 |
Book Summary InformationAuthor: Jazib Frahim, Qiang Huang Edition: Paperback Audio: English (Unknown); English (Original Language); English (Published) Published: 2008-06-20 ISBN: 1587052423 Number of pages: 384 Publisher: Cisco Press
Book Reviews of SSL Remote Access VPNs (Network Security)Book Review: Good Reference Summary: 3 Stars
SSL Remote Access VPNs
Jazib Frahim, CCIE No. 5459
Qiang Huang, CCIE No. 4937
Right in the middle of a pretty big SSL VPN roll out here at my place of employment, Cisco Press released SSL Remote Access VPNs. They couldn't have had better timing, as there was a good deal I was still confused about.
First, let me get this clear from the start: I hate ASDM. It has its uses, like monitoring. The traffic and VPN monitoring interfaces are wonderful. However, as far as configuration goes, the command-line is preferable. That being said, 95% of this book, including configuration, revolves around ASDM.
The first chapter explains remote access VPNs, which should be pretty familiar to anyone with IPSec VPN experience. Nothing new here, but certainly a good refresher and a good way to build context for the rest of the book.
The next couple chapters focus on SSL VPN technology, as well as SSL VPN design considerations. Definitely a nice review, considering SSL is certainly not a new technology, but building high encryption VPNs using SSL certainly is.
Chapter 4 is just an overview of ASA appliances and IOS routers and their SSL VPN capabilities. It's only a few pages, so it's not exactly deep reading, but useful nonetheless.
Next is a chapter on SSL VPN on the ASA. Probably the best part of the book, it mostly focuses on clientless SSL VPN. It has a (too short) section on configuring the AnyConnect client. This is the part that I personally found the most useful, which is why I was disappointed that it was so short. Also included are Dynamic Access Policies (DAP), and a couple of deployment scenarios.
The next chapter is on SSL VPN on IOS routers. I have to admit, I only skimmed this chapter, as it just wasn't relevant to my deployment. But from what I could tell, it was just as thorough as the previous chapter, and possibly more so. It also included most of the SDM configuration in CLI form as well, and I have to wonder why the ASA chapter didn't have more CLI in it as well.
Finally, there is a short chapter on SSL VPN management. This chapter basically just shows you some of the monitoring interface in ASDM. Sadly, nothing in the way of CLI, but that's a pretty recurring theme in this book.
In conclusion, I would have to say this book is certainly worth picking up if you're planning on doing an SSL VPN roll out any time soon. The only real issue I had with the book was what I've already mentioned a few times, and that is the lack of CLI. I realize Cisco is really pushing SDM and ASDM, but they need to understand that network engineers are -not- point and click kind of people. Leave that to the MCSEs! ;)
- Chris
Summary of SSL Remote Access VPNs (Network Security)SSL Remote Access VPNs An introduction to designing and configuring SSL virtual private networks Jazib Frahim, CCIE® No. 5459 Qiang Huang, CCIE No. 4937 Cisco® SSL VPN solutions (formerly known as Cisco WebVPN solutions) give you a flexible and secure way to extend networking resources to virtually any remote user with access to the Internet and a web browser. Remote access based on SSL VPN delivers secure access to network resources by establishing an encrypted tunnel across the Internet using a broadband (cable or DSL) or ISP dialup connection. SSL Remote Access VPNs provides you with a basic working knowledge of SSL virtual private networks on Cisco SSL VPN-capable devices. Design guidance is provided to assist you in implementing SSL VPN in existing network infrastructures. This includes examining existing hardware and software to determine whether they are SSL VPN capable, providing design recommendations, and guiding you on setting up the Cisco SSL VPN devices. Common deployment scenarios are covered to assist you in deploying an SSL VPN in your network. SSL Remote Access VPNs gives you everything you need to know to understand, design, install, configure, and troubleshoot all the components that make up an effective, secure SSL VPN solution. Jazib Frahim, CCIE® No. 5459, is currently working as a technical leader in the Worldwide Security Services Practice of the Cisco Advanced Services for Network Security. He is responsible for guiding customers in the design and implementation of their networks, with a focus on network security. He holds two CCIEs, one in routing and switching and the other in security. Qiang Huang, CCIE No. 4937, is a product manager in the Cisco Campus Switch System Technology Group, focusing on driving the security and intelligent services roadmap for market-leading modular Ethernet switching platforms. During his time at Cisco, Qiang has played an important role in a number of technology groups, including the Cisco TAC security and VPN team, where he was responsible for trouble-shooting complicated customer deployments in security and VPN solutions. Qiang has extensive knowledge of security and VPN technologies and experience in real-life customer deployments. Qiang holds CCIE certifications in routing and switching, security, and ISP Dial. - Understand remote access VPN technologies, such as Point-to-Point Tunneling Protocol (PPTP), Internet Protocol Security (IPsec), Layer 2 Forwarding (L2F), Layer 2 Tunneling (L2TP) over IPsec, and SSL VPN
- Learn about the building blocks of SSL VPN, including cryptographic algorithms and SSL and Transport Layer Security (TLS)
- Evaluate common design best practices for planning and designing an SSL VPN solution
- Gain insight into SSL VPN functionality on Cisco Adaptive Security Appliance (ASA) and Cisco IOS® routers
- Install and configure SSL VPNs on Cisco ASA and Cisco IOS routers
- Manage your SSL VPN deployment using Cisco Security Manager
This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks. Category: Networking: Security Covers: SSL VPNs
Privacy Books
|
 |
Cryptography Decryptedby H. X. Mel, Doris M. Baker Addison-Wesley Professional; Published: 2000-12-31; Paperback; BookBest price: $30.00Price in other shops: $54.99
The Law of Copyright and the Internet: The 1996 WIPO Treaties, Their Interpretation and Implementationby Mihï¿1/2ly Ficsor Oxford University Press, USA; Published: 2002-05-16; Hardcover; BookBest price: $157.09Price in other shops: $510.00
Network Security for Government and Corporate Executivesby Rand Morimoto, Chris Amaris, Andrew Abbate, Mark Weinhardt Prentice Hall; Published: 2006-10-01; Paperback; BookBest price: $70.00Price in other shops: $73.33
Myspace: Safe Online Networking for Your Kidsby Larry Magid, Anne Collier Prentice Hall; Published: 2006-12-07; Paperback; Book
Using Set for Secure Electronic Commerce with CDROMby Grady Drew Prentice Hall PTR; Published: 1998-11-30; Paperback; BookBest price: $3.80Price in other shops: $44.99
Network Security: Private Communication in a Public World (2nd Edition)by Charlie Kaufman, Radia Perlman, Mike Speciner Prentice Hall; Published: 2002-05-02; Hardcover; BookBest price: $54.99Price in other shops: $84.99
Windows Internet Security: Protecting Your Critical Databy Seth Fogie, Cyrus Peikari Prentice Hall; Published: 2001-10-07; Paperback; BookBest price: $6.99Price in other shops: $39.99
Administrating Web Servers, Security, & Maintenance Interactive Workbookby Eric Larson, Brian Stephens Prentice Hall; Published: 2000-01-09; Paperback; BookBest price: $12.99Price in other shops: $65.32
Keeping Found Things Found: The Study and Practice of Personal Information Management (Interactive Technologies)by William Jones Morgan Kaufmann; Published: 2007-11-15; Paperback; BookBest price: $34.00Price in other shops: $57.95
Upgrade Your Life: The Lifehacker Guide to Working Smarter, Faster, Betterby Gina Trapani Wiley; Published: 2008-03-17; Paperback; BookBest price: $5.99Price in other shops: $29.99
|
BGP Design and Implementationby Randy Zhang, Micah Bartell Cisco Press; Published: 2003-12-22; Hardcover; BookBest price: $51.57Price in other shops: $75.00
CCNP Security VPN 642-647 Official Cert Guideby Howard Hooper Cisco Press; Published: 2011-08-03; Hardcover; BookBest price: $34.90Price in other shops: $69.99
Internet Routing Architectures (2nd Edition)by Sam Halabi Cisco Press; Published: 2000-09-02; Hardcover; BookBest price: $49.50Price in other shops: $72.00
Network Security Technologies and Solutions (CCIE Professional Development Series)by Yusuf Bhaiji Cisco Press; Published: 2008-03-30; Hardcover; BookBest price: $51.99Price in other shops: $82.99
CISSP All-in-One Exam Guide, Fifth Editionby Shon Harris McGraw-Hill Osborne Media; Published: 2010-01-15; Hardcover; BookBest price: $38.60Price in other shops: $79.99
AAA Identity Management Security (Networking Technology: Security)by Vivek Santuka, Premdeep Banga, Brandon J. Carroll Cisco Press; Published: 2010-12-26; Paperback; BookBest price: $16.46Price in other shops: $70.00
The Complete Cisco VPN Configuration Guideby Richard Deal Cisco Press; Published: 2005-12-25; Paperback; BookBest price: $31.99Price in other shops: $90.00
IPSec VPN Designby Vijay Bollapragada, Mohamed Khalid, Scott Wainner Cisco Press; Published: 2005-04-08; Paperback; BookBest price: $30.99Price in other shops: $60.00
The Accidental Administrator: Cisco ASA Security Appliance: A Step-by-Step Configuration Guideby Don R Crawley CreateSpace; Published: 2010-08-03; Paperback; BookBest price: $28.91Price in other shops: $40.00
Cisco ASA: All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance (2nd Edition)by Jazib Frahim, Omar Santos Cisco Press; Published: 2010-01-08; Paperback; BookBest price: $50.99Price in other shops: $82.00
|