Technical Update African Safari 09 Gabriel Fuster, gbfuster@cisco.com Technical Advocacy April 2009
Agenda CCNA Security Overview CCNP Certification Course Details Equipment Requirements Enrollment, Training and Support Release Dates and Availability CCNP Certification Voucher CCNA Tutorials
CCNA Security
CCNA Security Overview A new course that provides students with in-depth network security education and develop a comprehensive understanding of network security concepts Provides students with knowledge and skills to design and support Network Security Provides an experience-oriented course to prepare for entry-level specialist jobs in network security Prepares students for CCNA Security certification (IINS 640-553 exam). CCNA Security course IS NOT a replacement for the current Network Security 1 and Network Security 2 (NS1 and NS2) Courses 4
Cisco Networking Academy Curricula Portfolio Building Scalable Internetworks Implementing Secured Converged Wide-Area Networks Building Multilayer Switched Networks Optimizing Converged Networks Networking for Home and Small Businesses Working at a Small-to-Medium Business or ISP Introducing Routing and Switching in the Enterprise Designing and Supporting Computer Networks CCNA Security Network Fundamentals Routing Protocols and Concepts LAN Switching and Wireless Accessing the WAN Network Professional IT Essentials: PC Hardware and Software CCNP Security CCNA Discovery CCNA Exploration NOTE: this is a build slide Our current portfolio consists of 13 courses, plus a new course will be added to the portfolio in 2009 IT Essentials: PC Hardware and Software —the IT Essentials curriculum provides an overview of how the internal components of a computer work The course covers laptops and portable devices, assembling/disassembling PC components, wireless connectivity, security, safety and environmental issues associated with installing, configuring and troubleshooting and a PC. CCNA Discovery (4 courses) —the CCNA Discovery curriculum provides an introduction to networking. It teaches networking based on application and helps students develop foundational routing, switching, and WAN knowledge and experience, which can be applied toward entry-level careers in networking for small and medium-sized businesses. CCNA Exploration (4 courses) —the CCNA Exploration curriculum provides an introduction to networking. It teaches networking based on technology. It covers routing, switching, and WAN protocols and theory at deeper levels to help students succeed in networking-related degree programs and a range of professions. CCNA Security - We are developing an entirely new security course that aligns with the new Cisco CCNA Security certification. This new course, named CCNA Security, is being designed to help Networking Academy students develop a comprehensive understanding of network security concepts, gain knowledge and skills needed to earn the CCNA Security certification and become entry-level security specialists. The global, generally available (GA) release of CCNA Security is scheduled for July 2009 CCNP (4 courses) —the CCNP curriculum focuses on the advanced routing, secure wide area access, multilayer switching, and networking management skills required to implement and maintain converged enterprise networks. Packet Tracer — Provides a realistic simulation and visualization learning environment that supplements classroom equipment. Packet Tracer is a foundational teaching tool for CCNA Discovery and CCNA Exploration, and Packet Tracer activities are embedded in the course content. Both curricula include embedded e-doing, which applies the principle that people learn best by interacting with computer-based activities. Interactive learning promotes the exploration of networking concepts and experimentation with tools such as Packet Tracer and Flash-based activities to help students develop a greater understanding of networking technologies. IT Essentials IT Technician Packet Tracer Student Networking Knowledge and Skills
Course Details One semester long (~70-hr) course format Enabled for both ILT and Blended Distance Learning (BDL) Delivered in the same Graphical User Interface (GUI) as the CCNA Discovery and CCNA Exploration curricula One complex hands-on lab per chapter and Packet Tracer activities Provided as separate .zip files downloaded from AC; not packaged within the GUI Available in English only, no translated versions are planned 6
CCNA Security Course Outline Course Chapter Titles Ch. 1 Modern Network Security Threats Goal: Explain network threats, mitigation techniques, and the basics of securing a network. Ch. 2 Securing Network Devices Goal: Securing administrative access on Cisco routers. Ch. 3 Authentication, Authorization and Accounting Goal: Securing administrative access with AAA. Ch. 4 Implementing Firewall Technologies Goal: Implement firewall technologies to secure the network perimeter. Ch. 5 Implementing Intrusion Prevention Goal: Configure IPS to mitigate attacks on the network. Ch. 6 Securing the Local Area Network Goal: Describe LAN security considerations and implement endpoint and Layer 2 security features. Ch. 7 Cryptographic Systems Goal: Describe methods for implementing data confidentiality and integrity. Ch. 8 Implementing Virtual Private Networks Goal: Implement secure virtual private networks. Ch. 9 Managing A Secure Network Goal: Given the security needs of an enterprise, create and implement a comprehensive security policy. 7
Equipment Requirements Goal is to minimize equipment costs Uses CCNA Discovery/Exploration equipment bundle and topology NetLab compatible topology—enabled for remote operation Additional investment required for memory upgrade and Advanced IOS images Description Mfr. Part Number Qty. Modular Router w/2xFE, 2 WAN slots, 32 FL/128 DR Cisco CISCO1841 3 128 to 192MB SODIMM DRAM factory upgrade for the Cisco 1841 MEM1841-64D 2 64MB Cisco 1800 Compact Flash Memory MEM1800-64CF 2-Port Async/Sync Serial WAN Interface Card WIC-2A/S or WIC-2T V.35 Cable, DTE Male to Smart Serial, 10 Feet CAB-SS-V35MT V.35 Cable, DCE Female to Smart Serial, 10 Feet CAB-SS-V35FC Catalyst 2960 24 10/100 + 2 1000BT LAN Base Image WS-C2960-24TT-L (Optional) Rackmount Kit for the 1841 ACS-1841-RM-19 Cisco IOS Release 12.4(20)T1 Advanced IP Services c1841-advipservicesk9-mz.124-20.T1.bin 8
Enrollment, Training & Support Student Enrollment Pre-requisite: CCNA-level knowledge required Instructor Training Guidelines CCNA-level knowledge required Required for new CCNA Security instructors; Fast track possible with evidence of CCNA Security or higher certification or industry experience Recommended for existing NS1, NS2 and CCNP: ISCW instructors Existing NS1, NS2 and CCNP: ISCW instructors allowed to teach CCNA Security course Instructor Training BDL format with 3-day in-person preferred; Can also be delivered 100% remote BDL Best Practices guide developed to provide guidelines on how to deliver course in a BDL environment Training Support Model – similar to CCNP model; Cisco Networking Academy Global Support Desk will provide day-to-day technical support 9
CCNA Security Release Dates and Availability Early January 2009 Draft Scope and Sequence Mid-April 2009 Beta Release of student course: For instructor training and preview purposes End of July 2009 General Availability (GA) Release—student and instructor materials: Released at same time with Packet Tracer v5.2 GA Use for teaching student classes Mar 2009 Virtual SMT for Beta Release End of Jun 2009 Virtual SMT for GA Release Jan Mar Apr Jun Jul 2009
Communications Announcements sent via email to all instructors: New CCNA Security Course announced – Sep 2008 Current NS1 and NS2 courses move to unsupported – Sep 2008 CCNA Security course availability announced – Oct 2008 Preliminary CCNA Security Scope & Sequence available – Jan 2009 FAQs
CCNP 12
Access to the CCNP program in MEA Effective 1/1/2009, the following requirements are mandatory for an academy to become a CCNP academy: 4 years higher educational institution or Accredited Educational Institution. At least teaching CCNA for 2 years OR 1 year with an excellent CCNA track record (student satisfaction, student marks, etc.) Has at least 1 instructor with CCNA-CCAI certification and a commitment to have at least 2 people with CCNA-CCAI within 12 months of entering the CCNP program. Has at least one CCNP bundle or can provide reasonable proof of approved budget for equipment purchase and a commitment to have the placed the purchase order within 6 months of the approval.
Staying in the CCNP program in MEA Effective 1/1/2009, the following requirements are mandatory for an academy to keep its CCNP academy status: CCAI instructors: Instructors should earn their CCNA-CCAI within 12 month of entering the CCNP program, also Instructors should earn their CCNP-CCAI within 24 month of completing their CCNP training. Academic teaching: The academy shall not remain operating in case it did not open any class for a full academic year without valid reason, a full class being defined with a minimum of 10 students. Equipment ratio: Not more than 3-4 students per pod per session. For Instructor training max 2 instructors per pod. Teaching and Technical excellence: Updated Criteria to be released by the Cisco team at a later stage.
Lab Bundle 15
CCNP v5.0 Equipment Requirements CCNP Equipment ISR 2811, 2801 or 1841 with IOS 12.4 with ADVANCED IP SERVICES pack image + required interfaces Routers C3560-24PS-E (PoE), C3560-24TS-E C2960-24TT-L, C2960-24TT-L Switches Wireless LAN controller module for 28/38xx ISR 2000 Series WLAN Controller for up to 8 Lightweight APs LWAPP 1242 AP, Antennas, Wireless NICs Wireless Equipment Cisco 2800 Software feature pack - IP VOICE IOS IP Communicator VoIP Equipment Optional Cisco Works and Cisco Secure Software Subscription Removed ADTRAN is not required 16
Lab Content for the CCNPv5.0 Courses All Labs are developed on the ISR platform The content and labs for CCNP: Building Scaleable Internetworks and CCNP: Building Multilayer Switched Networks are re-developed. New approach used in the lab development process – all labs will have a challenging components to increase complexity Additional challenging labs for each course Majority of the labs can be completed using NetLab 17
Certification Information
CCNA v3.1 End-of-Life Milestones and Dates* (English version) Definition Date End of Offering Last date to create new instructor classes: courses 1–4 January 31, 2008 Course 1 Last date to create new student classes March 31, 2008 End of Support Last date to receive Help Desk support for course maintenance July 31, 2008 End of Availability Last date to access content on Academy Connection Courses 2–4 January 31, 2009 Last date to receive Help Desk support for curriculum maintenance July 31, 2009 Last date to access content and receive curriculum operational support on Academy Connection Certification Exams Certification Exams Retired Last date for students to take INTRO (640-821), ICND (640-811), and CCNA (640-801) exams *Academy Connection announcement, October 2007
CCNA v3.1 and ITE PC Hardware and Software v3 End-of-Life Milestones and Dates (French, Spanish and Arabic version) Milestone Definition Date End of Offering Last date to create new student classes: courses January 31, 2009 End of Support Last date to receive Help Desk support for curriculum maintenance July 31, 2009 End of Availability Last date to access content and receive curriculum operational support on Academy Connection
Changes to CCNA Exams Now certifying ability to install, operate and trouble-shoot a secure, medium-size enterprise network Includes configuration and verification of basic wireless and voice over IP networks Greater emphasis on understanding and mitigating threats to network security Troubleshooting extended to network maintenance Expired Exams Current Exams INTRO 640-821 ICND1 640-822 ICND 640-811 ICND2 640-816 CCNA 640-801 CCNA 640-802 (composite) X 21
Certification Exam Options CCNA Composite Exam (640-802 ) More Complex Networks LANs and VLANs IP Routing Access Lists Simple Networks Connected Networks Cisco IOS Devices Network Management Interconnecting Cisco Networking Devices Part 1 (ICND1- 640-822 ) Simple Networks Connected Networks Cisco IOS Devices Network Management CCENT Certification Interconnecting Cisco Networking Devices Part 2 (ICND2- 640-816) More Complex Networks LANs and VLANs IP Routing Access Lists CCNA Certification 22
Cisco CCNP Certification Certifies knowledge and skills to install, configure, and troubleshoot converged local & wide area networks Includes skills required to manage routers & switches that form network core & integrating voice, wireless, & security into the network Requires four exams: 642-901 BSCI 642-812 BCMSN 642-825 ISCW 642-845 ONT CCIE The new CCENT certification: Certified the knowledge and skills to …. The program is aligned with entry level positions in network support and indicates to employers the candidate’s ability to work with Cisco routers, switches and IOS The Entry Level Certification provides a tangible first step in earning CCNA, the foundation level certification for networking careers Recipients of the certification gain access to resources and benefits of the Cisco Certification Community, as well as use of the entry certification logo CCNP CCNA CCENT www.cisco.com/go/ccent 23
Security Certifications Professional-level Associate-level Cisco Certified Security Professional (CCSP) Certification Revised CCSP Certification CCNA Security Certification CCNA Security Course SND IINS (640-553) Network Security 1 & 2 (NS1/NS2) Courses SNRS SNRS CCNA certification is a pre-requisite for CCNA Security certification SNPA SNAF Key Points: Current NS1/NS2 courses prepared students for 2 of the 5 exams at the professional level certification. The new CCNA Security course will prepare students for the new associate level certification of CCNA Security. As shown, the exam for CCNA Security is fundamentally different then what NS1/NS2 courses prepared for. Background Info: The arrow showing “pre-req” mean that CCNA Security certification is a requirement to achieve CCSP professional certification Exams for CCSP (Cisco Certified Security Professional) certification IINS = Implementing Cisco IOS Network Security – This is the exam that is taken to earn CCNA Security certification SND (Exam 642-522) = Securing Network Devices – This exam was revised and evolved to the IINS exam SNRS (642-503) = Securing Networks with Cisco Routers and Switches – This exam is being revised as 642-504 SNPA (642-523) = Securing Networks with PIX and ASA – This exam is being replaced by 642-524, Securing Networks with ASA Foundation IPS (642-533) = Implementing Cisco Intrusion Prevention Systems – no changes to this exam HIPS (642-513) = Securing Hosts Using Cisco Security Agent – This is 1 of 4 elective exam, being EOL’ed SNAF (642-524) = Security Networks with ASA Foundation CCNA Security certification represents the first certification step for individuals interested in a career in security technologies and serves as a pre-requisite for professional level certifications. CCNA certification is a pre-requisite for CCNA Security certification IPS IPS Elective Exam Elective Exam
Certification Exam Vouchers 25
Certification Mapping CCNA Discovery 1, 2, 3, 4 ** Or CCNA Exploration 1, 2, 3, 4** CCNA Discovery 1 + CCNA Discovery 2 * CCNA Exploration 1 + CCNA Exploration 2 X CCNA CCENT (ICND1 640-822) CCENT (ICND1 640-822) * If student passes CCNA Discovery 2 final from the first attempt with 75% or higher they are eligible for ICND1 voucher ICND1 (640-822) + ICND2 (640-816) CCNA Composite CCNA (640-802) Student is not eligible for an ICND1 voucher ** Student passes CCNA Discovery 4 or Exploration 4 final from the first attempt with 75% or higher they are eligible either the two or one exam offer, but not both
Exam Fee Waiver For Instructors In support of the Cisco® Networking Academy® instructor community, Learning@Cisco, the business unit within Cisco that is responsible for authoring and managing the Cisco portfolio of certification exams, and Pearson VUE,Cisco’s primary vendor for test delivery, have developed an exam fee waiver program for active instructors in the Networking Academy community. This offer will be available to all active Networking Academy instructors from early September 2008 through January 1, 2010. This program was designed to facilitate the certification and recertification process for interested instructors
Exam Fee Waiver All active instructors in the Networking Academy community will be eligible to receive up to one voucher for each of the certification exams that map to the Networking Academy curricula: Cisco CCENT™ Certification Cisco CCNA® Certification Cisco CCNP® Certification You may choose a maximum of six distinct vouchers. You may not choose ICND1, ICND2, and CCNA composite.
Exam Fee Waiver An active instructor is an instructor who has taught a class, with at least 3 students, within the past 12 months. Links to request vouchers for each of the exams will appear on the Academy Connection homepage of active instructors Links to request vouchers will remain active until they are used or until January 1, 2010 Vouchers within this program will cover 100 % of the cost of each exam. Minimum duration of 3 months. Cisco is supporting this program to facilitate the certification and recertification process for interested Networking Academy instructors
How to Obtain your CCNA Voucher
Q and A
Questions Do you know about CCNA tutorial? Are you aware of the Webinar series? Have you joined the Facebook MEA NetAcad instructor group? Is your information on AC current?