SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions...
Transcript of SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions...
![Page 1: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/1.jpg)
![Page 2: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/2.jpg)
SIMOS
Implementing Cisco Secure Mobility Solutions
Instructor: Graham Tuthill
Location: Wokingham
Start Time 9:30
Please check you have access to the electronic course material,details of which would have been emailed to you directly formCisco Check your SPAM folder
![Page 3: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/3.jpg)
Course Times:Monday 9:30 to 4:30Tuesday 9:00 to 4:30Wednesday 9:00 to 4:30Thursday 9:00 to 4:30Friday 9:00 to ?
Breaks:Coffee am 10:45/15 minsLunch 12:30/35 minsCoffee pm 2:45/15 mins
My Websitedefaultgateway.co.uk
Wireless key323-010-323
Local Admin PCPassword =Pa$$w0rd
![Page 4: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/4.jpg)
Here are you license codes for the course material
![Page 5: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/5.jpg)
Monza
![Page 6: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/6.jpg)
ConfidentialityEncryption
Symetric &Asymetric(keys)
Symetricencryption
Alice Bob
DES3DESAESTKIPRC4CAST/SWORDFISH
![Page 7: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/7.jpg)
DES
64Clear Text
Alice Bob
32 32
xor
32!6 Rounds
Cipher Text
Encrypted
Clear Text
56 Key
![Page 8: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/8.jpg)
3DES
56
56
56
![Page 9: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/9.jpg)
Data Intergrity
101
eve
101
SHA/MD5
111111
SHA_HMAC
+ Authentication
![Page 10: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/10.jpg)
Amazon
https://
Public Key
VerisignPubPvt
RC4
![Page 11: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/11.jpg)
Nick/AndreasRalf/Colin
Graham/PaulPhil/Mohamed
AndrejIan
Paul
PerRadoslaw
Internet
London
Wokingham
![Page 12: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/12.jpg)
Lunch to 1:15
![Page 13: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/13.jpg)
IPSEC
AH ESPAuthenticationHeader
Encapsulatingsecurity Payload
Data IntergrityData AuthenticationAnti Replay Data Confidentiality
Data IntergrityData AuthenticationAnti Replay
AES/DES/3DESetc
SHA_HMAC
Sequencenumbers
![Page 14: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/14.jpg)
IPSEC-ESP
IP
Tunnel
Transport
PubPVT PVT
Hashed
Encrypted
![Page 15: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/15.jpg)
ESP
SPI#
Seq #Padding
HASH
![Page 16: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/16.jpg)
IKE V1 & V2(isakmp)
IPSEC/ESP
Diffie Hellman
Auhenticate
DHValue DH
Value
PSKs/Certs
UDP/500
SADs
ESP-DESESP-SHA
1234
POLICY
DES/3DES/AES
Main Mode
Aggresive Mode
Quick Mode
Policy #
Transform set (name)
![Page 17: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/17.jpg)
Complete Lab 2-1 by 9:00 am tomorrow
We will start the theory at 9:00
![Page 18: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/18.jpg)
IKE V1
Phase 1
Phase 2
IKE V2
All in one phase
Child SA mainSA
Policy # (Low is best)
Transform Set (Name) x
DH GroupDES/3DESPSK/CertsLifetimeHashing (HAGLE)
ESP - AESESP -SHA_HMACDefault (Tunnel mode) PFS DH Group #
![Page 19: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/19.jpg)
IOS/ASA
Crypto-Map 10 (name)
Peer IP AddressCrypto ACLTransform-set (name)
Ge0/0
ASAstill uses crypto maps
IPSEC
IOSOld way crypto maps
New way VTIs and or DVTIs
![Page 20: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/20.jpg)
Ge0/0 Tunnel 0 IPSEC
![Page 21: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/21.jpg)
VTI VTI
DVTI
TEMPLATE
DVTI
VTI VTI
DMVPNsSpoke to Spoke (Dymanically)Spoke to Hub is ManualThere are no VTIs or DVTIsGRE & NHRP
![Page 22: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/22.jpg)
192.168.3.0/24 N/H = 10.1.1.3
OSPFOSPF
NHR Request
NHR Response
192.168.2.0/24 N/H = 10.1.1.2
![Page 23: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/23.jpg)
IPSEC
IKEv1
Ph1
Ph2
Policy
D/H
Authc
IkeV2
![Page 24: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/24.jpg)
Complete Lab 3-1 by 12:00 am (maybe :-))
![Page 25: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/25.jpg)
![Page 26: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/26.jpg)
Complete Lab 3-1 by 1:10 pm including a Lunch Break
At 1:10 I will complete the FlexVPN Theory about 20minutes
There will still be 2 labs left 3-2 and 3-3 however wehave to stop and move onto the Remote Access VPNpart of the course.
You can return to the remaining FlexVPNs labs at anytime between now and Friday afternoon as theirconfigration and operation or non operation :-) willhave no impact on any of the labs we will be doing forremote access.
![Page 27: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/27.jpg)
ISPSSL/TLS
WWW
Web Portal
Bookmarks-URL Hyperlinks
HttphttpsFTPCIFS
PLUGINS
RDPVNCCITRIXSSH
Cisco.com & downloadInstall
Smart Tunnels Broker Applet
RDPNatively
TCP (Basic)
![Page 28: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/28.jpg)
ISP
ASA
Clientless SSLSSL IPSEC(IKEV2)
Clients
Server
Connection ProfileAKA Tunnel Groups
Tunnel Groups = CLIConnection Prof = ASDM
A method ofAuthentication
AB Group Policy
![Page 29: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/29.jpg)
DfltGrpPolicy
Hours of Access = 9 - 5
Manchester office/CP
Hours Access 6 - 6
IT Admins 6-12
London 9 - 4/CP
Man Manachester 24
![Page 30: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/30.jpg)
Complete Lab 4-1 by 9:15 Thursday morning
Then straight into the next theory
Lab approx 45/60 minutes
![Page 31: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/31.jpg)
Complete Lab 4-2 by 11:00 am including coffee
![Page 32: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/32.jpg)
Complete Lab 4-3 advanced Clientless Config (Authc/Authz)
Should take you about 30 minutes. With about a 40 Minute Lunchbreak.
I am going to start Module 5 Client SSL & IPSEC VPNs Theory at1:15.
The rest of today will be a mixture of SSL/IPSEC Client theory andlabs. I anticipate completing 2 more labs today 5-1 & 5-2.
This will leave lab 5-3 for tomorrow (IPSEC Client VPN IKEv2)
Tomorrow morning I will start module 6 (DAP) and have the theoryand lab for this module complete around 1:30.
If you then wish to return to Lab 3-2/3-3 you have the rest of thetomorrow afternoon to do this.
![Page 33: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/33.jpg)
ISPPvt Pvt
SSL
![Page 34: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/34.jpg)
Complete Lab 5-1 by 3:00pm including coffee
![Page 35: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/35.jpg)
Complete Lab 5-2 Advanced SSL Client by 9:00 am Friday
Please check the time on the ISE & AD they have to be within5 minutes of each other, show time in the ISE CLI.
If they are not then delete the NTP Server from ISE in the CLIand Add again, this will solve your problem.
To access the ISE CLI click on the icon in the diagram.
The ISE cli is nearly the same as IOS.
![Page 36: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/36.jpg)
Lab 5-3 Completed by 10:35 including coffee
![Page 37: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/37.jpg)
DAP Policy
ActionRich set
AAA Criteria(Local/Remote)
Host Scan
![Page 38: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/38.jpg)
Complete Lab 6-1 (3-2 & 3-3) by 4:00 pm FridayLab 6-1 should only take you about 45 minutes
I will post these drawings to my website now
My email is [email protected]
Have a good weekend
Please read the Lab tips for Lab 6-1
![Page 39: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/39.jpg)
![Page 40: SIMOS - Default Gateway · 2019. 11. 18. · SIMOS Implementing Cisco Secure Mobility Solutions Instructor: Graham Tuthill Location: Wokingham Start Time 9:30 Please check you have](https://reader035.fdocuments.in/reader035/viewer/2022071416/611356b4f41a985d07744398/html5/thumbnails/40.jpg)