Start reading SSL Remote Access VPNs (Network Security) on your Kindle in under a minute. Don't have a Kindle? Get your Kindle here.

Deliver to your Kindle or other device

 
 
 

Try it free

Sample the beginning of this book for free

Deliver to your Kindle or other device

Read books on your computer or other mobile devices with our FREE Kindle Reading Apps.
SSL Remote Access VPNs (Network Security)
 
 

SSL Remote Access VPNs (Network Security) [Kindle Edition]

Jazib Frahim , Qiang Huang
2.7 out of 5 stars  See all reviews (3 customer reviews)

Digital List Price: $43.99 What's this?
Print List Price: $55.00
Kindle Price: $24.19 includes free wireless delivery via Amazon Whispernet
You Save: $30.81 (56%)

Formats

Amazon Price New from Used from
Kindle Edition $24.19  
Paperback $42.59  
certification
Certification Central
Ace your tech certification test with resources from Certification Central. Get guides for a full range of certifications--from CCNA and SQL server to PMP and Network+. Explore more.

Book Description

April 4, 2011

This is the eBook version of the printed book.

SSL Remote Access VPNs

An introduction to designing and configuring SSL virtual private networks

Jazib Frahim, CCIE® No. 5459

Qiang Huang, CCIE No. 4937

Cisco® SSL VPN solutions (formerly known as Cisco WebVPN solutions) give you a flexible and secure way to extend networking resources to virtually any remote user with access to the Internet and a web browser. Remote access based on SSL VPN delivers secure access to network resources by establishing an encrypted tunnel across the Internet using a broadband (cable or DSL) or ISP dialup connection.

SSL Remote Access VPNs provides you with a basic working knowledge of SSL virtual private networks on Cisco SSL VPN-capable devices. Design guidance is provided to assist you in implementing SSL VPN in existing network infrastructures. This includes examining existing hardware and software to determine whether they are SSL VPN capable, providing design recommendations, and guiding you on setting up the Cisco SSL VPN devices. Common deployment scenarios are covered to assist you in deploying an SSL VPN in your network.

SSL Remote Access VPNs gives you everything you need to know to understand, design, install, configure, and troubleshoot all the components that make up an effective, secure SSL VPN solution.

Jazib Frahim, CCIE® No. 5459, is currently working as a technical leader in the Worldwide Security Services Practice of the Cisco Advanced Services for Network Security. He is responsible for guiding customers in the design and implementation of their networks, with a focus on network security. He holds two CCIEs, one in routing and switching and the other in security.

Qiang Huang, CCIE No. 4937, is a product manager in the Cisco Campus Switch System Technology Group, focusing on driving the security and intelligent services roadmap for market-leading modular Ethernet switching platforms. During his time at Cisco, Qiang has played an important role in a number of technology groups, including the Cisco TAC security and VPN team, where he was responsible for trouble-shooting complicated customer deployments in security and VPN solutions. Qiang has extensive knowledge of security and VPN technologies and experience in real-life customer deployments. Qiang holds CCIE certifications in routing and switching, security, and

ISP Dial.


Understand remote access VPN technologies, such as Point-to-Point Tunneling Protocol (PPTP), Internet Protocol Security (IPsec), Layer 2 Forwarding (L2F), Layer 2 Tunneling (L2TP) over IPsec, and SSL VPN
Learn about the building blocks of SSL VPN, including cryptographic algorithms and SSL and Transport Layer Security (TLS)
Evaluate common design best practices for planning and designing an SSL VPN solution
Gain insight into SSL VPN functionality on Cisco Adaptive Security Appliance (ASA) and Cisco IOS® routers
Install and configure SSL VPNs on Cisco ASA and Cisco IOS routers
Manage your SSL VPN deployment using Cisco Security Manager

This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.

Category: Networking: Security

Covers: SSL VPNs


Editorial Reviews

About the Author

Jazib Frahim, CCIE No. 5459, has been with Cisco for more than nine years. Having a bachelor’s degree in computer engineering from Illinois Institute of Technology, he started out as a TAC engineer in the LAN Switching team. He then moved to the TAC Security team, where he acted as a technical leader for the security products. He led a team of 20 engineers in resolving complicated security and VPN technologies. He is currently working as a technical leader in the Worldwide Security Services Practice of Advanced Services for Network Security. He is responsible for guiding customers in the design and implementation of their networks with a focus on network security. He holds two CCIEs, one in routing and switching and the other in security. He has written numerous Cisco online technical documents and has been an active member on the Cisco online forum NetPro. He has presented at Networkers on multiple occasions and has taught many on-site and online courses to Cisco customers, partners, and employees.

 

He has recently received his master of business administration (MBA) degree from North Carolina State University. He is also an author of the following Cisco Press books: Cisco Network Admission Control, Volume II: NAC Deployment and Troubleshooting, and Cisco ASA: All-in-One Firewall, IPS, and VPN Adaptive Security Appliance.

 

Qiang Huang, CCIE No. 4937, is a product manager in the Cisco Systems Campus Switch System Technology Group, focusing on driving the security and intelligent services roadmap for Cisco marketleading modular Ethernet switching platforms. He has been with Cisco for almost ten years. During his time at Cisco, Qiang played an important role in a number of technology groups including the following: technical lead in the Cisco TAC security and VPN team, where he was responsible for troubleshooting complicated customer deployments in security and VPN solutions; a security consulting engineer in the Cisco Advanced Service Group, providing security posture assessment and consulting services to customers; a technical marketing engineer focusing on competitive analysis and market intelligence in network security with specialization in the emerging SSL VPN technology. Qiang has extensive knowledge of security and VPN technologies and experience in real-life customer deployments. Qiang holds CCIE certifications in routing and switching, security, and ISP dial. He is also one of the contributing authors of Internetworking Technologies Handbook, Fourth Edition. Qiang received a master’s degree in electrical engineering from Colorado State University.

 

Excerpt. © Reprinted by permission. All rights reserved.

Introduction

Introduction

This book provides a complete guide to the SSL VPN technology and discusses its implementation on Cisco SSL VPN–capable devices. Design guidance is provided to assist you in implementing SSL VPNs in an existing network infrastructure. This includes examining existing hardware and software to determine whether they are SSL VPN capable, providing design recommendations, and guiding you on setting up the Cisco SSL VPN devices.

Toward the end of Chapters 5 and 6, common deployment scenarios are covered to assist you in deploying an SSL VPN in your network.

Who Should Read This Book?

This book serves as a guide for network professionals who want to implement the Cisco SSL VPN remote access solution in their network to allow users to access the corporate resources easily and safely. The book systematically walks you through the product or solution architecture, installation, configuration, deployment, monitoring, and troubleshooting the SSL VPN solution. Any network professional should be able to use this book as a guide to successfully deploy SSL VPN remote access solutions in their network. Requirements include a basic knowledge of TCP/IP and networking, familiarity with Cisco routers/firewalls and their command-line interface (CLI), and a general understanding of the overall SSL VPN solution.

How This Book Is Organized

Part I of this book includes Chapters 1 and 2, which provide an overview of the remote access VPN technologies and introduce the SSL VPN technology. The remainder of the book is divided into two parts.

Part II encompasses Chapters 3 and 4 and introduces the Cisco SSL VPN product lines, with guidance on different design considerations.

Part III encompasses Chapters 5 through 7 and covers the installation, configuration, deployment, and troubleshooting of the individual components that make up the SSL VPN solution.

  • Part I, "Introduction and Technology Overview," includes the following chapters:

  • Chapter 1, "Introduction to Remote Access VPN Technologies": This chapter covers the remote access Virtual Private Network (VPN) technologies in detail. Protocols, such as the Point-to-Point Tunneling Protocol (PPTP), Internet Protocol Security (IPsec), Layer 2 Forwarding (L2F), Layer 2 Tunneling Protocol (L2TP) over IPsec, and SSL VPN, are discussed to provide readers with an overview of the available remote access VPN technologies.

    Chapter 2, "SSL VPN Technology": This chapter provides a technology overview of the building blocks of SSL VPNs, including cryptographic algorithms, SSL and Transport Layer Security (TLS), and common SSL VPN technologies.

  • Part II, "SSL VPN Design Considerations and Cisco Solution Overview," includes the following chapters:

  • Chapter 3, "SSL VPN Design Considerations": This chapter discusses the common design best practices for planning and designing an SSL VPN solution.

    Chapter 4, "Cisco SSL VPN Family of Products": This chapter discusses the SSL VPN functionality on Cisco Adaptive Security Appliance (ASA) and Cisco IOS routers and provides product specifications that are focused on SSL VPNs.

  • Part III, "Deploying Cisco SSL VPN Solutions," includes the following chapters:

  • Chapter 5, "SSL VPNs on Cisco ASA": This chapter provides details about the SSL VPN functionality in Cisco ASA. This chapter discusses clientless and full tunnel SSL VPN client implementations and focuses on Cisco Secure Desktop (CSD). This chapter also discusses the Host Scan feature that is used to collect posture information about end workstations. The dynamic access policy (DAP) feature, its usage, and detailed configuration examples are also provided. To reinforce learning, many different deployment scenarios are presented along with their configurations.

    Chapter 6, "SSL VPNs on Cisco IOS Routers": This chapter provides details about the SSL VPN functionality in Cisco IOS routers. It begins by offering design guidance and then discusses the configuration of SSL VPNs in greater detail. The configurations of clientless, thin client, and AnyConnect Client modes are discussed. The second half of the chapter focuses on Cisco Secure Desktop (CSD) and offers guidance in setting up CSD features. To reinforce learning, two different deployment scenarios are presented along with their configurations. Toward the end of this chapter, SSL VPN monitoring through SDM is also discussed.

    Chapter 7, "Management of SSL VPNs": This chapter discusses the central management of SSL VPN devices using Cisco Security Manager.


© Copyright Pearson Education. All rights reserved.


Product Details

  • File Size: 7061 KB
  • Print Length: 384 pages
  • Simultaneous Device Usage: Up to 5 simultaneous devices, per publisher limits
  • Publisher: Cisco Press; 1 edition (April 4, 2011)
  • Sold by: Amazon Digital Services
  • Language: English
  • ASIN: B004V9O94Y
  • Text-to-Speech: Enabled
  • Amazon Best Sellers Rank: #586,031 Paid in Kindle Store (See Top 100 Paid in Kindle Store)
  •  Would you like to give feedback on images?


Customer Reviews

Most Helpful Customer Reviews
3 of 3 people found the following review helpful
SSL Remote Access VPN July 12, 2008
By Martin
Format:Paperback
This book's goal is to serve as a complete guide to the SSL VPN technology and its implementation on Cisco SSL VPN-capable devices. It starts with the introduction to remote access VPN and SSL VPN technology before exploring the design consideration and Cisco SSL VPN family of products. The last part explains the SSL VPN implementation and configuration for Cisco ASA and Cisco IOS routers before it ends with the discussion on SSL VPN management.

This book is not for network beginners. Prior knowledge of VPN technology and familiarity with Cisco command line interface is needed as the book explains the remote access VPN technology concepts only briefly.

The book does come with a lot of screen shots and illustrations particularly on SSL VPN configuration chapters. It is trying to show readers how to configure SSL VPN thru ASDM but it also needs to provide CLI configuration so readers have alternative if they do not want to wade thru pages of pages of screenshots to configure SSL VPN.

The book also needs to provide more reference as the provided configurations will only help readers to get the SSL VPN up and running but are missing many optional SSL VPN configurations.

Although the book claims to be a complete guide, it does not even dedicate a chapter for SSL VPN troubleshooting guide. The troubleshooting section provided at the end of configuration chapters is quite meaningless.

The last chapter on SSL VPN management looks more like a brochure for Cisco Security Manager (CSM) and Cisco Access Control Server (ACS) product. It only covers a very general concept of SSL VPN policy configuration and provisioning using CSM and ACS with a reference at the back of the chapter to go to Cisco web site to look up on how to configure CSM and ACS.

All of this makes me confused on what target audience the book tries to cover as it is too complex for network beginners but not detail enough for people who already have extensive VPN knowledge. I find it interesting that the cover of the book indicates that it will serve as an introduction for SSL VPN but inside it claims to be a complete guide for SSL VPN technology.

In spite of these, I rate this book 4 out of 5 and still recommend the book. It has a lot of helpful information that can help readers to get familiar with SSL VPN concept and configuration quickly. Beginners who have no VPN knowledge should read Richard Deal's The Complete Cisco VPN Configuration Guide book first before moving on to read this. VPN network experts can read this to get the basic working knowledge of SSL VPN.
Comment | 
Was this review helpful to you?
Good Reference February 5, 2009
Format:Paperback
SSL Remote Access VPNs
Jazib Frahim, CCIE No. 5459
Qiang Huang, CCIE No. 4937

Right in the middle of a pretty big SSL VPN roll out here at my place of employment, Cisco Press released SSL Remote Access VPNs. They couldn't have had better timing, as there was a good deal I was still confused about.

First, let me get this clear from the start: I hate ASDM. It has its uses, like monitoring. The traffic and VPN monitoring interfaces are wonderful. However, as far as configuration goes, the command-line is preferable. That being said, 95% of this book, including configuration, revolves around ASDM.

The first chapter explains remote access VPNs, which should be pretty familiar to anyone with IPSec VPN experience. Nothing new here, but certainly a good refresher and a good way to build context for the rest of the book.

The next couple chapters focus on SSL VPN technology, as well as SSL VPN design considerations. Definitely a nice review, considering SSL is certainly not a new technology, but building high encryption VPNs using SSL certainly is.

Chapter 4 is just an overview of ASA appliances and IOS routers and their SSL VPN capabilities. It's only a few pages, so it's not exactly deep reading, but useful nonetheless.

Next is a chapter on SSL VPN on the ASA. Probably the best part of the book, it mostly focuses on clientless SSL VPN. It has a (too short) section on configuring the AnyConnect client. This is the part that I personally found the most useful, which is why I was disappointed that it was so short. Also included are Dynamic Access Policies (DAP), and a couple of deployment scenarios.

The next chapter is on SSL VPN on IOS routers. I have to admit, I only skimmed this chapter, as it just wasn't relevant to my deployment. But from what I could tell, it was just as thorough as the previous chapter, and possibly more so. It also included most of the SDM configuration in CLI form as well, and I have to wonder why the ASA chapter didn't have more CLI in it as well.

Finally, there is a short chapter on SSL VPN management. This chapter basically just shows you some of the monitoring interface in ASDM. Sadly, nothing in the way of CLI, but that's a pretty recurring theme in this book.

In conclusion, I would have to say this book is certainly worth picking up if you're planning on doing an SSL VPN roll out any time soon. The only real issue I had with the book was what I've already mentioned a few times, and that is the lack of CLI. I realize Cisco is really pushing SDM and ASDM, but they need to understand that network engineers are -not- point and click kind of people. Leave that to the MCSEs! ;)

- Chris
Comment | 
Was this review helpful to you?
0 of 5 people found the following review helpful
By Jian Gu
Format:Paperback
Most part of this book talks about how to configure VPN by using GUI interface without mention CLI at all, but seasoned network engineers only use CLI, with CLI you know exactly what you are doing.

This book is worthless to me.
Comment | 
Was this review helpful to you?
Search Customer Reviews
Only search this product's reviews

More About the Author

Discover books, learn about writers, read author blogs, and more.

Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   
Related forums


So You'd Like to...


Create a guide

Look for Similar Items by Category