Posts

Showing posts with the label CCIE Security

Configuring NAT on the Cisco ASA

Image
In this article, we will take a look at how to configure different types of NAT on the Cisco ASA post 8.4 software code. Accompanying this post is a video demonstration covering what has been discussed in this article. We will cover the following types of NAT: Static NAT Dynamic NAT Dynamic PAT Identity NAT Before jumping into the demonstrations I will explain the purpose of each type of NAT on the Cisco ASA. Overview of NAT NAT addresses can be defined as the following: Inside local address: This is the IP address that is assigned to a host on the inside of a network. The inside local address is most certainly bound to fall within the RFC 1918 reserved private IP address spaces. Inside global address: This is a globally routable IP address (public IP address) that can represent one or more inside local IP addresses to the outside world. Outside local address: This is the IP address of an outside host as it appears to the inside network. Outside global address: This is the IP addre...

CCIE Security WebEx Teams Group

Image
I've had many people reach out to me over the last couple of months and ask if we could get together to share ideas and methods in order to attain the CCIE Security certification. This has led me to write this post and hopefully have something productive come from it. I've been apart of internal/external study groups before and although it's nice to meet people within these groups, there hasn't really been any structure as to how we can actually work in tandem to achieve certifications. So, today I would like to put together what would hopefully be a productive and valuable study group for the CCIE Security. With that said I've decided to create this post as a call to those that want to be apart of a new Cisco WebEx Teams space that I am putting together for the CCIE Security certification. I want to keep the group as simple as possible but with a strong focus on REALLY keeping the members of the group focused on the task in hand... attaining the CCIE Security certi...

Configuring Site-to-Site VPN for Firepower Threat Defense

Image
In this article we will take a look at how to configure site-to-site virtual private networks (VPN) on Firepower Threat Defense (FTD) managed devices. Note: This demonstration assumes that managed devices are licensed appropriately. In this demonstration, the site-to-site VPN will be configured using IKEv2. One Firepower device is configured as a standalone and will be configured using the Firepower Device Manager (FDM) and the other is configured to be managed using the Firepower Management Center (FMC). The underlying network is already configured and will NOT be covered as part of this demonstration. Configuring Firepower S2S VPN using FDM Access the FDM GUI and login to the Firepower appliance From the device summary page, scroll to the bottom of the page and click on Site to Site VPN Click on 'Create Site-to-Site Connection' Configure the following settings relevant to your environment: Connection Profile Name Local VPN Access Interface Local Network for interesting VPN tr...