Cisco SAFE Blueprint - A Security Blueprint for Enterprise Networks
MCSE, CISSP, Security+, Network+, A+ Certification Practice Exams, Study Guides and Vouchers Sign Up | Login   
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE Video + 10 Free Vouchers Practice Exams Exam Vouchers Video Training Get a free MS Cert
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE CCNA  A+ CERTIFICATION NETWORK+ ETHICAL HACKER SECURITY+   CISSP   CCNP MORE...
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
NEWS

Cisco SAFE Blueprint - A Security Blueprint for Enterprise Networks

Email this ArticleEmail this Article  Print this ArticlePrint this Article

• Relates to: CCNA | CCDA | CCNP | CCDP | CCIP | CCSP | CCIE

The SAFE document outlines best practice for securing an enterprise network. Since the release of the SAFE document for enterprise networks, other SAFE documents have been released extending the original SAFE blueprint. New topics include a Security Blueprint for Small, Midsize, and Remote-User Networks, IPSEC VPNs, Wireless network security, and IP Telephony security. Recently, Cisco released the Cisco SAFE Implementation exam in beta (9E1-131), which covers the material in the Security Blueprint for Small, Midsize, and Remote-User Networks (Safe: SMR). In this week's article, I will look at the information covered in the SAFE: SMR.

The SAFE: SMR begins with several caveats. One is that Cisco does not endorse implementing any security technology without having an associated security policy in place. One of the fundamental concepts of the SAFE architecture is that there is a formal security policy before security is implemented. Another caveat introduced in the SAFE: SMR is that no network is totally secure, and that following the SAFE blueprint does not guarantee a secure environment. Once the warnings are out of the way, the SAFE: SMR gets into the meat of document.

Immediately following the caveats, the SAFE: SMR describes the architecture of the SAFE blueprint. The basic design objectives for SAFE are (in order):

* Security and attack mitigation based on policy

* Security implementation through the infrastructure (not just on specialized security devices)

* Cost-effective deployment

* Secure management and reporting

* Authentication and authorization of users and administrators to critical network resources

* Intrusion detection for critical resources and subnets

The SAFE: SMR then discusses the different types of targets and the basic precautions that should be taken to secure the devices.

Following the basic theory behind the blueprint, the SAFE: SMR launches into actual examples of how a secure small or medium network could be configured. The examples take a modular approach, dividing the network into separate segments that can be looked at separately. The diagrams show where to place specialized security devices. The examples are divided into small and medium networks, and provide information for head office/branch office scenarios. Every network component's place in the security architecture is described, as well as expected attacks, and mitigation strategies.

The appendices that follow this information are very helpful. The first contains detailed configuration information for the various devices described in the SAFE: SMR. These configuration examples provide helpful tips for developing your own device configurations. The next appendix is a network security primer. The primer covers the need for network security, different types of network attacks, why a security policy is necessary, and the different network management protocols. The primer conveys only very basic concepts, but is a good starting point for security information.

The document ends with what is call the architecture taxonomy, which is a combination of glossary, index of diagrams, and bibliography.

The Cisco SAFE Implementation exam covers all of the information found in the SAFE: SMR. There are a few additional exam objectives that should be studied outside of the SAFE: SMR. The capabilities and specifications of the different types of hardware in the Cisco security portfolio are also tested. Devices included in this list are the 3000 access concentrator series, PIX firewalls, and the Cisco secure scanner. The exam objectives also reference something called a security wheel. The security wheel is not mentioned in the SAFE: SMR, and documents on Cisco's website reference a four-step and a five-step wheel, making it difficult to study for this objective. It is also necessary to be familiar with the actual commands used to configure these devices, as well as the IOS firewall and IPSEC VPN tunnels. It will be very difficult to pass the exam without some hands-on experience, as the exam does include simulations.

The Cisco SAFE blueprints are a great idea whose time has definitely come. The principals outlined in SAFE could be applied to almost any situation, including non-Cisco equipment. The SAFE documents should be required reading for any network professional.

 Subscribe to our Free Must Know News Newsletter
 Name:     Email:  
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification

KEYWORD
 
What is this?
Microsoft, CompTIA, Cisco Realistic Practice Exams
Microsoft, CompTIA, Cisco Realistic Practice Exams
Microsoft, CompTIA, Cisco Realistic Practice Exams
FREE STUDY GUIDES
FREE RESOURCES
FREE QUESTIONS >>
HOME
CERTIFICATIONS
VIDEO TRAINING
PRACTICE EXAMS
AUDIO TRAINING
EXAM VOUCHERS
FREE IT MAGAZINES
CERT COMPARISON
EXAM COMPARISON
SALARY SURVEY
CAREER TRACKS
ARTICLE DIRECTORY
WHITE PAPERS
QUESTION OF THE DAY
NEWSLETTER
ADVERTISE
Industry Updates &
Special Offers
Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
Picks for November
Untitled Document > Persistent Group Chat: An Approach for More Profitable Team Communications : Unlike email, instant messages (IMs) do not allow group communication; nor do they persist -- you can't hold on to them for as long as you wish. Persistent group chat, however, allows businesses to organize persistent dialogue around business-critical topics, and keep them for easy retrieval later.

> Recent White Papers
> Get a free Microsoft Certification exam

> NetworkWorld - FREE Subscription Center

> Never Open a Book Again! LearnSmart Video Training for A+, CCNA, Network+ and more.

> Pass Guaranteed: Hundreds of practice exam questions and the most authentic exam simulation.

> Lecture Series audio: Learn at home, on your iPod or while driving to work.

> PMP: Learn everything for the Project Management Professional (PMP) certification

> Quiz Me Series Audio: Rapid-fire question and answer session training

Marketplace

Get a free second shot at your Microsoft Certification exam.
For a limited time, you can get an extra chance to pass any Microsoft IT Professional, Developer, or Microsoft Dynamics™ Certification exam – free. Register for this offer before your 1st exam and you’ll get two shots at success. Register now: www.microsoft.com/learning/secondshot

IT Certifications may waive some degree requirements for an online degree. Free catalog!
For several of the IT degrees at WGU, if you hold a relevant IT certification (such as MCSE), you automatically clear a significant portion of the degree requirements. Don't hold an IT certification yet? Don't worry. Not every WGU degree program requires an IT certification in advance. You can earn both at the same time. Lower tuition too!

Earn an online bachelor's degree in Information Technology plus eight IT certifications
Including CompTIA, MySQL Core, and Sun Certified Programmer for the Java Platform. Your prior college and IT certifications may waive some degree requirements; however, you do not have to hold a major certification to enroll.


Earn an affordable, online bachelor's degree in Information Technology—Security Emphasis
plus nine IT certifications including Sun Certified Programmer for the Java Platform, MySQL Core, and Security+. Your prior college and IT certifications may waive some degree requirements

FREE subscription to Network World.
Your complimentary subscription will include 50 weekly issues jam packed with news analysis, expert industry opinion and management/career advice, all of which is packaged with your business needs in mind. We want to help you connect the technology dots and help you advance your company's business goals




Sponsored Link

MCSE, CCNA, CCNP, Security+, Network+, A+ Certification
Free Certification Training Free Certification Training Free Study Guides
   © 1999 - 2008 CramSession. All Rights Reserved. Home   Advertise   Corporate Info   Opportunities   Help