
Speaker(s) Jason Scobbie - Technical Lead, Cisco
The increase in network complexity has pushed security to the forefront of design and policy. This session provides guidance on design and deployment of an effective security access policy for IOS routers. It starts by providing configuration guidance on deploying a comprehensive Zone Based Firewall (ZBFW) policy, including monitor tools, rate limiting, connection control and advanced application layer filtering.
The session reinforces advanced security through identity-based features including downloadable ACLs, user-based authentication and SGT integration. These solutions are provided within the framework of active, passive and transparent authentication. The session continues with ensuring redundancy by showing examples of setting up two routers with ZBFW in a high availability pair. The session concludes with protections against various network common network attacks. IPv6 security features are integrated throughout the session. The session integrates troubleshooting and monitoring tools to bridge theory and application. A complete sample configuration is a deliverable for participants to build a custom and independent security policy.
The session is targeted at security administrators who are responsible for their network access policies. It is important to emphasize that this breakout does not cover VPN, L2 Security, IOS IPS or IOS hardening techniques. This session expands on the fundamentals discussed in BRKSEC-2007.
PDF+APPENDIX: Download BRKSEC-3007-ADVANCED-IOS-SECURITY
Recent Comments