CCNP
Security
SECURE 642-637
Official Cert Guide
Sean
Wilkins
Franklin H. Smith III
x CCNP
Security
SECURE 642-637 Official Cert GuideContents
Introduction xxxiii
PartI Network
Security Technologies
OverviewChapter
1 NetworkSecurity
Fundamentals 3 "Do I Know ThisAlready?"
Quiz 3 FoundationTopics
7Defining
NetworkSecurity
7Building
Secure Networks 7Cisco SAFE 9 SCF Basics 9
SAFE/SCFArchitecture
Principles
12SAFE/SCF NetworkFoundationProtection
(NFP)
14 SAFE/SCFDesignBlueprints
14SAFE
Usage
15Exam
Preparation
17Chapter2 Network
Security
Threats 21 "Do r KnowThisAlready?"
Quiz 21 FoundationTopics
24Vulnerabilities 24
Self-imposed
NetworkVulnerabilities 24 IntruderMotivations 29Lack
of Understanding of Computers
orNetworks 30In
truding fo
rCuriosity 3 0Intruding for
Fun andPride 30Intruding for
Revenge 30Intruding for Profit
31Intruding for
PoliticalPurposes
31Types
of Network Attacks 31 Reconnaissance Attacks 32 Access Attacks 33DoSAttacks 35 Exam
Preparation
36Chapter
3 Network Foundation Protection(NFP)
Overview 39"DoI Know This
Already?" Quiz
39 FoundationTopics
42XI
Control Plane 43
Data Plane 44
Management Plane 45
Identifying
NetworkFoundation ProtectionDeployment
Models 45Identifying
Network Foundation Protection FeatureAvailability
48 CiscoCatalyst
Switches 48Cisco
Integrated
Services Routers(ISR)
49 CiscoSupporting Management Components
50Exam
Preparation
53Chapter
4Configuring
andImplementing
Switched DataPlaneSecurity
Solutions 57
"Do I Know This
Already?" Quiz
57Foundation
Topics
60SwitchedDataPlane Attack
Types
60 VLANHopping
Attacks 60CAM
Flooding
Attacks 61 MACAddressSpoofing
63SpanningTreeProtocol (STP)
Spoofing
Attacks 63DHCPStarvation Attacks 66
DHCPServer
Spoofing
67 ARPSpoofing
67SwitchedData Plane
Security
Technologies
67 PortConfiguration
67Port
Security
71RootGuard,BPDUGuard,and PortFast 74 DHCP
Snooping
75Dynamic
ARPInspection (DAI)
77 IP Source Guard 79Private VLANs(PVLAN) 80 Exam
Preparation
84Chapter5 802.1X and Cisco
Identity-Based Networking
Services(IBNS)
91"Do I Know This
Already?" Quiz
91 FoundationTopics
94Identity-Based Networking
Services (IBNS) andIEEE 802.1x Overview 94CCNP
Security
SECURE 642-637 Official Cert Guide 8 02.lx Interworking 97Extensible Authentication Protocol
(EAP)
97 EAPoverLAN(EAPOL) 98EAP
Message Exchange
99PortStates 100
PortAuthentication Host Modes 101 EAP
Type
Selection 102EAP-MessageD
igest
AIgo
rithm 5 102Protected EAPw/MS-CHAPv2 102 Cisco
Lightweight
EAP 103EAP-Transport
LayerSecurity
104EAP-Tunneled
Transport
Layer Security 104EAP-Flexible Authentication via Secure
Tunneling
105 ExamPreparation
106Chapter6
Implementing
andConfiguring
Basic 802.1X 109 "Do I Know ThisAlready?" Quiz
109Foundation
Topics
112Plan Basic 802.1X
Deployment
onCiscoCatalyst
IOSSoftwareGathering Input
Parameters 113Deployment
Tasks 113Deployment
Choices 114General
Deployment
Guidelines 114Configure
andVerify
CiscoCatalyst
IOSSoftware802.1XAuthenticator 115
Configuration
Choices 115Configuration
Scenario 115Verify
Basic 802.1XFunctionality
121Configure
andVerify
Cisco ACS for EAP-FAST 121Configuration
Choices 122Configuration
Scenario 122Configure
the Cisco Secure Services Client 802.1XSupplicant
128Task 1: Create the CSSC
Configuration Profile
128 Task 2: CreateaWired NetworkProfile
128Tasks 3 and 4:
(Optional)
Tune 802.1X Timers and Authentication Mode 130Task 5:
Configure
theInner and Outer EAP Modefor
theXiil
Task6: Choose the
Login
Credentialsto BeUsedfor
Authentication 132Task7:Create the CSSC Installation
Package
133 NetworkLogin
134Verify
andTroubleshoot 802.1 XOperations
134Troubleshooting
Flow 134Successful
Authentication 135Verify
Connection Status 135Verify
Authentication onAAAServer 135Verify
Guest/Restricted VLAN Assignment 135 802.1X ReadinessCheck 135Unresponsive
Supplicant
135Failed Authentication: RADIUS
Configuration
Issues 135 Failed Authentication:Bad Credentials 135Exam
Preparation
136Chapter
7Implementing
andConfiguring
Advanced 802.1X 139 "Do I KnowThisAlready?" Quiz
139Foundation
Topics
143Plan the
Deployment
of Cisco Advanced 802.IXAuthenticationFeatures 143
Gathering
InputParameters 143Deployment
Tasks 144Deployment
Choices 144Configure and
Verify
EAP-TLS Authentication on Cisco IOS ComponentsandCiscoSecure ACS 145EAP-TLS with 802.1X
Configuration
Tasks 145Configuration
Scenario 146Configuration
Choices 146Task 1:
Configure
RADIUSServer 147Task 2:Install
Identity
andCertificate
Authority Certificates
onAllClients 147
Task 3:
Configure
anIdentity Certificate
onthe Cisco Secure ACSServer 147
Task 4:
Configure
Support of
EAP-TLS onthe Cisco SecureACS Server 149
Task 5:
(Optional)
Configure
EAP-TLSSupportUsing
theMicrosoft
Windows NativeSupplicant
151xiv CCNP
Security
SECURE 642-637 Official Cert GuideImplementation
Guidelines 153Feature
Support
153Verifying
EAP-TLSConfiguration
153Deploying
User and MachineAuthentication 153Configuring
User and Machine Authentication Tasks 154Configuration
Scenario 154Task1:Install
Identity
andCertificate Authority Certificates
onAllClients 155
Task2:
Configure
Supportof
EAP-TLSonCisco SecureACS Server 155
Task3:
Configure
Support
of
Machine AuthenticationonCisco SecureACS Server 156
Task4:
Configure
Support
of
Machine AuthenticationonMicrosoft
WindowsNative 802.1XSupplicant
156Task 5:
(Optional) Configure
Machine AuthenticationSupport Using
the Cisco Secure Services Client(CSSC)
Supplicant
157Task 6:
(Optional) Configure
Additional UserSupport Using
the Cisco Secure Services Client(CSSC)Supplicant
158Implementation
Guidelines 158Feature
Support
158Deploying
VLAN and ACLAssignment
159Deploying
VLANand ACL Assignment Tasks 159Configuration
Scenario 159Configuration
Choices 160Task 1:
Configure
Cisco IOSSoftware
802.1XAuthenticator Authorization 160Task2:
(Optional) Configure
VLANAssignment
on CiscoSecure ACS 161
Task3:
(Optional)
Configure
andPrepare
for
ACLAssignment
onCiscoIOS
Softwa
reSwitch 162Task4:
(Optional) Configure
ACLAssignment
on Cisco Secure ACSServer 162
Verification
of
VLANandACLAssignment
with Cisco IOSSoftware
CLI 164Verification of
VLAN and ACLAssignment
onCiscoSecure ACS 165
Configure
andVerify
Cisco Secure ACS MACAddressException
Policies 165
Cisco
Catalyst
IOSSoftware
MAC AuthenticationXV
Configuration
Tasks 166Configuration
Scenario 166Tasks 1 and2:
Configure
MAC AuthenticationBypass
onthe Switch andACS 167Verification
of
Configuration
168Implementation
Guidelines 168Configure
andVerify
Web AuthenticationonCisco IOS Software LANSwitches and Cisco Secure ACS 168
Configuration
Tasks 169Configuration
Scenario 169Task h
Configure
Web Authenticationonthe Switch 169Task 2:
Configure
Web Authenticationonthe Cisco SecureACS Server 171
Web Authentication
Verification
172 UserExperience
172ChooseaMethodto
Support Multiple
Hostson aSingle
Port 172Multiple
HostsSupport
Guidelines 172Configuring Support
of Multiple
Hostson aSingle
Port 172Configuring Fail-Open
Policies 174Configuring
CriticalPorts 174Configuring Open
Authentication 176Resolve 802.1X
Compatibility
Issues 176 Wake-on-LAN (WOL) 176Non-802.1XIP Phones 177
PrebootExecution Environment(PXE) 177
ExamPreparation 178
PartII Cisco IOS FoundationSecurity Solutions
Chapter8 ImplementingandConfiguringCisco IOS Routed Data PlaneSecurity 183
"DoIKnow This
Already?"
Quiz 183 FoundationTopics
186RoutedData PlaneAttack
Types
186 IPSpoofing
186Slow-Path Denial
of
Service 186Traffic Flooding
187CCNP
Security
SECURE 642-637 Official Cert Guide Flexible PacketMatching
196 Flexible NetFlow 203Unicast Reverse Path
Forwarding
(Unicast RPF) 209 ExamPreparation
212Chapter
9Implementing
andConfiguring
CiscoIOS Control PlaneSecurity 219"DoI KnowThis
Already?"
Quiz 219Foundation Topics 222
ControlPlaneAttack
Types
222Slow-Path Denial
of
Service 222Routing
ProtocolSpoofing
222 Control PlaneSecurity Technologies
222 ControlPlanePolicing (CoPP)
222 Control Plane Protection(CPPr)
226Routing
Protocol Authentication 232 ExamPreparation
237Chapter10
Implementing
andConfiguring
Cisco IOSManagementPlane
Security
245"Do I Know This
Already?"
Quiz 245 FoundationTopics
248Management
Plane AttackTypes
248Management
PlaneSecurity
Technologies
248Basic
Management Security
andPrivileges
248 SSH 254SNMP 256
CPUand
Memory
Thresholding
261Managemen
tPlane Protection 2 62 AutoSecure 263Digitally Signed
CiscoSoftware
265 ExamPreparation
267Chapter
11Implementing
andConfiguring
NetworkAddressTranslation
(NAT)
275"Do I Know This
Already?"
Quiz 2 75Foundation
Topics
278Network Address Translation 278 Static NAT
Example
280XVII
PAT
Example
281 NATConfiguration
282Overlapping
NAT 287 ExamPreparation
290Chapter
12Implementing
andConfiguring
Zone-Based Policy Firewalls 295 "Do I KnowThisAlready?" Quiz
295Foundation
Topics
298Zone-Based
Policy
FirewallOverview 298Zones/SecurityZones 298 Zone Pairs 299
Transparent
Firewalls 300Zone-Based
Layer
3/4Policy
FirewallConfiguration
301 ClassMap Configuration
302Parameter
Map Configurations
304Policy Map Configuration
306 ZoneConfiguration
308 Zone PairConfiguration
309Portto
Application Mapping (PAM) Configuration
310Zone-Based
Layer
7Policy
FirewallConfiguration
312 URL Filter 313HTTP
Inspection
318 ExamPreparation
323Chapter 13
Implementing
andConfiguring
IOS Intrusion PreventionSystem (IPS)
333"Do I Know This
Already?" Quiz
333 FoundationTopics
336Configuration
Choices, BasicProcedures,andRequired Input
Parameters 336Intrusion Detection and Preventionwith Signatures 337
Sensor
Accuracy
339Choosing
aCiscoIOSIPSSensorPlatform 340Software-Based
Sensor 340 Hardware-BasedSensor 340Deployment
Tasks 341Deployment
Guidelines 342Deploying
Cisco IOS Software IPSSignature Policies 342xviii CCNPSecurity SECURE642-637 Official Cert Guide
Configuration
Scenario 342Verification
346 Guidelines 347TuningCiscoIOSSoftware IPS
Signatures
347 EventRiskRating System
Overview 348 EventRisk RatingCalculation 348 EventRisk RatingExample
349Signature
Event Action Overrides(SEAO)
349Signature
EventActionFilters(SEAF)
349Configuration
Tasks 350Configuration
Scenario 350Verification
355Implementation
Guidelines 355Deploying
Cisco IOS Software IPSSignatureUpdates
355Configuration
Tasks 356Configuration
Scenario 356Task 1; Install
Signature Update
License 356 Task2:Configure
AutomaticSignature
Updates
357Verification
357MonitoringCisco IOSSoftwareIPSEvents 358 Cisco IOS
Software
IPS Event Generation 358 Cisco IMEFeatures 358Cisco IME MinimumSystem
Requirements
359Configuration
Tasks 359Configuration
Scenario 360Task 2: Add the Cisco IOS
Software
IPS SensortoCisco IME 361Verification
362Verification:
Local Events 362Verification:
IME Events 363 Cisco IOS Software IPS Sensor 363Troubleshooting
Resource Use 365 AdditionalDebug
Commands 365Exam
Preparation
366Chapter 14 IntroductiontoCisco IOS Site-to-SiteSecuritySolutions 369
"Do I KnowThis
Already?" Quiz
3 69Foundation
Topics
372XIX
Input
Parametersfor
Choosing theBestVPNLANTopology
373General
Deployment
Guidelinesfor Choosing
the Best VPN LANTopology
373Choosean
Appropriate
VPN WANTechnology
373Input
Parametersfor
Choosingthe Best VPN WANTechnology
374 GeneralDeployment
Guidelinesfor Choosing
the Best VPN WANTechnology
376Core Features of IPsec VPN
Technology
376 IPsecSecurity
Associations 3 77Internet
Key Exchange (IKE)
377 IPsec Phases 377IKE Main and
Aggressive
Mode 378Encapsulating Security Payload
378ChooseAppropriateVPN
Cryptographic
Controls 379IPsecSecurityAssociations 379
Algorithm
Choices 379General
Deployment
Guidelinesfor
Choosing
Cryptographic
Controls
for
aSite-to-Site VPNImplementation
381Design
andImplementation
Resources 382 ExamPreparation
383Chapter15 DeployingVTI-Based Site-to-Site IPsec VPNs 387 "Do I Know This
Already?"
Quiz 387Foundation
Topics
390PlanaCisco IOSSoftwareVTI-Based Site-to-Site VPN 390
Virtual Tunnel
Interfaces
390Input
Parameters 392Deployment
Tasks 393Deployment
Choices 393General
Deployment
Guidelines 393Configuring
Basic IKEPeering
393Cisco IOS
Software Default
IKE PSK-Based Policies 394Configuration
Tasks 394Configuration
Choices 395Configuration
Scenario 395Task 1:
(Optional)
Configure
anIKEPolicy
onEachPeer 395Tasks 2 and3:Generate and
Configure
Authentication CredentialsonEachPeer 396
XX CCNPSecurity SECURE 642-637 OfficialCertGuide
Verify
Local IKE Policies 396Verify
aSuccessful
Phase 1Exchange
397Implementation
Guidelines 397Troubleshooting
IKEPeering 397Troubleshooting
Flow 397Configuring
Static Point-to-Point IPsec VTI Tunnels 398Default
Cisco IOSSoftware
IPsecTransform
Sets 398Configuration
Tasks 398Configuration
Choices 399Configuration
Scenario 399Task 1:
(Optional) Configure
anIKEPolicy
onEachPeer 399 Task2:(Optional) Configure
anIPsecTransform
Set 399 Task3:Configure
anIPsecProtectionProfile
400Task4:
Configure
a VirtualTunnelInterface
(VTI) 400Task5:
Apply
theProtectionProfile
tothe TunnelInterface
401Task 6;
Configure Routing
into the VTI Tunnel 401Implementation
Guidelines 401Verify
Tunnel Status andTraffic
401Troubleshooting
Flow 402Configure Dynamic
Point-to-Point IPsec VTI Tunnels 403 VirtualTemplates
and Virtual AccessInterfaces
403 ISAKMPProfiles
404Configuration
Tasks 404Configuration
Scenario 404 Task1:Configure
IKEPeering 405Task 2:
(Optional) Configure
anIPsecTransform
Set 405 Task 3:Configure
anIPsec ProtectionProfile
405Task4:
Configure
a VirtualTemplate Interface
406Task 5:
Map
Remote Peertoa VirtualTemplate
Interface
406Verify
Tunnel Statusonthe Hub 407Implementation
Guidelines 407 ExamPreparation 408Part III Cisco IOS ThreatDetection and Control
Chapter
16 DeployingScalable Authentication in Site-to-Site IPsec VPNs 411 "Do I Know ThisAlready?"
Quiz 411Foundation
Topics
414XXI
Trusted
Introducing
414Public Key
Infrastructure: Certificate
Authorities 416 X.509Identity Certificate
417Certificate
RevocationChecking
418Using Certificates
in NetworkApplications
419Deployment
Choices 420Deploy
men tSteps
420Input
Parameters 421Deployment
Guidelines 421Configure,
Verify,
andTroubleshootaBasic Cisco IOS Software CertificateServer 421Configuration
Tasksfor
aRootCertificate
Server 422Configuration
Scenario 423Task 1: CreateanRSA
Key
Pair 423 Task2: CreateaPK1Trustpoinr
424Tasks3and4: Create the CS and
Configure
the DatabaseLocation 424
Task5:
Configure
anIssuing Policy
425 Task6:Configure
the RevocationPolicy
425 Task 7:Configure
the SCEPInterface
426 Task 8: Enable theCertificate
Server 426 CiscoConfiguration Professional Support
426Verify
the Cisco IOSSoftware
Certificate
Server 427 FeatureSupport
427Implementation
Guidelines 428Troubleshooting
Flow 429PKI and Time: AdditionalGuidelines 429
EnrollaCisco IOS SoftwareVPNRouter intoaPKI and Troubleshoot the
EnrollmentProcess 429
PKI Client Features 42 9
Simple Certificate
EnrollmentPro tocol 43 0Key Storage
430Configuration
Tasks 430Configuration
Scenario 431 Task1: CreateanRSAKey
Pair 431Task2: CreateanRSA
Key
Pair 432Task3:Authenticatethe PKI
Certificate Authority
432xxii CCNP
Security
SECURE 642-637 Official Cert GuideTask5:Issue theClient
Certificate
ontheCA Server 434Certificate
Revocationon the Cisco IOSSoftware
Certificate
Server 434Cisco
Configuration Professional
Support
434Verify
the CA andIdentity Certificates
435 FeatureSupport
435Implementation
Guidelines 436Troubleshooting
Flow 436Configure
andVerify
theIntegrationofaCiscoIOS SoftwareVPN Routerwith SupportingPKI Entities 436
IKE Peer Authentication 436
IKEPeer
Certificate
Authorization 437Configuration
Tasks 437Configuration
Scenario 437Task 1:
Configure
anIKEPolicy
438Task 2:
Configure
an1SAKMPProfile
438Task3:
Configure
Certificate-Based
Authorizationof
Remote Peers 438Verify
IKE SA Establishment 43 9 FeatureSupport
439Implementation
Guidelines 440Troubleshooting
Flow 44 0Configuring
Advanced PKIIntegration 440Configuring
CRLHandling
onPKIClients 441Using
OCSPorAAAonPKIClients 441ExamPreparation 442
Chapter
17 DeployingDMVPNs 447"Do IKnowThis
Already?"
Quiz
447Foundation Topics 451
Understanding
theCisco IOS Software DMVPNArchitecture 451
Building
Blocksof
DMVPNs 452Hub-and-Spoke
Versus On-DemandFully
MeshedVPNs 452 DMVPN Initial State 453DMVPN
Spoke-to-Spoke
Tunnel Creation 453 DMVPNBenefits
and Limitations 454Plan the
Deployment
ofaCisco IOS SoftwareDMVPN 455Deployment
Tasks 455Deployment
Choices 456General
Deployment
Guidelines 456Configure
andVerify
Cisco IOS SoftwareGRETunnels 456GRE Features and Limitations 456
Point-to-PointVersus
Point-to-Multipoint
GRETunnels 457 Point-to-PointTunnelConfiguration Example
457Configuration
Tasksfor
aHub-and-Spoke
Network 459Configuration
Scenario 459Task1:
Configure
anmGREInterface
onthe Hub 459Task2:
Configure
aGREInterface
ontheSpoke
459Verify
the StateofGRE Tunnels 460Configure
andVerify
aCisco IOS Software NHRP Client andServer 461(m)GREand NHRP
Integration
461Configuration
Tasks 461Configuration
Scenario 461Task 1:
Configure
anNHRP Server 461Task 2:
Configure
anNHRP Client 462Verify
NHRPMappings
462Debugging
NHRP 463Configure
andVerify
a Cisco IOS Software DMVPN Hub 464Configuration
Tasks 464Configuration
Scenario 464Task 1:
(Optional) Configure
anIKEPolicy
464Task 2; Generate and/or
Configure
Authentication Credentials 465Task 3:
Configure
anIPsecProfile
465Task 4: CreateanmGRETunnel
Interface
465Task 5:
Configure
the NHRP Server 465Task 6: Associate the IPsec
Profile
with themGREInterface
466 Task 7:Configure
IP Parametersonthe mGREInterface
466Cisco
Configuration Professional Support
466Verify Spoke Registration
466Verify Registered
Spoke
Details 467Implementation
Guidelines 468 FeatureSupport
468xxiv CCNP
Security
SECURE 642-637Official Cert GuideConfiguration
Tasks 468Configuration
Scenario 469Task 1:
(Optional) Configure
anIKEPolicy
469Task 2: Generate and/or
Configure
AuthenticationCredentials 469Task3:
Configure
anIPsecProfile
469 Task4: CreateanmGRETunnelInterface
470 Task5:Configure
theNHRPClient 470Task6: AssociatetheIPsec
Profile
with themGREInterface
470Task7:
Configure
IP ParametersonthemGREInterface
471Verify
TunnelStateandTraffic
Statistics 471Configure
andVerify Dynamic
RoutinginaCisco IOSSoftware DMVPN 471 EIGRP Hub
Configuration
472 OSPF HubConfiguration
473Hub-and-Spoke Routing
and IKEPeering
onSpoke
473Full Mesh
Routing
and IKEPeering
onSpoke
474TroubleshootaCisco IOS Software DMVPN 474
Troubleshooting
Flow 475ExamPreparation 476
Chapter 18 Deploying High AvailabilityinTunnel-Based IPsecVPNs 481
"DoIKnowThis
Already?"
Quiz 481 FoundationTopics
484Plan the
Deployment
ofCisco IOSSoftwareSite-to-Site IPsec VPNHigh-Availability
Features 484VPNFailureModes 484
PartialFailure
of
theTransport
Network 484PartialorTotal Failure
of
the ServiceProvider (SP)Transport
Network 485
PartialorTotalFailure
of
aVPN Device 485Deployment
Guidelines 485Use
Routing
Protocols for VPN Failover 486Routing
to VPN TunnelEndpoints
486Routing
Protocol Inside the VPN Tunnel 486Recursive
Routing
Hazard 487Routing
ProtocolVPNTopologies
487XXV
Choosethe Most
Optimal
Method ofMitigating
Failure inaVTI-Based VPN 488
Path
Redundancy
Using
aSingle-Transport
Network 489 PathRedundancy Using
TwoTransport
Networks 489Path and Device
Redundancy
inSingle-Transport
Networks 489 Path and DeviceRedundancy
withMultiple-Transport
Networks 489
Choose the Most
Optimal
MethodofMitigating
Failure inaDMVPN 490Recommended Architecture 490 Shared IPsecSAs 490
Configuring
aDMVPN withaSingle-Transport
Network 490Configuring
aDMVPNoverMultiple-Transport
Networks 493ExamPreparation 495
Chapter
19Deploying
GET VPNs 499"DoI Know This
Already?" Quiz
499Foundation
Topics
502Describethe
Operation
ofaCisco IOS Software GET VPN 502Peer Authentication and
Policy Provisioning
502GET VPN
Traffic Exchange
504Packet
Security
Services 504Key Management
Architecture 505Rekeying
Methods 505Traffic
Encapsulation
507Benefits
and Limitations 507Plan the
Deployment
ofaCisco IOSSoftware GETVPN 508Input
Parameters 508Deployment
Tasks 508Deployment
Choices 509Deployment
Guidelines 509Configure
andVerify
aCiscoIOSSoftware GET VPNKey
Server 509Configuration
Tasks 509Configuration
Choices 510Configuration
Scenario 510Task 1:
(Optional)
Configure
anIKEPolicy
511Task 2:Generate and/or
Configure
AuthenticationCredentials 511
xxvi CCNPSecuritySECURE 642-637 Official Cert Guide
Task4:
Configure
aTraffic
ProtectionPolicy
ontheKey
Server 512Task 5:Enableand
Configure
theGETVPNKey
ServerFunction 512
Task 6:
(Optional)
Tune theRekeyingPolicy
513Task7: Create and
Apply
the GET VPNCrypto Map
513Cisco
Configuration Professional Support
514Verify
BasicKeyServerSettings
514Verify
the RekeyPolicy
514 ListAllRegistered
Members 515Implementation
Guidelines 515Configure
andVerify
CiscoIOSSoftware GET VPNGroup
Members 515Configuration
Tasks 516Configuration
Choices 516Configuration
Scenario 516Task 1:
Configure
anIKEPolicy
516Task2: Generate and/or
Configure
Authentication Credentials 517Task3:Enable the GET VPN
Group
Member Function 518 Task 4: Create andApply
the GET VPNCrypto Map
518Task5:
(Optional) Configure
aFail-ClosedPolicy
518Cisco
Configuration Professional Support
519Verify
Registrationof
theGroup
Member 519Implementation
Guidelines 519Troubleshooting
Flow 519Configure
andVerify
High-Availability
Mechanisms inaGET VPN 520Network
Splits
and Network Merges 521Configuration
Tasks 521Configuration
Scenario 521Task 1: Distribute the
Rekey
RSAKey
Pair 522Task2:
Configure
aFull Meshof Key
Server IKEPeering 522Task 3:
Configure
COOP 522Tasks4 and5:
Configure Traffic
ProtectionPolicy
andMultiple
Key ServersonGroup
Members 523Verify
IKEPeering
523XXVil
Implementation
Guidelines 524Troubleshooting
Flow 524ExamPreparation 525
Part IV
Managing
andImplementing
Cisco IOS Site-to-SiteSecurity
SolutionsChapter20
Deploying
Remote Access SolutionsUsing
SSL VPNs 529 "Do I Know ThisAlready?" Quiz
529Foundation
Topics
533Choosean
Appropriate
Remote Access VPNTechnology
533Cisco IOS
Software
Remote Access VPNOptions
533 FullTunneling
Remote Access SSL VPN: Features 533 FullTunneling
RemoteAccess SSL VPN:Benefits
andLimitations 534
Clientless RemoteAccessSSL VPN:Features 534 ClientlessSSLVPN:
Benefits
andLimitations 535Software
ClientRemoteAccessIPsecVPN (EZVPN):Features 535 Hardware ClientRemote Access IPsec VPN(EZVPN):Features 536 Remote Access IPsec VPN:Benefits
andLimitations 53 6VPN AccessMethods: Use Cases 536
Choose
Appropriate
Remote Access VPNCryptographic
Controls 537
SSL/TLS
Refresher
537Algorithm
Choices in Cisco SSL Remote Access VPNs 539 IKE Remote Access VPN Extensions 53 9Algorithm
Choices in Cisco IPsec Remote Access VPNs 540Deploying
Remote Access SolutionsUsing
SSL VPNs 541 SolutionComponents
541Deployment
Tasks 541Input
Parameters 542Configure
andVerify
Common SSL VPN Parameters 542Configuration
Tasks 543Configuration
Choices 543Configuration
Scenario 543Task 1:
(Optional) Verify
SSL VPNLicensing
544 Task 2: ProvisionanIdentity
Server SSL/TLSCertificate
tothe ISR 544
xxviii CCNP
Security
SECURE 642-637 Official Cert GuideTask 5:
(Optional) Configure Gateway High Availability
545Gateway Verification
545Implementation
Guidelines 546Configure
andVerify
Client Authentication and Policiesonthe SSL VPN
Gateway
546Gateway,
Contexts,andPolicy Groups
546BasicUser Authentication Overview 546
Configuration
Tasks 547ConfigurationScenario 547
Task 1: Createand
Apply
aDefault Policy
548Task 2:Enable UserAuthentication
Using
LocalAAA 548Implementation
Guidelines 548Configure
andVerify
FullTunneling Connectivity
onthe Cisco 10S SSLVPN
Gateway
549Configuration
Tasks 549Configuration
Scenario 549Task 1: Enable Full
Tunneling
Access 549Task 2:
Configure
LocalIPAddress Assignment 550 Task3:(Optional)
Configure
ClientConfiguration
551 Task 4:(Optional)
Configure Split Tunneling
551 Task 5:(Optional) Configure
AccessControl 551 CiscoConfiguration
Professional
Support
552Install and
Configure
theCiscoAnyConnect
Client 552AnyConnect
2.4-Supported Platforms
553Configuration
Tasks 553Configuration
Scenario 553Task1: Enable Full
Tunneling
Access 553Task2:
Verify
ServerCertificate
Authentication Chain 554 Task 3:Configure
BasicAnyConnect Profile Settings
554Task 4: Establish the SSLVPN Connection 554 Client-Side
Verification
554Gateway-Side Verification
555 CiscoConfiguration
Professional
556Configure
andVerify
Clientless Accessonthe Cisco IOS SSL VPNGateway
556BasicPortalFeatures 556
xxix
Port
Forwarding Benefits
andLimitations 558 Portal ACLs 558Configuration
Tasks 558Configuration
Scenario 559Task1: EnableFull
Tunneling
Access 560Task 2:
(Optional)
Configure
PortForwarding
560 Task 3:(Optional) Configure
Cisco SecureDesktop
561Task4:
(Optional) Configure
Access Control 561 Basic PortalVerification
562Web
Application
Access 562 File ServerAccess 562 PortForwarding
Access 562Cisco Secure
Desktop Verification
563Gateway-Side Verification
563Troubleshoot the BasicSSLVPN
Operation
563Port
Forwarding
Access 563Troubleshooting
Flow(VPN Establishment) 563Troubleshooting
Flow(DataFlow)
563Gateway-Side
Issue 564Client-Side Issues:
Certificates
564ExamPreparation 565
Chapter21 Deploying Remote Access SolutionsUsingEZVPNs 569 "Do I Know This
Already?"
Quiz 569Foundation
Topics
572Plan the
Deployment
ofa Cisco IOS Software EZVPN 572Solution
Components
573Deployment
Tasks 573Input
Parameters 574Deployment
Guidelines 574Configure
andVerify
aBasic Cisco IOS Software VTI-Based EZVPNServer 575
Group
Pre-SharedKey
Authentication 575ExtendedAuthentication
(XAUTH)
Overview 575Configuration Groups
and ISAKMPProfiles
576Configuration
Tasks 576Configuration
Scenario 576XXX CCNPSecuritySECURE 642-637 Official Cert Guide
Task 2:
Configure
anIPsecTransform
Set andProfile
577 Task3:Configure
aDynamic
VTITemplate
577Task 4; CreateaClient
Configuration Group
578Task 5: CreateanISAKMP
Profile
578Tasks 6 and 7:
Configure
and EnableUserAuthentication 579 CiscoConfiguration Professional Support
579Implementation
Guidelines 580Configure
theCiscoVPNClient 580Configuration
Tasks 580Configuration
Scenario 580Task1:Install theCisco VPNClient
Software
580Task2:
Configure
the VPN Client ConnectionEntry
580 Task3:Establish theEZVPN Connection 581Client-Side
Verification
581Gateway-Side Verification
581Configure
andVerify
VTI-Based EZVPN Remote ClientFunctionality
onthe Cisco ISR 582EZVPN Remote Modes 582
Configuration
Tasks 583Configuration
Scenario 583Task1:
Configure
EZVPN RemoteProfile
583 Task2;Designate
EZVPNInterface
Roles 584Implementation
Guidelines 584Configure
andVerify
EZVPN Server and VPN ClientPKIFeatures 585Head-EndPKI
Configuration
585VPNClient
Configuration:
SCEP Enrollment 585 VPNClientEnrollmentVerification
586VPNClient
Configuration:
Profile
586TroubleshootBasic EZVPN
Operation
587Troubleshooting
Flow: VPNSession Establishment 587Troubleshooting
Flow. VPNDataFlow 587Exam
Preparation
588Chapter
22 FinalPreparation 591Tools for Final
Preparation
591Pearson Cert PracticeTest Engine and QuestionsontheCD 591
Install the
Software
from
the CD 592xxxi
Activating
Other Exams 593 Premium Edition 593Cisco
Learning
Network 593MemoryTables 593
Chapter-Ending
Review Tools 594Suggested
Plan for FinalReview/Study
594Step1: Review the Key
Topics,
the DIKTAQuestions,and theFill intheBlanks Questions 595
Step2:
Complete
theMemoryTables 595Step
3: Do Hands-OnPractice 595Step
4:BuildConfiguration
Checklists 596Step
5: Use theExamEngine 596Appendix
A Answers toChapterDIKTAQuizzesand Fill in the Blanks Questions 599Appendix
B CCNPSecurity
642-637 SECUREExamUpdates,
Version 1.0 621 Index 622ElementsAvailableonCD AppendixC MemoryTables
AppendixD