IPS v6.0 - Implementing Cisco Intrusion Prevention System
Revision: TE5504_20100304
- Course Length:
- 4 Days
- Course Description:
- Implementing Cisco Intrusion Prevention Systems (IPS) v6.0 provides the knowledge and skills needed to design, install, configure, and maintain a Cisco IPS sensor for small, medium, and enterprise networks. The course also describes the procedures for managing intrusion prevention system (IPS) alarms.
- Who Should Attend:
- The primary audience for this course are network designers and network security administrators.
- Benefits of Attendance:
-
Upon completion of this course, students will be able to:
- Explain how the Cisco IPS protects network devices from attacks
- Install and configure the basic settings on a Cisco IPS 4200 Series Sensor
- Use the Cisco IDM to configure built-in signatures to meet the requirements of a given security policy
- Configure some of the more advanced features of the Cisco IPS product line
- Initialize and install into your environment the rest of the Cisco IPS family of products
- Use the CLI and the Cisco IDM to obtain system information, and configure the Cisco IPS sensor to allow an SNMP NMS to monitor the Cisco IPS sensor
- Prerequisites:
- Students must have familiarity with networking and security terms and concepts, including completion of the Securing Cisco Network Devices (SND) course. Students must also have strong user-level experience with Microsoft Windows operating systems.
- Course Outline:
-
- Course Introduction
- Overview
- Course Goal and Objectives
- Course Flow
- Additional References
- Your Training Curriculum
- Module 1: Intrusion Prevention Overview
- Explaining Intrusion Prevention
- Examining Cisco IPS Products
- Examining Cisco IPS Sensor Software Solutions
- Examining Evasive Techniques
- Module 2: Installation of a Cisco IPS 4200 Series Sensor
- Installing a Cisco IPS Sensor Using the CLI
- Using the Cisco IDM
- Configuring Basic Sensor Settings
- Lab 2-1: Install and Configure a Cisco IPS Sensor from the CLI
- Lab 2-2: Use the Cisco IDM to Perform a Basic Sensor Configuration
- Module 3: Cisco IPS Signatures
- Configuring Cisco IPS Signatures and Alerts
- Examining the Signature Engines
- Customizing Signatures
- Lab 3-1: Working with Signatures and Alerts
- Lab 3-2: Customizing Signatures
- Module 4: Advanced Cisco IPS Configuration
- Performing Advanced Tuning of Cisco IPS Sensors
- Monitoring and Managing Alarms
- Configuring a Virtual Sensor
- Configuring Advanced Features
- Configuring Blocking
- Lab 4-1: Tune a Cisco IPS Sensor Using the Cisco IDM
- Lab 4-2: Monitor and Manage Alarms
- Lab 4-3: Configure a Virtual Sensor (Optional)
- Lab 4-4: Configure Anomaly Detection and POSFP
- Module 5: Additional Cisco IPS Devices
- Installing the Cisco Catalyst 6500 Series IDSM-2
- Initializing the Cisco ASA AIP-SSM
- Module 6: Cisco IPS Sensor Maintenance
- Maintaining Cisco IPS Sensors
- Managing Cisco IPS Sensors
- Lab 6-1: Maintain Sensors and Verify System Configuration
- Course Introduction













