Securing Networks with Cisco Firepower Next Generation Firewall (SSNGFW) v1.0

Duration: 5 Days (40 Hours)

Securing Networks with Cisco Firepower Next Generation Firewall (SSNGFW) v1.0 Course Overview:

What you’ll learn in this course

The Securing Networks with Cisco Firepower Next Generation Firewall (SSNGFW) v1.0 course is a hands-on training program that focuses on deploying and utilizing the Cisco Firepower® Threat Defense system. Participants will gain the knowledge and skills necessary to configure and use Cisco® Firepower Threat Defense technology effectively.

The course covers a wide range of topics, starting from initial device setup and configuration, routing, high availability, and migration from Cisco Adaptive Security Appliance (ASA) to Cisco Firepower Threat Defense. Participants will also learn about traffic control, Network Address Translation (NAT), and the implementation of advanced Next-Generation Firewall (NGFW) and Next-Generation Intrusion Prevention System (NGIPS) features.

These advanced features include network intelligence, file type detection, network-based malware detection, and deep packet inspection. Additionally, participants will gain expertise in configuring site-to-site VPN, remote-access VPN, and SSL decryption. The course also covers detailed analysis, system administration, and troubleshooting techniques.

By the end of the course, participants will have a solid understanding of deploying and utilizing Cisco Firepower Threat Defense, enabling them to enhance network security, perform detailed analysis, and effectively troubleshoot issues.

This course helps you prepare to take the exam, Securing Networks with Cisco Firepower (300-710 SNCF), which leads to CCNP Security and Cisco Certified Specialist – Network Security Firepower certifications. The 300-710 SNCF exam has a second preparation course as well, Securing Networks with Cisco Firepower NextGeneration Intrusion Prevention System (SSFIPS). You can take these courses in any order. This course also earns you 40 Continuing Education (CE) credits towards recertification.

How you’ll benefit
This class will help you:
● Implement Cisco Firepower NGFW to provide advanced threat protection before, during, and after attacks
● Gain leading-edge skills for high-demand responsibilities focused on security
● Earn 40 CE credits toward recertification

Intended Audience

● Security administrators
● Security consultants
● Network administrators
● System engineers
● Technical support personnel
● Cisco integrators and partners

Technology areas
● Security


● Cisco Firepower Threat Defense Overview
◦ Examining Firewall and IPS Technology
◦ Firepower Threat Defense Features and Components
◦ Examining Firepower Platforms
◦ Examining Firepower Threat Defense Licensing
◦ Cisco Firepower Implementation Use Cases
● Cisco Firepower NGFW Device Configuration
◦ Firepower Threat Defense Device Registration
◦ FXOS and Firepower Device Manager
◦ Initial Device Setup
◦ Managing NGFW Devices
◦ Examining Firepower Management Center Policies
◦ Examining Objects
◦ Examining System Configuration and Health Monitoring
◦ Device Management
◦ Examining Firepower High Availability
◦ Configuring High Availability
◦ Cisco ASA to Firepower Migration
◦ Migrating from Cisco ASA to Firepower Threat Defense
● Cisco Firepower NGFW Traffic Control
◦ Firepower Threat Defense Packet Processing
◦ Implementing QoS
◦ Bypassing Traffic
● Cisco Firepower NGFW Address Translation
◦ NAT Basics
◦ Implementing NAT
◦ NAT Rule Examples
◦ Implementing NAT

● Cisco Firepower Discovery
◦ Examining Network Discovery
◦ Configuring Network Discovery

● Implementing Access Control Policies
◦ Examining Access Control Policies
◦ Examining Access Control Policy Rules and Default Action
◦ Implementing Further Inspection
◦ Examining Connection Events
◦ Access Control Policy Advanced Settings
◦ Access Control Policy Considerations
◦ Implementing an Access Control Policy
● Security Intelligence
◦ Examining Security Intelligence
◦ Examining Security Intelligence Objects
◦ Security Intelligence Deployment and Logging
◦ Implementing Security Intelligence
● File Control and Advanced Malware Protection
◦ Examining Malware and File Policy
◦ Examining Advanced Malware Protection
● Next-Generation Intrusion Prevention Systems
◦ Examining Intrusion Prevention and Snort Rules
◦ Examining Variables and Variable Sets
◦ Examining Intrusion Policies
● Site-to-Site VPN
◦ Examining IPsec
◦ Site-to-Site VPN Configuration
◦ Site-to-Site VPN Troubleshooting
◦ Implementing Site-to-Site VPN

● Remote-Access VPN
◦ Examining Remote-Access VPN
◦ Examining Public-Key Cryptography and Certificates
◦ Examining Certificate Enrollment
◦ Remote-Access VPN Configuration
◦ Implementing Remote-Access VPN
● SSL Decryption
◦ Examining SSL Decryption
◦ Configuring SSL Policies
◦ SSL Decryption Best Practices and Monitoring
● Detailed Analysis Techniques
◦ Examining Event Analysis
◦ Examining Event Types
◦ Examining Contextual Data
◦ Examining Analysis Tools
◦ Threat Analysis

● System Administration
◦ Managing Updates
◦ Examining User Account Management Features
◦ Configuring User Accounts
◦ System Administration
● Cisco Firepower Troubleshooting
◦ Examining Common Misconfigurations
◦ Examining Troubleshooting Commands
◦ Firepower Troubleshooting

● Initial Device Setup
● Device Management
● Configuring High Availability
● Migrating from Cisco ASA to Cisco Firepower Threat Defense
● Implementing QoS
● Implementing NAT
● Configuring Network Discovery
● Implementing an Access Control Policy
● Implementing Security Intelligence
● Implementing Site-to-Site VPN
● Implementing Remote Access VPN
● Threat Analysis
● System Administration
● Firepower Troubleshooting

To fully benefit from this course, you should have
● Knowledge of TCP/IP and basic routing protocols
● Familiarity with firewall, VPN, and Intrusion Prevention System (IPS) concepts

Discover the perfect fit for your learning journey

Choose Learning Modality

Live Online

  • Convenience
  • Cost-effective
  • Self-paced learning
  • Scalability


  • Interaction and collaboration
  • Networking opportunities
  • Real-time feedback
  • Personal attention


  • Familiar environment
  • Confidentiality
  • Team building
  • Immediate application

Training Exclusives

This course comes with following benefits:

  • Practice Labs.
  • Get Trained by Certified Trainers.
  • Access to the recordings of your class sessions for 90 days.
  • Digital courseware
  • Experience 24*7 learner support.

Got more questions? We’re all ears and ready to assist!

Request More Details

Please enable JavaScript in your browser to complete this form.

Subscribe to our Newsletter

Please enable JavaScript in your browser to complete this form.