- Static Configuration of Load Balancing
- Static definitions of authentication keys on all peers unless digital certificates are used
- Static Preshared Secrets
- Step 2 IS exchange and authentication of SH key
- Step 2 Verification of both nonces which are used to generate the key
- Still used for Stack Group Bidding Protocol SGBP
- Stream Ciphers
- Summary - 2 3 4 5
- Supported Products
- Symmetric Encryption Algorithms
- Task
- Task 1 Design the VPN as an Overlay of the Existing WAN
- Task 1 Design the VPN Equivalent to the Old WAN - 2
- Task 1 Feasibility Study
- Task 2 Add a SOHO Network to the VPN - 2
- Technical Analysis
- TED Caveats
- TED Operation
- The Crucial XOR Operation
- The Current DSS Choices
- The Diffie Hellman Exchange
- The DSA Algorithm and its Relationship to DSS
- The hexkeystring
- The Ietf Pkix Working Group
- The master redirects clients to least utilized VPN concentrators
- The New Situation
- The PKCS Standards
- The Problem
- The Process of Encryption
- The rationale behind this is
- The Rijndael Cipher
- The RSA Algorithm - 2
- The Seqnum Example
- The X509 Standard
- This is computationally infeasible
- This lesson presented these key points - 2 3 4 5
- Those keys are longterm monthsyears
- Threats mitigated
- Threats Mitigated
- Topology Considerations
- Traffic Analysis
- Transforming Plaintext into Ciphertext
- Transport Network Guarantees
- Trusted Third Party Protocol Cont
- Trustpoint Configuration Configuring a Trustpoint CA - 2
- Trustpoint Configuration Configuring a Trustpoint CA Cont
- Trustpoint Configuration PKI Configuration Example
- Tunnel Rekey Rate
- Tunneling Protocol - 2
- Typical QoS Designs - 2
- Typical Reasons for Intentional Security Leaks
- Upon completing this lesson you will be able to
- Usage Guidelines - 2
- Usage Keys and Usage Certificates
- Usage of Digital Signatures in Cisco Product Line
- Usage of Hashing in Cisco Product Line
- Use longer keys to be on the safe side
- Used in low volume crypto services signatures key exchange
- Using Public Key Cryptography for Key Exchange
- USP IPsec tunneling is recommended
- Voice over IP
- VPN 3000 as the terminating peer
- VPN 3000 as the terminating sitetosite peer
- VPN Clusters - 2
- VPN Device Failure Solution 1 Convergence Time
- VPN Device Failure Solution 2 Convergence Time
- VPN Encryption Accelerators
- VPN Gateway Concentrator Guidelines
- VPN High Availability
- VPN Link Failure Scenario 1 Solution
- VPN Link Failure Solution 1 Convergence Time
- VPN Link Failure Solution 2 Convergence Time
- VPN Path Failure Scenario Cont
- VPN Path Failure Solution Convergence Time
- VPN Solution Center
- Vpn Wlan Example Scenario Analysis
- Vpn Wlan Guidelines Cont
- Wan
- WAN as the Transport Network
- WEP and IV Collisions
- WEP Details
- WEP Vulnerabilities Summary
- What is Key Management
- Wildcard Pre Shared Keys
- Wireless Access VPN
- Basic Principles Refresher
