F5 Networks BIG-IP ASM V17 / WAF
Seminar / Training F5 Networks BIG-IP ASM V17 / WAF
BIG-IP system setup - BIG-IP system introduction - BIG-IP system initial setup - Archiving the BIG-IP system configuration Traffic handling with BIG-IP - BIG-IP traffic processing objects - Network packet flow - Profiles Local Traffic Policies and ASM Web Application Concepts - Anatomy of a Web Application - Security Methods - HTTP and Web Application Components - HTTP Header HTTP Response - Testing HTML Components - How ASM Parses File Types, URLs and Parameters - Fiddler HTTP Proxy Tools Web Application Vulnerabilities - OWASP Top 10 Vulnerabilities Security Policies - Deployment Wizards - Deployment Wizard: Provisioning local traffic - Provisioning wizard: Workflow - Checking requests - Security checks through rapid deployment - Data guards
Policy Tuning and Violations - Post-Configuration Traffic Processing - Defining False Positives - How Violations are Categorized - Enforcement Settings and Staging: Policy Control - Signature Staging - Defining the Period for Enforcement Readiness - Defining Learning - Violations and Learning Suggestions - Learning Mode: Automatic or manual - Learning, alert and block settings - Blocking response page Attack signatures - Defining attack signatures - Custom attack signatures - Normalizing attack signatures - Attack signature structure - Attack signature sets - Attack signature pools - Updating attack signatures - Attack signatures and staging
Building a positive security policy - Security policy components - Selecting an explicit entity learning scheme - Entity lifecycle - Real threats vs. False positives and other headers - ASM cookies - Allowed and forced cookies - Security processing on HTTP headers Reporting and logging - Reporting capabilities in ASM - DoS reports - ASM security event report - Viewing log files and local setup - Understanding logging profiles User roles and policy change - User roles and partitions - Comparing policies - Editing and exporting security policies - ASM deployment types - ASM synchronization - Diagnostic data collection with asmqkview Advanced parameter management - Defining parameters - Defining static parameters - Dynamic parameters and extractions - Defining parameter levels - Attack signatures and parameters Applicable templates - Application templates Automatic policy creation - Overview - Selecting a policy type - Rules for policy building process - Learning web application vulnerability scanners - ASM with vulnerability scanners - Importing vulnerabilities - Resolving vulnerabilities - Generic XML scanner output Log enforcement and session tracking - Defining login URL - Session awareness and user tracking Brute force and web scraping mitigation - Defining anomalies - Mitigating brute force attacks - Sessionbased brute force protection - Dynamic brute force protection prevention policy - Geolocation enforcement - IP address exceptions Layer 7 DoS mitigation - Denial of service attacks - L7 DoS profile - TPS-based DoSProtection - Mitigation Methods - Stress-Based Detection - Proactive Bot Defense - Bot Signatures ASM and iRules - iRule Events for Application Security - ASM iRule Event Modes - iRule Syntax - ASM iRule Commands
XML and Web Services - Defining XML - Web Services - Configuring an XML Profile - Schema and WSDL Configuration - XML Attack Signatures - Web Services Security Web 2.0 Support: JSON profiles - Asynchronous JavaScript and XML - JavaScript object notation - JSON profile
We conduct this seminar online for you. You can book the training as a public seminar or as a company seminar. The practical exercises are carried out in our Remotelab and make up 40-50 percent of the seminar.
Your contacts
-
Promise Akachukwu Kelechi
E-Mail: promise@computer-training.ng
Phone: +234 1 227 9218 -
Peter Chidiebere Ugochukuw
E-Mail: peter@computer-training.ng
Phone: +234 1 227 9218 -
Raphael Chukuwgozie Ndubuisi
E-Mail: raphael@computer-training.ng
Phone: +234 1 227 9218
We offer seminars with a high practical relevance. The contents and exercises are geared to your daily tasks in the company and completely dispense with advertising references to other products of the software manufacturer.
All our training courses are manufacturer-independent. This enables us to offer critical considerations of the products themselves and comparisons with competitors of the manufacturer in the seminar. The course contents are our own and derived from the practical experience of our trainers in projects.
Of course, the contents of company seminars can be individually adapted to your needs. Please do not hesitate to contact us.
- Implementation guarantee - Implementation guarantee for two or more participants
- Mobile classrooms - the ideal complement for company seminars
- Free support - for questions after the seminar
- Delivery on account - no prepayment required
- Interview with the trainer / quality assurance - get to know and assess the trainer in advance
- Clarify seminar requirements - review your knowledge with the trainer
- Assistance with travel costs - we cover part of the costs of hotel accommodation
- Meals - all day cold / hot drinks and a full lunch in the restaurant
- Location of training centres - always centrally located and easily accessible
- Discount - we have attractive prices, take advantage of our additional discounts
- Remotelabs - rent our Remotelabs for your own seminars or as a complement to your company seminars
Prestations de service
Nous vous proposons des séminaires très pertinents sur le plan pratique. Le contenu et les exercices sont axés sur vos tâches quotidiennes dans l'entreprise et évitent totalement les références publicitaires à d'autres produits du fabricant de logiciels.
Toutes les formations que nous proposons sont indépendantes du fabricant. Cela nous permet d'offrir des observations critiques sur les produits eux-mêmes et des comparaisons avec les concurrents du fabricant dans le séminaire. Le contenu des cours nous est propre et découle de l'expérience pratique de nos formateurs dans le cadre de projets.
Bien entendu, le contenu des séminaires d'entreprise peut être adapté à vos besoins. N'hésitez pas à nous contacter.
Réservation
Das Seminar wurde auf die Merkliste gesetzt
Das von Ihnen gewählte Seminar wurde bereits auf die Merkliste gesetzt
Bitte wählen Sie einen freien Termin aus
Bitte geben Sie Ihren Wunschtermin im Format tt.mm.jjjj ein
Bitte wählen Sie einen freien Termin aus
Bitte geben Sie den gewünschten Termin im Format tt.mm.jjjj der Schulung ein