CND (312-38) Network Defense Simulation
In this simulation, you will analyze a corporate network perimeter defense strategy. You will learn to identify legacy and modern hardware-based security controls used to facilitate secure remote access and stateful traffic inspection.
1 Network Scenario
You are a Network Security Analyst for a mid-sized enterprise. The infrastructure consists of a DMZ hosting web/mail servers and an internal LAN. Management is reviewing legacy documentation of the perimeter architecture to understand how VPN and firewall functions were traditionally integrated.
Perimeter Assets
- • Exterior Router: Edge Filtering
- • Security Appliance: VPN Termination & SPI
- • Internal Switch: Core Distribution
Defense Objectives
- • Secure IPsec/SSL VPN tunnels
- • Stateful Packet Inspection (SPI)
- • Network Address Translation (NAT)
2 Traffic & Logs
Device: Perimeter_Security_Appliance
● LIVE_FEED
[2023-10-27 14:20:01] %PIX-6-302013: Built outbound TCP connection 40192 for outside:192.168.10.5/443 to inside:10.0.1.50/51022
[2023-10-27 14:20:05] %PIX-4-106023: Deny tcp src outside:203.0.113.15/1024 dst inside:10.0.1.20/23 by access-group "OUTSIDE_IN"
[2023-10-27 14:22:15] %PIX-5-713041: IPsec VPN Tunnel established: Remote Peer 198.51.100.42
[2023-10-27 14:22:16] %PIX-5-713119: Group [Remote_Users] User [jdoe] Session established.
[2023-10-27 14:25:00] %PIX-7-710001: TCP access denied by ACL from 192.168.5.10/445 to 10.0.1.5/445
3 Question
Which of the following is a Cisco product that performs VPN and firewall functions?
Look at the device log prefix in the terminal output; it specifically identifies the hardware model name.