Integrated Security Technologies and Solutions - Volume II CCIE Professional Development (整合安全技術與解決方案 - 第二卷)

Aaron Woland , Vivek Santuka , Jamie Sanbower , Chad Mitchell

  • 出版商: Cisco Press
  • 出版日期: 2019-04-06
  • 售價: $2,860
  • 貴賓價: 9.5$2,717
  • 語言: 英文
  • 頁數: 688
  • 裝訂: Paperback
  • ISBN: 1587147076
  • ISBN-13: 9781587147074
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=1)

買這商品的人也買了...

相關主題

商品描述

The essential reference for security pros and CCIE Security candidates: identity, context sharing, encryption, secure connectivity and virtualization

 

Integrated Security Technologies and Solutions – Volume II brings together more expert-level instruction in security design, deployment, integration, and support. It will help experienced security and network professionals manage complex solutions, succeed in their day-to-day jobs, and prepare for their CCIE Security written and lab exams.

 

Volume II focuses on the Cisco Identity Services Engine, Context Sharing, TrustSec, Application Programming Interfaces (APIs), Secure Connectivity with VPNs, and the virtualization and automation sections of the CCIE v5 blueprint. Like Volume I, its strong focus on interproduct integration will help you combine formerly disparate systems into seamless, coherent, next-generation security solutions.

 

Part of the Cisco CCIE Professional Development Series from Cisco Press, it is authored by a team of CCIEs who are world-class experts in their Cisco security disciplines, including co-creators of the CCIE Security v5 blueprint. Each chapter starts with relevant theory, presents configuration examples and applications, and concludes with practical troubleshooting.

 

  • Review the essentials of Authentication, Authorization, and Accounting (AAA)

  • Explore the RADIUS and TACACS+ AAA protocols, and administer devices with them

  • Enforce basic network access control with the Cisco Identity Services Engine (ISE)

  • Implement sophisticated ISE profiling, EzConnect, and Passive Identity features

  • Extend network access with BYOD support, MDM integration, Posture Validation, and Guest Services

  • Safely share context with ISE, and implement pxGrid and Rapid Threat Containment

  • Integrate ISE with Cisco FMC, WSA, and other devices

  • Leverage Cisco Security APIs to increase control and flexibility

  • Review Virtual Private Network (VPN) concepts and types

  • Understand and deploy Infrastructure VPNs and Remote Access VPNs

  • Virtualize leading Cisco Security products

  • Make the most of Virtual Security Gateway (VSG), Network Function Virtualization (NFV), and microsegmentation

商品描述(中文翻譯)

《整合安全技術與解決方案 - 第二卷》是安全專業人士和CCIE Security考生的必備參考書籍,涵蓋身份識別、內容共享、加密、安全連接和虛擬化等主題。

本書是Cisco Press的《Cisco CCIE專業發展系列》之一,由一群CCIE專家撰寫,他們在Cisco安全領域擁有世界級的專業知識,其中包括CCIE Security v5藍圖的共同創作者。每一章節都以相關理論開始,提供配置示例和應用,並以實際故障排除結束。

第二卷主要關注Cisco Identity Services Engine、內容共享、TrustSec、應用程式編程接口(API)、使用虛擬私人網路(VPN)進行安全連接,以及CCIE v5藍圖中的虛擬化和自動化部分。與第一卷一樣,本書強調產品間的整合,幫助讀者將以前分散的系統結合成無縫、一致的下一代安全解決方案。

本書的內容包括身份驗證、授權和記帳(AAA)的基本知識、RADIUS和TACACS+ AAA協議的介紹與設定、使用Cisco Identity Services Engine(ISE)實施基本網絡存取控制、實現複雜的ISE配置、擴展網絡存取支援BYOD、MDM整合、姿態驗證和訪客服務、安全共享ISE上下文、實施pxGrid和快速威脅遏制、將ISE與Cisco FMC、WSA和其他設備整合、利用Cisco安全API增加控制和靈活性、VPN概念和類型、部署基礎設施VPN和遠程訪問VPN、虛擬化領先的Cisco安全產品、充分利用虛擬安全網關(VSG)、網絡功能虛擬化(NFV)和微分段。

《整合安全技術與解決方案 - 第二卷》是一本實用的參考書籍,適合有經驗的安全和網絡專業人士,能夠幫助他們應對複雜的解決方案,成功完成日常工作,並為CCIE Security筆試和實驗考試做好準備。

作者簡介

Aaron Woland, CCIE® No. 20113, is a principal engineer in Cisco’s Advanced Threat Security group and works with Cisco’s largest customers all over the world. His primary job responsibilities include security design, solution enhancements, standards development, advanced threat solution design, endpoint security, and futures.

 

Aaron joined Cisco in 2005 and is currently a member of numerous security advisory boards and standards body working groups. Prior to joining Cisco, Aaron spent 12 years as a consultant and technical trainer.

 

Aaron’s other publications include Integrated Security Technologies and Solutions - Volume I; both editions of Cisco ISE for BYOD and Secure Unified AccessCisco Next- Generation Security Solutions: All-in-one Cisco ASA FirePOWER ServicesNGIPS and AMPCCNP Security SISAS 300-208 Official Cert Guide; the CCNA Security 210-260 Complete Video Course; and many published white papers and design guides.

 

Aaron is one of only five inaugural members of the Hall of Fame Elite for Distinguished Speakers at Cisco Live, and he is a security columnist for Network World, where he blogs on all things related to security. His other certifications include GHIC, GCFE, GSEC, CEH, MCSE, VCP, CCSP, CCNP, and CCDP, among others.

 

You can follow Aaron on Twitter: @aaronwoland.

 

Vivek Santuka, CCIE® No. 17621, is a consulting systems engineer at Cisco and is a security consultant to some of Cisco’s largest customers. He has over 13 years of experience in security, focusing on identity management and access control. Vivek is a member of multiple technical advisory groups.

 

Vivek holds two CCIE certifications: Security and Routing and Switching. In addition, he holds RHCE and CISSP certifications and is a Distinguished Speaker at Cisco Live.

 

Vivek is also the coauthor of the Cisco Press books AAA Identity Management Security and Integrated Security Technologies and Solutions – Volume I.

 

You can follow Vivek on Twitter: @vsantuka.

 

Jamie Sanbower, CCIE® No. 13637 (Routing and Switching, Security, and Wireless), is a principal systems engineer for Cisco’s Global Security Architecture Team. Jamie has been with Cisco since 2010 and is currently a technical leader and member of numerous advisory and working groups.

 

With over 15 years of technical experience in the networking and security industry, Jamie has developed, designed, implemented, and operated enterprise network and security solutions for a wide variety of large clients. He is coauthor of the Cisco Press book Integrated Security Technologies and Solutions - Volume I.

 

Jamie is a dynamic presenter and is a Cisco Live Distinguished Speaker. Prior to Cisco, Jamie had various roles, including director of a cyber security practice, senior security consultant, and senior network engineer.

 

Chad Mitchell, CCIE® No. 44090, is a technical solutions architect at Cisco supporting the Department of Defense and supporting agencies. In his daily role, he supports the sales teams as a technical resource for all Cisco security products and serves as the Identity Services Engine subject matter expert for Cisco’s US Public Sector team.

 

Chad has been with Cisco since 2013 supporting the DoD and other customers and is a contributing member to the Policy & Access Technical Advisors Group. Prior to joining Cisco, Chad spent 7 years as a deployment engineer and systems administrator implementing Cisco security products for customers.

 

While his primary area of expertise is enterprise network access control with ISE, Chad is well versed on all Cisco security solutions such as ASA firewalls, Firepower NGFW/IPS/IDS, and Stealthwatch, to name a few; he also has first-hand experience deploying these solutions in customer production environments.

作者簡介(中文翻譯)

Aaron Woland,CCIE® No. 20113,是思科高級威脅安全團隊的首席工程師,與全球最大的思科客戶合作。他的主要工作職責包括安全設計、解決方案增強、標準開發、高級威脅解決方案設計、端點安全和未來發展。

Aaron於2005年加入思科,目前是多個安全諮詢委員會和標準機構工作組的成員。在加入思科之前,Aaron擔任顧問和技術培訓師長達12年。

Aaron的其他出版物包括《集成安全技術和解決方案-第一卷》、《Cisco ISE for BYOD和Secure Unified Access》的兩個版本、《Cisco Next-Generation Security Solutions: All-in-one Cisco ASA FirePOWER Services》、《NGIPS和AMP》、《CCNP Security SISAS 300-208官方認證指南》、《CCNA Security 210-260完整視頻課程》以及許多發表的白皮書和設計指南。

Aaron是思科Live杰出演講者名人堂的五位創始成員之一,也是Network World的安全專欄作家,他在博客中討論與安全相關的所有事項。他的其他認證包括GHIC、GCFE、GSEC、CEH、MCSE、VCP、CCSP、CCNP和CCDP等。

您可以在Twitter上關注Aaron:@aaronwoland。

Vivek Santuka,CCIE® No. 17621,是思科的諮詢系統工程師,是思科最大客戶的安全顧問。他在安全領域擁有超過13年的經驗,專注於身份管理和訪問控制。Vivek是多個技術諮詢組的成員。

Vivek擁有兩個CCIE認證:安全和路由交換。此外,他還擁有RHCE和CISSP認證,並且是思科Live的杰出演講者。

Vivek還是思科出版社書籍《AAA Identity Management Security》和《集成安全技術和解決方案-第一卷》的合著者。

您可以在Twitter上關注Vivek:@vsantuka。

Jamie Sanbower,CCIE® No. 13637(路由交換、安全和無線),是思科全球安全架構團隊的首席系統工程師。Jamie自2010年加入思科,目前是技術領導者和多個諮詢和工作組的成員。

Jamie在網絡和安全行業擁有超過15年的技術經驗,為各種大型客戶開發、設計、實施和運營企業網絡和安全解決方案。他是思科出版社書籍《集成安全技術和解決方案-第一卷》的合著者。

Jamie是一位富有活力的演講者,是思科Live的杰出演講者。在加入思科之前,Jamie擔任過多個職位,包括網絡安全實踐總監、高級安全顧問和高級網絡工程師。

Chad Mitchell,CCIE® No. 44090,是思科的技術解決方案架構師,支持國防部和相關機構。在日常工作中,他作為思科安全產品的技術資源,支持銷售團隊,並擔任思科美國公共部門團隊的身份服務引擎專家。

Chad自2013年加入思科,支持國防部和其他客戶,並成為政策和訪問技術顧問組的貢獻成員。在加入思科之前,Chad在部署工程師和系統管理員方面擁有7年的經驗,為客戶實施思科安全產品。