Préparation de l’ISCW (642-825) – Implementing Secure Converged Wide Area Networks

Ayant réussi la CCNA la semaine dernière, il est maintenant temps de penser à  l’avenir, avec la CCNP.

La CCNP regroupe les 4 examens suivants:

  • BSCI 642-901- Building Scalable Cisco Internetworks
  • BCMSN 642-812 – Building Cisco Multilayer Switched Networks
  • ISCW 642-825 – Implementing Secure Converged Wide Area Networks
  • ONT 642-845 – Optimizing Converged Cisco Networks

Je compte commencer par l’ISCW, qui semble être un des deux plus compliqués avec le BSCI. L’ISCW me permettra d’acquérir des connaissances plus approfondies sur les technologies réseaux WAN que j’utilise actuellement au cours de mon stage au sein d’un opérateur virtuel de réseaux globaux.

J’ai créer un petit planning pour gérer l’apprentissage de cette certification, vous pourrez donc suivre au fur et à mesure mon avancement, et ça se passe ici, dans la partie Papers.

Voici un aperçu du contenu de cette certification ISCW (tiré des présentations CISCO):

The Implementing Secure Converged Wide Area Networks (ISCW 642-825) is a qualifying exam for the Cisco Certified Network Professional CCNP®. The ISCW 642-825 exam will certify that the successful candidate has important knowledge and skills necessary to secure and expand the reach of an enterprise network to teleworkers and remote sites with focus on securing remote access and VPN client configuration. The exam covers topics on Cisco hierarchical network model as it pertains to the WAN, teleworker configuration and access, frame mode MPLS, site-to-site IPSEC VPN, Cisco EZVPN, strategies used to mitigate network attacks, Cisco device hardening and IOS firewall features.

Exam Topics

The following information provides general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes the guidelines below may change at any time without notice.

Implement basic teleworker services

  • Describe Cable (HFC) technologies.
  • Describe xDSL technologies.
  • Configure ADSL (i.e., PPPoE or PPPoA).
  • Verify basic teleworker configurations.

Implement Frame-Mode MPLS

  • Describe the components and operation of Frame-Mode MPLS (e.g., packet-based MPLS VPNs).
  • Configure and verify Frame-Mode MPLS.

Implement a site-to-site IPSec VPN

  • Describe the components and operations of IPSec VPNs and GRE Tunnels.
  • Configure a site-to-site IPSec VPN/GRE Tunnel with SDM (i.e., preshared key).
  • Verify IPSec/GRE Tunnel configurations (i.e., IOS CLI configurations).
  • Describe, configure, and verify VPN backup interfaces.
  • Describe and configure Cisco Easy VPN solutions using SDM.

Describe network security strategies

  • Describe and mitigate common network attacks (i.e., Reconnaissance, Access, and Denial of Service).
  • Describe and mitigate Worm, Virus, and Trojan Horse attacks.
  • Describe and mitigate application-layer attacks (e.g., management protocols).

Implement Cisco Device Hardening

  • Describe, Configure, and verify AutoSecure/One-Step Lockdown implementations (i.e., CLI and SDM).
  • Describe, configure, and verify AAA for Cisco Routers.
  • Describe and configure threat and attack mitigation using ACLs.
  • Describe and configure IOS secure management features (e.g., SSH, SNMP, SYSLOG, NTP, Role-Based CLI, etc.)

Implement Cisco IOS firewall

  • Describe the functions and operations of Cisco IOS Firewall (e.g., Stateful Firewall, CBAC, etc.).
  • Configure Cisco IOS Firewall with SDM.
  • Verify Cisco IOS Firewall configurations (i.e., IOS CLI configurations, SDM Monitor).

Describe and configure Cisco IOS IPS

  • Describe the functions and operations of IDS and IPS systems (e.g., IDS/IPS signatures, IPS Alarms, etc.)
  • Configure Cisco IOS IPS using SDM

Benoit

Network engineer at CNS Communications. CCIE #47705, focused on R&S, Data Center, SD-WAN & Automation.

More Posts - Website

Follow Me:
TwitterLinkedIn

Laisser un commentaire

Votre adresse de messagerie ne sera pas publiée. Les champs obligatoires sont indiqués avec *