Description
The Cisco ASA Firewall Migration (ASA-UPGRD) v8.3 course is an instructor-led course designed for network security engineers that already design, implement, & configure Cisco ASA adaptive security appliances. This 2.5 day advanced level course aims at providing network security engineers with the knowledge and skills needed to perform a migration from operating system 8.x to 8.3+ on the Cisco ASA adaptive security appliance. This course will take students through all of the various stages of migration; including hardware requirements & upgrades, overview of major changes, NAT migration, NAT exemption migration, Network & Service object migration. The course will also examine ‘What’s new” in the ASA - features & capabilities, the 5585-x platform.
Objectives
Upon completing this course, the learner will be able to meet these overall objectives:
- Evaluate the hardware & software requirements to migrate from operating system 8.x to 8.3+ on the Cisco ASA adaptive security appliance.
- Perform an 8.x to 8.3+ version migration - This will include performing hardware upgrade, software upgrade, saving the configuration, & auto migration of the 8.x to 8.3+ configuration.
- Understand 8.2 to 8.3+ NAT migration guidelines & limitations
- Migrate, configure, & deploy 8.3+ version of NAT, NAT exemption, Network & Service objects.
Who Should Attend
The primary audience for this course is as follows:
- Cisco Partners.
- Network Security Engineers (NSEs) with prior experience on Cisco ASA adaptive security appliances.
Course Outline
Module 1 - ASA Software Requirements & Process
Lesson 1 - System Requirments
- Memory Information
- ASDM, SSM, SSC, VPN Capability
- Upgrade Process
- Lab 1
Module 2 - ASA Migration
Lesson 1 - Migrated Features
- Overview of Major Changes
Lesson 2 - Migrating the Configuration
- Backup of Configuration
- Auto Migration
- Saving the Migrated Configuration
- Features that use Real IP Addresses
- Real IP Addresses in Access List Migration w/Examples
- Lab 2
Module 3 - ASA 8.3 NAT Migration
Lesson 1 - NAT Migration
- NAT Then & Now
- Old Nat Commands
- New Nat Commands
- Supporting Commands for Nat
- Nat Migration Guidelines & Limitations
- Scenario & Examples
- Lab 3
Lesson 2 - Nat Exemption
- NAT Control
- DNS Rewrite
- Connection Settings
- Source and Destination Nat
- alias Command
- Nat Migration Messages
- Scenario & Examples
- Lab 4
Lesson 3 - Network & Service Object Migration
- Supported Features for Objects
- Object Migration
- Object Migration Naming Conventions
- Scenario & Examples
- Lab 5
Module 4 - What's New for the ASA
Lesson 1 - Features & Capabilities
Lesson 2 - New Hardware Platform
- Overview & Explanation 5585-x
Prerequisites
The knowledge and skills a learner must have before attending this course include the following:
- Cisco Certified Network Associate Security (CCNA Security) certification. - Preferred
- One of the following:
- Cisco SNAF v1.0 course
- Cisco Firewall v1.0 course
- Working knowledge of the Cisco ASA adaptive security appliance.