Custom Cisco
ASA and Cisco NAC workshop for UK service Provider
ProNetExpert was asked to provide customised training for the SSL VPN Feature of
the Cisco ASA5500 series Firewall appliance in tandem with the Cisco Clean
Access Solution for NAC (Network Admission Control).
The customer, a major worldwide service provider with in excess of £3.6 billion
revenue, was introducing a new offering for its customers - Managed SSL VPN
service through a wireless partner with the additional level of security
provided by Cisco Clean Access as NAC Solution (Network Admission Control
Clean). The design was built by experienced engineers in close cooperation with
Cisco, and it provided a turnkey solution for the clients of the customer
enterprise. However, the challenge was the operation of this network, especially
due to the fact that both technologies were brand new (SSL VPN and NAC) and the
operations staff had no expertise in this area. Of course it was clear to our
customer that this new solution – which was unique in the marketplace – could
only be a success if it was maintained correctly.
The customer had the choice to send his team (approximately 36 employees from
the operations team – working in shifts) to several different standard courses.
This would have required a significant amount of time and money (SNPA course for
ASA5500 series 5 days, CANAC for Cisco Clean Access 3 days – all for 3
deliverables as not all employees could attend at the same time). On top of that
– due to the nature of the courses (being more general) they didn’t focus on the
specialities of our customers implementation (the combination of the ASA5500
series and the Cisco NAC).
Therefore, ProNetExpert visited the customer site in an effort to gain a greater
understanding of the business concept of the new service offering, the design
and the implementation as well as special requirements and workarounds that have
been identified by the customers design team. Based on this information,
ProNetExpert then produced a custom workshop for 3 days including a specific lab
that reflected the customers real environment. This workshop was held 3 times in
order to meet the customers organizational constraints (not all employees could
attend at the same time due to daily operation commitments).
Our customer expressed great satisfaction with the results, and even though the
students weren’t able to learn about all the features of the Cisco ASA5500
series (like site-to-site VPN, transparent mode or contexts), they knew how the
ASA was used in their network in great detail (and of course the same applied to
the NAC solution). |