Preamble
This training course aims to present the advanced features of the Stormshield Network Security product.
This training is accredited SecNumedu – Continuing Education by the French National Cybersecurity Agency (ANSSI).
The Expert certification allows your company to become a Stormshield “Gold” Partner and to be listed as such on the Stormshield website ( https://www.stormshield.eu/partenaires/trouver-un-partenaire/).
In addition, you receive an access code that allows you to contact the Stormshield Level 2 Technical Support Center directly and to open Level 2 support tickets via your partner space or by phone.
Teaching methods
The in-person training is conducted face-to-face in a classroom setting, alternating between theoretical lessons and hands-on exercises.
Participants receive a printed course manual. This material includes the lessons, practical exercises (Labs), and their solutions. To apply the course content, participants have access to a complete technical environment.
To maintain participants’ expertise, all updates to the course material are available in PDF format for three years on the platform https://institute.stormshield.eu.
Participants will also find on this platform a virtual environment that allows them to use the product and redo the Labs independently.
Training objectives
At the end of the training, and after a review of basic knowledge, participants will have acquired the following skills:
- advanced use of the user interface,
- precise configuration of the intrusion prevention engine,
- deployment of a PKI and transparent authentication,
- deployment of an IPsec VPN using certificates,
- configuration of a high-availability cluster.
Instructor
All our CSNE instructors hold the CSNEI (Certified Stormshield Network Expert Instructor) certification issued by the vendor, which attests to their level of expertise.
Duration
This training lasts 3 consecutive days (21 hours of training in total).
Location
This inter-company, in-person training can take place in Lille, Paris, Lyon, Toulouse, or on your premises (please contact us).
Schedule
The training starts at 9:00 a.m. and ends around 5:30 p.m., with a 1.5-hour lunch break from 12:30 p.m. to 2:00 p.m.
Pricing
The public price of this training course is €2,600.
Registration
For registration, please contact the training department ([email protected]).
To ensure proper organization, registration requests must be submitted at least 15 (fifteen) days before the desired training start date.
Registration is confirmed and final upon receipt of the purchase order.
Target audience
IT managers, network administrators, and any IT technician who has obtained the CSNA certification.
Prerequisites and equipment
Participants must have passed the CSNA exam within the three years preceding the CSNE training.
Good knowledge of TCP/IP is required (routing, TCP connection establishment phases, IP packet structure, etc.).
Access to this training is reserved for individuals who have completed the Administrator track (CSNA).
To complete the exercises, participants must bring a laptop computer, preferably running Windows (physical or virtual, with bridged network access), with administrator rights, and equipped with the following software: Firefox, PuTTY (or any other SSH client), WinSCP (or equivalent SCP client), Wireshark, VirtualBox or equivalent VMware software (VMware Player or VMware Workstation).
Certification exam
The certification consists of an online exam (2 hours, 90 questions).
The minimum passing score is 70%.
The exam is automatically made available the day after the end of the training for a period of three weeks on the platform https://institute.stormshield.eu.
In case of failure or inability to take the exam during this period, a second and final attempt is automatically opened immediately afterward for an additional one-week period.
Course outline
Day 1
- Participant introductions
- Detailed presentation of the Stormshield Network intrusion prevention engine
- Differences between intrusion prevention and intrusion detection
- Types of analysis
- Protocol and application profiles
- Public Key Infrastructure
- Basics of symmetric and asymmetric cryptography
- Types of encryption
- Stormshield Network PKI
- Creation of a certification authority, a server identity, and a user identity
Day 2
- SSL proxy
- Operating principles
- SSL proxy configuration
- Advanced IPsec VPN
- Detailed operation and NAT traversal mechanisms
- Dead Peer Detection (DPD) support
- Star VPN architecture and chaining
- NAT in IPsec
- IPsec VPN architecture with backup tunnel
- Configuration of a site-to-site VPN using certificates
- Configuration of a remote-access VPN
Day 3
- GRE and GRETAP
- Operating principles
- Configuration and deployment
- Transparent authentication
- Operating principles
- SPNEGO authentication method
- SSL certificate-based authentication method
- High availability
- Operating principles
- HA cluster creation and configuration wizard
- Network interface configuration Advanced configuration