Cisco ASA: All-in-one Next-Generation Firewall, IPS, and VPN Services, 3/e (Paperback)
暫譯: Cisco ASA:全方位下一代防火牆、入侵防護系統及虛擬私人網路服務,第3版(平裝本)

Jazib Frahim, Omar Santos, Andrew Ossipov

買這商品的人也買了...

相關主題

商品描述

Cisco® ASA

All-in-One Next-Generation Firewall, IPS, and VPN Services, Third Edition

 

Identify, mitigate, and respond to today’s highly-sophisticated network attacks.

 

Today, network attackers are far more sophisticated, relentless, and dangerous. In response, Cisco ASA: All-in-One Next-Generation Firewall, IPS, and VPN Services has been fully updated to cover the newest techniques and Cisco technologies for maximizing end-to-end security in your environment. Three leading Cisco security experts guide you through every step of creating a complete security plan with Cisco ASA, and then deploying, configuring, operating, and troubleshooting your solution.

 

Fully updated for today’s newest ASA releases, this edition adds new coverage of ASA 5500-X, ASA 5585-X, ASA Services Module, ASA next-generation firewall services, EtherChannel, Global ACLs, clustering, IPv6 improvements, IKEv2, AnyConnect Secure Mobility VPN clients, and more. The authors explain significant recent licensing changes; introduce enhancements to ASA IPS; and walk you through configuring IPsec, SSL VPN, and NAT/PAT.

 

You’ll learn how to apply Cisco ASA adaptive identification and mitigation services to systematically strengthen security in network environments of all sizes and types. The authors present up-to-date sample configurations, proven design scenarios, and actual debugs–
all designed to help you make the most of Cisco ASA in your rapidly evolving network.

 

Jazib Frahim, CCIE® No. 5459 (Routing and Switching; Security), Principal Engineer in the Global Security Solutions team, guides top-tier Cisco customers in security-focused network design and implementation. He architects, develops, and launches new security services concepts. His books include Cisco SSL VPN Solutions and Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting.

 

Omar Santos, CISSP No. 463598, Cisco Product Security Incident Response Team (PSIRT) technical leader, leads and mentors engineers and incident managers in investigating and resolving vulnerabilities in Cisco products and protecting Cisco customers. Through 18 years in IT and cybersecurity, he has designed, implemented, and supported numerous secure networks for Fortune® 500 companies and the U.S. government. He is also the author of several other books and numerous whitepapers and articles.

 

Andrew Ossipov, CCIE® No. 18483 and CISSP No. 344324, is a Cisco Technical Marketing Engineer focused on firewalls, intrusion prevention, and data center security. Drawing on more than 16 years in networking, he works to solve complex customer technical problems, architect new features and products, and define future directions for Cisco’s product portfolio. He holds several pending patents.

 

Understand, install, configure, license, maintain, and troubleshoot the newest ASA devices

Efficiently implement Authentication, Authorization, and Accounting (AAA) services

Control and provision network access with packet filtering, context-aware Cisco ASA next-generation firewall services, and new NAT/PAT concepts

Configure IP routing, application inspection, and QoS

Create firewall contexts with unique configurations, interfaces, policies, routing tables, and administration

Enable integrated protection against many types of malware and advanced persistent threats (APTs) via Cisco Cloud Web Security and Cisco Security Intelligence Operations (SIO)

Implement high availability with failover and elastic scalability with clustering

Deploy, troubleshoot, monitor, tune, and manage Intrusion Prevention System (IPS) features

Implement site-to-site IPsec VPNs and all forms of remote-access VPNs (IPsec, clientless SSL, and client-based SSL)

Configure and troubleshoot Public Key Infrastructure (PKI)

Use IKEv2 to more effectively resist attacks against VPNs

Leverage IPv6 support for IPS, packet inspection, transparent firewalls, and site-to-site IPsec VPNs

 

 

商品描述(中文翻譯)

® 全方位下一代防火牆、入侵防護系統 (IPS) 和虛擬私人網路 (VPN) 服務,第三版

識別、減輕並應對當今高度複雜的網路攻擊。

如今,網路攻擊者的手法更加複雜、無情且危險。為此,Cisco ASA: 全方位下一代防火牆、IPS 和 VPN 服務已全面更新,以涵蓋最新的技術和 Cisco 技術,最大化您環境中的端到端安全性。三位領先的 Cisco 安全專家將指導您完成使用 Cisco ASA 創建完整安全計劃的每一步,然後部署、配置、操作和故障排除您的解決方案。

本版針對當今最新的 ASA 發行版進行了全面更新,新增了 ASA 5500-X、ASA 5585-X、ASA 服務模組、ASA 下一代防火牆服務、EtherChannel、全域 ACL、叢集、IPv6 改進、IKEv2、AnyConnect 安全移動 VPN 客戶端等內容。作者解釋了最近的重大授權變更;介紹了 ASA IPS 的增強功能;並指導您配置 IPsec、SSL VPN 和 NAT/PAT。

您將學習如何應用 Cisco ASA 自適應識別和減輕服務,系統性地加強各種規模和類型網路環境的安全性。作者提供了最新的範例配置、經過驗證的設計場景和實際除錯,旨在幫助您在快速演變的網路中充分利用 Cisco ASA。

Jazib Frahim, CCIE® 編號 5459 (路由與交換;安全), 全球安全解決方案團隊的首席工程師,指導頂級 Cisco 客戶進行以安全為重點的網路設計和實施。他設計、開發並推出新的安全服務概念。他的著作包括《Cisco SSL VPN 解決方案》和《Cisco 網路入場控制,第二卷:NAC 部署與故障排除》。

Omar Santos, CISSP 編號 463598,Cisco 產品安全事件響應團隊 (PSIRT) 的技術領導,負責領導和指導工程師及事件經理調查和解決 Cisco 產品中的漏洞,並保護 Cisco 客戶。在 IT 和網路安全領域擁有 18 年的經驗,他為《財富》500 強公司和美國政府設計、實施和支持了多個安全網路。他也是幾本其他書籍以及多篇白皮書和文章的作者。

Andrew Ossipov, CCIE® 編號 18483 和 CISSP 編號 344324, 是一名專注於防火牆、入侵防護和數據中心安全的 Cisco 技術行銷工程師。憑藉超過 16 年的網路經驗,他致力於解決複雜的客戶技術問題,設計新功能和產品,並定義 Cisco 產品組合的未來方向。他擁有多項待批專利。

了解、安裝、配置、授權、維護和故障排除最新的 ASA 設備


有效實施身份驗證、授權和會計 (AAA) 服務


通過封包過濾、上下文感知的 Cisco ASA 下一代防火牆服務和新的 NAT/PAT 概念控制和提供網路訪問


配置 IP 路由、應用檢查和 QoS


創建具有獨特配置、介面、政策、路由表和管理的防火牆上下文


通過 Cisco Cloud Web Security 和 Cisco Security Intelligence Operations (SIO) 啟用對多種惡意軟體和高級持續威脅 (APT) 的集成保護


通過故障轉移和彈性擴展實施高可用性


部署、故障排除、監控、調整和管理入侵防護系統 (IPS) 功能


實施站點到站點的 IPsec VPN 和所有形式的遠端訪問 VPN (IPsec、無客戶端 SSL 和基於客戶端的 SSL)


配置和故障排除公鑰基礎設施 (PKI)


使用 IKEv2 更有效地抵抗對 VPN 的攻擊


利用 IPv6 支援 IPS、封包檢查、透明防火牆和站點到站點的 IPsec VPN