|
|
Day One
|
|
|
Introduction
|
|
|
ScreenOS VPN Review
|
|
|
- Review policy-based VPN configuration
|
|
|
- Review route-based VPN configuration
|
|
|
- Review Security Manager VPN Manager
|
|
|
- Review verification commands
|
|
|
- Review troubleshooting tools
|
|
|
- Describe and configure VPN Monitor
|
|
|
VPN Variations
|
|
|
- Configure LAN-to-LAN VPN with a dynamic peer using ID
|
|
|
- Configure LAN-to-LAN VPN with a dynamic peer using FQDN
|
|
|
- Configure VPN with ScreenOS device in transparent mode
|
|
|
- Configure VPN with ScreenOS device in transparent mode
|
|
|
Hub and Spoke VPNs
|
|
|
- Describe the concept of a Hub and Spoke VPN
|
|
|
- Describe different Hub and Spoke scenarios
|
|
|
- Configure Hub and Spoke VPNs using the following scenarios:
|
|
|
- Policy-based
|
|
|
- Interfaces in same zone as protected resources (using NHTB)
|
|
|
- Interfaces in different zones than protected resources
|
|
|
- Centralized spoke-to-spoke control
|
|
|
- Verify Configuration
|
|
|
Routing over VPNs
|
|
|
- Explain dynamic routing operations over VPN links
|
|
|
- Configure RIP over VPN links
|
|
|
- Configure OSPF over VPN links
|
|
|
|
|
|
Day Two
|
|
|
Using Certificates
|
|
|
- Define and explain the following concepts:
|
|
|
- Public Key Cryptography
|
|
|
- Digital Signatures
|
|
|
- Digital Certificates
|
|
|
- Public Key Cryptography Standard (PKCS)
|
|
|
- Certification Authority (CA)
|
|
|
- Certificate Revocation List (CRL)
|
|
|
- Online Certificate Status Protocol (OCSP)
|
|
|
- Acquire and load certificates and CRLs
|
|
|
- Configure LAN-to-LAN IPSec VPN using certificates for authentication
|
|
|
Redundant VPN Gateways
|
|
|
- Describe the functionality of the ScreenOS redundant VPN gateway feature
|
|
|
- Configure redundant VPN gateways
|
|
|
- Discuss other redundancy
|
|
|
GRE
|
|
|
- Explain GRE technology and terminology
|
|
|
- Discuss GRE applications
|
|
|
- Configure GRE
|
|
|
- Verify operations
|
|
|
Dial-Up VPNs
|
|
|
- Discuss dial-up VPN options
|
|
|
- Basic
|
|
|
- Multiple tunnels/split tunneling
|
|
|
- Group IKE ID
|
|
|
- Shared IKE ID and XAUTH
|
|
|
- Compare/contrast dial-up IPSec VPNs with SSL VPNs
|
|
|
- Configure ScreenOS device for dial-up VPN connection
|
|
|
NetScreen-Remote
|
|
|
- Introduce NetScreen-Remote VPN client product
|
|
|
- Configure client for dial-up VPN connectivity
|
|