Master Network Engineering Program
Master Network Engineering Program
Become a Network Engineer - learn to design, build and configure new network infrastructure
and maintain existing network systems.
This Master's Program consists of CCNA, CCNP and Firewalls (Palo Alto Firewall, Fortigate
Firewall or Check Point Firewall).
[Link] | [Link]
1. 1.
multiple switches
network components.
Access ports
Routers Servers
Default VLAN
L2 and L3 Switches Endpoints and Access
Connectivity
Points
2. 2.
topology architectures. Rapid PVST+ Spanning Tree Protocol and identify
basic operations
2-tier WAN
3-tier Root port Port States
SOHO
Spine-leaf Root bridge PortFast benefits
On-premise and cloud
3. Learn the difference between these two Internet Understand physical infrastructure connections of
WLAN components
protocols.
3. AP/WLC management WLAN connection
5. Global unicast
Unique local
Anycast
Multicast
Link local Modified EUI 64
Switching
Understand switching concepts
1.
Configure and verify inside source NAT using static
2.
default
Longest match
Administrative distance
Routing protocol metric
3.
and Domain Name System (DNS)
Explain the role of DHCP and DNS within the network
Static Routing
Configure and verify IPv4 and IPv6 static routing
3. Default route
Network route
Host route
Floating static
4.
Syslog features
OSPFv2 Facilities
Configure and verify single area OSPFv2 Levels
4. Neighbor adjacencies
Point-to-point
Broadcast
Router ID
TFTP/ FTP
6. Explain the functions of TFTP and FTP in a network
[Link] | [Link]
Module 5 Security Fundamentals Module 6 Automation & Programmability
1.
Explain how automation impacts network
1. Threats
Vulnerabilities
Exploits
Mitigation techniques
management
2. User awareness
Control Plane North bound APIs
Training
Data Plane South bound APIs
Physical access control
Device Management
Virtual Private Networks (VPNs)
3.
Compare traditional campus device management
3. Define remote access and site-to-site VPNs with Cisco DNA Center
Security Features
REST-based APIs
Configure Layer 2 security features
4.
Describe characteristics of REST-based APIs
DHCP snooping
Dynamic ARP inspection
4. CRUD
HTTP verbs
Port security
Data encoding
WLAN
Configure WLAN using:
[Link] | [Link]
Module 7 Industry Oriented Lab Practice
[Link] | [Link]
Module 7 Industry Oriented Lab Practice
[Link] | [Link]
Cisco Certified Network Professional (CCNP):
Become a Network Professional- Implement and troubleshoot both LAN and WAN networks.
1. network
1. Hypervisor type 1 and 2
Virtual machine
Tier 2, Tier 3 planning High availability
Virtual switching
Fabric Capacity planning techniques (FHRP, SSO,
Redundancy)
2. 2.
topology architectures. virtualization technologies
Wireless deployment models
Location services in a WLAN design VRF IPsec Tunneling
infrastructure deployments
3. solution
3. LISP
SD-WAN control plane elements Traditional WAN VXLAN
SD-WAN data plane elements SD-WAN solutions
4. solution
Wireless QoS
Describe concepts of wired and wireless QoS
Switching mechanisms
Differentiate hardware and software switching
6. mechanisms
Process and CEF FIB vs. RIB
MAC address table and TCAM
[Link] | [Link]
Module 3 Infrastructure Module 4 Network Assurance
1.
Static and dynamic EtherChannels Trace route
Spanning Tree Protocols (RSTP and MST) Ping, SNMP, Syslog
Configure and verify:
o SPAN/RSPAN/ERSPA
o IPSLA
o NETCONF & RESTCONF
Layer 3
Learn routing concepts, configure and verify OSPF
environments and eBGP.
Wireless
Describe Layer 1 concepts, access point discovery
and join process.
IP Services
Describe, configure and verify
related protocols.
[Link] | [Link]
Module 5 Security Module 6 Automation
1.
APIs
Interpret REST API response code
Construct EEM applet
Compare agent vs. Agentless orchestration tools
(Chef, Ansible, Puppet)
2. ACLs
CoPP
3.
4. EAP
WebAuth
PSK
Threat defence
5. Endpoint security
Next-generation firewall
TrustSec
MACsec
Network access control
[Link] | [Link]
CCNP 300-401 ENARSI:
2. 2.
Policy-based routine
VRF-Lite
Bidirectional forwarding Detection
Address families
[Link] | [Link]
Module 3 Infrastructure Security Module 4 Infrastructure Services
1. IOS AAA
TACACS+ 1. Console and VTY
Telent, HTTP, HTTPS, SSH, SCP
RADIUS (T)FTP
Local database
2.
2. IPv4 access control lists
IPv6 traffic filter
Unicast reverse path forwarding (uRPF)
Troubleshoot control plane policing (CoPP) Network problems using logging & Cisco DNA
3. Center assurance
3.
Telnet EIGRP IPv4 and IPv6 DHCP
SSH OSPF Network performance issues using IP SLA
HTTP(S) BGP NetFlow
SNMP
4. RA guard
DHCP guard
ND inspection/snooping
Source guard
Binding table
[Link] | [Link]
Palo Alto Firewall:
Become a Palo Alto Firewall Engineer- Install, configure, manage and fix the Palo Alto firewall.
You need to clear the Palo Alto Networks Certified Network Security Administrator (PCNSA).
Cybersecurity Portfolio
Identify components and operation of Single-Pass
1. interfaces
Identify how to manage firewall configurations
Identify and schedule dynamic updates.
Parallel Processing architecture
2.
How it relates to traffic movies through your
network Identify and configure security policy match
conditions
Actions
Logging options
Cyberattack lifecycle Identify purpose of specific security rule types
[Link] | [Link]
Module 3 Traffic Visibility Module 4 Securing Traffic
Security policies
Security Profile
1.
1.
Select application-based security
policy rules
[Link] | [Link]
Apply appropriate security profile in a risk scenario
Security policy actions
Configure application filters
Security profile actions
Configure application groups
Customize security profiles in a network scenario
Optimize security policies
App-ID Firewall
2.
Firewall protection against packet-based attacks
policy rules
Features used to streamline App-ID 2. Firewall protection against protocol-based attacks
Use of cloud DNS security to control traffic
policy creation Use of PAN-DB database to control traffic
Application characteristics in App-ID Control access to specific URLs using custom URL
database filtering categories
1. 1.
Method to map IP addresses to usernames Identify the benefits and differences between
Appropriate User-ID agent to deploy Heatmap and BPA reports
Map usernames to user groups using firewall
User-ID configuration options in a graphic
[Link] | [Link]
Fortigate Firewall:
Become a FortiGate Firewall Engineer – Maintain a high level of service on security/network devices and run operations to support network
security infrastructure. We prepare candidates for NSE 4 and NSE 7.
Security Routing
2. Firewall Authentication
Logging and Monitoring
3. Fortinet Single Sign-on (FSSO)
Certificate Operations
Web Filtering
Application Control
4. High Availability (HA)
Privacy
5. Diagnostics
3. Antivirus
Intrusion Prevention and Denial of Service
SSL VPN
[Link] | [Link]
NSE 7 (Advanced course) Course Curriculum:
Security Fabric
1. Introduction
1.
FortiOS Architecture
Traffic and Session Monitoring
[Link] | [Link]
Routing
FortiGuard Routing
High Availability
Central Management
2. Routing [Link] | [Link]
Sessions
Performance SLA
Routing Protocols
3.
Border Gateway Protocol (BGP)
4. UEBA
Clear Conditions
Remediation
[Link] | [Link]
Module 5 OT Security Module 6 FortiSOAR Design and Development
[Link] | [Link]
1.
1.
Learn about the fundamentals of an OT infrastructure
Dashboard Templates and Widgets [Link] | [Link]
Secure an OT infrastructure
Module Templates and Widgets
Use segmentation and micro segmentation in an OT
Application Editor
network
Authentic users
Secure OT network traffic using a FortiGate device
Variables
FortiSIEM
2. Dynamic Variable and values [Link] | [Link]
2.
Jinja Filters
Use FortiGate and FortiNAC to manage and identify Functions and Conditions
devices
Use FortiAnalyzer for logging and reporting
Use FortiSIEM to centralize security information
Playbooks
Produce real-time analysis of security events with
FortiSIEM
3. Introduction to Playbooks [Link] | [Link]
Playbook Core Steps
Playbook Evaulate Steps
Playbook Connectors
Data Ingestion and Execution Steps
[Link] | [Link]
[Link] | [Link]
Check Point Firewall:
Become a Checkpoint Certified Security Administrator (CCSA) certified professional – support, install, develop or
administer Checkpoint software blades.
What is a Firewall?
Launching SmartDashboard
Types of the firewall
Defining basic objects
Packet filtering
1. 1.
Configuring anti-spoofing measures
Application Layer Gateway (Proxy)
Defining basic rules
Check Point's Stateful Inspection Technology
Creating objects using object cloning
Using Database Revision Control
Blocking intruder connections
Setting up a Suspicious Activity Rule in SmartView Monitor
Checking status in SmartView Monitor
Configuring SmartDefence
Configuring Hide NAT
Configuring Static NAT
Encryption math and mechanics
Defining user templates
Defining users
Configuring User Authentication
Configuring Client Authentication
Configuring LDAP authentication with SmartDirectory
Backing up and restoring a Security Gateway and SmartCenter
Server
Module 3 Check Point Firewall-1 Architecture Module 4 Check Point Firewall-1 Overview
1.
Check Point Firewall-1 Kernel
Check Point Firewall-1 Daemon 1. Secure Internal Communications
1.
Access control for administrators
Creating the Rule Base 1. How to install license
[Link] | [Link]
Module 7 Working with the SmartDashboard Module 8 SmartDefence
Active defense
Masking and disabling rules
SmartDefense in action
Uninstalling a Security Policy
SmartDefence Storm Center
1. 1.
Improving VPN-1/Firewall-1 performance
1.
How to create RuleBase Outgoing Packets
Importance of the Rule Base Order
1. Additional Settings
Module 11 Troubleshooting the Security Policy Module 12 Detecting Hacking Method- Spoofing
1.
Anti-spoofing configuration
Any, Any, Any, Accept Rule not accepting traffic
1.
1.
Disabling rules Log Viewer Modes
Uninstalling a Security Policy
Security Policy File 1. Creating and Selecting Selection Criteria
Blocking Connections
Command Line Options for the Security Policy
Block intruder
[Link] | [Link]
Module 15 System Status GUI Module 16 Authentication and Authentication Parameters
Understanding authentication
System Status logon
How user authentication works
Log viewer modes
1.
Static NAT
Hide NAT
Address Resolution Protocol (ARP)
NAT Routing
Static NAT and anti-spoofing
Troubleshooting NAT
[Link] | [Link]
[Link]
[Link]
[Link]
info@[Link]
+918130537300
[Link] | [Link]
[Link]
[Link]