Course Overview
In Module two of the CSSA Instructor-led series, emphasis is on building a comprehensive network that demonstrates most of the commonly used features in SonicOS Enhanced firmware. Students will build a network consisting of a LAN, DMZ, and VPN tunnels. Using this network, they will create NAT policies, access rules, and layered security, apply port address translations, static and dynamic routing, configure SNMP and failover, interpret logs and generate reports, and use basic administrative features.
This module is intended to provide practical hands-on learning and troubleshooting experience for students interested in obtaining Certified SonicWALL System Administrator certification. Skills applied in this class leverage concepts taught in the Technical e*Training courses, and form the basis for the CSSA certification exam. Labs for this class are based on SonicOS 3.1 Enhanced firmware.
Audience
Those persons tasked with the support, installation, deployment or administration of SonicWALL products, including but not limited to System Administrators, Security staff, Firewall Administrators, Network Engineers, Pre-Sales Engineers, System Engineers, Reseller Support, Installation Consultants
Skills Gained
Upon completing this training course, participants should be able to:
- Install SonicWALL Firewall Appliances within a network
- Configure Network Access Rules, working with Zones, Objects, and Groups
- Configure VPN Solutions
- Configure routing options and QoS
- Configure and Test Load Balancing and Failover
- Install and Configure SonicWALL Layered Security Services, including Content Filtering, Antivirus, and Intrusion
- Prevention
- Configure and interpret logs and reports
- Perform basic administrative tasks and troubleshooting
- All students should have a basic knowledge of networking concepts including network topologies and an understanding of the OSI model of networking protocol stacks. Familiarity with Microsoft Windows Networking is helpful.
- SonicWALL recommends that attendees have an understanding of TCP/IP, network addressing, subnet masks, and Network Address Translation, as well as knowledge of basic router concepts. Familiarity with Virtual Private Networking and IPSec functionality would also be helpful.
- Students are assumed to have a basic conceptual knowledge of firewalls and their role within a network.
- Students MUST complete the SonicWALL Technical e*Training courses prior to attending instructor-led courses. The Technical e*Training courses are: Securing Networks with SonicOS and Virtual Private Networking with SonicWALL and Securing SonicWALL Wireless Networks.
- Completion of CSSA1 or equivalent knowledge basis
- Students who do not meet course prerequisites may have difficulty completing classroom labs.
Course Outline
Note: The Standard Enhanced Security course has been designed to provide hands-on experience with common SonicWALL network integration features using SonicOS Enhanced firmware. While the topic areas are similar to those presented in the CSSA 1: Fundamentals course, this day of instruction assumes prior knowledge of networking concepts and focuses time on more advanced labs rather than on lecture.
Security Overview
- Network Security Definitions, Risks, and Techniques
- SonicWALL Security Upgrades
- Real-Time Gateway Anti Virus
- Intrusion Prevention Services v2.0
- SonicOS Enhancements for 3.0
- AD and LDAP
- 802.1q VLAN Support
- Advanced Routing Services
- Dynamic DNS
- Real-Time Monitoring
- Static ARO Support
- Virtual Adapter Static Support
- SYN Cookie/Other TCP Enhancements
- VPN Auto-Added Access Rule Control
- SonicSetup
- Configuring the Firewall (Labs)
- Booting in safe mode
- Physical interface addressing
- Enabling DHCP on LAN 0
- Registering firewall and configuring layered security services
Extending Firewall Functionality: Zones, Objects, NAT and Rules (Labs)
- Assigning interfaces to Zones
- Creating Address Objects
- Applying NAT Policies
- Configuring Access Rules
Applying Advanced User Level Access (Labs)
Designing VPN Networks (Labs)
- Creating a Hub & Spoke network with NAT on VPN tunnel
- Provisioning remote site communication through single VPN tunnel to the head-end
- Provisioning VPN between two sites using same LAN subnet
Extending the Firewall Functionality with Security Services (Labs)
- Provision and test AV, CFS, and IPS
- Apply group-level CFS policies
- Restricting web-access by user
Applying Advanced NAT policies
- Creating Inbound Port-address Translation
Creating Advanced routing (Labs)
Follow On Courses
PWW0143 (CSSA3), PWW0144 (CSGM)