¼Öµ¥½ºÅ©Çпø CCIE SECURITY
¼Öµ¥½ºÅ©Çпø CCIE SECURITY

Cisco System¿¡¼ ¹ßÇàÇÏ°í ³×Æ®¿öÅ© ¾÷ü¿¡¼ ÀÎÁ¤ÇÏ´Â ÃÖ°íÀÇ ±ÇÀ§¸¦ °®°í ÀÖ´Â CCIE ÀÚ°ÝÁõ ½Ç±â ½ÃÇè ´ëºñ¹ÝÀÔ´Ï´Ù. º» °úÁ¤Àº ½Ç½Ã ½ÃÇèÀ» ´ëºñÇÏ´Â °ÍÀ» ¸ñÀûÀ» µÎ°í Àֱ⠶§¹®¿¡ ÇöÀç ÃâÁ¦µÇ°í ÀÖ´Â ÃֽнÃÇè Á¤º¸¸¦ ±â¹ÝÀ¸·Î ÁøÇàÇÕ´Ï´Ù.
¢¹ ±³À° ´ë»ó
- CCIE Security ÀÚ°ÝÁõ Ãëµæ ÁغñÀÚ
- ½Ã½ºÄÚ º¸¾È Á¦Ç°¿¡ ´ëÇÑ Àü¹®ÀûÀÎ ±â¼úÀ» ¿ä±¸ÇÏ´Â ³×Æ®¿öÅ© º¸¾È ´ã´çÀÚ
¢¹ ±³À° ÁøÇà
- ½ÇÁ¦ ½ÃÇè¿¡ ÃâÁ¦µÇ°í ÀÖ´Â Ãֽй®Á¦¸¦ °»ç°¡ ¹®Á¦ Ç®ÀÌ Çü½ÄÀ¸·Î ÁøÇàÇÕ´Ï´Ù.
- ½Ç½À ¹æ½Ä : ÀÓ´ë Àåºñ »ç¿ë + °¡»ó ¼¹ö »ç¿ë
[Âü°í] CCIE ½ÃÇè °ü·Ã ³»¿ë
1. CCIE ÇØ´ç Æ®·¢¿¡ ´ëÇÑ Çʱ⠽ÃÇèÀ» ÆÐ½ºÇÏ¼Å¾ß ÇÕ´Ï´Ù. À̶§, Çʱ⠽ÃÇèÀº ½ÃÇè ºñ¿ëÀÌ 350$À̸ç,
¡®ÇǾ ºä¡¯ ±¹Á¦ °øÀÎ ½ÃÇè ¼¾ÅÍ¿¡¼ ÀÀ½ÃÇÏ½Ã¸é µË´Ï´Ù. Áï, Çʱ⠽ÃÇèÀº ±¹³»¿¡¼µµ ÀÀ½Ã °¡´ÉÇÕ´Ï´Ù.
2. Çʱ⸦ ÇÕ°ÝÇϽøé, ½Ç±â ½ÃÇè ÀÀ½Ã°¡ °¡´ÉÇÕ´Ï´Ù. ½Ç±â ½ÃÇèÀº Cisco »çÀÌÆ®¿¡¼ °³ÀÎÀÌ Á÷Á¢ ¿¹¾àÇØ¾ß
Çϸç, À̶§, ½Ç½Ã ½ÃÇè ºñ¿ëÀº 1500$ÀÔ´Ï´Ù. ¶ÇÇÑ, ±¹³»¿¡´Â ½Ç±â ½ÃÇè ¼¾ÅͰ¡ ¾ø±â ¶§¹®¿¡ ÀϺ», È«Äá, Áß
±¹, È£ÁÖ, ¹Ì±¹, µÎ¹ÙÀÌ µî ÇØ¿Ü·Î °¡¼Å¼ ½ÃÇèÀ» ÀÀ½ÃÇØ¾ß ÇÕ´Ï´Ù. ´Ü, 1³â¿¡ 1~2¹ø Á¤µµ ±¹³»¿¡¼µµ ½Ã
ÇèÀ» º¸½Ç ¼ö ÀÖ´Â ¸ð¹ÙÀÏ ½ÃÇè À̺¥Æ®°¡ ÀÖÁö¸¸, ¿¹¾àÇϱⰡ »ó´çÈ÷ ¾î·Æ½À´Ï´Ù.
¡ß CCIE Security Pre-LAB Blue Print
1) System Hardening and Availability
- Routing plane security features
- Control Plane Policing
- Control device access (e.g. Telnet, HTTP, SSH, SNMP, Syslog, NTP)
- Transit Traffic Control and Congestion Management
2) Threat Identification and Mitigation
- Identify and protect against fragmentation attacks
(malicious IP option usage, network reconnaissance, IP spoofing, MAC spoofing,
ARP spoofing , DoS, DDoS, Man-in-the-Middle (MiM), port redirection, DHCP,
DNS, MAC Flooding, VLAN hopping attacks)
- NBAR, NetFlow (Capture and utilize packet captures )
3) Intrusion Prevention and Content Security
- IPS 4200 Series Sensor Appliance
- VACL/SPAN & RSPAN on Cisco switches
4) Identity Management
- Identity Based Authentication/Authorization/Accounting
- Device Admin (Cisco IOS Routers, ASA, ACS5.x)
- Network Access (TrustSec Model)
- Cisco Identity Services Engine (ISE)
5) Perimeter Security and Services
- Cisco ASA Firewall
- Cisco IOS Zone Based Firewall
- Perimeter Security Services
6) Confidentiality and Secure Access
- IKE , IPsec LAN-to-LAN, DMVPN, FlexVPN, GET VPN , Remote Access VPN
- VPN High Availability, QoS for VPN , VRF-aware VPN , MacSec
- Wireless Access (EAP methods, WPA/WPA-2, WIPS)
¡ß ±³À°Àåºñ

¡ß ±³À° ³»¿ë
±â°£
|
ÁÖÁ¦/³»¿ë
|
1ÁÖÂ÷
|
- º¸¾È ±âÃÊ, ½Ç½À¿ë ³×Æ®¿öÅ© ±¸Ãà
- AAA ±âÃÊ, RADIUS,TACACS+
- ACS ³×Æ®¿öÅ©, ÇÁ·ÎÆÄÀÏ, »ç¿ëÀÚ, ±×·ì, ½Ã½ºÅÛ, ·Î±× ¼³Á¤
- Authentication, Authorization ¹× Accounting ¼³Á¤
|
- °í±Þ ¾×¼¼½º ¸®½ºÆ®, NAT, ¶ó¿ìÆÃ ÇÁ·ÎÅäÄÝ º¸¾È, CBAC
- Web ÇÊÅ͸µ, ÀÎÁõ ÇÁ·Ï½Ã, ħÀÔŽÁö, DoS °ø°Ý ¹æ¾î
- Sinkhole/Blackhole, STP º¸¾È, 802.1X, Æ÷Æ® º¸¾È
|
2ÁÖÂ÷
|
- »óÀ§°èÃþ Æ®·¡ÇÈ Á¦¾îÇϱâ
- AAA, IDS, VPN, ½Ã½ºÅÛ ¹× ¼º´É °ü¸®
|
- IDS ±âº»µ¿ÀÛ ¹æ½Ä ¹× ¼³Á¤, À̺¥Æ® µ¿ÀÛ ·ê ¼³Á¤
- ½Ã±×´ÏÃÄ Á¤ÀÇ, ÇÁ·Î¹Ì/ÀζóÀÎ/¹ÙÀÌÆÐ½º ¸ðµå
- ħÀÔ Å½Áö ¹× Â÷´Ü
- IPSec VPN µ¿ÀÛ¹æ½Ä ¹× ¼³Á¤
- SSL VPN µ¿ÀÛ¹æ½Ä ¹× ¼³Á¤
|
3ÁÖÂ÷
|
- ASA µ¿ÀÛ ¹æ½Ä ¹× ±âº» ¼³Á¤
- ASA¸¦ ÀÌ¿ëÇÑ ¹æÈº® µ¿ÀÛ ¹æ½Ä ¹× ¼³Á¤
- ASA¸¦ ÀÌ¿ëÇÑ IPS/VPN µ¿ÀÛ ¹æ½Ä ¹× ¼³Á¤
- ASDMÀ» ÀÌ¿ëÇÑ ASAÀÇ FW/IPS/VPN ¼³Á¤
|
- Section 1:
1) Config ASA1 & ASA2 HA Single Context
2) Config ASA3 Multi-Context
3) Config ASA4 Transparent Mode
- Section 2:
1) IPS Sensor Setup
2) IPS VLAN INLine PAIR
3) IPS Custom Signature
4) WSA Setup and WCCP
|
4ÁÖÂ÷
|
- Section 3:
1) IPsec not working
2) Troubleshoot IPv6 VTI
3) DMVPN Phase 3 Dual Hubs
4) Security Feature on WLC
- Section 4:
1) Troubleshoot OSPFv3
2) IP Options Management on ASA
|
- Section 5:
1) Application Inspection on ASA
2) DAI & DHCP
3) LDAP Question
- Section 6:
1) 802.1X on AP (ISE)
2) 802.1X on Phone (ISE)
|
