• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod: NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide

    AvJoseph Muniz,Steven Chimes

    Pearson Education

    2022

    Del i serien Official Cert Guide

    569 kr

    Beställningsvara. Skickas inom 7-10 vardagar. Fri frakt över 249 kr.

    Beskrivning

    Trust the best-selling Official Cert Guide series from Cisco Press to help you learn, prepare, and practice for exam success. They are built with the objective of providing assessment, review, and practice to help ensure you are fully prepared for your certification exam.

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide presents you with an organized test preparation routine using proven series elements and techniques. “Do I Know This Already?” quizzes open each chapter and enable you to decide how much time you need to spend on each section. Exam topic lists make referencing easy. Chapter-ending Exam Preparation Tasks help you drill on key concepts you must know thoroughly.

    * Master Implementing Secure Solutions with Virtual Private Networks (SVPN) 300-730 exam topics
    * Assess your knowledge with chapter-opening quizzes
    * Review key concepts with exam preparation tasks
    * Practice with realistic exam questions in the practice test software

    CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide from Cisco Press enables you to succeed on the exam the first time and is the only self-study resource approved by Cisco. Three leading Cisco security technology experts share preparation hints and test-taking tips, helping you identify areas of weakness and improve both your conceptual knowledge and hands-on skills.

    This complete study package includes
    * A test-preparation routine proven to help you pass the exams
    * Do I Know This Already? quizzes, which enable you to decide how much time you need to spend on each section
    * Chapter-ending exercises, which help you drill on key concepts you must know thoroughly
    * The powerful Pearson Test Prep Practice Test software, with two full exams comprised of well-reviewed, exam-realistic questions, customization options, and detailed performance reports
    * A final preparation chapter, which guides you through tools and resources to help you craft your review and test-taking strategies
    * Study plan suggestions and templates to help you organize and optimize your study time

    Well regarded for its level of detail, study plans, assessment features, and challenging review questions and exercises, this official study guide helps you master the concepts and techniques that ensure your exam success.

    This official study guide helps you master all the topics on the Implementing Secure Solutions with Virtual Private Networks (SVPN) 300-730 exam, deepening your knowledge of
    * Site-to-site virtual private networks on routers and firewalls
    * Remote access VPNs
    * Troubleshooting using ASDM and CLI
    * Secure communications architectures
    Companion Website:
    The companion website contains two full practice exams, an interactive Flash Cards application, a Study Planner, Glossary, and more.
    Includes Exclusive Offers for Up to 80% Off Video Training, Practice Tests, and more

    Pearson Test Prep online system requirements:

    Browsers: Chrome version 73 and above, Safari version 12 and above, Microsoft Edge 44 and above.

    Devices: Desktop and laptop computers, tablets running Android v8.0 and above or iPad OS v13 and above, smartphones running Android v8.0 and above or iOS v13 and above with a minimum screen size of 4.7.

    Pearson Test Prep offline system requirements:

    Windows 10, Windows 8.1; Microsoft .NET Framework 4.5 Client; Pentium-class 1 GHz processor (or equivalent); 512 MB RAM; 650 MB disk space plus 50 MB for each downloaded practice exam; access to the Internet to register and download exam databases

    Also available from Cisco Press for CCNP Security study is the CCNP Security Virtual Private Networks SVPN 300-730 Official Cert Guide Premium Edition eBook and Practice Test. This digital-only certification preparation product combines an eBook with enhanced Pearson Test Prep Practice Test.

    This integrated learning package
    * Enables you to focus on individual topic areas or take complete, timed exams
    * Includes direct links from each question to detailed tutorials to help you understand the concepts behind the questions
    * Provides unique sets of exam-realistic practice questions
    * Tracks your performance and provides feedback on a module-by-module basis, laying out a complete assessment of your knowledge to help you focus your study where it is needed most

    Produktinformation

    • Märke:Pearson Education
    • Utgivningsdatum:2022-03-07
    • Höjd:183 x 234 x 33 mm
    • Vikt:1 040 g
    • Språk:Engelska
    • Serie:Official Cert Guide
    • Antal sidor:496
    • Upplaga:1
    • Förlag:Pearson Education
    • EAN:9780136660606

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • It-certifieringar inom Data och IT

    Mer om författaren

    Joseph Muniz is an architect and security researcher in the Cisco Security Sales and Engineering organization. He is driven by making the world a safer place through education and adversary research. Joseph has extensive experience in designing security solutions and architectures as a trusted advisor for top Fortune 500 corporations and the U.S. government. Joseph is a researcher and industry thought leader. He speaks regularly at international conferences, writes for technical magazines, and is involved with developing training for various industry certifications. He invented the fictitious character Emily Williams to create awareness around social engineering. Joseph runs The Security Blogger website, a popular resource for security and product implementation. He is the author of and contributor to several publications, including titles ranging from security best practices to exploitation tactics.When Joseph is not using technology, you can find him on the futbal (soccer) field or raising the next generation of hackers, also known as his children. Follow Joseph at https://www.thesecurityblogger.com and @SecureBlogger.Steven Chimes, CCIE No. 35525, is a security architect in the Security Sales Engineering organization at Cisco, focused on building cybersecurity solutions for Cisco's largest global customers. He has more than 15 years of experience in the networking and cybersecurity fields, specializing in cross-domain solutions and emerging technologies. He has led the technical design for projects across the IT spectrum, including networking, security, analytics, identity, collaboration, compute, data center, and cloud.When not building solutions, Steven is either teaching or learning. He is a distinguished speaker at Cisco Live and has spoken at Cisco Live events all over the world. He is also a serial collector of certifications, including CCIE Security, CCNP Enterprise, DevNet Associate, CISSP-ISSAP, GMON, and GCIH, among many others. What Steven finds most fulfilling, though, is mentoring the next generation of inspired cybersecurity professionals through programs such as Cisco High. Follow Steven @StevenChimes on Twitter.James Risler, CCIE No. 15412, is a security training development manager in the Cisco Customer Experience organization. As senior manager of security content engineering at Cisco, he's constantly discovering and exploring the latest trends and issues in security, IT, and business. In his current role, he oversees teams responsible for both security and collaboration course development.James is passionate about helping organizations understand the impact that security events can have on business and how to mitigate that risk. That's why he works to educate individuals and organizations in a variety of cybersecurity topics, including threat defense, virtual private networks, and firewall configuration, among others. Besides his work at Cisco, James works to help create the next generation of security defenders by holding training sessions and presentations for the University of Tampa Cybersecurity Club.James is a distinguished speaker at Cisco Live; he holds Certified Information Systems Security Professional (CISSP) and Cisco Certified Internetwork Expert (CCIE) certifications; and he has earned a master's of business administration (MBA) from the University of Tampa. When he is not at work, he is either home brewing or cooking up a complex meal. Follow James @JimRisler on Twitter.

    Innehållsförteckning

    • Introduction xxxiPart I Virtual Private Networks (VPN)Chapter 1 Understanding the Implementing Secure Solutions with Virtual Private Networks SVPN 300-730 Exam 2Why Learn VPN Technology 2The Cisco Certification Program 6The SVPN 300-730 Exam 8Exam Preparation 13Summary 13Chapter 2 Introduction to Virtual Private Networks (VPN) 14"Do I Know This Already?" Quiz 15Foundation Topics 17VPN Offerings 17VPN Technologies vs. Services 17Remote Access VPNs 18Remote Access VPN Use Cases 19Site-to-Site VPNs 20Hub-and-Spoke Design 20Spoke-to-Spoke Design 20Full Mesh Design 21Hybrid Design 21Tiered Hub-and-Spoke Design 22VPN Technology Components 23Hardware VPN Support 23Routers 23Security Appliances 26VPN Clients 28Other VPN Clients 29VPN Protocols 29Point-to-Point Tunneling Protocol (PPTP) 30PPTP Pitfalls 30Secure Socket Tunneling Protocol (SSTP) 31SSL/TLS 31IPsec with IKE 31IPsec with IKEv2 32Easy VPN 32L2TP 32VPN Protocol Comparison 33Cisco VPN Portfolio 33DMVPN 33DMVPN Use Cases 33Group Encrypted Transport VPN (GETVPN) 33FlexVPN 34SSL VPN 34SSL VPN Use Cases 34Site-to-Site VPN Comparison 34Cisco ASA Licensing 37Time-Based License 37Licensing Options 38Cisco Secure Firewall Series for Site-to-Site VPNs 39Cisco Secure Firewall Limitations 39Cisco Meraki Licensing 40Cisco Meraki VPN Options 40Cisco Security Appliance Management 41Cisco Security Management Options 41VPN Logging 42Logging Collection Points 42ASA Logging 42SIEM 43VPN Client Logging 44DART 44Logging Challenges 45Summary 47References 47Exam Preparation Tasks 48Part II Site-to-Site VPNChapter 3 Site-to-Site VPNs 50"Do I Know This Already?" Quiz 51Foundation Topics 53Site-to-Site VPN Architecture 54Site-to-Site Design Considerations 54Scoping a Project 54Site-to-Site Components 55Routers vs. Security Appliances 55Cisco Security Appliances for Site-to-Site VPNs 56IPsec 56Authentication Header 56Encapsulating Security Payload 57Comparing AH and ESP 57ISAKMP 58IKE Security Association 58IKE Version 1 and 2 58Key IKE Concepts 60IKE Authentication 61VPN Tunnel Concepts 62IPsec Tunnel Mode 63IPsec Transport Mode 63Certificate Authorities 64Crypto Map Concepts 64GETVPN/DMVPN/FlexVPN 64GETVPN 65DMVPN 65FlexVPN 65Router Configuration with IKEv1 66Planning the VPN 67Configuring the Tunnel 68Why Use GRE with IPsec? 68Configuring a GRE Tunnel 68Configuring Network Address Translation 70NAT Example 71Configuring Encryption and IPsec 72IKE Policy Example 73Authentication Options 73Pre-shared Key Example 74Digital Certificate Example 74Configuring a Crypto Map 75Crypto Map Example 76Applying Crypto Maps 77Configuring QoS 78Router Configuration with IKEv2 78Primary Router Configuration Example 78Defining the IKEv2 Keyring 78Defining the IKEv2 Proposal 79Defining IKEv2 Policies 79Defining a Crypto ACL for IPsec Secured Traffic 79Defining a Transform Set 80Defining an IKEv2 Profile 80Defining Crypto Maps 80Activating Crypto Maps 81Repeating Similar Steps for the Other Router 81Appliance Configuration 83ASDM Example 83ASA Command-Line Example 87Cisco Secure Firewall Example 93Cisco Meraki Example 97High Availability 99High Availability Options 100High Availability Considerations 101High Availability Costs 102High Availability Technology Considerations 102Bidirectional Forwarding Detection 103IOS Failover Example 103Summary 104References 104Exam Preparation Tasks 105Chapter 4 Group Encrypted Transport VPN (GETVPN) 106"Do I Know This Already?" Quiz 107Foundation Topics 109MPLS Security Challenges 109GETVPN Overview 111GDOI Protocol 111GETVPN Benefit Summary 113GETVPN Components 113GETVPN Key Server 113GETVPN Group Member 115GETVPN GDOI Protocol 115GETVPN Security Controls 115Rekeying 115TBAR 115IP-D3P 116GETVPN Design Considerations 116GETVPN Fault Tolerance Considerations 116Key GETVPN Considerations 117GETVPN Implementation and Configuration 117Configuring a Key Server 119IKE Phase 1 Policy 119Key Server PSK Authentication 120IKE Phase 2 Policy 120Key Server RSA Key 120Key Server GDOI 120Unicast Rekeying Parameters 120Key Server Policy Access List 121Configuring Group Members 121Group Member IKE Phase 1 Policy 121Group Member PSK Authentication 122Group Member GDOI Information 122Crypto Maps 123GETVPN Status Commands 123Group Member Show Commands 126GETVPN Status Commands Summary 128Summary 128References 129Exam Preparation Tasks 129Chapter 5 Dynamic Multipoint Virtual Private Network (DMVPN) 130"Do I Know This Already?" Quiz 131Foundation Topics 134DMVPN Overview 134Legacy Crypto Map VPN Solutions 135Modern VPN Needs 135DMVPN Risks 136DMVPN Core Concepts 136DMVPN Example 136DVMPN Network Components 137mGRE 137GRE and mGRE Advantages 138NHRP 138NHRP Example 139Remaining DMVPN Components 139Solution Breakdown 139DMVPN Design Considerations 140DMVPN Planning 140DMVPN Fault Tolerance Considerations 141Key DMVPN Considerations 141DMVPN Phases 141DMVPN Phase 1 141DMVPN Phase 2 142DMVPN Phase 3 143DMVPN Phase 1 Hub-and-Spoke Implementation 144Crypto IPsec Policy Configuration 145Creating an IKE Policy 145Creating Pre-shared Key Authentication Credentials 146Creating a Profile 147Creating a Transform Set 148GRE Tunnel Configuration 148Creating a Multipoint GRE Tunnel on the Hub 148Creating a GRE Tunnel on the Spoke 149NHRP Hub-and-Spoke Configuration 150Configure NHRP on the Hub 150Configure NHRP on the Spoke 150Configure Tunnel Protection 151Configure Tunnel Optional Parameters 152Routing Protocol Configuration 152Configure Routing on the Hub 152Configure Routing on the Spoke Using IPV4 153Configure Routing on the Spoke Using IPV6 153DMVPN Phase 2 Spoke-to-Spoke Implementation 154IPsec for Spoke-to-Spoke 154Spoke-to-Spoke Routing 154IPv6 Spoke-to-Spoke Routing Configuration 155DMVPN Phase 3 Spoke-to-Spoke Implementation 155Enable NHRP Redirects on the Hub 155Enable NHRP Shortcuts on the Spoke 156DMVPN Troubleshooting 156Troubleshooting the Crypto IPsec Policy Configuration 156Troubleshooting IKE Phase 2 157Troubleshooting the GRE Tunnel Configuration 157Validating the Tunnel 158Troubleshooting the NHRP Hub-and-Spoke Configuration 158NHRP Registration 158Tunnel Configuration 158Debugging 159Troubleshoot the Routing Configuration 159DMVPN Troubleshooting Summary 160Summary 160References 161Exam Preparation Tasks 161Chapter 6 FlexVPN Configuration and Troubleshooting 164"Do I Know This Already?" Quiz 165Foundation Topics 168FlexVPN Overview 168FlexVPN Advantages 169Modular Framework 169Configuring Service Parameters 169IKEv2 Benefits Summarized 169FlexVPN Versus Other Options 170Benefits of IKEv2 171FlexVPN Requirements 171FlexVPN Components 172FlexVPN Component Roles 173FlexVPN Smart Defaults 173Router Smart Defaults 174FlexVPN Design Considerations 174FlexVPN Planning 174Key FlexVPN Consideration 175FlexVPN Implementation: Hub-and-Spoke (IPv4/IPv6) 175Hub-and-Spoke Configuration Summary 176Step 1: IKEv2 Proposal and IKEv2 Policy Configuration 177FlexVPN IKEv2 Proposal 177FlexVPN Transform Set 178Step 2: IKEv2 Authorization Policy Configuration 178AAA 178Hub Pool 179ACL Permitting Traffic 179Attach to Authorization Policy 180Step 3: Keyring and IKEv2 Profile Configuration 180Keyring 180IKEv2 Profile 181Step 4: IPsec Profile Configuration 182Create Loopback Address 182Virtual Template 183Pre-shared IKEv2 Keyring 183FlexVPN Spoke Configuration 183Spoke AAA Configuration 183Spoke Access List 184Spoke Keyring 184Spoke Authorization Policy 184Spoke IKEv2 Profile 185Spoke IPsec Profile 185Spoke Tunnel Interface 186FlexVPN Implementation: Spoke-to-Spoke (IPv4/IPv6) 186FlexVPN NHRP 187FlexVPN Spoke-to-Spoke Spoke Router 188Spoke-to-Spoke Keyring 188Spoke-to-Spoke Route Injection 188Spoke-to-Spoke IKEv2 Profile 189Spoke-to-Spoke Add NHRP 189Spoke-to-Spoke Virtual Template 190FlexVPN Troubleshooting 191Connectivity Troubleshooting 192Step 1: IKEv2 Proposal and IKEv2 Policy Troubleshooting 192IKEv2 Debugging 193Step 2: IKEv2 Authorization Policy Troubleshooting 193Step 3: Keyring and IKEv2 Profile Troubleshooting 194Step 4: IPsec Profile Troubleshooting 194NHRP Troubleshooting 195Summary 197References 197Exam Preparation Tasks 198Part III Remote Access Virtual Private NetworkChapter 7 Remote Access VPNs 200"Do I Know This Already?" Quiz 202Foundation Topics 204Remote VPN Architecture 205NAS and Client-Side Software 205Remote Access Technology Considerations 206Remote Access Components 207Remote Access Capable Routers 207Remote Access Capable Security Appliances 208AnyConnect Secure Mobility Client 209User Experience 209AnyConnect Protocol Support 209AnyConnect Security Capabilities 210AnyConnect Platform Support 210AnyConnect Profile Editor 211AnyConnect VPN Profile Example 212VPN Connection Profiles, Group Policies, and Users 214Group Policies 214Connection Profiles 214Split Tunneling 215Split Tunneling Configuration 216SSL VPN/WebVPN 219WebVPN Example 220SSL VPN Options 221SSL VPN Licensing 222Encryption Algorithms 223Encryption Trends 223Encryption Algorithm Categories 223Comparing Encryption Options 224Elliptic Curve Cryptography Algorithms 225ECC Threats 225Encryption Algorithm Math 225ECC Math 226Combining ECC with Other Algorithms 227Applying Elliptic Curve Cryptography to a VPN 227Diffie Hellman Groups 228High Availability 228Load Balancing 229Failover Design 229Load Balancing Considerations 229Cisco ASDM Remote Access Configuration 230Cisco ASA CLI Remote Access Configuration 237Default Tunnel Groups 239Cisco Secure Firewall Remote Access VPN 241Cisco Secure Firewall Features 241Cisco Meraki Remote Access VPN 248Meraki Remote Access Configuration Example 249Router Configuration 250Key Concepts for Remote Access on Routers 251Remote Access on Router Configuration Example 251Summary 255References 256Exam Preparation Tasks 257Chapter 8 Clientless Remote Access SSL VPNs on the ASA 258"Do I Know This Already?" Quiz 259Foundation Topics 260Clientless SSL VPN Overview 261ASA as a Proxy 262Cisco VPN Options 262Clientless SSL VPN Prerequisites 263Software Licenses 263License Options 264AnyConnect Plus Subscription and Perpetual 264AnyConnect Apex Subscription 264AnyConnect VPN Only Perpetual License 264License Option Summary 265Software Support Requirements 266Clientless SSL VPN Prerequisites Summary 267Basic Clientless SSL VPN Configuration 267Step 1: Installing an Identity Certificate 268Generating a New RSA Key Pair Using ASDM 268Generating a New RSA Key Pair Using CLI 269Creating an Identity Certificate Request Using ASDM 269Creating an Identity Certificate Request Using CLI 270Installing a Signed Identity Certificate Using ASDM 271Installing a Signed Identity Certificate Using CLI 272Step 2: Applying an Identity Certificate to the Interface(s) 273Applying the Identity Certificate Using ASDM 273Applying the Identity Certificate Using CLI 274Step 3: Enabling Clientless SSL VPN on an Interface 274Enable Clientless SSL VPN Interface Using ASDM 274Enable Clientless SSL VPN Interface Using CLI 275Step 4: Configuring Group Policies 276Group Policy Selection 276Creating Group Policies Using ASDM 277Creating Group Policies Using CLI 277Group Policy Attributes for Clientless SSL VPNs 278WebVPN Group Policy Attributes 279WebVPN Group Policy vs. Group Policy Attributes 280Step 5: Configuring Connection Profiles 280Default Connect Profiles 281Creating a Connection Profile Using ASDM 281Creating a Connection Profile Using CLI 282Connection Profile General Attributes 283Connection Profile WebVPN Attributes 283Step 6: Configuring User Authentication 284Authentication Servers 285Configuring Authentication Using ASDM 286Configuring Local Authentication Using CLI 287Extended Clientless SSL VPN Configuration Options 287Configuring Bookmarks 287Bookmark Support 288Creating a Bookmark List 289Applying the Bookmark List to a Group Policy Using ASDM 290Applying the Bookmark List to a Group Policy Using CLI 291Configuring Web ACLs 291Web ACL Support 291Creating a Web ACL Using ASDM 292Creating a Web ACL Using CLI 293Applying a Web ACL to a Group Policy Using ASDM 293Applying a Web ACL to a Group Policy Using CLI 294Configuring Application Access via Port Forwarding 294Creating a Port Forwarding List Using ASDM 295Creating a Port Forwarding List Using CLI 295Applying a Port Forwarding List to a Group Policy Using ASDM 296Applying a Port Forwarding List to a Group Policy Using ASDM 296Configuring Application Access via Smart Tunnels 297Smart Tunnel Requirements 297Smart Tunnel Benefits 298Creating a Smart Tunnel List Using ASDM 298Creating a Smart Tunnel List Using ASDM 299Applying the Smart Tunnel List to a Group Policy Using ASDM 300Applying the Smart Tunnel List to a Group Policy Using CLI 300Configuring Client/Server Plug-ins 301Obtaining Plug-ins 301Summary 302References 302Exam Preparation Tasks 303Chapter 9 AnyConnect VPNs on the ASA and IOS 306"Do I Know This Already?" Quiz 307Foundation Topics 309AnyConnect VPN Review 310SSL VPN Versus IKEv2 310AnyConnect SSL VPN Prerequisites on ASA 310AnyConnect Licenses 311Supported Operating Systems 311Compatible Browsers 311Administrative Privileges 311Basic AnyConnect SSL VPN Configuration on ASA 312Step 1: Installing an Identity Certificate 312Step 2: Loading an AnyConnect Package 312Loading an AnyConnect Package Using ASDM 313Loading an AnyConnect Package Using CLI 314Step 3: Enabling AnyConnect VPN Client SSL Access 315Enabling AnyConnect VPN Using ASDM 315Enabling AnyConnect VPN Using CLI 315Step 4: Configuring a Group Policy 316Configure Group Policy Using ASDM 317Configure Group Policy Using CLI 318Step 5: Configuring an AnyConnect Connection Profile 319Configuring an AnyConnect Connection Profile Using ASDM 319Configuring an AnyConnect Connection Profile Using CLI 320Configuring a Group URL for an AnyConnect Connection Profile Using ASDM 322Configuring a Group URL for an AnyConnect Connection Profile Using CLI 323Step 6: Configuring User Authentication 324Creating a AAA Server Group Using ASDM 324Creating a AAA Server Group Using CLI 325Adding RADIUS Servers to a AAA Server Group Using ASDM 325Adding RADIUS Servers to a AAA Server Group Using CLI 326Configuring a Connection Profile to Use the RADIUS Server Group Using ASDM 326Configuring a Connection Profile to Use the RADIUS Server Group Using CLI 327Step 7: Defining an Address Pool 328Creating an Address Pool Using ASDM 328Creating an Address Pool Using CLI 328Applying the Address Pool to a Group Policy Using ASDM 329Applying the Address Pool to a Group Policy Using CLI 330AnyConnect Installation 330Connecting from the AnyConnect Client 331Extended AnyConnect SSL VPN Configuration on ASA 331Configuring DNS and WINS Using ASDM 332Configuring DNS and WINS Using CLI 332Configuring Split Tunneling Using ASDM 333Configuring Split Tunneling Using CLI 335Configuring a Traffic Filter Using ASDM 335Configuring a Traffic Filter Using CLI 336AnyConnect IKEv2 VPN on ASA 337Step 1: Enabling IPsec (IKEv2) 337Configuring IPsec (IKEv2) Using ASDM 337Configuring IPsec (IKEv2) Using CLI 338Step 2: Configuring an AnyConnect Client Profile for IKEv2 340Profile Storage 340Creating AnyConnect Client Profile for IKEv2 Using ASDM 341AnyConnect IKEv2 VPN on Routers 342Step 1: Configuring PKI 343Generating a Key Pair 343Creating a Trustpoint 344Trust Point Policy 344Configuring a Trustpoint 345Define Trust Policy 345Disable FQDN 345Importing the Root CA Certificate 345Generating a Certificate Signing Request (CSR) 346Importing the Signed Server Certificate 347Step 2: Disabling the HTTP and HTTPS Servers on the Router 349Step 3: Configuring AAA 349Step 4: Creating an IKEv2 Authorization Policy 349Step 5: Creating an IKEv2 Profile 350Create New IKEv2 Profile 350Identifying Match Criteria 350RSA Certificate Authentication 351Authenticating Remote Users 351Authentication List 351Virtual Template 351AnyConnect Client Profile 351Configuration Summary 351Step 6: Creating a Virtual Template 352Creating the AnyConnect Client Profile 353AnyConnect Profile Editor 354Copying to the Router 355Reboot 356Configuring Split Tunneling 357Summary 357References 358Exam Preparation Tasks 358Chapter 10 Troubleshooting Remote Access VPNs 362"Do I Know This Already?" Quiz 363Foundation Topics 365Troubleshooting Clientless SSL VPNs on the ASA 366Troubleshooting Categories 366Step 0: SSL VPN Components 367Step 1: Connectivity Troubleshooting 368Troubleshooting Questions 368Exam-Focused Connectivity Troubleshooting 368ASA WebVPN Service 370Troubleshooting Certificates 370Applied Certificates 371Full Certificate Chain 371Correct Certificate 371Certificate Debug Commands 371The capture Command 372Connectivity Troubleshooting Summary 372Step 2: Login Troubleshooting 372Connection Profile Group URL 373Viewing Group URLs 373Profile Selection 373&nb