CISCO SECURITY PORTFOLIO

  1. IOS routers Provide RFC 2827 and RFC 1918 filtering, protocol filtering, and VPN termination, as well as stateful firewall and intercept features.

  2. PIX firewalls Provide stateful firewall and VPN termination; 515 and higher support VPN accelerator card from PIX OS v5.3(1) with DES or 3DES license.

  3. Cisco NIDS Provides intrusion monitoring across a network segment; usually set to alarm.

  4. Cisco HIDS Provides host-level intrusion monitoring; usually set to alarm, drop, and (possibly) reset.

  5. VPN concentrator Terminates many VPN tunnels at the headend; often used when more than 20 tunnels must be terminated . Can support a maximum of 10010,000 simultaneous users. Provides AES and DH Group 7 in addition to DES/3DES and DH Groups 1, 2, 5.

  6. VPN clients Hardware client often used for small branches that provides tunnel termination and local DHCP and NAT. Software client used for single-host tunnel termination, with split tunneling not recommended. Receive policy and configuration for both pushed from headend.

  7. Identity CiscoSecure ACS for AAA; runs on Windows 2000 server and Solaris (Solaris support ends in 2003).

  8. Security management CiscoWorks VPN/Security Management Solution (VMS); Web-based tools for VPN configuration, monitoring, troubleshooting, and firewall and IDS management; also, CiscoSecure Policy Manager (CSPM) firewall-management functions have been moved to VMS.



CSI Exam Cram 2 (Exam 642-541)
CCSP CSI Exam Cram 2 (Exam Cram 642-541)
ISBN: 0789730243
EAN: 2147483647
Year: 2002
Pages: 177
Authors: Annlee Hines

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net