JNCIE Info
Juniper Network Certified Internet Specialist - Firewall VPN is my
next target. I want to to it before going for my JNCIE.Lets narrow down the things to prepare.
I have got.
i) Screen OS Cook Book
ii) JNCIS FWV Study Guide v 1.3
VPNs* Identify IKE Phase 1/Phase2 negotiation sequence and proposals
* Identify/differentiate IPSec standard elements (encapsulations, SA, SPI, etc.)
* List steps for policy-based/route-based VPN configuration
* Relate proxy-ID to VPN setup
* Identify proper configuration for various hub/spoke configurations
(policy, int. placement, etc.)
* Identify NHTB requirements/configurations
* Configure/verify AC-VPNs
* Identify PKI components (certificates, CDL, etc.)
* List steps for PKI implementation w/ VPNs
* VPN Variations
* Configure Dynamic Peer VPNs
* Configure Transparent mode VPNs
* Configure Overlapping Networks
* Describe GRE applications/Configure GRENetwork Management
* Configure local management (SSL, SSH, management restrictions).
* Interpret internal counters and logs.
* Configure SYSLOG.
* Discuss logging levels.
* Configure SNMP.Troubleshooting with Debug/Snoop
* Enable debug/snoop.
* Set debug filters.
* Set snoop filters.
* Use get commands to validates/troubleshoot routing and policies.
* Use debug output to identify routing and policy problems.
* Use get commands to validate/troubleshoot address translation.
* Use debug output to identify problems
* Use get commands to validate/troubleshoot VPN setup.Traffic Management
* Describe the bandwidth allocation process.
* Describe queuing functionality.
* List requirements/steps for configuring traffic management.Virtual Systems
* Define VSYS applications
* Describe root vs. VSYS administration
* Explain VSYS vs. root assignment of routes/NAT pools/etc.
* Configure interface-based VSYS
* Configure inter-VSYS communications, including NAT.
* Use show/debug output to identify VSYS usage.
* Configure VSYS resource allocationNSRP
* Distinguish active/passive and active/active.
* Describe NSRP operations (HA link, session sync, master election, etc.)
* Configure active/passive and active/active NSRP.
* Validate NSRP operations.
* Adjust operations (secondary link, failover settings).
* Configure redundant interface.Dynamic Routing/Routing over VPNs
* Configure RIP over VPNs
* Configure OSPF over VPNs
* Configure/verify OSPF routing
* Configure OSPF options
* Configure/verify BGP
* Configure redistribution/filters/route maps
* Configure static routes incl. floating static routes
* Configure/verify source routing
* Configure/verify policy routingAttack Prevention
* Describe SCREEN functions
* Describe/configure Deep Inspection
* Describe/configure anti-virus functionality
* Configure web filteringMulticast
* Configure/verify IGMP
* Configure/verify PIM-SMJust study the book and also material is available for technical documentation
of Netscreen Products on Juniper website.
Filed under: Juniper Security No Comments
12Aug/090
New Certification of Juniper JNCIS-SEC JN0-331
Posted by Hasan RaufIt is new certification of Juniper Networks replacing JNCIS-ES(Enhanced Services)
JNCIS-SEC (Juniper Networks Certified Internet Specialist - Security ) JN0-331
This includes Juniper Networks SRX Introduction.
The topics should be covered are given below:
Introduction to SRX-series* Compare and contrast JUNOS Software for security platforms and traditional routing
* Describe major components of JUNOS Software for Security Platforms
* Contrast session and flow
* Compare and contrast packet flow of the first and consecutive packets of a flow
* Name elements used in session recognition.
* Describe session management processZones
* Describe the purpose of a zone
* Identify the relationship between zones assignments, interfaces, and routing instances
* Define zone types supported by JUNOS Software
* Compare and contrast security and functional zones
* List and identify the steps necessary to configure zones
* Compare and contrast device's behavior resulting from various configurations,
when handling transit packets and packets destined to various interfaces of the device.
* Demonstrate understanding of configuration precedence significance of various zone knobs.
* Describe the traffic behavior based on a sample zone configurationSCREEN Options
* Identify advantages of using SCREENs
* Compare and contrast reconnaissance, DoS, and suspicious packets attacks
* Identify best practices to be used when implementing SCREENs
* Configure SCREENs with necessary parameters based on threatsSecurity Policies
* Identify the purpose of a security policy
* Define the purpose of security policy configuration components
* Configure appropriate JUNOS Enhanced Services security policies actions
* Describe the purpose of an address book
* Based on policy configurations, compare and contrast scheduled and non-scheduled policies
* Based on policy configurations, describe the impact of security policy changes on session in progress
* Identify and explain the importance of policy ordering in the configuration fileNAT
* Describe the purpose of NAT
* Describe JUNOS Software support of NAT and different NAT types
* Describe JUNOS Software NAT operation
* Identify NAT scenarios requiring Proxy-ARP configurations
* Identify types of NAT used, based on various NAT configurations
* Configure NATIPSec VPNs
* Correlate between major security concerns and solutions
* Compare and contrast symmetric and asymmetric key encryption
* Describe the DH key exchange process
* List methods for IPSec VPN setup
* List specifics of Security Associations
* Describe the IKE phases functionality and purpose
* Compare and contrast policy-based and route-based IPSec implementations
* Configure route-based and policy-based IPSec VPNsHA Clustering
* Describe chassis cluster functionality
* Identify chassis cluster interfaces and their functions
* Configure redundany groupsIntro to IDP
* Describe the purpose of IDP
* Identify the components of JUNOS software IDP
* Identify IDP policy match conditions.
* Identify IDP policy actions
* Describe the procedure for updating the attack database.
* Describe the procedure for implementing an IDP template policyFirewall User Authentication
* Compare and contrast types of firewall user authentication.
* Describe the purpose of firewall user authentication
* Configure access profiles.
* Configure client groups.
* Describe the behavior when using external authentication servers
* Describe methods for monitoring firewall user authentication.Filed under: Juniper Security No Comments
Translator
JUNOCIS Posts Category* Cisco (99)
o Cisco BGP (1)
o Cisco Certifications (12)
o Cisco IGP (4)
o Cisco MPLS (4)
o Cisco Multicast (1)
o Cisco Press Release (78)
* Ericsson (1)
* Extreme (1)
* General (10)
* Huawei (1)
* Juniper (45)
o Juniper BGP (1)
o Juniper Certification (5)
o Juniper IGP (3)
o Juniper MPLS (1)
o Juniper Press Release (33)
o Juniper Security (2)
o JUNOS Simulator (2)
* NSN (36)
* Tools (1)JUNOCIS Recent Posts
* Tackling smartphone data deluge made simpler
* Next-generation combined packet data switch and optical platform unveiled
* LTE networks self-organize
* Cisco Quad: Much More Than Facebook for Businesses
* Elisa customers first to enjoy more flexible mobile broadbandJUNOCIS Archives
* June 2010 (32)
* May 2010 (54)
* April 2010 (70)
* March 2010 (25)
* November 2009 (1)
* August 2009 (1)
* May 2009 (2)
* April 2009 (3)JUNOCIS Users Access
* Register
* Log in
* Entries RSS
* Comments RSS
* WordPress.orgRSS JUNOCIS RSS
* Tackling smartphone data deluge made simpler
Press Release Espoo, Finland – June 15, 2010 Tackling smartphone data
deluge made simpler Nokia Siemens Networks and Cisco provide IP-based mobile
backhaul infrastructure. Mobile operators now have access to simpler all-IP backhaul
infrastructure to address the capacity demands of smart devices. Nokia Siemens
Networks has integrated its microwave backhaul sy […]
* Next-generation combined packet data switch and optical platform unveiled
Press Release Monaco – June 15, 2010 Next-generation combined packet data
switch and optical platform unveiled Nokia Siemens Networks simplifies network
infrastructure, cuts cost by integrating packet data handling into optical transport
platform Nokia Siemens Networks today unveiled a new platform that simplifies large
communications networks while addressi […]
* LTE networks self-organize
Press Release Singapore / Espoo, Finland – June 15, 2010 LTE networks self-organize
Nokia Siemens Networks takes human error, cost out of LTE with Self Organizing Networks
Operators can now automate LTE network set-up and operations. Nokia Siemens Networks
has today launched its SON (Self Organizing Networks) offering for [...] […]
* Cisco Quad: Much More Than Facebook for Businesses
Cisco's Murali Sitaram explains how the company's "enterprise collaboration platform" can
boost productivity, promote innovation, increase profitability and integrate distributed teams
Photo Murali Sitaram, Vice President and General Manager, Enterprise Collaboration Platform
More Info videos: Cisco Enterprise Collaboration Platform - Pro […]
* Elisa customers first to enjoy more flexible mobile broadband
Press Release Espoo, Finland – June 14, 2010 Elisa customers first to enjoy more flexible mobile
broadband Nokia Siemens Networks applies Quality of Service differentiation for Finnish operator
Elisa has activated new network features from Nokia Siemens Networks that provide flexible Quality
of Service (QoS). This is the first [...] […]Copyright © 2010 JUNOCIS · Powered by WordPress
Lightword Theme by Andrei Luca