Implementing Cisco Edge Network Security Solutions V 1.0


Implementing Cisco Edge Network Security Solutions (SENSS) v1.0 is a newly created five-day instructor-led training (vILT) course and is part of the curriculum path leading to the Cisco Certified Network Professional Security (CCNP Security) certification. Additionally, it is designed to prepare security engineers with the knowledge and hands-on experience to prepare them to configure Cisco perimeter edge security solutions utilizing Cisco Switches, Cisco Routers, and Cisco Adaptive Security Appliance (ASA) Firewalls. The goal of the course is to provide students with foundational knowledge and the capabilities to implement and managed security on Cisco ASA firewalls, Cisco Routers with the firewall feature set, and Cisco Switches. The student will gain hands-on experience with configuring various perimeter security solutions for mitigating outside threats and securing network zones. At the end of the course, students will be able to reduce the risk to their IT infrastructures and applications using Cisco Switches, Cisco ASA, and Router security appliance feature and provide detailed operations support for these products.

Duration – 5 Days hands-on training
Vendor – Cisco
Audience – Network Security Engineers
Level – Professional
Technology – Cisco
Category – Professional Borderless Networking / Security
Delivery Method – Instructor-led (Classroom)
Training Credits / Vouchers – Cisco Learning Credits Accepted

Course Content

1. Course Introduction

  • Overview
  • Course Goal and Objectives
  • Course Flow
  • Additional References
  • Your Training Curriculum

2. Cisco Secure Design Principles

  • Network Security Zoning
  • Cisco Module Network Architecture
  • Cisco SecureX Architecture
  • Cisco TrustSec Solutions

3. Implement NetworkInfrastructure Protection

  • Introducing Cisco Network Infrastructure Architecture
  • Deploying Cisco IOS Control Plane Security Controls
  • Deploying Cisco IOS Management Plane Security Controls
  • Deploying Cisco ASA Management Plane Security Controls
  • Deploying Cisco Traffic Telemetry Methods
  • Deploying Cisco IOS Layer 2 Data Plane Security Controls
  • Deploying Cisco IOS Layer 3 Data Plane Security Controls

4. Deploying NAT on Cisco IOS and Cisco Adaptive SecurityAppliance

  • Introducing Network Address Translation
  • Deploying Cisco ASA Network Address Translation
  • Deploying Cisco IOS Software Network Address Translation

5. Deploying Threat Controls on Cisco ASA

  • Introducing Cisco Threat Controls
  • Deploying Cisco ASA Basic Access Controls
  • Deploying Cisco ASA Application Inspection Policies
  • Deploying Cisco ASA Botnet Traffic Filtering
  • Deploying Cisco ASA Identity Based Firewall

6. Deploying Threat Controls onCisco IOS Software

  • Deploying Cisco IOS Software with Basic Zone-Based Firewall Policies
  • Deploying Cisco IOS Software Zone-Based Firewall with Application Inspection Policies


The knowledge and skills a learner should have before attending this course:

  • Cisco Certified Network Associate (CCNA) certification
  • Cisco Certified Network Associate (CCNA) Security certification
  • Knowledge of Microsoft Windows operating system

Course Objectives

Upon completing this course, the learner will be able to meet these overall objectives:

  • Understand current security threat landscape
  • Understanding and implementing Cisco modular Network Security Architectures such as SecureX and TrustSec
  • Deploy Cisco Infrastructure management and control plane security controls
  • Configuring Cisco layer 2 and layer 3 data plane security controls
  • Implement and maintain Cisco ASA Network Address Translations (NAT)
  • Implement and maintain Cisco IOS Software Network Address Translations (NAT)
  • Designing and deploying Cisco Threat Defense solutions on a Cisco ASA utilizing access policy and application and identity based inspection
  • Implementing Botnet Traffic Filters
  • Deploying Cisco IOS Zone-Based Policy Firewalls (ZBFW)
  • Configure and verify Cisco IOS ZBFW Application Inspection Policy

Target Audience

This course is intended primarily for:

  • Network Security Engineers

Associated Certifications & Exam

The 300-206 Implementing Cisco Edge Network Security (SENSS) exam tests the knowledge of a network security engineer toconfigure and implement security on Cisco network perimeter edge devices such as a Cisco Switch, Cisco Router, and Cisco ASAFirewall. This exam focuses on the technologies used to secure the perimeter of a network such as Network Address Translation(NAT), ASA policy and application inspect, and Zone-Based Firewall on Cisco routers.