Overview:
This three-day course covers the majority of features available on Juniper Firewall/VPN products. Students will have the opportunity to configure Juniper Security devices in a variety of lab scenarios. This course now incorporates Security Manager as a configuration interface, and includes coverage of the new SSG and ISG hardware platforms.
Target Audience
Network engineers, support personnel, reseller support, and others responsible for implementing Juniper Security/FWV products utilizing the basic Firewall/VPN features covered in this class.
Objectives
By the end of this course, students will be able to install, configure and maintain Juniper Firewall devices in common environments, and describe the Firewall/VPN packet handling process. Students will also be able to configure a wide range of features. Specific topics include:
- ScreenOS Concepts, Terminology, and Platforms
- ScreenOS Security Architecture
- Describe the flow of a packet through a ScreenOS device
- Establish connectivity to the ScreenOS device
- Device Management
- Manage configuration and software image files
- Perform disaster recovery procedures
- Layer 3 Operations
- Configure static routes
- Configure a loopback interface
- Configure interfaces for NAT or route mode
- Verify and troubleshoot Layer 3 operations
- Policy Configuration including:
o Traffic logging, counters, scheduling, User Authentication
- Address Translation
- Configure policy-based translation:
o NAT-src, NAT-dst, VIP, MIP
- Transparant Mode
- VPN Concepts
- Policy Based VPNs
- Configure a IKE based VPN binding to Policies with:
o Phase 1 Gateways, Phase 2 AutoKey IKE, Address and Service Books
- Route Based VPNs
Prerequisites:
This course assumes that students have basic networking knowledge and experience in the following areas:
- Ethernet
- Transparent Bridging
- TCP/IP Operations
- IP Addressing
- Routing
This course prepares students for the Juniper Networks JNCIA-FWV Certification exam, whose topics are based on the content of this course.
Duration: 3 Days