Skip to Content
Cisco Firewalls
book

Cisco Firewalls

by Alexandre M.S.P Moraes
June 2011
Intermediate to advanced
912 pages
21h 39m
English
Cisco Press

Overview

Cisco Firewalls

Concepts, design and deployment for Cisco Stateful Firewall solutions

¿

In this book, Alexandre proposes a totally different approach to the important subject of firewalls: Instead of just presenting configuration models, he uses a set of carefully crafted examples to illustrate the theory in action.¿A must read! —Luc Billot, Security Consulting Engineer at Cisco

¿

Cisco Firewalls thoroughly explains each of the leading Cisco firewall products, features, and solutions, and shows how they can add value to any network security design or operation. The author tightly links theory with practice, demonstrating how to integrate Cisco firewalls into highly secure, self-defending networks. Cisco Firewalls shows you how to deploy Cisco firewalls as an essential component of every network infrastructure. The book takes the unique approach of illustrating complex configuration concepts through step-by-step examples that demonstrate the theory in action. This is the first book with detailed coverage of firewalling Unified Communications systems, network virtualization architectures, and environments that include virtual machines. The author also presents indispensable information about integrating firewalls with other security elements such as IPS, VPNs, and load balancers; as well as a complete introduction to firewalling IPv6 networks. Cisco Firewalls will be an indispensable resource for engineers and architects designing and implementing firewalls; security administrators, operators, and support professionals; and anyone preparing for the CCNA Security, CCNP Security, or CCIE Security certification exams.

¿

Alexandre Matos da Silva Pires de Moraes, CCIE No. 6063, has worked as a Systems Engineer for Cisco Brazil since 1998 in projects that involve not only Security and VPN technologies but also Routing Protocol and Campus Design, IP Multicast Routing, and MPLS Networks Design. He coordinated a team of Security engineers in Brazil and holds the CISSP, CCSP, and three CCIE certifications (Routing/Switching, Security, and Service Provider). A frequent speaker at Cisco Live, he holds a degree in electronic engineering from the Instituto Tecnológico de Aeronáutica (ITA – Brazil).

¿

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Create advanced security designs utilizing the entire Cisco firewall product family

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Choose the right firewalls based on your performance requirements

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Learn firewall¿ configuration fundamentals and master the tools that provide insight about firewall operations

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Properly insert firewalls in your network’s topology using Layer 3 or Layer 2 connectivity

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Use Cisco firewalls as part of a robust, secure virtualization architecture

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Deploy Cisco ASA firewalls with or without NAT

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Take full advantage of the classic IOS firewall feature set (CBAC)

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Implement flexible security policies with the Zone Policy Firewall (ZPF)

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Strengthen stateful inspection with antispoofing, TCP normalization, connection limiting, and IP fragmentation handling

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Use application-layer inspection capabilities built into Cisco firewalls

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Inspect IP voice protocols, including SCCP, H.323, SIP, and MGCP

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Utilize identity to provide user-based stateful functionality

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Understand how multicast traffic is handled through firewalls

·Â¿Â¿Â¿Â¿Â¿Â¿Â¿ Use firewalls to protect your IPv6 deployments

¿

This security book is part of the Cisco Press Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end, self-defending networks.

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition

Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition

Jazib Frahim, Omar Santos, Andrew Ossipov

Publisher Resources

ISBN: 9781587141140Purchase book