This lab-intensive course introduces introduces students to the powerful features of the Cisco Sourcefire System, including FireSIGHT technology, in-depth event analysis, IPS tuning and configuration, and the Snort rules language.You will learn how to use and configure next-generation Sourcefire technology, including application control, firewall and routing and switching capabilities. You will also learn how to properly tune your system for better performance and greater network intelligence while taking full advantage of powerful tools for more efficient event analysis, including file type and network-based malware detection.This course combines lecture materials and hands-on labs throughout to reinforce the learning and ensure that you are able to successfully deploy and manage the Sourcefire System.
This course is designed for technical professionals who need to know how to deploy and/or manage a Sourcefire System in a network environment.
After completing this course, you should be able to:
Understand the Sourcefire System infrastructure
Navigate the UI and administrative features of the Sourcefire System, including reporting functionality to properly assess threats
Understand how to deploy and manage the Sourcefire device
Understand the role FireSIGHT technology plays in the Sourcefire System
Understand advanced policy configuration and Sourcefire System configuration options
Write and configure several basic rules
Attendees should meet the following prerequisites:
Technical understanding of TCP/IP networking and network architecture
Basic familiarity with the concepts of intrusion detection systems (IDS) and IPS
CCNA Security (ICND1 and IINS) recommended.
Module 1: Sourcefire System Overview and Classroom Setup
Module 2: Device Management
Module 3: Object Management
Module 4: Access Control Policy
Module 5: Network-based Malware Detection
Module 6: FireSIGH Technology
Module 7: Correlation Policies
Module 8: IPS Policy Basics
Module 9: Advanced IPS Polcity Configurations
Module 10: User Account Management
Module 11: Event Anlaysis
Module 12: Reporting
Module 13: Basic Rule Syntax and Usage
Module 14: Case Studies in Rule Writing and Packet Analysis
If you need training for 3 or more people, you should ask us about onsite training. Putting aside the obvious location benefit, content can be customised to better meet your business objectives and more can be covered than in a public classroom. It's a cost effective option.
Submit an enquiry from any page on this site, and let us know you are interested in the requirements box, or simply mention it when we contact you.