Overview
Learn how Cisco IPS protects network devices from attacks. Given an IPS sensor appliance, you will learn to install the appliance in the network and initialize it. You will also learn how to use IDS Device Manager (IDM) to configure basic sensor settings and to configure built-in signatures to meet the requirements of a given security policy. You will learn the functions of signature engines and their parameters and understand how to use IDM to tune and create signatures to meet the requirements of a given security policy.
You will learn how to use IDM to tune a sensor to work optimally in the network. You will also use the Monitoring Center for Security and Cisco Threat Response to maximize alarm management efficiency. The course covers blocking concepts and how to use IDM to configure blocking for a given scenario. You will be learn how to install both the NM-CIDS in a router and initialize it, install the module in a Cisco Catalyst 6500 Switch and initialize it using the switch to capture network traffic for intrusion prevention analysis. You will also install and recover the sensor software image and perform service pack and signature updates and will also verify system configuration using the CLI and IDM.
Who Should Attend
- System Engineers
- Channel Partner/Reseller
- Customers
Cisco Career Certifications
This course is part of the following Certifications:
-
CCSP (Cisco Certified Security Professional)
Course Objectives
After completing this course, you will be able to:
- Install an IPS sensor appliance in the Network and initialize it
- Use IDM to configure built-in signatures to meet the requirements of a given security policy
- Describe the functions of signature engines and their parameters and use IDM to tune and create signatures
- Tune a sensor to work optimally in the network
- Use the Monitoring Center for Security and Cisco Threat Response
- Install the NM-CIDS in a router and initialize it
- Install and recover the sensor software image and perform service pack and signature updates
Course Outline
This 4-day course is geared towards obtaining hands-on experience only; therefore, there is no exam
- Course Introduction
- Security Fundamentals
- Intrusion Prevention Overview
- Getting Started with the IDS Command Line Interface
- Using IDM Lesson 6:Basic Sensor Configuration
- Cisco Intrusion Detection System Alarms and Signatures
- Signature Engines
- Signature Configuration
- Sensor Tuning
- Alarm Monitoring and Management
- Blocking Configuration
- Cisco Intrusion Detection System Network Module
- Intrusion Detection System Module Configuration
- Capturing Network Traffic for Intrusion Detection Systems
- Sensor Maintenance
- Verifying System Configuration
Prerequisites
Students who attend this advanced course should meet the following prerequisites or have equivalent knowledge:
Interconnecting Cisco Networking Devices Part 1 (ICND1)
Interconnecting Cisco Networking Devices Part 2 (ICND2)
Securing Cisco Network Devices (SND)
Basic knowledge of the Windows operating system
Familiarity with basic networking and security terms and concepts
The Course Schedule is now opening...