This three-day course discusses edge security concepts for the service provider network.
It discusses security for 5G networks on the main GPRS interfaces.
Key topics include deploying an SRX Series device in different parts of the service provider network, implementing CGNAT, DDoS, malware inspection, command-and-control prevention, IPsec tunnels, 5G security, control plane hardening, and BGP hardening.
Students will gain experience in configuring, testing, and troubleshooting the Junos OS through demonstrations and hands-on labs.
This course is based on Junos OS 21.1R1.11.
The Juniper Service Provider Edge Security (JSPES) is an intermediate-level course.
Relevant Juniper Product
โข Junos OS โข SRX Series
โข Define the general security architecture for 4G and 5G networks.
โข Configure data plane security protections.
โข Explain DoS and DDoS attacks.
โข Describe BGP Flowspec in protecting against DDoS attacks.
โข Explain the Corero solution for DDoS attacks.
โข Describe the use of stateful firewalls.
โข Explain the use of ALGs in stateful security firewalls.
โข Explain how to secure BGP on Junos devices.
โข Describe how to use IPsec to secure traffic.
โข Explain the new IoT threat to networks.
โข Describe AutoVPN IPsec architectures.
โข Explain the use and configuration of CGNAT on SRX Series devices.
Day 1
Course Introduction
Security Challenges for Service Providers
โข Describe limitations of security devices
โข Describe DDoS attack threats
โข Describe BGP security threats
โข Explain IP address depletion challenges
โข Describe 5G security challenges
Juniper Networks Solutions for Service Providers
โข Describe Juniper Networksโ security solutions for the service provider challenges
Stateful Firewalls
โข Describe stateless firewall filters
โข Describe stateful firewall policies
โข Describe screens and ALGs
โข Explain asymmetrical routing
Lab 1: Configure Stateful Firewalls
5G Architecture using SRX Series Devices
โข Describe security insertion points
โข Describe 5G network evolution
DDoS Protection
โข Explain DDoS history and common protections
โข Describe SRX DDoS protection
โข Describe BGP FlowSpec
โข Describe Corero with MX DDoS protection
Lab 2: DDoS Protection
Day 2
Carrier-Grade NAT
โข Explain IPv4 address exhaustion
โข Describe Source NAT
โข Describe CGNAT
โข Describe NAT64
Lab 3: CGNAT
Juniper Connected Security for Service Providers
โข Explain Juniper Connected Security
โข Describe SecIntel feeds
โข Describe a use case for IoT protection
Lab 4: Implementing Juniper Connected Security
IPsec Overview
โข Describe the IPsec and IKE protocols
โข Configure site-to-site IPsec VPNs
โข Describe and configure Proxy IDs and Traffic selectors
โข Monitor site-to-site IPsec VPNs
โข Describe IPsec use with gNodeB devices
Lab 5: Site-to-Site IPsec VPN
Scaling IPsec
โข Describe and implement PKI certificates in Junos OS
โข Describe AutoVPN
โข Describe SecGW firewall use case for scaling IPsec
Lab 6: Configuring AutoVPN
Day 3
GPRS and GTP
โข Describe how to secure GTP tunnels
โข Describe the GPRS protocol
โข Describe the GTP
โข Explain how Roaming Firewall secures GTP
SCTP
โข Describe the SCTP
Lab 7: Video about Implementing the Roaming Firewall (Demo)
Securing the Control Plane
โข Explain how to secure the control plane on Junos devices
โข Describe how the loopback filter works to secure the control plane
โข Explain how to protect the control plane from DDoS attacks
โข Describe how to secure the IGP against attacks
Lab 8: Configure Control Plane Protections
Securing the BGP
โข Describe how to secure the BGP
โข Describe BGP security features
โข Describe BGP dampening
Lab 9: Configure BGP protections
โข Intermediate level of TCP/IP networking and security knowledge.
โข Attend the Introduction to Juniper Security (IJSEC) course before attending this class.
This course benefits those responsible for implementing, monitoring, and troubleshooting Juniper security components.
COURSE CONTENT: Day 1 Course Introduction Introduction to IPv6 AddressingโWhatโs New and Improved?ย โข Describe the IPv6 structureย โข Explain the different extension headers and their usesย โข Identify…
COURSE CONTENT: Day 1 Course Introduction Junos Layer 2 Packet Handling and Security Featuresย โขTransparent Mode Securityย โขSecure Wireย โขLayer 2 Next Generation Ethernet Switchingย โขMACsecย LAB 1: Implementing…