Juniper Networks
 
Country
  • United States
  • Australia
  • China
  • France
  • Germany
  • Japan
  • Korea
  • Spain
  • Taiwan
  • United Kingdom
Contact Us
|
Country
United States
Select a country
Solutions
Products & Services
Company
Partners
Support
Education

Implementing Intrusion Detection and Prevention Productss

Juniper Networks Home
Implementing Intrusion Detection and Prevention Productss - Juniper Networks
 
Print
Courses

Implementing Intrusion Detection and Prevention

Course No: EDU-JUN-IIDP

Length: 3 days

Cost: $2,500 (US)

> Register New Window

Course Overview

This three-day course discusses the configuration of Juniper Intrusion Detection and Prevention (IDP) sensors in a typical network environment. Key topics include sensor configuration, creating and fine-tuning security policies, managing attack objects, creating custom signatures, and troubleshooting. This course is based upon IDP software version 4.1 and Security Manager 2007.3.

Through demonstrations and hands-on labs, students will gain experience in configuring, testing, and troubleshooting the IDP sensor.

Objectives

After successfully completing this course, you should be able to:

  • Deploy an IDP sensor on the network.
  • Monitor and understand IDP logs.
  • Configure, install, and fine-tune IDP policies.
  • Configure the Profiler.
  • Troubleshoot sensor problems.
  • Create custom signature attack objects.
  • Configure sensors for high availability using third-party devices.

Intended Audience

This course is intended for network engineers, support personnel, reseller support, and others responsible for implementing Juniper Networks IDP products.

Course Level

This is an introductory-level course.

Prerequisites

This course assumes that students have basic networking knowledge and experience in the following areas:

  • Understanding of TCP/IP operation;
  • Understanding of network security concepts;
  • Experience in network security administration; and
  • Experience in UNIX system administration.

It also assumes that students have attended the Juniper Networks Security Manager Fundamentals course.

Course Contents

Day 1

Chapter 1: Course Introduction

Chapter 2: Intrusion Detection and Prevention Concepts

  • Network Attack Phases and Detection
  • Juniper Networks IDP Product Offerings
  • Juniper Networks IDP Three-Tier Architecture
  • Juniper IDP Deployment Modes

Chapter 3: Initial Configuration of IDP Sensor

  • Overview of IDP Sensor Deployment Process
  • Initial Configuration Steps—IDP Standalone Device
  • Initial Configuration Steps—ISG1000/ISG2000
  • Lab 1: Sensor Initial Configuration

Chapter 4: IDP Policy Basics

  • Attack Object Terminology
  • IDP Rule Components
  • IDP Rule-Matching Algorithm
  • Terminal rules
  • Lab 2: Configuring IDP Policies

Chapter 5: Fine-Tuning Policies

  • Tuning Process Overview
  • Step 1: Identifying Machines and Protocols to Monitor
  • Step 2: Identifying and Eliminating False Positives
  • Step 3: Identifying and Configuring Responses to Real Attacks
  • Step 4: Configuring Other Rulebases to Detect Attacks
  • Lab 3: Fine-Tuning IDP Policies

Day 2

Chapter 6: Configuring Additional Rulebases

  • Overview of IDP-Related Rulebases
  • Exempt Rulebases
  • Traffic Anomalies Rulebase
  • Backdoor Rulebase
  • SYN Protector Rulebase
  • Network Honeypot Rulebase
  • Rulebase Processing Order
  • Lab 4: Configuring Additional Rulebases

Chapter 7: Profiler

  • Profiler Overview
  • How to Operate Profiler
  • Using Profiler for Network Discovery
  • Using Profiler to Discover Running Applications
  • Using Profiler to Detect New Devices and Ports
  • Using Profiler to Detect Policy Violations
  • Lab 5: Using Profiler

Chapter 8: Sensor Operation and Sensor Commands

  • Main Components of the Sensor
  • Description of Sensor Processes
  • Managing Policies with the scio Utility
  • Managing Sensor Configuration with the scio Utility
  • Monitoring with the sctop Utility
  • Lab 6: Using Sensor Commands

Chapter 9: Troubleshooting

  • Review of Sensor Communication
  • Troubleshooting Tools
  • Troubleshooting Scenarios
  • Reimaging the Sensor
  • Lab 7: Troubleshooting

Day 3

Chapter 10: Managing Attack Objects

  • Examining Predefined Attack Objects
  • Examining Predefined Attack Object Groups
  • Creating New Custom Attack Object Groups
  • Updating the Attack Object Database
  • Searching the Attack Object Database
  • Lab 8: Managing Attack Objects

Chapter 11: Creating Custom Signatures

  • IDP Packet Inspection
  • Obtaining Attack Information
  • Understanding Regular Expressions
  • Creating a Signature-Based Attack Object
  • Creating a Compound Attack Object
  • Lab 9: Creating Custom Signatures

Chapter 12: Configuring Sensors for External High Availability

  • External HA Operation
  • Configuring Sensors for External HA

To Top
Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2009 Juniper Networks, Inc. All rights reserved.
Close
 

DEMAND MORE

IT SERVICES WITHOUT BOUNDARIES

Visit our Distributed Enterprise Solutions page and learn how to achieve 5X security performance for 50% less.

Start getting connectivity, security and savings you need to take your business further.

 

 

Enterprise

Business Needs 

  • Application Infrastructure
  • Business Continuity
  • Distributed Enterprise
  • Security and Compliance

Locations / Architectures 

  • Branch Office
  • Campus
  • Data Center Infrastructure
  • Remote Users
  • VPNs and WAN

Industries 

  • Healthcare
  • Financial Services
  • Research and Education
 

Service Provider

Business Needs 

  • Managed Service Provider
  • Network Infrastructure
  • Network Security
  • Network and Service Management
  • Residential

Locations / Architectures 

  • Core
  • Data Center Infrastructure
  • Intelligent Services Edge

Segments 

  • Cable Operator
  • Wireline Carrier
  • Content Service Provider
  • Wireless Carrier
 

Public Sector

Business Needs 

  • Application Infrastructure
  • Disaster Recovery / Business Continuity
  • Network Infrastructure
  • Security and Compliance

Locations / Architectures 

  • Branch Office
  • Campus
  • Data Center Infrastructure
  • Remote Users
  • VPNs and WAN

Verticals 

  • Central Governments
  • Federal Government
  • Healthcare
  • Research and Education
  • State and Local Governments
Close
 

DEMAND MORE

IT SERVICES WITHOUT BOUNDARIES

With Juniper Networks SRX Series Services Gateways, you can now achieve 5X security performance for 50% less than competitive solutions. The new SRX series deliver consistent HQ quality security across all your enterprise locations without security or performance trade off.

 

 

Find the Right Solution

Have a Juniper Networks Partner evaluate your business and create a solution that's right for you.

Find Reseller

Products by Category

Application Acceleration
Identity and Policy Control
Network Management
Network Operating System
Routing
Security
Software
Switching
End-of-Sale Products

Products By Family

BX Series
C Series
CTP Series
E Series
EX Series
IDP Series
ISG Series
J Series
JCS1200
JUNOS Software
M Series
MX Series
NetScreen Series
NSM Central Manager
NSMXpress
Odyssey Access Client
SA Series
SBR Series
SBR Series - Software
SDX Series
SRC Series
SRX Series
SSG Series
STRM Series
T Series
Unified Access Control
WX Series
WXC Series

Products By Name

A B C D E F G H I J K L M N O P Q R S T U W X Y Z  
 

Services

Consulting Services

  • Assessment and Analysis
  • Design and Planning
  • Project Implementation

Installation and Configuration Services

  • Conversion Services
  • QuickStart Services
  • Startup Services

Technical Services

  • J-Care Technical Services
  • Resident Engineer
Close
 

DEMAND MORE

IT SERVICES WITHOUT BOUNDARIES

Learn how to achieve 5X security performance for 50% less.

"The Juniper Networks Distributed Enterprise Solutions enable us to improve employee performance, build revenues, and reduce total cost of ownership to drive a sustainable competitive advantage."

Scotty Bevill
IT Project Manager, Intermatic, Inc.

 

 

See What We’re All About

Analyst Relations
Careers
Case Studies
Company Profile
Contact Us
Corporate Citizenship and Sustainability
Customer Quotes
Events
Industry
Innovation
Investor Relations
Key Business Partners
Leadership
Press Center
Subscriptions
 

EXECUTIVE BLOG

The Network Ahead

Juniper executives share their viewpoints on industry topics ranging from cloud computing to economics and green IT.

Read the Network Ahead

Annual Financial Analyst & Investor Event

Tuesday, February 24, 2009

Juniper Networks' corporate vision and operating plans as well as our business, technology and go-to-market strategies for the year ahead.

Learn more
 

Learn how to be green

See how the communications industry is helping address climate change issue.

Watch now

JUNOS SOFTWARE

Juniper's single operating system delivering the power of one. Learn how JUNOS® Software reduces complexity and drives operational excellence, lowering the cost of innovation.

Learn more
Help
|
My Account
|
Log Out