Cisco Secure Firewall Services Module (FWSM) and over one million other books are available for Amazon Kindle. Learn more

Buy New

or
Sign in to turn on 1-Click ordering.
or
Amazon Prime Free Trial required. Sign up when you check out. Learn More
Buy Used
Used - Good See details
$35.87 & this item ships for FREE with Super Saver Shipping. Details

or
Sign in to turn on 1-Click ordering.
 
   
Kindle Edition
 
   
More Buying Choices
Have one to sell? Sell yours here
Cisco Secure Firewall Services Module (FWSM)
 
 
Start reading Cisco Secure Firewall Services Module (FWSM) on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Cisco Secure Firewall Services Module (FWSM) [Paperback]

Ray Blair (Author), Arvind Durai (Author)
3.2 out of 5 stars  See all reviews (5 customer reviews)

List Price: $65.00
Price: $48.74 & this item ships for FREE with Super Saver Shipping. Details
You Save: $16.26 (25%)
  Special Offers Available
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.
Only 9 left in stock--order soon (more on the way).
Want it delivered Monday, February 6? Choose One-Day Shipping at checkout. Details
Textbook Student FREE Two-Day Shipping for students on millions of items. Learn more

Formats

Amazon Price New from Used from
Kindle Edition $35.10  
Paperback $48.74  

Book Description

September 8, 2008 1587053535 978-1587053535 1

Cisco Secure Firewall Services Module (FWSM)

 

Best practices for securing networks with FWSM

 

Ray Blair, CCIE® No. 7050

Arvind Durai, CCIE No. 7016

 

The Firewall Services Module (FWSM) is a high-performance stateful-inspection firewall that integrates into the Cisco® 6500 switch and 7600 router chassis. The FWSM monitors traffic flows using application inspection engines to provide a strong level of network security. The FWSM defines the security parameter and enables the enforcement of security policies through authentication, access control lists, and protocol inspection. The FWSM is a key component to anyone deploying network security.

 

Cisco Secure Firewall Services Module (FWSM) covers all aspects of the FWSM. The book provides a detailed look at how the FWSM processes information, as well as installation advice, configuration details, recommendations for network integration, and reviews of operation and management. This book provides you with a single source that comprehensively answers how and why the FWSM functions as it does. This information enables you to successfully deploy the FWSM and gain the greatest functional benefit from your deployment. Practical examples throughout show you how other customers have successfully deployed the FWSM.

 

By reading this book, you will learn how the FWSM functions, the differences between the FWSM and the ASA Security Appliance, how to implement and maintain the FWSM, the latest features of the FWSM, and how to configure common installations.

 

Ray Blair, CCIE® No. 7050, is a consulting systems architect who has been with Cisco for more than 8 years, working primarily on security and large network designs. He has 20 years of experience in designing, implementing, and maintaining networks that have included nearly all networking technologies. Mr. Blair maintains three CCIE certifications in Routing and Switching, Security, and Service Provider. He is also a CNE and a CISSP.

 

Arvind Durai, CCIE No. 7016, is an advanced services technical leader for Cisco. His primary responsibility has been in supporting major Cisco customers in the enterprise sector. One of his focuses has been on security, and he has authored several white papers and design guides in various technologies. Mr. Durai maintains two CCIE certifications, in Routing and Switching and Security.

 

  • Understand modes of operation, security levels, and contexts for the FWSM
  • Configure routing protocols and the host-chassis to support the FWSM
  • Deploy ACLs and Authentication, Authorization, and Accounting (AAA)
  • Apply class and policy maps
  • Configure multiple FWSMs for failover support
  • Configure application and protocol inspection
  • Filter traffic using filter servers, ActiveX, and Java filtering functions
  • Learn how IP multicast and the FWSM interact
  • Increase performance with firewall load balancing
  • Configure IPv6 and asymmetric routing
  • Mitigate network attacks using shunning, anti-spoofing, connection limits, and timeouts
  • Examine network design, management, and troubleshooting best practices

 

This security book is part of the Cisco Press® Networking Technology series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.

 

Category: Networking: Security

Covers: Firewall security

 


Special Offers and Product Promotions

  • Buy $50 in qualifying physical textbooks, get $5 in Amazon MP3 Credit. Here's how (restrictions apply)

Frequently Bought Together

Customers buy this book with Cisco ASA: All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance (2nd Edition) $56.82

Cisco Secure Firewall Services Module (FWSM) + Cisco ASA: All-in-One Firewall, IPS, Anti-X, and VPN Adaptive Security Appliance (2nd Edition)
Price For Both: $105.56

Show availability and shipping details



Editorial Reviews

About the Author

Ray Blair is a consulting systems architect and has been with Cisco Systems for more than eight years, working primarily on security and large network designs. He has 20 years of experience with designing, implementing, and maintaining networks that have included nearly all networking technologies. His first four years in the high-technology industry started with designing industrial computer systems for process monitoring. Mr. Blair maintains three Cisco Certified Internetwork Expert (CCIE) certifications in Routing and Switching, Security, and Service Provider. He also is a Certified Novell Engineer (CNE) and a Certified Information Systems Security Professional (CISSP).

 

Arvind Durai is an advanced services technical leader for Cisco Systems. His primary responsibility has been in supporting major Cisco customers in the Enterprise sector, some of which includes Financial, Manufacturing, E-commerce, State Government, and Health Care sectors. One of his focuses has been on security, and he has authored several white papers and design guides in various technologies. Mr. Durai maintains two Cisco Certified Internetwork Expert (CCIE) certifications in Routing and Switching and Security. Mr. Durai holds a Bachelor of Science degree in Electronics and Communication, a Master’s degree in Electrical Engineering (MS), and Master’s degree in Business Administration (MBA).

 

Excerpt. © Reprinted by permission. All rights reserved.

Cisco Secure Firewall Services Module (FWSM)

Cisco Secure Firewall Services Module (FWSM)

Introduction

Firewalls are one of the main components used in securing a network infrastructure, and having an in-depth understanding of how these devices function is paramount to maintaining a secure network.

This book was written to provide an understanding of the functionality of the Firewall Services Module (FWSM), from both a hardware and software perspective and to be a practical design guide with configuration examples for the design, implementation, operation, and management of FWSM in various deployment scenarios.

Who Should Read This Book?

This book is targeted at individuals who would like an in-depth understanding of the FWSM. It is focused primarily for those who design, implement, or maintain the FWSM, such as security/network administrators. To get the most value from the material, the reader should have at least an intermediate knowledge of networking and security.

How This Book Is Organized

This book is organized into five sections that cover the basic introduction of firewalls, initial and advanced configurations, design guides and configuration examples, and features and functionality introduced in FWSM version 4.x code:

  • Chapter 1, "Types of Firewalls": This chapter explains the functionality of the different types of firewalls.

  • Chapter 2, "Overview of the Firewall Services Module": This chapter covers specifications, installation information, performance, and virtualization; shows a comparison of IOS FW, ASA, and FWSM; and also explains the hardware and software architecture.

  • Chapter 3, "Examining Modes of Operation": This chapter examines the modes of operation (transparent/routed) and explains the advantages of each.

  • Chapter 4, "Understanding Security Levels": This chapter explains how traffic flows between interfaces, using both NAT and PAT and routed and transparent modes.

  • Chapter 5, "Understanding Contexts": This chapter provides an overview of the benefits of contexts and how to manage them.

  • Chapter 6, "Configuring and Securing the 6500/7600 Chassis": This chapter explains how to configure the host chassis to support the FWSM.

  • Chapter 7, "Configuring the FWSM": This chapter covers the initial configuration of the FWSM.

  • Chapter 8, "Access Control Lists": This chapter examines the use of ACLs.

  • Chapter 9, "Configuring Routing Protocols": This chapter explains the use of routing protocols on the FWSM.

  • Chapter 10, "AAA Overview": This chapter covers the principles of using authentication, authorization, and accounting.

  • Chapter 11, "Modular Policy": This chapter covers the use of class and policy maps.

  • Chapter 12, "Understanding Failover in FWSM": This chapter explains the use and configuration of using multiple FWSMs for high availability.

  • Chapter 13, "Understanding Application Protocol Inspection": This chapter covers the use and configuration of application and protocol inspection.

  • Chapter 14, "Filtering": This chapter examines how traffic can be filtered using filter servers and how Active X and Java filtering function.

  • Chapter 15, "Managing and Monitoring the FWSM": This chapter covers the different options of managing and monitoring the FWSM.

  • Chapter 16, "Multicast": This chapter explains the interaction of multicast with the FWSM and provides some practical examples.

  • Chapter 17, "Asymmetric Routing": This chapter provides an explanation of asymmetric routing and how it can be configured.

  • Chapter 18, "Firewall Load Balancing": This chapter covers the options of how to increase performance using multiple FWSMs.

  • Chapter 19, "IP Version 6": This chapter explains IPv6 and how it is configured on the FWSM.

  • Chapter 20, "Preventing Network Attacks": This chapter examines how to mitigate network attacks, using shunning, antispoofing, connection limits, and timeouts.

  • Chapter 21, "Troubleshooting the FWSM": This chapter explains how to leverage the appropriate tools to solve problems.

  • Chapter 22, "Designing a Network Infrastructure": This chapter covers an overview on placement of the FWSM in the network.

  • Chapter 23, "Design Scenarios": This chapter provides many practical examples of how the FWSM can be configured.

  • Chapter 24, "FWSM 4.x Performance and Scalability Improvements": This chapter covers the performance improvements in 4.x code.

  • Chapter 25, "Understanding FWSM 4.x Routing and Feature Enhancements": This chapter explains the use of commands introduced in 4.x code.


© Copyright Pearson Education. All rights reserved.


Product Details

  • Paperback: 528 pages
  • Publisher: Cisco Press; 1 edition (September 8, 2008)
  • Language: English
  • ISBN-10: 1587053535
  • ISBN-13: 978-1587053535
  • Product Dimensions: 8.8 x 7.3 x 1.1 inches
  • Shipping Weight: 1.9 pounds (View shipping rates and policies)
  • Average Customer Review: 3.2 out of 5 stars  See all reviews (5 customer reviews)
  • Amazon Best Sellers Rank: #1,309,691 in Books (See Top 100 in Books)

More About the Author

Discover books, learn about writers, read author blogs, and more.

 

Customer Reviews

5 Reviews
5 star:    (0)
4 star:
 (3)
3 star:
 (1)
2 star:    (0)
1 star:
 (1)
 
 
 
 
 
Average Customer Review
3.2 out of 5 stars (5 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

1.0 out of 5 stars This book contains a lot of errors, July 12, 2009
By 
Casey Simmons (Los Angeles, CA) - See all my reviews
Amazon Verified Purchase(What's this?)
This review is from: Cisco Secure Firewall Services Module (FWSM) (Paperback)
This book contains a lot of typographical errors. I wasn't sure if the configurations were right sometimes. I would download the configuration guide off Cisco's web site instead of ordering this book.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4.0 out of 5 stars Complex Security Material Made Easy, January 9, 2009
This review is from: Cisco Secure Firewall Services Module (FWSM) (Paperback)
The Cisco Press book, Cisco Secure Firewall Services Module (FWSM), written by Ray Blair and Arvind Durai promises the reader that he would be given 'an in-depth understanding of the FWSM' particularly 'for those who design, implement, or maintain the FWSM.' I would venture to write that this book delivers this and more. Written at a level accessible to a majority of readers, i.e. high school and beyond, this technical narrative helps to facilitate the rapid adoption of a product which would otherwise require a great deal of time and training resources necessary to successfully implement in a production network. To assist in achieving understanding of the complex topics related to network security and the FWSM, the book is replete with easy-to-grasp diagrams and simple to detailed module configuration examples. The text itself is terse though engaging, direct and even humorous in parts which aids in maintaining the reader's attention and prolonged interest in the difficult subject matter. Concepts are presented in clear and understandable language which also promotes rapid digestion of the material.

Of particular interest to this reviewer was the topic related to security contexts, a concept which prior to reading this manual was difficult to understand much less implement. However, after having read the overview of the product in chapter two followed by the security contexts material resident in chapter five and the configuration chapter seven, I am confidant of the technical knowledge gained to be able to quickly and securely configure this extraordinary feature of the product.

This manual is the perfect desk side companion to the information made available about the Firewall Services Module on the support section of Cisco's web site. Blair and Durai, both CCIEs, have provided security experts and the newcomer to the field a fine technical work which delivers comprehensive detail of the product and their real world experience designing for and implementing security solutions with the Firewall Services Module. Due to their vast and proven experience in the industry and due to their facile writing style, this reviewer looks forward to more titles written by this team.
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No


4.0 out of 5 stars Excellent guide for the practitioner., December 31, 2008
By 
TimH "Timpala" (Lexington, KY United States) - See all my reviews
This review is from: Cisco Secure Firewall Services Module (FWSM) (Paperback)
Cisco secure firewall services module FWSM
Best practices for securing networks with FWSM.

The authors note that this book is written for the user that has to have an in-depth understanding of their new FWSM and its operation. I absolutely agree that the book is rich in detail and delves deeply into the underpinnings of the new FWSM. If you have a background in PIX or the new ASA you will be right at home learning the nuances of the chassis mount evolution of the product line.

As both authors are CCIE holders they are fully qualified to discuss and contrast the various best practices of firewall and network design as well as the unlimited implementation possibilities of the FWSM. They are kind enough to begin at the beginning and explain the various kinds of firewalls available to the modern day security engineer/designer and how the FWSM fits in with its own unique capabilities.

Everything you would expect to be covered in a cisco press title is of course present and well laid out. But Wait, There's More! Blair and Durai not only present the basics of the physical characteristics of the device itself but go into how to physically secure the installation of the blade giving common sense but well needed tips on access control to the device rack etc. I've seen too many installations where the trusted equipment is racked up in a janitor's closet or other non-secure space just waiting for an enterprising bad actor to come along and mess with the IT staff if not perform full fledged attacks.

The FWSMs configuration power and flexibility comes in the concept of contexts. Contexts are virtual firewalls implemented within the single physical FWSM device. The FWSM can support up to 250 contexts depending on your license. The authors advise that implementing too many contexts can oversubscribe the firewall and cause performance issues. The context chapter fully describes how to balance resources to provide the greatest possible throughput with the least hardware necessary.

With the full fledged reliance on the internet to perform almost all daily business transactions Availability is of prime importance. The connections to the internet must be available 7X24X365. The FWSM helps to accomplish this goal by the use of high availability pairs. Blair and Durai give an entire chapter to the configuration and testing of Active/Standby and Active/Active configurations. Add the complexity of multiple contexts within the pairs and you'll be glad you have these guys leading you through the configuration maze. Another full chapter digs deeper into load balancing with multiple FWSMs which could also be pairs, with multiple contexts... You get the idea.

The book would be just fine if it is only intended to be a reference manual. However the authors go beyond the call by providing their years of expertise with network infrastructure examples including every command to implement the various layouts provided. They go on to provide detailed examples of how to use this new infrastructure to provide the services necessary to support a modern network installation. This includes VPN termination, various routing protocols, and even touches on the latest design goal of Regulatory Compliance and how to achieve it at the network level.

As you can tell by now I fully encourage you to acquire this book if you have to have detailed hands-on interaction with the FWSM. It is probably overkill for the occasional user or management. The cisco site has all you'll need to understand the basics of the FWSM and how it could fit into your organization. But once it has been bought and delivered this book will help you get it up and running and securing your network.

Tim M. Heagarty, CISSP, CISA, GCIA, PCI QSA
Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews



Only search this product's reviews



Inside This Book (learn more)
Key Phrases - Statistically Improbable Phrases (SIPs): (learn more)
dest port, configuration methods, network management protocol, datagram service, tree statistics, next hop router, flow label, intrusion prevention system, perimeter device, default gateway, supervisor engine, single context routed mode, inspect ftp inspect, asdm history enable arp timeout, hostname context, timeout sunrpc, multiple context mode, outside security domain, first hop layer, arp vrf, inside icmp permit, inside security domain, passive pager lines, system execution space, xdmcp inspect sip inspect netbios
Key Phrases - Capitalized Phrases (CAPs): (learn more)
Network Address Translation, List of Contexts, Supporting Routing Methods, Port Address Translation, Understanding Failover, Firewall Services Module, Trusted Flow Acceleration, Configuring Routing Protocols, User Datagram Protocol, Internet Control Message Protocol, Hypertext Transfer Protocol, Src Port, Router Age Seq, Determining Placement, Network Processor, Address Resolution Protocol, Network Infrastructure Example, Application Server, Media Access Control, File Transfer Protocol, Tunneling Protocol, Design Scenarios Example, Understanding Contexts, Rule Count, Asymmetric Routing Support
Browse Sample Pages:
Front Cover | Table of Contents | First Pages | Index | Back Cover | Surprise Me!
Search Inside This Book:


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 
(1)

Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums



So You'd Like to...



Look for Similar Items by Category


Look for Similar Items by Subject