0% found this document useful (0 votes)
25 views19 pages

Master Network Engineering Program

The Network Engineer Master's Program offers comprehensive training in network design, configuration, and maintenance, covering CCNA, CCNP, and firewall technologies. It includes modules on network fundamentals, IP connectivity, security, and automation, preparing students for various networking roles. The program emphasizes hands-on lab practice and industry-oriented skills to enhance employability in the field.

Uploaded by

bhavadeep.sr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views19 pages

Master Network Engineering Program

The Network Engineer Master's Program offers comprehensive training in network design, configuration, and maintenance, covering CCNA, CCNP, and firewall technologies. It includes modules on network fundamentals, IP connectivity, security, and automation, preparing students for various networking roles. The program emphasizes hands-on lab practice and industry-oriented skills to enhance employability in the field.

Uploaded by

bhavadeep.sr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Network Engineer Master's Program

Become a Network Engineer - learn to design, build and configure new network infrastructure
and maintain existing network systems.
This Master's Program consists of CCNA, CCNP and Firewalls (Palo Alto Firewall, Fortigate
Firewall or Check Point Firewall).
[Link] | [Link]

Cisco Certified Network Associate (CCNA):


Become a Network Associate- Install, configure and troubleshoot
networks using Cisco Products

Module 1 Network Fundamentals Module 2 Network Access

Network Components Multiple switches


Configure and verify VLANs spanning
You will learn about the roles and functions of

1. 1.
multiple switches
network components.

 Access ports
 Routers  Servers
 Default VLAN
 L2 and L3 Switches  Endpoints and Access
 Connectivity
Points

Network Topology Architecture Spanning Tree Protocol (STP)


You will understand the characteristics of network Understand the need for and basic operations of

2. 2.
topology architectures. Rapid PVST+ Spanning Tree Protocol and identify
basic operations
 2-tier  WAN
 3-tier  Root port  Port States
 SOHO
 Spine-leaf  Root bridge  PortFast benefits
 On-premise and cloud

Compare TCP to UDP WLAN

3. Learn the difference between these two Internet Understand physical infrastructure connections of
WLAN components
protocols.
3.  AP/WLC management  WLAN connection

access connections  WLAN advanced settings

 SSH, HTTP, HTTPS


 LAN access

IPv4 and IPv6 Addressing

4.  Understand the need for IPv4 addressing


 Configure and verify IPv4 addressing and subnetting
 Configure and verify IPv6 addressing and prefix

Compare IPv6 Address Types

5.  Global unicast
 Unique local
 Anycast
 Multicast
 Link local  Modified EUI 64

Switching
Understand switching concepts

6.  A MAC learning and  Frame flooding


ageing  MAC address table
 Frame switching
Module 3 IP Connectivity Module 4 IP Services

Routing Table Network Address Translation (NAT)


Interpret the components of routing table

1.
Configure and verify inside source NAT using static

1.  Routing protocol code  Network Mask


and pools [Link] | [Link]
 Prefix  Next hop

Network Time Protocol (NTP)


Router
2.
Configure and verify NTP operating in a client and
Determine how a router makes a forward decision by server mode

2.
default

 Longest match
 Administrative distance
 Routing protocol metric

Dynamic Host Configuration Protocol (DHCP)

3.
and Domain Name System (DNS)
Explain the role of DHCP and DNS within the network
Static Routing
Configure and verify IPv4 and IPv6 static routing

3.  Default route
 Network route
 Host route
 Floating static

SNMP and Syslog


Functions of SNMP in network operations and use of

4.
Syslog features

OSPFv2  Facilities
Configure and verify single area OSPFv2  Levels

4.  Neighbor adjacencies
 Point-to-point
 Broadcast
 Router ID

Per-Hop Behavior (PHB)


5. Explain the forwarding PHB for QoS

TFTP/ FTP
6. Explain the functions of TFTP and FTP in a network

[Link] | [Link]
Module 5 Security Fundamentals Module 6 Automation & Programmability

Key Security Concepts Network Management

1.
Explain how automation impacts network

1.  Threats
 Vulnerabilities
 Exploits
 Mitigation techniques
management

Controller-based and Software-defined


architectures
Security Program Elements
Describe the Security Program Elements
2. Describe Controller-based and Software-defined
architectures (overlay, underlay & fabric)

2.  User awareness
 Control Plane  North bound APIs
 Training
 Data Plane  South bound APIs
 Physical access control

Device Management
Virtual Private Networks (VPNs)
3.
Compare traditional campus device management

3. Define remote access and site-to-site VPNs with Cisco DNA Center

Security Features
REST-based APIs
Configure Layer 2 security features

4.
Describe characteristics of REST-based APIs

 DHCP snooping
 Dynamic ARP inspection
4.  CRUD
 HTTP verbs
 Port security
 Data encoding

Wireless Security Protocols


Describe wireless security protocols
Configuration Management
5.  WPA
5. Recognize the capabilities of configuration
management mechanisms
 WPA2
 WPA3
 Puppet
 Chef
 Ansible

WLAN
Configure WLAN using:

6.  WPA2 PSK JSON (JavaScript Object Notation)


 GUI
6. Interpret JSON encoded data

[Link] | [Link]
Module 7 Industry Oriented Lab Practice

[Link] | [Link]
Module 7 Industry Oriented Lab Practice

[Link] | [Link]
Cisco Certified Network Professional (CCNP):
Become a Network Professional- Implement and troubleshoot both LAN and WAN networks.

Module 1 Architecture CCNP 350-401 ENCOR: Module 2 Virtualization

Enterprise Network Virtualization technologies


Describe device virtualization technologies.
Understand design principles used in an enterprise

1. network
1.  Hypervisor type 1 and 2
 Virtual machine
 Tier 2, Tier 3 planning  High availability
 Virtual switching
 Fabric Capacity planning techniques (FHRP, SSO,
Redundancy)

WLAN deployment Path Virtualization technologies


You will understand the characteristics of network Configure and verify data path

2. 2.
topology architectures. virtualization technologies
 Wireless deployment models
 Location services in a WLAN design  VRF  IPsec Tunneling

 Difference between on-premises & cloud  GRE Tunneling

infrastructure deployments

Cisco SD-WAN solutions Virtualization concepts


Explain the working principles of the Cisco SD-WAN Describe network virtualization concepts

3. solution
3.  LISP
 SD-WAN control plane elements  Traditional WAN  VXLAN
 SD-WAN data plane elements  SD-WAN solutions

Cisco SD-Access solution


Explain the working principles of the Cisco SD-Access

4. solution

 SD-Access control plane element  Interoperating


 SD-Access data plane elements SD-Access

Wireless QoS
Describe concepts of wired and wireless QoS

5.  QoS components  QoS policy

Switching mechanisms
Differentiate hardware and software switching

6. mechanisms
 Process and CEF  FIB vs. RIB
 MAC address table and TCAM

[Link] | [Link]
Module 3 Infrastructure Module 4 Network Assurance

Layer 2 Network Assurance


Learn to troubleshoot and configure the following. Diagnose network problems using various tools.

1.  Static and dynamic trunking protocols  Debugs, conditional debugs

1.
 Static and dynamic EtherChannels  Trace route
 Spanning Tree Protocols (RSTP and MST)  Ping, SNMP, Syslog
 Configure and verify:
o SPAN/RSPAN/ERSPA
o IPSLA
o NETCONF & RESTCONF
Layer 3
Learn routing concepts, configure and verify OSPF
environments and eBGP.

2.  Compare EIGRP and OSPF


 Configure and verify multiple
 Filtering
 Best path selection
normal areas algorithm
 Summarization  Neighbor relationship

Wireless
Describe Layer 1 concepts, access point discovery
and join process.

3.  RF power, RSSI, SNR


 AP modes
 Band channels
 Wireless client devices
 Antenna types capabilities
 Interference noise  Troubleshoot WLAN configuration

IP Services
Describe, configure and verify
related protocols.

4.  Network Time  First hop redundancy


Protocol (NTP) protocols (HDRP & VRRP)
 NAT/PAT  Multicast protocols (PIM &
IGMP v2/v3)

[Link] | [Link]
Module 5 Security Module 6 Automation

Configure and verify device access control Automation

1.  Lines and password protection


 Authentication and authorization using AAA


Basic Python components &. scripts
Construct JSON encoded file
 Data modeling language benefits (YANG)

1. 

APIs
Interpret REST API response code
 Construct EEM applet
 Compare agent vs. Agentless orchestration tools
(Chef, Ansible, Puppet)

Configure and verify infrastructure security


features

2.  ACLs
 CoPP

Describe REST API security

3.

Configure and verify wireless security features

4.  EAP
 WebAuth
 PSK

Describe components of network security


design

 Threat defence

5.  Endpoint security
 Next-generation firewall
 TrustSec
 MACsec
 Network access control

[Link] | [Link]
CCNP 300-401 ENARSI:

Module 1 Layer 3 technologies Module 2 VPN Technologies

Troubleshoot and verify the following. Describe MPLS operations


 Administrative distance

1.  Route map for routing protocol


 Loop prevention mechanisms
1.
 LSR
 LDP
 Redistribution between routing protocols &  Label switching
routing sources  LSP
 Manual and auto-summarization

Configure and verify the following.


Describe MPLS Layer 3 VPN

2. 2.
 Policy-based routine
 VRF-Lite
 Bidirectional forwarding Detection

Configure and verify DMVPN (single hub)


Troubleshoot EIGRP
 GRE/mGRE
 EIGRP (classic & named mode)
3.  NHRP

3.  Address families (IPv4, IPv6)  IPsec


 Neighbor relationship & authentication  Dynamic neighbor
 Loop-free path selections  Spoke-to-spoke
 Stubs
 Load balancing
 Metrics

Troubleshoot OSPF (v2/v3)

 Address families

4.  Neighbor relationship & authentication


 Path reference
 Route reflector
 Policies

[Link] | [Link]
Module 3 Infrastructure Security Module 4 Infrastructure Services

Troubleshoot device security using: Troubleshoot device management

1.  IOS AAA
 TACACS+ 1.  Console and VTY
 Telent, HTTP, HTTPS, SSH, SCP
 RADIUS  (T)FTP
 Local database

Troubleshoot route security features Troubleshoot SNMP (v2c, v3)

2.
2.  IPv4 access control lists
 IPv6 traffic filter
 Unicast reverse path forwarding (uRPF)

Troubleshoot the following.

Troubleshoot control plane policing (CoPP)  Network problems using logging & Cisco DNA

3. Center assurance

3.
 Telnet  EIGRP  IPv4 and IPv6 DHCP
 SSH  OSPF  Network performance issues using IP SLA
 HTTP(S)  BGP  NetFlow
 SNMP

Describe IPv6 First Hop security


features

4.  RA guard
 DHCP guard
 ND inspection/snooping
 Source guard
 Binding table

[Link] | [Link]
Palo Alto Firewall:
Become a Palo Alto Firewall Engineer- Install, configure, manage and fix the Palo Alto firewall.
You need to clear the Palo Alto Networks Certified Network Security Administrator (PCNSA).

Palo Alto Networks Security Operating Module 2 Simply Passing Traffic


Module 1
Platform Core Components

Components and operation Firewall Interfaces

1.  Identify components of the Palo Alto Networks


 Identify and configure firewall management

Cybersecurity Portfolio
 Identify components and operation of Single-Pass
1. interfaces
 Identify how to manage firewall configurations
 Identify and schedule dynamic updates.
Parallel Processing architecture

Zero Trust security model


Security

2.  Apply Zero Trust security model to a network


design scenario  Create security zones in a network diagram
 Identify purpose of specific security rule types

2.
 How it relates to traffic movies through your
network  Identify and configure security policy match
conditions
 Actions
 Logging options
Cyberattack lifecycle  Identify purpose of specific security rule types

3.  Identify stages in cyberattack lifecycle


 Firewall mitigations that can prevent attacks
Virtual Router

3.  Create and configure a virtual router


 Implement proper NAT solution

[Link] | [Link]
Module 3 Traffic Visibility Module 4 Securing Traffic

Security policies
Security Profile

1.
1.
 Select application-based security
policy rules
[Link] | [Link]
 Apply appropriate security profile in a risk scenario
 Security policy actions
 Configure application filters
 Security profile actions
 Configure application groups
 Customize security profiles in a network scenario
 Optimize security policies

App-ID Firewall

 Impact of App-ID on existing security

2.
 Firewall protection against packet-based attacks
policy rules
 Features used to streamline App-ID 2.  Firewall protection against protocol-based attacks
 Use of cloud DNS security to control traffic
policy creation  Use of PAN-DB database to control traffic
 Application characteristics in App-ID  Control access to specific URLs using custom URL
database filtering categories

Module 5 Identifying Users Module 6 Deployment Optimization

Usernames Heatmap and BPA reports

1. 1.
 Method to map IP addresses to usernames  Identify the benefits and differences between
 Appropriate User-ID agent to deploy Heatmap and BPA reports
 Map usernames to user groups using firewall
 User-ID configuration options in a graphic

[Link] | [Link]
Fortigate Firewall:
Become a FortiGate Firewall Engineer – Maintain a high level of service on security/network devices and run operations to support network
security infrastructure. We prepare candidates for NSE 4 and NSE 7.

Module 1 FortiGate Security NSE 4 Course Curriculum: Module 2 FortiGate Infrastructure

Security Routing

1.  Introduction and initial configuration


 Security Fabric
1.  Routing
 SD-WAN Local Breakout
 Virtual Domains (VDOMs)
 Firewall Policies
 Layer 2 Switching
 Network Address Translation (NAT)

Authentication 2. IPsec VPN

2.  Firewall Authentication
 Logging and Monitoring
3. Fortinet Single Sign-on (FSSO)
 Certificate Operations
 Web Filtering
 Application Control
4. High Availability (HA)

Privacy
5. Diagnostics

3.  Antivirus
 Intrusion Prevention and Denial of Service
 SSL VPN

[Link] | [Link]
NSE 7 (Advanced course) Course Curriculum:

Module 1 Enterprise Firewall Module 2 SD-WAN

Security Fabric
1. Introduction

1.
 FortiOS Architecture
 Traffic and Session Monitoring
[Link] | [Link]
 Routing
 FortiGuard Routing
 High Availability
 Central Management
2.  Routing [Link] | [Link]
 Sessions
 Performance SLA

Routing Protocols

2.  Open Shortest Pathway First (OSPF) SD-WAN Rules

3.
 Border Gateway Protocol (BGP)

 Traffic shaping [Link] | [Link]


 Integration
 Advanced IPsec
Web Filtering  Auto-discovery VPN (ADVPN)

3.  Intrusion Prevention System (IPS)


 IPsec
 Auto-discovery VPN (ADVPN)

Module 3 Advanced Analytics Module 4 Advanced Threat Protection

1. Introduction to Multi-Tenancy Attack Methodologies

1.  Attack Methodologies [Link] | [Link]


 The ATP Framework
Collectors and Agents
 FortiSandBox Key Components

2.  Understanding Collectors and Agents


 High Availability
 Maintenance and Troubleshooting
 Operating Collectors
 Windows and Linux Agents

Protecting the Edge


Rules

3.  Single Sub pattern Security Rule


2.  Protecting the Edge [Link] | [Link]
 Protecting Email Networks
 Multiple Sub Pattern Rules
 Protecting End Users
 Protecting Third-Party Appliances
 Result Analysis
Introduction to Baseline

4.  UEBA
 Clear Conditions
 Remediation

[Link] | [Link]
Module 5 OT Security Module 6 FortiSOAR Design and Development

[Link] | [Link]

OT Infrastructure Introduction to FortiSOAR

1.
1.
 Learn about the fundamentals of an OT infrastructure
 Dashboard Templates and Widgets [Link] | [Link]
 Secure an OT infrastructure
 Module Templates and Widgets
 Use segmentation and micro segmentation in an OT
 Application Editor
network
 Authentic users
 Secure OT network traffic using a FortiGate device
Variables

FortiSIEM
2.  Dynamic Variable and values [Link] | [Link]

2.
 Jinja Filters

 Use FortiGate and FortiNAC to manage and identify  Functions and Conditions

devices
 Use FortiAnalyzer for logging and reporting
 Use FortiSIEM to centralize security information
Playbooks
 Produce real-time analysis of security events with
FortiSIEM
3.  Introduction to Playbooks [Link] | [Link]
 Playbook Core Steps
 Playbook Evaulate Steps
 Playbook Connectors
 Data Ingestion and Execution Steps

Module 7 Secure Access

[Link] | [Link]

Authentication and Authorization

1.  Configure advanced user authentication and


authorization with RADIUS and LDAP
 Troubleshoot user authorization and
authentication
 Implement two-factor authentication
 Implement and troubleshoot RADIUS
 Configure Layer 2 authentication

Configuration and Security

2.  Provision, configure and manage FortiSwitch using


FortiManager
 Deploy complex wireless networks
 Secure wired and wireless networks
 Provide secure access to guest users

[Link] | [Link]
Check Point Firewall:
Become a Checkpoint Certified Security Administrator (CCSA) certified professional – support, install, develop or
administer Checkpoint software blades.

Module 1 Installing VPN-1 NGX in a stand-alone environment Module 2 Defining a Firewall

 What is a Firewall?
 Launching SmartDashboard
 Types of the firewall
 Defining basic objects
 Packet filtering

1. 1.
 Configuring anti-spoofing measures
 Application Layer Gateway (Proxy)
 Defining basic rules
 Check Point's Stateful Inspection Technology
 Creating objects using object cloning
 Using Database Revision Control
 Blocking intruder connections
 Setting up a Suspicious Activity Rule in SmartView Monitor
 Checking status in SmartView Monitor
 Configuring SmartDefence
 Configuring Hide NAT
 Configuring Static NAT
 Encryption math and mechanics
 Defining user templates
 Defining users
 Configuring User Authentication
 Configuring Client Authentication
 Configuring LDAP authentication with SmartDirectory
 Backing up and restoring a Security Gateway and SmartCenter
Server

Module 3 Check Point Firewall-1 Architecture Module 4 Check Point Firewall-1 Overview

 How does Check Point Firewall-1 work?  Methods of securing networks


 Check Point Firewall-1 components & modules  Check Point firewall-1 architecture

1.
 Check Point Firewall-1 Kernel
 Check Point Firewall-1 Daemon 1.  Secure Internal Communications

 Distributed client/server model

 Application Intelligence technology

Module 5 Security Policy Module 6 Firewall-1 Setup and Installation

 Security Policy definition  Pre-installation configuration


 SmartDashboard  System requirement

1.
 Access control for administrators
 Creating the Rule Base 1.  How to install license

 Install additional firewall module


 Implicit and explicit rules
 Command-line options for the Security Policy

[Link] | [Link]
Module 7 Working with the SmartDashboard Module 8 SmartDefence

 Active defense
 Masking and disabling rules
 SmartDefense in action
 Uninstalling a Security Policy
 SmartDefence Storm Center

1. 1.
 Improving VPN-1/Firewall-1 performance

Module 9 Understanding RuleBase Order Module 10 Implicit and Explicit Rules

 What is a RuleBase  FW1 Control Connections

1.
 How to create RuleBase  Outgoing Packets
 Importance of the Rule Base Order
1.  Additional Settings

 Implicit Drop Rule

Module 11 Troubleshooting the Security Policy Module 12 Detecting Hacking Method- Spoofing

 Maximum number of rules and objects  What is Spoofing?


 Deleting Administrator accounts

1.
 Anti-spoofing configuration
 Any, Any, Any, Accept Rule not accepting traffic
1.

Module 13 Advanced Security Policy Module 14 Log Management

 Masking rules  Log Viewer GUI

1.
 Disabling rules  Log Viewer Modes
 Uninstalling a Security Policy
 Security Policy File 1.  Creating and Selecting Selection Criteria

 Blocking Connections
 Command Line Options for the Security Policy
 Block intruder

[Link] | [Link]
Module 15 System Status GUI Module 16 Authentication and Authentication Parameters

 Understanding authentication
 System Status logon
 How user authentication works
 Log viewer modes

1.  Creating and selecting selection criteria


 Blocking connections 1.
 Types of authentications
 User authentication
 Client authentication
 Block intruder
 Session authentication
 Authentication schemes
 Defining a User Template
 Defining Users and Groups

Module 17 Network Address

 How NAT works


 Type of NAT

1.
 Static NAT
 Hide NAT
 Address Resolution Protocol (ARP)
 NAT Routing
 Static NAT and anti-spoofing
 Troubleshooting NAT

[Link] | [Link]
[Link]

[Link]

[Link]

info@[Link]

+918130537300

Network kings IT services Private Limited,


Chandigarh Citi Center , VIP Road, SCO 41-43, B
Block 4th oor, Zirakpur, Chandigarh

Network kings 60 Parrotta Drive Toronto ON


M9M Oe5

[Link] | [Link]

[Link]

[Link]

You might also like