Book description
The official study guide helps you master all the topics on the CCNP Security VPN exam, including
Configuring policies, inheritance, and attributes
· AnyConnect Remote Access VPN solutions
· AAA and Dynamic Access Policies (DAP)
· High availability and performance
· Clientless VPN solutions
· SSL VPN with Cisco Secure Desktop
· Easy VPN solutions
· IPsec VPN clients and site-to-site VPNs
The CD-ROM contains a free, complete practice exam.
Includes Exclusive Offer for 70% Off Premium Edition eBook and Practice Test
Pearson IT Certification Practice Test minimum system requirements:
Windows XP (SP3), Windows Vista (SP2), or
Windows 7; Microsoft .NET Framework 4.0 Client; Pentium class 1GHz
processor (or equivalent);
512 MB RAM; 650 MB disc space plus 50 MB for each downloaded
practice exam
This volume is part of the Official Cert Guide Series from Cisco Press. Books in this series provide officially developed exam preparation materials that offer assessment, review, and practice to help Cisco Career Certification candidates identify weaknesses, concentrate their study efforts, and enhance their confidence as exam day nears.
CCNP Security VPN 642-648 Official Cert Guide is a best of breed Cisco exam study guide that focuses specifically on the objectives for the CCNP Security VPN exam. Cisco Certified Internetwork Expert (CCIE) Howard Hooper shares preparation hints and test-taking tips, helping you identify areas of weakness and improve both your conceptual knowledge and hands-on skills. Material is presented in a concise manner, focusing on increasing your understanding and retention of exam topics.
CCNP Security VPN 642-648 Official Cert Guide presents you with an organized test-preparation routine through the use of proven series elements and techniques. “Do I Know This Already?” quizzes open each chapter and enable you to decide how much time you need to spend on each section. Exam topic lists make referencing easy. Chapter-ending Exam Preparation Tasks help you drill on key concepts you must know thoroughly.
The companion CD-ROM contains a powerful testing engine that enables you to focus on individual topic areas or take a complete, timed exam. The assessment engine also tracks your performance and provides feedback on a module-by-module basis, laying out a complete assessment of your knowledge to help you focus your study where it is needed most.
Well-regarded for its level of detail, assessment features, and challenging review questions and exercises, this official study guide helps you master the concepts and techniques that will enable you to succeed on the exam the first time.
CCNP Security VPN 642-648 Official Cert Guide is part of a recommended learning path from Cisco that includes simulation and hands-on training from authorized Cisco Learning Partners and self-study products from Cisco Press. To find out more about instructor-led training, e-learning, and hands-on instruction offered by authorized Cisco Learning Partners worldwide, please visit www.cisco.com/go/authorizedtraining.
Table of contents
- Title Page
- Copyright Page
- About the Author
- About the Technical Reviewers
- Dedications
- Acknowledgments
- Contents at a Glance
- Contents
- Icons Used in This Book
-
Introduction
- Who Should Read This Book
- How to Use This Book
- Certification Exam and This Preparation Guide
- Overview of the Cisco Certification Process
- Taking the VPN Certification Exam
- Tracking CCNP Security Status
- How to Prepare for an Exam
- Assessing Exam Readiness
- Cisco Security Specialist in the Real World
- Cisco ASA Software Commands
- Rules of the Road
- Exam Registration
- Book Content Updates
- Premium Edition eBook and Practice Test
-
Part I. ASA Architecture and Technologies Overview
- Chapter 1. Examining the Role of VPNs and the Technologies Supported by the ASA
-
Chapter 2. Configuring Policies, Inheritance, and Attributes
- “Do I Know This Already?” Quiz
- Foundation Topics
- Policies and Their Relationships
- Understanding Connection Profiles
- Understanding Group Policies
- Configure User Attributes
- Using External Servers for AAA and Policies
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Part II. Cisco Clientless Remote-Access VPN Solutions
-
Chapter 3. Deploying a Clientless SSL VPN Solution
- “Do I Know This Already?” Quiz
- Foundation Topics
- Clientless SSL VPN Overview
- Deployment Procedures and Strategies
- Deploying Your First Clientless SSL VPN Solution
- Basic Access Control
- Content Transformation
- Troubleshooting a Basic Clientless SSL VPN
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 4. Advanced Clientless SSL VPN Settings
- “Do I Know This Already?” Quiz
- Foundation Topics
- Overview of Advanced Clientless SSL VPN Settings
- Application Access Through Port Forwarding
- Application Access Using Client-Server Plug-Ins
- Application Access Through Smart Tunnels
- Configuring SSL/TLS Proxies
- Troubleshooting Advanced Application Access
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 5. Customizing the Clientless Portal
- “Do I Know This Already?” Quiz
- Foundation Topics
- Basic Portal Layout Configuration
- Outside-the-Box Portal Configuration
- Portal Language Localization
- Getting Portal Help
- AnyConnect Portal Integration
- Clientless SSL VPN Advanced Authentication
- Using an External and Internal CA for Clientless Access
- Clientless SSL VPN Double Authentication
- Deploying Clientless SSL VPN Single Signon
- Troubleshooting PKI and SSO Integration
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
- Chapter 6. Clientless SSL VPN Advanced Authentication and Authorization
-
Chapter 7. Clientless SSL High Availability and Performance
- “Do I Know This Already?” Quiz
- Foundation Topics
- High-Availability Deployment Information and Common Strategies
- Content Caching for Optimization
- Clientless SSL VPN Load Sharing Using an External Load Balancer
- Clustering Configuration for Clientless SSL VPN
- Troubleshooting Load Balancing and Clustering
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 3. Deploying a Clientless SSL VPN Solution
-
Part III. Cisco AnyConnect Remote-Access VPN Solutions
-
Chapter 8. Deploying an AnyConnect Remote-Access VPN Solution
- “Do I Know This Already?” Quiz
- Foundation Topics
- AnyConnect Full-Tunnel SSL VPN Overview
- Configuration Procedures, Deployment Strategies, and Information Gathering
- Deploying Your First Full-Tunnel AnyConnect SSL VPN Solution
- Deploying Your First AnyConnect IKEv2 VPN Solution
- Client IP Address Allocation
- Advanced Controls for Your Environment
- Troubleshooting the AnyConnect Secure Mobility Client
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 9. Advanced Authentication and Authorization of AnyConnect VPNs
- “Do I Know This Already?” Quiz
- Foundation Topics
- Authentication Options and Strategies
- Provisioning Certificates as a Local CA
- Configuring Certificate Mappings
- Provisioning Certificates from a Third-Party CA
- Advanced PKI Deployment Strategies
- Doubling Up on Client Authentication
- Troubleshooting Your Advanced Configuration
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 10. Advanced Deployment and Management of the AnyConnect Client
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- AnyConnect Installation Options
- Managing AnyConnect Client Profiles
- Advanced Profile Features
- Advanced AnyConnect Customization and Management
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 11. AnyConnect Advanced Authorization Using AAA and DAPs
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- Configuring Local and Remote Group Policies
- Full SSL VPN Accountability
- Authorization Through Dynamic Access Policies
- Troubleshooting Advanced Authorization Settings
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 12. AnyConnect High Availability and Performance
- “Do I Know This Already?” Quiz
- Foundation Topics
- Overview of High Availability and Redundancy Methods
- Deploying DTLS
- Performance Assurance with QOS
- AnyConnect Redundant Peering and Failover
- Hardware-Based Failover with VPNs
- Redundancy in the VPN Core
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 8. Deploying an AnyConnect Remote-Access VPN Solution
-
Part IV. Cisco Secure Desktop
-
Chapter 13. Cisco Secure Desktop
- “Do I Know This Already?” Quiz
- Foundation Topics
- Cisco Secure Desktop Overview and Configuration
- CSD Order of Operations
- Configure Prelogin Criteria
- Host Endpoint Assessment
- Authorization Using DAPs
- Troubleshooting Cisco Secure Desktop
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 13. Cisco Secure Desktop
-
Part V. Cisco IPsec Remote-Access Client Solutions
-
Chapter 14. Deploying and Managing the Cisco VPN Client
- “Do I Know This Already?” Quiz
- Foundation Topics
- Cisco IPsec VPN Client Features
- Cisco ASA Basic Remote IPsec Client Configuration
- IPsec Client Software Installation and Basic Configuration
- Advanced Profile Settings
- VPN Client Software GUI Customization
- Troubleshooting VPN Client Connectivity
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 14. Deploying and Managing the Cisco VPN Client
-
Part VI. Cisco Easy VPN Solutions
-
Chapter 15. Deploying Easy VPN Solutions
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Procedures, and Information Gathering
- Easy VPN Basic Configuration
- Controlling Your Environment with Advanced Features
- Troubleshooting a Basic Easy VPN
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 16. Advanced Authentication and Authorization Using Easy VPN
- “Do I Know This Already?” Quiz
- Foundation Topics
- Authentication Options and Strategies
- Configuring PKI for Use with Easy VPN
- Configuring Mutual/Hybrid Authentication
- Configuring Digital Certificate Mappings
- Provisioning Certificates from a Third-Party CA
- Advanced PKI Deployment Strategies
- Troubleshooting Advanced Authentication for Easy VPN
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 17. Advanced Easy VPN Authorization
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- Configuring Local and Remote Group Policies
- Accounting Methods for Operational Information
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 18. High Availability and Performance for Easy VPN
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- Easy VPN Client HA and Failover
- Hardware-Based Failover with VPNs
- Clustering Configuration for Easy VPN
- Troubleshooting Device Failover and Clustering
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 19. Easy VPN Operation Using the ASA 5505 as a Hardware Client
- “Do I Know This Already?” Quiz
- Foundation Topics
- Easy VPN Remote Hardware Client Overview
- Configuring a Basic Easy VPN Remote Client Using the ASA 5505
- Configuring Advanced Easy VPN Remote Client Settings for the ASA 5505
- Troubleshooting the ASA 5505 Easy VPN Remote Hardware Client
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 15. Deploying Easy VPN Solutions
-
Part VII. Cisco IPsec Site-to-Site VPN Solutions
-
Chapter 20. Deploying IPsec Site-to-Site VPNs
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- IKEv1
- IKEv2
- Configuring a Basic IKEv1 IPsec Site-to-Site VPN
- Configuring a Basic IKEv2 IPsec Site-to-Site VPN
- Configure Advanced Authentication for IKEv1 IPsec Site-to-Site VPNs
- Troubleshooting an IPsec Site-to-Site VPN Connection
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 21. High Availability and Performance Strategies for IPsec Site-to-Site VPNs
- “Do I Know This Already?” Quiz
- Foundation Topics
- Configuration Procedures, Deployment Strategies, and Information Gathering
- High Assurance with QoS
- Deploying Redundant Peering for Site-to-Site VPNs
- Site-to-Site VPN Redundancy Using Routing
- Hardware-Based Failover with VPNs
- Troubleshooting HA Deployment
- Exam Preparation Tasks
- Review All Key Topics
- Complete Tables and Lists from Memory
- Define Key Terms
-
Chapter 20. Deploying IPsec Site-to-Site VPNs
- Part VIII. Exam Preparation
- Part IX. Appendixes
- Glossary
- Index
- Add Pages
- Appendix C. Memory Tables
- Appendix D. Memory Tables Answer Key
Product information
- Title: CCNP Security VPN 642-648 Official Cert Guide, Second Edition
- Author(s):
- Release date: June 2012
- Publisher(s): Cisco Press
- ISBN: 9780132966399
You might also like
book
CCNP Security VPN 642-647 Official Cert Guide
Trust the best selling Official Cert Guide series from Cisco Press to help you learn, prepare, …
book
CCNP Security FIREWALL 642-618 Official Cert Guide
Trust the best selling Official Cert Guide series from Cisco Press to help you learn, prepare, …
book
CCNA Security 640-554 Official Cert Guide
Trust the best selling Official Cert Guide series from Cisco Press to help you learn, prepare, …
book
CCNP Security SISAS 300-208 Official Cert Guide
CCNP Security SISAS 300-208 Official Cert Guide CCNP Security SISAS 300-208 Official Cert Guide from Cisco …