Course Introduction
- Overview
- Course Objectives
- Lab Topology Overview
-
Security Fundamentals
- Need for Network Security
- Network Security Policy
- Primary Network Threats and Attacks
- Reconnaissance Attacks and Mitigation
- Access Attacks and Mitigation
- Denial of Service Attacks and Mitigation
- Worm, Virus and Trojan Horse Attacks and Mitigation
- Management Protocols and Fucntions
Intrusion Detection Overview
- Intrusion Detection Terminology
- Intrusion Detection Technologies
- Network Based Intrusion Detection Systems
- Host Based Intrusion Prevention System
- Intrusion Protection Benefits
- Network Sensor Platforms
- Host Based Intrusion Protection System
- Sensor Appliances
Deploying Cisco Ids
Cisco Intrusion Detection System Architecture.
- Cisco IDS Software Architecture
- Cisco IDS Communication
- User Accounts and Roles
Getting Started with the IDS Command Line Interface
- Sensor Installation
- Sensor Initialization
- Command Line Modes
- Completing the Initial Configuration
- Preventive Maintenance and Troubleshooting
Sensor Management and Monitoring
- IDS Device Manager Overview
- IDS Event Viewer Overview
- IDS Event Viewer Installation
- IDS Event Viewer Views
- IDS Event Viewer Filters Network Security Database
Using the Intrusion Detection System
Device Manager to Configure a Sensor
Configuring Basic Sensor Settings
Configuring SSH Communications
Configuring TLS Communcications
Configuring Monitoring
Viewing Diagnostics and System Information
Cisco Intrusion Detection System Alarms and Signatures
- Cisco IDS Signatures
- Cisco IDS Alarms
- Cisco IDS Signature Engines
- Atomic Signature Engines
- Flood Signature engines
- Service Signature Engines
- State Signature Engines
- String Signature Engines
- Sweep Signature Engines
- Miscellaneous Signature Engines
Signature Configuration
- Signature Configuration
- Signature Tuning
- Custom Signatures
- Custom Signature Scenarios
Sensor Tuning
- Intrusion Detection Evasive Techniques
- Tuning the Sensor
- Logging
- Reassembly Options
- Alarm Channel System Variables
- Alarm Channel Event Filtering
Blocking Configuration
- ACL Considerations
- Blocking Sensor Configuration
- Master Blocking Sensor Configuration
Cisco Intrusion Detection System Maintenance
- Service Pack and Signature Updates
- Image Recovery
- Resetting, Powering Down, and Restoring the Default Configuration
- Time Settings
Enterprise Intrusion Detection System Maintenance
- Windows Installation
- Solaris Installation
- Architecture
- Getting started with the IDS MC
- Sensors and Sensor Groups
- Using the IDSMC to configure the Sensor
- IDS MC Workflow
- Updating the IDS MC
Enterprise Intrusion Detection System Monitoring and Reporting
- Installation
- Getting Started
- Monitoring
- Customizing the Event Viewer
- Reporting
- Administration
- Cisco Threat Response
Cisco Intrusion Detection System Network Module
- NM-CIDS Overview
- How the NM-CIDS Works
- Design Considerations
- Installation and Configuration Tasks
- Maintenance Tasks Unique to the NM-CIDS
Intrusion Detection System Module Configuration
- Ports and Traffic
- Initialization
- Verifying IDSM-2 Status
Capturing Network Traffic for Intrusion Detection Systems
- Traffic Capture Overview
- Configuring SPAN for Catalyst 4500 and 6500 Traffic Capture
- Configuring RSPAN fro Catalyst 4500 and 6500 Traffic capture
- Configuring VACLs for Catalyst 6500 Traffic Capture Advanced Catalyst 6500 Traffic Capture
Objectives
- Describe the basic intrusion detection terminology.
- Explain the different intrusion detection technologies and evasive techniques.
- Design a Cisco IDS protection solution for small, medium, and enterprise customers.
- Identify the Cisco IDS Sensor platforms and describe their features.
- Install and configure a Cisco IDS Sensor.
- Install and configure a Cisco Intrusion Detection System Module 2.
- Install and configure a Cisco Network Module for Cisco 2600, 3600, and 3700 routers.Tune Cisco IDS signatures to work optimally in unique network environments.
- Create and implement customized intrusion detection signatures.
- Create alarm exceptions to reduce alarms and possible false positives.
- Configure a Cisco IDS Sensor to perform device management of supported blocking devices.
- Describe the Cisco IDS signatures and determine the immediate threat posed to the network.
- Perform maintenance operations such as signature updates and software upgrades.
- Describe the Cisco IDS architecture.Manage a large scale deployment of Cisco IDS Sensors with Cisco IDS Management and Monitoring software