Curso F5 Networks Configuring BIG-IP AFM Advanced Firewall Manager
16 horasVisão Geral
Este Curso F5 Networks Configuring BIG-IP AFM, utiliza palestras e exercícios práticos para proporcionar aos participantes experiência em tempo real na instalação e configuração do sistema BIG-IP Advanced Firewall Manager (AFM). Os alunos são apresentados à interface de usuário do AFM, percorrendo diversas opções que demonstram como o AFM é configurado para construir um firewall de rede e para detectar e proteger contra ataques DoS (Denial of Service). Os recursos de relatórios e registros também são explicados e usados nos laboratórios do curso. São discutidas outras funcionalidades do Firewall e recursos adicionais de DoS para tráfego DNS e SIP.
Publico Alvo
Este Curso F5 Networks Configuring BIG-IP AFM é destinado a operadores de rede, administradores de rede, engenheiros de rede, arquitetos de rede, administradores de segurança e arquitetos de segurança responsáveis pela instalação, instalação, configuração e administração do sistema BIG-IP AFM.
Pre-Requisitos
- Administração de BIG-IP, modelo OSI, endereçamento e roteamento TCP/IP, ambientes WAN, LAN e conceitos de redundância de servidores; ou ter obtido a Certificação de Administração TMOS
Materiais
Português/Inglês + Exercícios + Lab PraticoConteúdo Programatico
Setting up the BIG-IP System
- Introducing the BIG-IP System
- Initially Setting Up the BIG-IP System
- Archiving the BIG-IP System Configuration
- Leveraging F5 Support Resources and Tools
AFM Overview
- AFM Overview
- AFM Availability
- AFM and the BIG-IP Security Menu
Network Firewall
- AFM Firewalls
- Contexts
- Modes
- Packet Processing
- Rules and Direction
- Rules Contexts and Processing
- Inline Rule Editor
- Configuring Network Firewall
- Network Firewall Rules and Policies
- Network Firewall Rule Creation
- Identifying Traffic by Region with Geolocation
- Identifying Redundant and Conflicting Rules
- Identifying Stale Rules
- Prebuilding Firewall Rules with Lists and Schedules
- Rule Lists
- Address Lists
- Port Lists
- Schedules
- Network Firewall Policies
- Policy Status and Management
- Other Rule Actions
- Redirecting Traffic with Send to Virtual
- Checking Rule Processing with Packet Tester
- Examining Connections with Flow Inspector
Logs
- Event Logs
- Logging Profiles
- Limiting Log Messages with Log Throttling
- Enabling Logging in Firewall Rules
- BIG-IP Logging Mechanisms
- Log Publisher
- Log Destination
- Filtering Logs with the Custom Search Facility
- Logging Global Rule Events
- Log Configuration Changes
- QKView and Log Files
- SNMP MIB
- SNMP Traps
IP Intelligence
- Overview
- IP Intelligence Policy
- Feature 1 Dynamic White and Black Lists
- Black List Categories
- Feed Lists
- IP Intelligence Log Profile
- IP Intelligence Reporting
- Troubleshooting IP Intelligence Lists
- Feature 2 IP Intelligence Database
- Licensing
- Installation
- Configuration
- Troubleshooting
- IP Intelligence iRule
DoS Protection
- Denial of Service and DoS Protection Overview
- Device DoS Protection
- Configuring Device DoS Protection
- Variant 1 DoS Vectors
- Variant 2 DoS Vectors
- Automatic Threshold Configuration
- Variant 3 DoS Vectors
- Device DoS Profiles
- DoS Protection Profile
- Dynamic Signatures
- Dynamic Signatures Configuration
- DoS iRules
Reports
- AFM Reporting Facilities Overview
- Examining the Status of Particular AFM Features
- Exporting the Data
- Managing the Reporting Settings
- Scheduling Reports
- Examining AFM Status at High Level
- Mini Reporting Windows (Widgets)
- Building Custom Widgets
- Deleting and Restoring Widgets
- Dashboards
DoS White Lists
- Bypassing DoS Checks with White Lists
- Configuring DoS White Lists
- tmsh options
- Per Profile Whitelist Address List
DoS Sweep Flood Protection
- Isolating Bad Clients with Sweep Flood
- Configuring Sweep Flood
IP Intelligence Shun
- Overview
- Manual Configuration
- Dynamic Configuration
- IP Intelligence Policy
- tmsh options
- Extending the Shun Feature
- Route this Traffic to Nowhere – Remotely Triggered Black Hole
- Route this Traffic for Further Processing – Scrubber
DNS Firewall
- Filtering DNS Traffic with DNS Firewall
- Configuring DNS Firewall
- DNS Query Types
- DNS Opcode Types
- Logging DNS Firewall Events
- Troubleshooting
DNS DoS
- Overview
- DNS DoS
- Configuring DNS DoS
- DoS Protection Profile
- Device DoS and DNS
SIP DoS
- Session Initiation Protocol (SIP)
- Transactions and Dialogs
- SIP DoS Configuration
- DoS Protection Profile
- Device DoS and SIP
Port Misuse
- Overview
- Port Misuse and Service Policies
- Building a Port Misuse Policy
- Attaching a Service Policy
- Creating a Log Profile
Network Firewall iRules
- Overview
- iRule Events
- Configuration
- When to use iRules
- More Information
Recap
- BIG-IP Architecture and Traffic Flow
- AFM Packet Processing Overview