Vous voulez voir cette page en français ? Cliquez ici.

Have one to sell? Sell yours here
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Network Security Principles and Practices (CCIE Professional Development) [Hardcover]

Saadat Malik
5.0 out of 5 stars  See all reviews (12 customer reviews)

Available from these sellers.



Book Description

Nov 25 2002 CCIE Professional Development

Expert solutions for securing network infrastructures and VPNs

  • Build security into the network by defining zones, implementing secure routing protocol designs, and building safe LAN switching environments
  • Understand the inner workings of the Cisco PIX Firewall and analyze in-depth Cisco PIX Firewall and Cisco IOS Firewall features and concepts
  • Understand what VPNs are and how they are implemented with protocols such as GRE, L2TP, and IPSec
  • Gain a packet-level understanding of the IPSec suite of protocols, its associated encryption and hashing functions, and authentication techniques
  • Learn how network attacks can be categorized and how the Cisco IDS is designed and can be set upto protect against them
  • Control network access by learning how AAA fits into the Cisco security model and by implementing RADIUS and TACACS+ protocols
  • Provision service provider security using ACLs, NBAR, and CAR to identify and control attacks
  • Identify and resolve common implementation failures by evaluating real-world troubleshooting scenarios

As organizations increase their dependence on networks for core business processes and increase access to remote sites and mobile workers via virtual private networks (VPNs), network security becomes more and more critical. In today's networked era, information is an organization's most valuable resource. Lack of customer, partner, and employee access to e-commerce and data servers can impact both revenue and productivity. Even so, most networks do not have the proper degree of security. Network Security Principles and Practices provides an in-depth understanding of the policies, products, and expertise that brings organization to this extremely complex topic and boosts your confidence in the performance and integrity of your network systems and services. Written by a CCIE engineer who participated in the development of the CCIE Security exams, Network Security Principles and Practices is the first book that provides a comprehensive review of topics important to achieving CCIE Security certification.

Network Security Principles and Practices is a comprehensive guide to network security threats and the policies and tools developed specifically to combat those threats. Taking a practical, applied approach to building security into networks, the book shows you how to build secure network architectures from the ground up. Security aspects of routing protocols, Layer 2 threats, and switch security features are all analyzed. A comprehensive treatment of VPNs and IPSec is presented in extensive packet-by-packet detail. The book takes a behind-the-scenes look at how the Cisco PIX(r) Firewall actually works, presenting many difficult-to-understand and new Cisco PIX Firewall and Cisco IOS® Firewall concepts. The book launches into a discussion of intrusion detection systems (IDS) by analyzing and breaking down modern-day network attacks, describing how an IDS deals with those threats in general, and elaborating on the Cisco implementation of IDS. The book also discusses AAA, RADIUS, and TACACS+ and their usage with some of the newer security implementations such as VPNs and proxy authentication. A complete section devoted to service provider techniques for enhancing customer security and providing support in the event of an attack is also included. Finally, the book concludes with a section dedicated to discussing tried-and-tested troubleshooting tools and techniques that are not only invaluable to candidates working toward their CCIE Security lab exam but also to the security network administrator running the operations of a network on a daily basis.


Customers Who Bought This Item Also Bought


Product Details


Product Description

From the Back Cover

Expert solutions for securing network infrastructures and VPNs

  • Build security into the network by defining zones, implementing secure routing protocol designs, and building safe LAN switching environments
  • Understand the inner workings of the Cisco PIX Firewall and analyze in-depth Cisco PIX Firewall and Cisco IOS Firewall features and concepts
  • Understand what VPNs are and how they are implemented with protocols such as GRE, L2TP, and IPSec
  • Gain a packet-level understanding of the IPSec suite of protocols, its associated encryption and hashing functions, and authentication techniques
  • Learn how network attacks can be categorized and how the Cisco IDS is designed and can be set upto protect against them
  • Control network access by learning how AAA fits into the Cisco security model and by implementing RADIUS and TACACS+ protocols
  • Provision service provider security using ACLs, NBAR, and CAR to identify and control attacks
  • Identify and resolve common implementation failures by evaluating real-world troubleshooting scenarios

As organizations increase their dependence on networks for core business processes and increase access to remote sites and mobile workers via virtual private networks (VPNs), network security becomes more and more critical. In today's networked era, information is an organization's most valuable resource. Lack of customer, partner, and employee access to e-commerce and data servers can impact both revenue and productivity. Even so, most networks do not have the proper degree of security. Network Security Principles and Practices provides an in-depth understanding of the policies, products, and expertise that brings organization to this extremely complex topic and boosts your confidence in the performance and integrity of your network systems and services. Written by a CCIE engineer who participated in the development of the CCIE Security exams, Network Security Principles and Practices is the first book that provides a comprehensive review of topics important to achieving CCIE Security certification.

Network Security Principles and Practices is a comprehensive guide to network security threats and the policies and tools developed specifically to combat those threats. Taking a practical, applied approach to building security into networks, the book shows you how to build secure network architectures from the ground up. Security aspects of routing protocols, Layer 2 threats, and switch security features are all analyzed. A comprehensive treatment of VPNs and IPSec is presented in extensive packet-by-packet detail. The book takes a behind-the-scenes look at how the Cisco PIX(r) Firewall actually works, presenting many difficult-to-understand and new Cisco PIX Firewall and Cisco IOS® Firewall concepts. The book launches into a discussion of intrusion detection systems (IDS) by analyzing and breaking down modern-day network attacks, describing how an IDS deals with those threats in general, and elaborating on the Cisco implementation of IDS. The book also discusses AAA, RADIUS, and TACACS+ and their usage with some of the newer security implementations such as VPNs and proxy authentication. A complete section devoted to service provider techniques for enhancing customer security and providing support in the event of an attack is also included. Finally, the book concludes with a section dedicated to discussing tried-and-tested troubleshooting tools and techniques that are not only invaluable to candidates working toward their CCIE Security lab exam but also to the security network administrator running the operations of a network on a daily basis.

About the Author

Saadat Malik, CCIE No. 4955, manages the Technical Support Operations for the VPN and Network Security groups at Cisco Systems. As a contributor to the CCIE Security exams, he has developed deep knowledge of the issues important to CCIE Security certification. Saadat has taught computer networking at the graduate level at San Jose State University, and he is a regular speaker on various advanced network security topics at industry events and conferences.


Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Reviews

4 star
0
3 star
0
2 star
0
1 star
0
5.0 out of 5 stars
5.0 out of 5 stars
Most helpful customer reviews
Format:Hardcover
This is simply the best book for SecurIE's or security specialist's that I have ever read, the depth to which Mr Malik goes into and its accuracy are astounding.

It reads very well but also makes great reference material, and his explanation of IPsec and IKE has got rid of my 'numb feeling' from reading other books.

I cannot recommend this book enough!

Was this review helpful to you?
5.0 out of 5 stars Essential Network Security Reference Dec 29 2003
By A Customer
Format:Hardcover
I recently had the opportunity to read Network Security Principles and Practices (ISBN 1587050250) from Cisco Press's CCIE Professional Development series.

I am a CCNA currently studying for the CCSP, however I am not interested only in putting more letters on my resume; I want to understand and apply the knowledge on the networks that I work on. I want to know bit-by-bit what happens when two peers negotiate a connection and especially how it can go wrong. Additionally, what tools can I use to detect problems and monitor the health of the network?

I appreciate that Malik respects and expects the reader's understanding of basic networking concepts. I have too many books on the shelf that claim to cover advanced topics, yet they spend hundreds of pages explaining the basics of subnetting or binary to decimal conversion before they dive in to content promised by the title.

I am currently reading another book to prepare for the Securing Cisco IOS Networks exam (SECUR 642-501). While it adequately covers the "whats" and all of the topics required for the exam it does not always fill in the "whys". Network Security Principles and Practices has helped to fill in the gaps.

Since the text is published by Cisco Press and is deigned to support the CCIE Security written exam, it is naturally Cisco-centric. However I would like to see coverage of more non-cisco solutions such as Snort for IDS or possibly typical problems creating VPN tunnels between Cisco equipment non-Cisco equipment.

The organization of content within the chapters is logical and easy to navigate. Chapters are prefaced by an outline of the key topics and wrapped up with a summary and a set of review questions. Malik uses examples and drawings that are easy to understand and most illustrate common real-world scenarios.

The case studies at the end of many chapters were especially valuable to me. For example each of the case studies in the PIX chapter include a description of the case, a drawing of the network topology (including host & network addresses), and most importantly the device configuration annotated with Malik's explanations. There is no need to look up the commands in another reference or to guess what concept in the chapter's text the command addresses.

As one would expect from the manager of the Cisco VPN & Network Security groups, Malik's sections for troubleshooting NAT, PIX Firewalls, IOS Firewalls, VPN's, Intrusion Detection, and AAA are very thorough. Malik explains the IOS show and debug commands used for troubleshooting, as well as their output. Anyone responsible for NAT should make the NAT troubleshooting section mandatory reading for the Order of Operations and Common Problems and Resolutions sections.

Every page of Saadat Malik's tome of Network Security has helped me to better understand security principles and best practices. This book will become a key text in my reference library not just for exam preparation, but for daily network security administration. This text won't collect any dust on my shelf. I rate it five out of five stars and I eagerly await new titles from Malik.

Was this review helpful to you?
By K. CHIU
Format:Hardcover
As an independent computer consultant in the Bay Area, I had read more than 20 titles on Cisco products and technologies (routing, switching, remote access, and troubleshooting) from Cisco Press and other publishers in order to be certified as Cisco Certified Network Professional (CCNP) and Cisco Certified Network Associated (CCNA). After comparing the quality of those books between Cisco Press and other publishers, such as Sybex and The Coriolis Group, I personally think that Cisco Press is still the number one source to learn Cisco products and network technologies.
Before preparing for the Cisco Certified Internetworking Expert(Security) exam, I started to search for books to study. Then, I found this very well organized book written by Saadat Malik, who is also the author of the CCIE Security written and lab exams. This book ¡§Network Security Principles and Practices¡(ISBN: 1587050250) is designed for network engineers or security officers to give them an in-depth understanding and help them widely implement network security in medium size or enterprise networks.
Before reading the book, I thought that it might be just like some of the books from Cisco Press which are similar to the printouts from Cisco Systems website, but this book is extraordinary by the reason of its complete explanations on the latest network security tools. After finishing the book, it should become part of your reference collection if you are serious about learning network security.
In the book, each chapter starts with a comprehensive introduction to show the big picture of each technology, such as Virtual Private Networks, IPsec, PIX Firewall, and Intrusion Detection Systems. After that, Saadat Malik illustrates the technological concepts in great detail by using graphs, examples, configurations and even case studies. You can find information on security concepts you want to learn form math formulas to complex system configurations. The parts I liked the most were the case studies which made the book different from other books since they used scenarios to show readers how to implement the concepts they just learned from the pervious chapter.
Another exceptional feature of the book was the detailed explanation on code examples. While some other books leave readers guessing the meaning of system configurations, this book showed all the settings with highlights and comments. Readers don¡t need to look up the those commands from other books or Cisco¡s website to understand those examples .
This book can help networkers to open the door of network security and candidates to get ready for the CCIE Security exam. Some people even used it for other industrial security examinations, such as CISSP and Security+, since this book was ranked as the best book for preparing networking security exams in Certification preparation websites.
Saadat Malik did a great job of writing this classic network security book. I look forward to seeing his other publications from Cisco Press. I even think about taking his class on this topic at San Jose State University.
I would rate this must-have book as 5/5 stars and I would recommended this book to all network professionals who face security threats as their networks expand and more new technologies, such as 802.1b, are implemented.
Sunny Chiu, Kwok Pang (CCNP & CCNA)
Was this review helpful to you?
Want to see more reviews on this item?
Most recent customer reviews
5.0 out of 5 stars Not just if you want to be a CCIE
I am not one to read a book only to get a certification: I want to understand what's going on under the hood of all the processes operating on the network and systems I'm working... Read more
Published on Dec 12 2003 by A. A. Hines
5.0 out of 5 stars Great Book for All Security Professionals
I have read quite a number of Cisco Press Titles and several books on Computer Security. Saadats's book is in the same class as some of the best I have read. Read more
Published on Nov 22 2003 by Wole Akpose
5.0 out of 5 stars A textbook-style instructional, reference
Written by Saadat Malik (the CCIE engineer who wrote the CCIE Security lab exam and helped instigate the CCIE Security written exam), Network Security Principles And Practices is a... Read more
Published on Nov 13 2003
5.0 out of 5 stars Get a copy!
This is one of the best Cisco Security books available! I would read this book next in your preparation - and I would read it more than once. Read more
Published on Aug 19 2003 by Vitaliy Pindyura
5.0 out of 5 stars This is the best book for the CCIE Security written and Lab
This book is very well written and covers everything you need to pass the Security part of your CCIE security lab. Read more
Published on May 6 2003 by Double CCIE
5.0 out of 5 stars An Excellent Reference!
Many people criticize Cisco Press titles as being bound versions of the documentation that is freely available on their website. Read more
Published on Mar 26 2003 by A BSG Fan
5.0 out of 5 stars 1st Rate
This book is extremely well organized and thought out for these topics. Some of the clearest explanations of IPSec and associated protocols I've seen anywhere. Read more
Published on Jan 23 2003 by W. Newsham
5.0 out of 5 stars Two Thumbs Up
I read a portion of this book and it is definitely 5 stars. Saadat covered too many topics in Cisco securtiy portfolio with great ease. Read more
Published on Jan 12 2003 by Shahid Shafi
5.0 out of 5 stars SUPERB! A must-buy
Yes, this is one of the very best books from Cisco Press.
I haven't checked it for errors yet, but the depth & breadth
of topics covered makes it an apparant... Read more
Published on Dec 4 2002 by Ron C.
Search Customer Reviews
Only search this product's reviews

Listmania!

Create a Listmania! list

Look for similar items by category


Feedback