The course introduces students to a list of threats and vulnerabilities inherent in typical switched (L2) networks, and security measures (settings) that can be used to prevent these threats. These settings do not require a specific functionality (feature set) of the operating systems of Cisco Systems switches and routers and, in general, are available in the vast majority of IOS already running network devices.
After completing this course, students will be able to:
- Identify threats: recognize typical vulnerabilities and attacks typical of switched (L2) networks.
- Protect network infrastructure: configure security measures on switches and routers yourself.
- Prevent network attacks: practically apply standard device functionality to neutralize threats
Audience Profile
- Cisco corporate routed network administrators
- Information security specialists for enterprises and organizations with developed network infrastructures
Before attending this course, students must have:
- CCNA (Cisco Certified Network Associate) level knowledge
- significant work experience with Cisco Systems routers (Cisco IOS CLI)
1. Introduction.
2. Data Plane (L2) Security Controls.
- VLAN-Based Attacks Mitigation.
- STP Attacks Mitigation
- Private VLANs
- DHCP Snooping.
- ARP Inspection.
- Storm Control.
3. Data Plane (L3) Security Controls.
- Infrastructure (Antispoofing) ACLs.
- Unicast Reverse Path Forwarding (URPF).
- IP Source Guard.
4. Control Plane Security.
- Control Plane Policing (CoPP).
- Control Plane Protection (CoPPr).
- Routing Protocols Security.
5. Cisco Identity-Based Network Services (IBNS v1/v2).
- IBNS Architecture and Components.
6. 802.1X Authentication.
- 802.1X EAP Authentication.
- EAP Methods.
- RADIUS in EAP Communications.
7. 802.1X Authentication Configuration.