Implementing Secure Converged Wide Area Networks (ISCW) Course

Course Code: TO 101
Course Abstract:

The Implementing Secure Converged Wide Area Networks (ISCW 642-825) is a qualifying exam for the Cisco Certified Network Professional CCNP®. The ISCW 642-825 exam will certify that the successful candidate has important knowledge and skills necessary to secure and expand the reach of an enterprise network to teleworkers and remote sites with focus on securing remote access and VPN client configuration. The exam covers topics on Cisco hierarchical network model as it pertains to the WAN, teleworker configuration and access, frame mode MPLS, site-to-site IPSEC VPN, Cisco EZVPN, strategies used to mitigate network attacks, Cisco device hardening and IOS firewall features.

The 642-825 exam will be replacing the 642-821 (BCRAN) exam.  The 642-825 exam is one of four core exams required for the Cisco CNP certification.

Audience: This course is primarily targeted at IT professionals who have a large amount of experience with network design and implementation.
Duration: 5 days
Learning Outcomes: Upon completion of this course, the participant will be able to:
> Specify and /or identify the Cisco products that best meet the WAN connection requirements for permanent or dialup access connections
> Explain and/or identify the advantages and disadvantages of WAN connection types
> Select the appropriate WAN connection types that address specific site connection considerations
> Select Cisco equipment that will suit the specific needs of a WAN topology
> Identify the components and connections necessary to allow WAN connections like Frame Relay, and ISDN PRI from the central site to a branch office
> Identify the components and connections necessary to allow WAN connections like Frame Relay, and ISDN BRI from a branch office to the central site
> Identify the components and connections necessary to allow a WAN connections like ISDN BRI from a telecommuter site to the central site
> Specify the commands and procedures necessary to configure an access server for modem connectivity so telecommuters can access the central site
> Specify the commands and procedures to configure the central site for dial out connections
> Specify the commands used to reverse Telnet to the modem and configure the modem for basic asynchronous operations
> Specify the commands and procedures used to set up the modem auto configuration feature
> Specify the commands and syntax used to configure a PPP connection between the central site and a branch office
> Specify the commands and syntax to configure PAP or CHAP authentication to allow access to a secure site
> Configure Multilink PPP to increase the data throughput
> Specify the commands used to verify proper PPP configuration and troubleshoot an incorrect PPP configuration
> Accessing the Central Site with Windows 95
> Specify the commands and procedures to configure a PC to complete a dialup call to the central site router through the traditional telephone network
> Identify when to use ISDN BRI and PRI services and select the service that best suits a set of given requirements
> Identify the Q921 and Q931 signaling and call setup sequences
> Specify the commands used to configure ISDN BRI and PRI
> Specify the commands used to configure DDR
> Specify or select appropriate dialup capabilities to place a call
> Specify the commands and procedures to configure rotary groups and dialer profiles
> Specify the commands used to verify proper dialer profile or rotary group configuration and troubleshoot an incorrect configuration
> Specify the commands and procedures to configure an X25 WAN connection between the central office and branch office
> Specify proper X121 addresses and the commands used to assign them to router interfaces
> Specify the commands and procedures used to verify proper X25 configuration and troubleshoot incorrect X25 configuration
> Specify the commands and procedures used to configure a Frame Relay WAN connection between the central office and branch office
> Specify the commands to configure sub-interfaces on virtual interfaces to solve split horizon problems
> Specify the commands used to configure Frame Relay traffic shaping
> Specify the commands and procedures used to verify proper Frame Relay configuration and troubleshoot an incorrect configuration
> Specify the procedure and commands used to configure a backup
Specify the procedure and commands used to configure a backup connection to activate when the primary line reaches a specified threshold
> Specify the procedure and commands used to configure a dialer to function as backup to the primary interface
> Determine why queuing is enabled, identify alternative queuing protocols that Cisco products support, and determine the best queuing method to implement
> Specify the commands to configure weighted-fair, priority and custom queuing
> Specify the commands and procedures used to verify proper queuing configuration and troubleshoot incorrect configuration
> Specify the commands and procedures used to effectively select and implement compression
> Describe how NAT and PAT operate
> Specify the commands and procedures to configure NAT and PAT to allow reuse of registered IP addresses in a private network
> Verify proper configuration of NAT and PAT with available Cisco verification commands
> Specify, recognize or describe the security features of CiscoSecure and the operation of a CiscoSecure server
> Specify the commands and procedures used to configure a router to access a CiscoSecure server and to use AAA
> Specify the commands used to configure AAA on a router to control access from remote access clients
Course Topics:

IMPLEMENT BASIC TELEWORKER SERVICES
Describe Cable (HFC) technologies
Describe xDSL tedchnologies
Configure ADSL (i.e., PPPoE or PPPoA)
Verify basic teleworker configurations

IMPLEMENT FRAME-MODE MPLS
Describe the components and operation of Frame-Mode MPLS (e.g., packet-based MPLS VPNs)
Configure and verify Frame-Mode MPLS

IMPLEMENT A SITE-TO-SITE IPSEC VPN
Describe the components and operations of IPSec VPNs and GRE Tunnels
Configure a site-to-site IPSec VPN/GRE Tunnel with SDM (i.e., preshared key)
Verify IPSec/GRE Tunnel configurations (i.e., IOS CLI configurations)
Describe, configure, and verify VPN backup interfaces
Describe and configure Cisco easy VPN solutions using SDM

DESCRIBE NETWORK SECURITY STRATEGIES
Describe and mitigate common network attacks (i.e., Reconnaissance, Access, and Denial of Service)
Describe and mitigate Worm, Virus, and Trojan Horse attacks
Describe and mitigate application-layer attacks (e.g., management protocols)

IMPLEMENT CISCO DEVICE HARDENING
Describe, configure, and verify AutoSecure/One-Step Lockdown implementations (i.e., CLI and SDM)
Describe, configure, and verify AAA for Cisco Routers
Describe and configure threat and attack mitigation using ACLs
Describe and configure IOS secure management features (e.g., SSH, SNMP, SYSLOG, NTP, Role-Based CLI, ect.)

IMPLEMENT CISCO FIREWALL
Describe the functions and operations of Cisoc IOS Firewall (e.g., Stateful Firewall, CBS, etc.)
Configure Cisco IOS Firewall with SDM
Verify Cisco IOS Firewall configurations (i.e., IOS CLI configurations, SDM Monitor)

DESCRIBE AND CONFIGURE CISCO IOS IPS
Desdcribe the functions and operations of IDS and IPS systems (e.g., IDS/IPS signatures, IPS Alarms, etc.)
Configure Cisco IOS IPS using SDM

Prerequisites: Due to the pace and duration of this course, ideal candidates for this course operate in medium to very large computing environment:
> They have a minimum of one-year experience working in a LAN/WAN environment
> They have a minimum of six months experience in a multi-LAN environment
> Hold the Cisco Certified Network Associate Certification
Note: All fields are required
At the present time we do not offer training for individuals or groups less then 6 individuals. We apologize for any inconvenience.


We Value Your Privacy!

Ready to get started or in need of more information? Contact us today.

Go To Blog Virtual Learning