Professional Documents
Culture Documents
SMBEN v2.04-1
Lesson Overview
Upon completing this lesson, you will be able to apply Main Office with Cisco ASA topologies, including mobile workers. This ability includes being able to meet these objectives:
Articulate relevant Main Office Hybrid model topology of the SNF Architecture Guide Compare integrated and hybrid topologies and capabilities Identify VPN technologies, services, and features
SMBEN v2.04-2
SMBEN v2.04-3
WAN router
Aggregation switch
Access switches
SMBEN v2.04-4
Integrated Model
No
Hybrid Model
Yes
WAN router
WAN router WAN router WAN router WAN router
WAN router
Cisco ASA Cisco ASA Cisco ASA Cisco ASA
SMBEN v2.04-5
VPN Options
Branch Office
DMVPN Easy VPN
2 WAN connections
DMVPN HUB
DMVPN tunnel (split tunnel) DMVPN Tunnel (split tunnel) Easy VPN connection (split tunnel) GE Standby router Active/Standby ASA (in Hybrid model) Easy VPN/SSL VPN Gateway Aggregation switches SSL VPN connection or Easy VPN connection GE Primary router
Teleworker
Easy VPN
DMVPN branch
Single WAN connections
Mobile user
SSL VPN
Easy VPN
SMBEN v2.04-6
VPN (DMVPN) VPN (Easy VPN) VPN (SSL VPN) QoS Voice ready
Video ready
Multicast Firewall Intrusion prevention system Infrastructure security GUI-based configuration
Yes
Yes (source) Yes Yes Yes Yes
Yes
Yes (destination) Yes Yes Yes Yes
Yes
No Yes No Yes Yes
Yes
NA Yes (Firewall on laptop) NA NA NA
SMBEN v2.04-7
SMBEN v2.04-8
Teleworker
SMBEN v2.04-9
WAN link Redundancy Redundancy technology L3 or L2 forwarding Easy VPN client Firewall IPS Upstream traffic shaping (via HQoS) QoS to support voice IP telephony
2008 Cisco Systems, Inc. All rights reserved.
No NA
WAN link Redundancy Redundancy technology L3 or L2 forwarding SSL VPN client (AnyConnect) Firewall No
Functionality support by the VPN client No (user needs to re-establish connection) NA L3 (from laptop) Yes (Clientless SSL VPN possible) Yes (on laptop) No (laptop may have virus protection software) No No (Best effort voice only) Yes (Softphone application on laptop)
SMBEN v2.04-11
IPS
Upstream traffic shaping (via HQoS) QoS to support voice IP telephony
2008 Cisco Systems, Inc. All rights reserved.
Q&A
SMBEN v2.04-12
Lesson Summary
SMBEN v2.04-13
Lesson Summary
The Main Office Hybrid model is similar to the integrated model except for its use of a dedicated firewall appliance (Cisco ASA). A comparison of the Integrated and Hybrid models reveals that the Hybrid model takes advantage of the firewall appliance. Secure Network Foundation (SNF) 2.0 uses multiple VPN technologies suitable for diverse environments. Smart Design offers a choice of two VPN technologies to a mobile worker: Easy VPN or SSL VPN.
SMBEN v2.04-14
SMBEN v2.04-15