View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

Security

SEC0136 - SSL VPN AnyConnect Mobile and On-Demand VPN (Part 1)

The video goes over Cisco AnyConnect Secure Mobility VPN client on iPhone and Android devices in more detail. We will then implement an On-Demand VPN feature on an iPhone to allow automatic VPN establishment when application traffic that requires connectivity back to corporate resources are detected. We will use Cisco Jabber and web-based applications in our demonstration.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0135 - SSL VPN AnyConnect Secure Mobility Always-On VPN

The video shows how to enforce VPN connection upon users with Cisco AnyConnect Secure Mobility Always-On VPN feature. If your company security policy requires your users to establish a VPN back to corporate network before having any kind of network connectivity, including local internet, and prevent users from disconnecting from the VPN this video is for you. We will go through different configurable behaviors of Always-On VPN to help you make a decision on adopting the feature.
Rating: 
5
Average: 5 (2 votes)
Difficulty Level: 
0

SEC0150 - ASA CX Application Filtering

The video demonstrates Cisco ASA CX ability to perform application matching beyond just protocols and ports by using Application Visibility and Control (AVC) feature. You will see how to deploy access policy at ease without worrying about being circumvented by application running on non-default port, or even those that sprawl multiple dynamic ports. This intelligence take you as far as matching based on a group of application by type, and specific application behavior. All of these will be demonstrated through three applications; RDP, Bittorrent, and Facebook, in this lab.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0149 - ASA CX Traffic Decryption

The video shows you how to configure Cisco ASA CX to gain visibility to encrypted traffic by enabling decryption capability. We will first used a self-signed certificate and present a problem of certificate warning. We will then try to resolve this by having the certificate signed by a client trusted CA. Most importantly you will get to see what user experience is like when the CX inserts itself in between HTTPS transactions.  

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
5

SEC0134 - SSL VPN AnyConnect Secure Mobility SCEP Proxy (Part 2)

The video shows you how to configure SCEP proxy on Cisco AnyConnect Secure Mobility to help VPN clients remotely obtain an identity certificate without allowing client to communicate directly to an internal Certificate Authority (CA) server. We will also show you how to solve the problem of how to select a correct certificate for VPN authentication when VPN client possesses multiple identity certificate using Certificate Matching feature. A basic working knowledge of certificate and SCEP is recommended before viewing this video.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0134 - SSL VPN AnyConnect Secure Mobility SCEP Proxy (Part 1)

The video shows you how to configure SCEP proxy on Cisco AnyConnect Secure Mobility to help VPN clients remotely obtain an identity certificate without allowing client to communicate directly to an internal Certificate Authority (CA) server. We will also show you how to solve the problem of how to select a correct certificate for VPN authentication when VPN client possesses multiple identity certificate using Certificate Matching feature. A basic working knowledge of certificate and SCEP is recommended before viewing this video.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0133 - SSL VPN AnyConnect Secure Mobility OnConnect Script

The video shows you how you can have Cisco AnyConnect Secure Mobility VPN to perform client-side script execution at both VPN connect and disconnect. This can be an alternative solution to Start-Before-Logon when used specifically for Windows logon script, which is what we will be demonstrating in this lab. At the end, we will also discuss caveats when using this technique.
Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0148 - ASA CX Passive Authentication with ISE (Part 2)

The video provide a method to enhance reliability of Cisco ASA CX Passive Authentication by integrating Cisco ISE with CDA. You will see how the caveats inherent to CDA can be solved by using realtime user and IP information provided by 802.1x identity-based authentication network. We will analyze RADIUS packets being communicated between Cisco ISE and CDA to try to understand the underlying mechanism. Testing will be performed on both domain and non-domain devices, that have been onboarded through ISE, and this includes both wired and wireless.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0148 - ASA CX Passive Authentication with ISE (Part 1)

The video provide a method to enhance reliability of Cisco ASA CX Passive Authentication by integrating Cisco ISE with CDA. You will see how the caveats inherent to CDA can be solved by using realtime user and IP information provided by 802.1x identity-based authentication network. We will analyze RADIUS packets being communicated between Cisco ISE and CDA to try to understand the underlying mechanism. Testing will be performed on both domain and non-domain devices, that have been onboarded through ISE, and this includes both wired and wireless.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

SEC0147 - ASA CX Passive Authentication

The video shows you the second method of obtaining user identity on Cisco ASA CX using Passive Authentication. We will leverage the User-to-IP mapping information provided by CDA by configuring CX device as a consumer. Once the mapping information is available to CX, minor modification will be performed on the Identity Policy and you will see how users are saved from having to enter their credentials as we saw in the Active Authentication. We will also discuss and demonstrate some caveats to this method towards the end of the lab.

Rating: 
5
Average: 5 (1 vote)
Difficulty Level: 
0

Pages

Subscribe to RSS - Security