Book description
Cisco® ASA
All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition
Identify, mitigate, and respond to today’s highly-sophisticated network attacks.
Today, network attackers are far more sophisticated, relentless, and dangerous. In response, Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services has been fully updated to cover the newest techniques and Cisco technologies for maximizing end-to-end security in your environment. Three leading Cisco security experts guide you through every step of creating a complete security plan with Cisco ASA, and then deploying, configuring, operating, and troubleshooting your solution.
Fully updated for today’s newest ASA releases, this edition adds new coverage of ASA 5500-X, ASA 5585-X, ASA Services Module, ASA next-generation firewall services, EtherChannel, Global ACLs, clustering, IPv6 improvements, IKEv2, AnyConnect Secure Mobility VPN clients, and more. The authors explain significant recent licensing changes; introduce enhancements to ASA IPS; and walk you through configuring IPsec, SSL VPN, and NAT/PAT.
You’ll learn how to apply Cisco ASA
adaptive identification and mitigation services to systematically
strengthen security in network environments of all sizes and types.
The authors present up-to-date sample configurations, proven design
scenarios, and actual debugs–
all designed to help you make the most of Cisco ASA in your rapidly
evolving network.
Jazib Frahim, CCIE® No. 5459 (Routing and Switching; Security), Principal Engineer in the Global Security Solutions team, guides top-tier Cisco customers in security-focused network design and implementation. He architects, develops, and launches new security services concepts. His books include Cisco SSL VPN Solutions and Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting.
Omar Santos, CISSP No. 463598, Cisco Product Security Incident Response Team (PSIRT) technical leader, leads and mentors engineers and incident managers in investigating and resolving vulnerabilities in Cisco products and protecting Cisco customers. Through 18 years in IT and cybersecurity, he has designed, implemented, and supported numerous secure networks for Fortune® 500 companies and the U.S. government. He is also the author of several other books and numerous whitepapers and articles.
Andrew Ossipov, CCIE® No. 18483 and CISSP No. 344324, is a Cisco Technical Marketing Engineer focused on firewalls, intrusion prevention, and data center security. Drawing on more than 16 years in networking, he works to solve complex customer technical problems, architect new features and products, and define future directions for Cisco’s product portfolio. He holds several pending patents.
Understand, install, configure, license, maintain, and troubleshoot the newest ASA devices
Efficiently implement Authentication, Authorization, and Accounting (AAA) services
Control and provision network access with packet filtering, context-aware Cisco ASA next-generation firewall services, and new NAT/PAT concepts
Configure IP routing, application inspection, and QoS
Create firewall contexts with unique configurations, interfaces, policies, routing tables, and administration
Enable integrated protection against many types of malware and advanced persistent threats (APTs) via Cisco Cloud Web Security and Cisco Security Intelligence Operations (SIO)
Implement high availability with failover and elastic scalability with clustering
Deploy, troubleshoot, monitor, tune, and manage Intrusion Prevention System (IPS) features
Implement site-to-site IPsec VPNs and all forms of remote-access VPNs (IPsec, clientless SSL, and client-based SSL)
Configure and troubleshoot Public Key Infrastructure (PKI)
Use IKEv2 to more effectively resist attacks against VPNs
Leverage IPv6 support for IPS, packet inspection, transparent firewalls, and site-to-site IPsec VPNs
Table of contents
- About This eBook
- Title Page
- Copyright Page
- About the Authors
- About the Technical Reviewers
- Dedications
- Acknowledgments
- Contents at a Glance
- Contents
- Icons Used in This Book
- Command Syntax Conventions
- Foreword
- Introduction
- Chapter 1. Introduction to Security Technologies
-
Chapter 2. Cisco ASA Product and Solution Overview
- Cisco ASA Model Overview
- Cisco ASA 5505 Model
- Cisco ASA 5510 Model
- Cisco ASA 5512-X Model
- Cisco ASA 5515-X Model
- Cisco ASA 5520 Model
- Cisco ASA 5525-X Model
- Cisco ASA 5540 Model
- Cisco ASA 5545-X Model
- Cisco ASA 5550 Model
- Cisco ASA 5555-X Model
- Cisco ASA 5585-X Models
- Cisco Catalyst 6500 Series ASA Services Module
- Cisco ASA 1000V Cloud Firewall
- Cisco ASA Next-Generation Firewall Services (Formerly Cisco ASA CX)
- Cisco ASA AIP-SSM Module
- Cisco ASA Gigabit Ethernet Modules
- Summary
- Chapter 3. Licensing
- Chapter 4. Initial Setup
- Chapter 5. System Maintenance
- Chapter 6. Cisco ASA Services Module
-
Chapter 7. Authentication, Authorization, and Accounting (AAA) Services
- AAA Protocols and Services Supported by Cisco ASA
- Defining an Authentication Server
- Configuring Authentication of Administrative Sessions
- Authenticating Firewall Sessions (Cut-Through Proxy Feature)
- Customizing Authentication Prompts
- Configuring Authorization
- Configuring Accounting
- Troubleshooting Administrative Connections to Cisco ASA
- Summary
- Chapter 8. Controlling Network Access: The Traditional Way
-
Chapter 9. Implementing Next-Generation Firewall Services with ASA CX
- CX Integration Overview
- ASA CX Architecture
- Preparing ASA CX for Configuration
- Managing ASA CX with PRSM
- Defining CX Policy Elements
- Enabling User Identity Services
- Enabling TLS Decryption
- Enabling NG IPS
- Defining Context-Aware Access Policies
- Configuring ASA for CX Traffic Redirection
- Monitoring ASA CX
- Summary
- Chapter 10. Network Address Translation
- Chapter 11. IPv6 Support
- Chapter 12. IP Routing
-
Chapter 13. Application Inspection
- Enabling Application Inspection
- Selective Inspection
- CTIQBE Inspection
- DCERPC Inspection
- DNS Inspection
- ESMTP Inspection
- File Transfer Protocol
- General Packet Radio Service Tunneling Protocol
- H.323
- Cisco Unified Communications Advanced Support
- HTTP
- ICMP
- ILS
- Instant Messenger (IM)
- IPsec Pass-Through
- MGCP
- NetBIOS
- PPTP
- Sun RPC
- RSH
- RTSP
- SIP
- Skinny (SCCP)
- SNMP
- SQL*Net
- TFTP
- WAAS
- XDMCP
- Summary
- Chapter 14. Virtualization
- Chapter 15. Transparent Firewalls
- Chapter 16. High Availability
- Chapter 17. Implementing Cisco ASA Intrusion Prevention System (IPS)
- Chapter 18. Tuning and Monitoring IPS
- Chapter 19. Site-to-Site IPsec VPNs
- Chapter 20. IPsec Remote-Access VPNs
- Chapter 21. Configuring and Troubleshooting PKI
- Chapter 22. Clientless Remote-Access SSL VPNs
- Chapter 23. Client-Based Remote-Access SSL VPNs
- Chapter 24. IP Multicast Routing
- Chapter 25. Quality of Service
- Index
Product information
- Title: Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition
- Author(s):
- Release date: April 2014
- Publisher(s): Cisco Press
- ISBN: 9780132954389
You might also like
book
Network Security, Firewalls, and VPNs
PART OF THE NEW JONES & BARTLETT LEARNING INFORMATION SYSTEMS SECURITY & ASSURANCE SERIES! Network Security, …
book
CCNP Security Cisco Secure Firewall and Intrusion Prevention System Official Cert Guide
The official Cisco Press Certification Guide designed to help candidates prepare for the new SNCF 300-710 …
book
Network Security, Firewalls, and VPNs, 3rd Edition
Network Security, Firewalls, and VPNs, third Edition provides a unique, in-depth look at the major business …
book
Cisco ISE for BYOD and Secure Unified Access, 2nd Edition
Fully updated: The complete guide to Cisco Identity Services Engine solutions Using Cisco Secure Access Architecture …