CCNA Security Labs


CCNA SECURITY LAB MANUAL (Cisco Networking Academy & Pearson/CiscoPress Book)

Chapter 1 Lab A: Researching Network Attacks and Security Audit Tools

Part 1. Researching Network Attacks
Part 2. Researching Security Audit Tools

Chapter 2 Lab A: Securing the Router for Administrative Access

Part 1. Basic Router Configuration
Part 2. Control Administrative Access for Routers
Part 3. Configure Administrative Roles
Part 4. Configure IOS Resilience and Management Reporting
Part 5. Configure Automated Security Features

Chapter 3 Lab A: Securing Administrative Access Using AAA and RADIUS

Part 1. Basic Network Device Configuration
Part 2. Configure Local Authentication
Part 3. Configure Local Authentication Using AAA on R3
Part 4. Configure Centralized Authentication Using AAA and RADIUS

Chapter 4 Lab A: Configuring CBAC and Zone-Based Firewalls

Part 1. Basic Router Configuration
Part 2. Configuring a Context-Based Access Control (CBAC) Firewall
Part 3. Configuring a Zone-Based Firewall (ZBF) Using SDM

Chapter 5 Lab A: Configuring an Intrusion Prevention System (IPS) Using the CLI and SDM

Part 1. Basic Router Configuration
Part 2. Configuring IPS Using the Cisco IOS CLI
Part 3. Configuring IPS using SDM

Chapter 6 Lab A: Securing Layer 2 Switches

Part 1. Basic Device Configuration
Part 2. SSH Configuration
Part 3. Secure Trunks and Access Ports
Part 4. Configure SPAN and Monitor Traffic

Chapter 7 Lab A: Exploring Encryption Methods

Part 1. (Optional) Build the Network and Configure the PCs
Part 2. Decipher a Pre-encrypted Message Using the Vigenere Cipher
Part 3. Create a Vigenere Cipher Encrypted Message and Decrypt It
Part 4. Use Steganography to Embed a Secret Message in a Graphic

Chapter 8 Lab A: Configuring a Site-to-Site VPN Using Cisco IOS and SDM

Part 1. Basic Router Configuration
Part 2. Configure a Site-to-Site VPN with Cisco IOS
Part 3. Configure a Site-to-Site IPsec VPN with SDM

Chapter 8 Lab B: Configuring a Remote Access VPN Server and Client

Part 1. Basic Router Configuration
Part 2. Configuring a Remote Access VPN

Chapter 8 Lab C: Configuring a Remote Access VPN Server and Client

Part 1. Basic Router Configuration
Part 2. Configuring a Remote Access VPN

Chapter 9 Lab A: Security Policy Development and Implementation

Part 1. Create a Security Policy
Part 2. Basic Network Device Configuration (Chapters 2 and 6)
Part 3. Secure Network Routers
Part 4. Secure Network Switches (Chapter 6)
Part 5. Configuring VPN Remote Access


ADDITIONAL SECURITY LAB EXERCISES

Section 1: IPSec VPNs

Lab 1.1: Configuring SDM on a Router
Lab 1.2: Configuring a Basic GRE Tunnel
Lab 1.3: Configuring Wireshark and SPAN
Lab 1.4: Configuring Site-to-Site IPsec VPNs with SDM
Lab 1.5: Configuring Site-to-Site IPsec VPNs with the IOS CLI
Lab 1.6: Configuring a Secure GRE Tunnel with SDM
Lab 1.7: Configuring a Secure GRE Tunnel with the IOS CLI
Lab 1.8: Configuring IPsec VTIs (Virtual Tunnel Interfaces)
Lab 1.9: Configuring Easy VPN with SDM
Lab 1.10: Configuring Easy VPN with the IOS CLI


Section 2: Cisco IOS Threat Defense

Lab 2.1: Configuring a Cisco IOS Firewall Using SDM
Lab 2.2: Configuring CBAC
Lab 2.3: Configuring IPS with SDM
Lab 2.4: Configuring IPS with CLI


Section 3: Cisco Device Hardening

Lab 3.1: Using SDM One-Step Lockdown
Lab 3.2: Securing a Router with Cisco AutoSecure
Lab 3.3: Disabling Unneeded Services
Lab 3.4: Enhancing Router Security
Lab 3.5: Configuring Logging
Lab 3.6a: Configuring AAA and TACACS+
Lab 3.6b: Configuring AAA and RADIUS
Lab 3.6c: Configuring AAA Using Local Authentication
Lab 3.7: Configuring Role-Based CLI Views
Lab 3.8: Configuring NTP