Overview
Join Keith Barker as he demonstrates each of the steps to create a home Cisco Firepower lab.
Gain an understanding of the Firepower Management Center (FMC), Firepower Threat Defense (FTD), and VMs as clients to test and verify.
Note: Images and software demonstrated are not provided or distributed by CBT Nuggets.
Recommended Experience
- An understanding of concepts taught in CCNA and SCOR
- Three to five years of experience implementing security solutions is recommended, but not required
Related Certifications
- CCNP Security
Related Job Functions
- Network Security Engineer
- Security Analyst
- Security Auditor
- Penetration Tester
- Security Architect
Keith Barker has been a CBT Nuggets trainer since 2012 and has nearly three decades of IT experience. He has received certifications from Cisco, CompTIA, and more. His expertise areas include networking and security.
Intro to Building a Firepower Lab on an ESXi Host
Keith introduces this set of videos.
Lab Game Plan
In this video, Keith shares the big-picture plan for the ESXi-based FirePower lab.
Knowledge Check
For the lab design in this video, which devices are deployed as VMs? (Choose four)
ESXi Host Networking Design
Keith walks through the design for the networking that will be provided by the ESXi host.
Knowledge Check
How many NEW ESXi virtual switches will be created (above and beyond vSwitch0) to support the lab networking?
ESXi Host Networking Configuration
Keith demonstrates the networking configuration on the vSphere standard switches, on the ESXi host.
Knowledge Check
On the newly created ESXi switches, how many uplinks (physical interfaces) are needed?
Vyos Router VM Configuration
In this video, Keith walks you through the Vyos router VM as part of the lab infrastructure.
Knowledge Check
In the lab environment, which services are we planning on using from the Vyos router VM? (Choose two)
Windows Server VM
In this video, Keith demonstrates adding a Windows Server VM to the lab environment.
Knowledge Check
Which network is the Windows Server VM connected to in the lab network?
Deploy the FMC
Keith demonstrates the deployment of an FMC (Firepower Management Center) VM on the ESXi that is hosting the lab.
Knowledge Check
How many network interfaces are involved on the FMC in our lab?
Deploy the FTDs
In this video, Keith demonstrates the deployment of the FTDs in the lab environment.
Knowledge Check
Match the devices from the lab with IP addresses used by those devices.
This interactive assessment is available in the full learning experience.
Add FTDs to the FMC for Mgmt
In this video, Keith demonstrates adding the FTDs to the FMC for centralized management.
Knowledge Check
Which is the correct syntax on an FTD to be managed by an FMC at 192.168.1.10?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro to Building a Firepower Lab on an ESXi Host
0:06Hello and welcome.
0:08My name is Keith Barker.
0:09And in this set of videos, you and I
0:11get to walk through the process of setting up our own home lab
0:14environment for Firepower.
0:16Or if you're doing it in an office,
0:17I guess it would be called an office lab environment.
0:20There are several different ways of getting this done.
0:23We could do it using an ESXi host as the parent hypervisor.
0:27We could use VMware Workstation or a set of VMware Workstations
0:30to support it.
0:31We can also do it in other products, like Eve-NG.
0:34So in this set of videos, I'd like
0:35to walk you through the setting up of this lab environment
0:38using an ESXi host, and also the networking,
0:40and the behind-the-scenes components that
0:42make it all work.
0:43Because it's tough to practice with a technology,
0:47such as Firepower, unless you have
0:49the gear or the virtualized version of the gear
0:52to practice and play with.
0:53So the intent of this set of videos that you and I are going
0:56to do right now is to walk you through setting up
0:58that infrastructure.
0:59So that if you choose to, you can build a lab environment
1:01using all eval software.
1:02So you don't have to buy the software.
1:04You can evals for it.
1:05And then with that infrastructure setup,
1:07you can follow along and do hands-on practice
1:10in your own home lab environment as we proceed
1:12through these sets of videos.
1:13So if you're ready, in the next video, what we'll do
1:15is we'll take a look at our game plan for this lab environment,
1:18and then we'll proceed to implement it step by step.
1:20I'll see you, my friend, in the very next video.
Lab Game Plan
0:06It's important to have a good idea of where we're
0:08going before we just jump in and start configuring
0:11things for our lab environment.
0:12So in this video, you and I get to take a look
0:14at the big picture regarding networks, hypervisor, software
0:16that's involved so we can have a really clear idea of where
0:19we're going as we're building this lab.
0:22So let's use this as our backdrop.
0:24And if we're building a lab for Firepower
0:26and we're going to use a single ESXi host,
0:28some of the software we're going to need
0:30is VMware's ESXi software.
0:34They have a free version for individuals.
0:36You can download it.
0:37It's simply software that gets installed
0:39on a computer as a type 1 hypervisor.
0:41And then inside of that one physical computer with ESXi,
0:45we then create and emulate the entire environment.
0:48So as far as some of the software required,
0:50we'll need ESXi.
0:52And as far as ESXi goes, you can either download a trial or eval
0:56version, or you can register yourself
0:58for a free version of ESXi.
1:00They'll give you a single license for a server
1:02that you can then run forever.
1:03And as far as running that on a computer,
1:06you'd want to make sure that that computer supports
1:08the running of ESXi.
1:09So the current flavor of ESXi, as of this recording, is 7.x
1:13And so whatever hardware you're planning to run this on,
1:16you'd want to make sure that's compatible with 7.x
1:19And we have separate videos here at CBT Nuggets
1:21about the basic deployment of a single ESXi host.
1:24You can check those out if you need details
1:25on installing ESXi on a dedicated
1:28computer for that purpose.
1:29And in the world of ESXi, they refer to these often as a host.
1:32An ESXi host-- that's a computer that's
1:35running the ESXi hypervisor software that's
1:38going to support the whole environment.
1:40And as far as the demos that I'm going
1:41to be setting up here and working with,
1:43I currently have a host here.
1:44It's a blade server.
1:45I got it used.
1:46And it has 128 gigs of RAM.
1:50You don't have to have that much.
1:51You don't have to have 128 gigs.
1:53But the more RAM you have, the more resources
1:56you can give, RAM-wise, to all of these virtual machines.
1:59Also, as far as software goes, we'll also need the FMC.
2:03So the FMC-- it's an acronym.
2:04If you're brand new to it, that's
2:05the acronym for Firepower Management Center.
2:08Think of it as control central, where
2:10we log into the Firepower Management Center,
2:13and then the Firepower Management Center, based
2:15on what we tell it to do there, will then
2:16communicate with the firewalls and actually implement
2:19the commands.
2:20And these firewalls are called FTDs,
2:22which is an acronym for Firepower Threat Defense.
2:25And they are the next-generation firewall and IPS/IDS
2:29solution from Cisco Systems.
2:31So today, for our current implementations,
2:33when we think of Firepower, we're thinking of FTDs--
2:36that's the actual firewalls them self--
2:38and the FMC, which is our Management
2:40Center that allows us to manage all of those firewalls.
2:43And so this software, as well, you
2:45can register and request an eval from Cisco.
2:48And when we deploy the FMC and the FTD,
2:50they automatically give us the option for an eval period
2:54when they're first installed, which is absolutely
2:56perfect for a lab environment.
2:57So the ESXi host software, we can get an eval of that.
3:00We can get evals of FMC and FTD.
3:03Everything over here is going to be running as a VM.
3:05So the FTDs are going to be running as a VM
3:08on the ESXi host.
3:10The Firepower Management Center is going to be running as a VM
3:13on the ESXi host.
3:14And the networking that we see here on the screen
3:16is all going to be provided inside of the ESXi host.
3:19And have no fear.
3:20I'll walk you through each and every step of getting that set
3:22up exactly right, as well.
3:24Another element that might be nice, but not required,
3:26is some version of Windows Server,
3:28which also can be run as a virtual machine in the ESXi
3:32hypervisor.
3:33And Windows Server-- we could use that for things
3:35like Active Directory, if we want
3:37to integrate with Active Directory for user
3:39identification.
3:40Or if we wanted to use an NTP server,
3:42the Windows Server can do that, or it
3:44can do DHCP, or NTP, and other features, as well.
3:49And then also in our environment,
3:50we're going to want to have some VMs that we can pop in
3:53on these sites-- so site 3, and site 4, and the headquarters
3:56site.
3:57And that way, we can test and verify functionality
3:59with traffic that's actually going through, or being
4:02forced through, or sent through the Firepower Threat Defense
4:05appliances.
4:05And those also would be virtual machines
4:08all living inside the ESXi host.
4:10And so these virtual machines could be Linux.
4:12They could be Windows.
4:13Whatever we want to deploy there is great.
4:15And ideally, we want something that we
4:16can use to send traffic through so we can verify our firewalls.
4:20So let me clean that up a little bit
4:21and let's talk about networking.
4:23Regarding networking, at the headquarter location,
4:25we're going to use 10.1.0.0 as the IP addressing space
4:29with a 24-bit mask.
4:30At site 3, we'll use 10.3.0.
4:32And at site 4, we'll use 10.4.0.
4:35Also, for these three FTDs I have on the screen here,
4:38FTD-1 will have the last octet of its IP address
4:41always end in .11 And the benefit
4:43of that is that whenever we see .11, we'll know it's
4:46associated with this FTD, this Firepower Threat Defense
4:48device.
4:49And similarly, FTD-3 will have the last octet of .13,
4:53and FTD-4 have the last octet of .14.
4:56And for the simulated lab internet,
4:59I'm going to use this address space, 23.1.2.0
5:01with a 24-bit mask.
5:03And I'll have the default gateway
5:04for this pseudo-internet here as being .1
5:08So that way, whenever we see the 23.1.2 network,
5:10we'll just say, oh, yeah.
5:11That's the internet, or the pseudo-internet,
5:13inside of our lab environment.
5:15To manage all the FTDs, we are going
5:17to use the FMC, the Firepower Management Center.
5:20And it's a VM, and it's going to have the IP address of .10.
5:23And all of these devices in the lab,
5:26I'd like to, for simplicity, connect them
5:29to a management network.
5:30So the Firepower Management Center on its interface,
5:33the .10, will be connected to the management network, which
5:36is my home office network.
5:37That's the network that I'm currently sitting at.
5:39And the benefit of that is that if our PC is sitting
5:43on this same network, we can then
5:45use our browser to open up sessions with those FTDs
5:49if we need to, or to the Firepower Management Center,
5:51or do other local configuration and management,
5:54because our PC right here is on the 192.168 network.
5:58So in your home network environment,
5:59if your primary address space is 172.16.1 and then
6:04with a 24-bit mask, for example, use that
6:06as your management network.
6:08And that way, it'll be easier to get from your PC
6:11to any of the devices that we're deploying inside the ESXi host,
6:14because logically, the management interface
6:16for all those devices is going to be
6:18on your same common network that your computer is on right now.
6:21So here on the FTD appliances, I have represented an m there
6:24for this management interface connected to the management
6:27network.
6:27And I'll walk you through that as we configure the ESXi hosts
6:30to support all this, as well.
6:31And one other element I'd like to talk about for a moment,
6:34as far as our design, is let's say
6:36we have a client device, a virtual machine, that
6:40is using the Firepower Threat Defense as its default gateway,
6:43using .11 as the default gateway.
6:45And then we're doing NAT, and we're sending traffic
6:47out to the pseudo-internet.
6:48It would also be great, for the benefit of testing and working
6:51with our Firepower, to have real internet connectivity, as well.
6:55So in addition, in the lab environment,
6:56we're also going to introduce another little virtual router
6:59which is running as a VM.
7:00And it'lll have ethernet1 that's connected to the 23 network.
7:04And then it'll have ethernet0, which
7:06is then connected to another network, which then leads off
7:09to the real internet.
7:11And so I hear we can do things like PAT, network address
7:14translation, as well as routing, so
7:17that if we give this router the IP address of .1
7:19on the 23.1.2 network, then FTD-1, FTD-3, FTD-4--
7:23if we tell each one of those devices
7:26that their default gateway is using .1 on the 23.1.2 network,
7:31and we're doing PAT here at this little virtualized router,
7:34then these Firepower Threat Defense
7:36appliances can get access to the live, real internet.
7:39And a PC like this one over here,
7:42as it goes through address translation,
7:44and inspection, and so forth, can actually go out also
7:46to the live internet.
7:48And that gives us a perfect lab environment
7:50to practice with things like URL filtering, reputation
7:54filtering, IDS, IPS functionality,
7:57as well as next-generation application layer inspection.
8:01So that, my friend, is our game plan.
8:03And we'll come back to this topology
8:04and look at it as we reference and build the pieces.
8:07So in the next video, we'll take a look
8:08at those exact pieces for an ESXi host
8:10to support our lab environment.
8:12I'll see you in that next video in just a moment.
8:14Meanwhile, I hope this has been informative for you,
8:17and I'd like to thank you for viewing.
ESXi Host Networking Design
0:07And welcome back.
0:08In this video, you and I get to take a look at the networking
0:11requirements for our lab.
0:12And then what we'll do is we'll proceed in the next video
0:15to actually implement it on the ESXi host.
0:18And so in the lab environment, we're
0:19going to need networking for the 10.1.0 network.
0:22We're going to need networking for the 23.1.2 network.
0:25We're going to need networking for the 10.3
0:27network and the 10.4 network, and also for the management
0:32network of 192.168.1.
0:34So here's what I propose we do, and let
0:36me put these in purple on the--
0:38and I'll just jot up here what we're doing.
0:40So the ESXi-related components, I will place in this color.
0:44So to support the management network on the ESXi host,
0:47we have a switch, which currently is in place.
0:50It comes with-- [LAUGHS] Every time you deploy an ESXi host,
0:53it has something called switch0.
0:55It's a virtual standard Switch
0:57And based on the standard deployment of an ESXi host,
1:00this vSwitch0 has a port group for VMkernel adapters.
1:04That's like the layer 3 IP address on the ESXi host
1:06itself.
1:07It also has a port group associated
1:10with this switch that's called VM Network that we can then
1:13associated with VMs that want to connect out
1:15to the outside world.
1:16So what we'll do is we'll use switch0.
1:19And I took the default port, I just renamed it--
1:21and I'll walk you through this.
1:22I'm just going to rename the port group
1:24on that standard switch to Management 192.
1:27And that way, any virtual machines
1:29that need to pugin to the 192.168.1 management network,
1:34we can just associate with that port group, and boom.
1:36It's there.
1:37So the FMC will have one interface in that port group.
1:41And FTD-1 will have an interface associated
1:43with that port group, and FTD-3 and FTD-4.
1:46And if we deploy a Windows Server,
1:48we can plug it into that port group, as well.
1:50So for the management network, we'll use switch0,
1:53and we'll have a port group named Management 192.
1:57And again, that's on the ESXi host
1:59that's providing this virtualized environment.
2:01Let's go from left to right, then.
2:02So for the 10.1.0 network, I recommend
2:05that we create, on the ESXi host, a whole new switch.
2:08And let's call that switch HQ 10.1 That'll
2:12be the name of the switch.
2:13And we can also create a port group called HQ 10.1
2:18Net, or something similar.
2:19And the way it works in VMware with vSphere
2:21is that you associate a virtual machine
2:23with a port group, which is associated with a switch.
2:26So we'll create a switch called HQ 10.1,
2:28and a port group that's like a very similar name.
2:30And that way, when we connect to it,
2:32we'll know exactly where it goes.
2:33So anytime we have a device, including this Firepower Thread
2:36Defense appliance in this interface,
2:38or a VM that we want to connect to the 10.1 network,
2:41we can just connect it logically in ESXi to this port group,
2:46and it'll be a nice happy place for anybody who
2:48wants be on the 10.1.0 network.
2:50So we have switch0 that we're going to work with.
2:52We're going to create a brand new switch called 10.1
2:54to support this network.
2:56And for site 3, we'll do a similar thing.
2:58Let's create a virtual switch on the ESXi host
3:01and let's call it Site 3 10.3 or something similar.
3:06And then we'll also create a port group with a similar name.
3:09And then any time we need to connect
3:11a device, a virtual machine, to the 10.3 network,
3:14we'll just associate its network interface card--
3:16like this one right here on the Firepower Thread Defense number
3:193 appliance.
3:20We can just associate it with that port group,
3:22and it'll be in 10.3.
3:23If we have a client machine or some other device,
3:25we can do the same thing and just associate them
3:27with that port group.
3:28And boom, that device will then be in network 10.3.
3:31And we'll do the same thing over here for site 4.
3:33We'll create a brand new standard switch
3:35on the ESXi host.
3:36We'll call it something like Site 4 10.4.
3:40And then we'll create a port group with a very similar name.
3:44And then we can connect this interface, when we get to it,
3:46for the FTD-4.
3:48We'll connect that interface to that port group.
3:50And that will allow this interface
3:52to be involved with this 10.4 network,
3:54and any other devices that we have in the place and associate
3:56with that 10.4 network via this port group.
4:00So that's 1, 2, 3, 4 switches-- one that's already there
4:03and three that we're going to create.
4:05Let's also simulate the internet here
4:08by creating another standard switch.
4:11So the switch on the ESXi host, we'll
4:13call it Lab Internet or something similar.
4:16We might add the 23 on there just to remember what it is.
4:19And then once we deploy the Firepower Threat Defense
4:21appliances, we'll take these interfaces, respectively,
4:25associate them with this port group,
4:27and then they will all be on this 23.1.2 network logically.
4:30And there's definitely one more that we want to add,
4:32and that is going to be supporting our router.
4:34So we're going to deploy a little VM as a router in ESXi.
4:38It's going to have two interfaces.
4:39One of those interfaces is going to connect here
4:41to the lab internet.
4:43So we already got the switch for that.
4:44And the other interface, I'm going
4:46to have it connect over to this management network.
4:49And the reason for that is that off of this 192.168.1 network,
4:55I actually have a default gateway of .1, which
4:58leads out to the real internet.
5:00So effectively, this router, going through my real router
5:04in my home office, if it does NAT or PAT on behalf of the lab
5:09traffic, it can allow that traffic
5:10to go out to the internet.
5:12So now that I've said that, we don't actually
5:13have to create any new switches, because we're
5:15going to have this switch already
5:16and we're going to have this switch already.
5:18But we are going to need to plugin that virtual machine,
5:21the router, into both those networks
5:23so it can provide default gateway services off
5:25of the pseudo-internet.
5:27And then one last virtual switch that I'd like to create.
5:30I'd like to create a virtual switch, again,
5:32on the ESXi host.
5:33And I'd like to name it Parking Lot.
5:36And what we can do is we can take any interfaces
5:38on these Firepower Threat Defense
5:39appliances-- which they have a whole bunch of interfaces.
5:42We'll take a look at that in a little bit.
5:43But we can assign the ones that we're not actively
5:46using to this vSwitch Parking Lot with a port group
5:49of the similar name.
5:50And that way, we can associate-- let's
5:52say we have interfaces 5, 6, 7, 8, 9, and so forth
5:56that we're not using.
5:57We can just plug them all into the Parking Lot Port Group.
6:00And that way, unused interfaces aren't accidentally
6:03in our production or our pseudo-production network
6:05environments here.
6:06And later, if things change, if we
6:07want to start using some of those interfaces,
6:09we can reassign them from the Parking Lot,
6:11just as a place to park, over to the actual networks
6:14we want them to belong to.
6:16So that, my friend, is our game plan for the networking portion
6:19that we need to setup on the ESXi host.
6:21And with this plan in place, in our next video, what
6:24we're going to do is jump in the interface for an ESXi
6:27host in my lab environment.
6:28I'm going to use ESXi-2, which happens to be available.
6:31And we're going to configure the networking
6:33to support this on ESxi-2.
6:35So if you are following along and doing this on an ESXi host,
6:38you won't want to miss the next video,
6:40because we're going to implement the networking.
6:41I'll see you there in just a moment.
6:43Meanwhile, I hope this has been informative for you,
6:45and I'd like to thank you for viewing.
ESXi Host Networking Configuration
0:07It is time.
0:08It is time to go to the interface--
0:09the graphical user interface-- on our ESXi host
0:12and modify and/or create the switches
0:16to support our networking that we discussed
0:17in the previous video.
0:19So without further ado, let's log into my ESXi host number 2.
0:23So we're going to log into the ESXi host.
0:25If you need any help in the installation of ESXi itself,
0:28just check out the first two or three
0:29videos of our vSphere courses, and that'll
0:32walk through that process, as well.
0:33So I mentioned earlier, but it's worth mentioning again,
0:36that all of this software--
0:37ESXi, the FTD, the FMC, Windows, everything else--
0:40you can get eval versions from the vendors respectively
0:43for those.
0:43And that can be a great way, and an affordable way,
0:46to do some labbing and testing without having to invest
0:49in the licenses themselves.
0:51So I'm going to login as root to this ESXi host.
0:54And let me make the font a little bit bigger here.
0:58And here's the Recent Tasks down here.
0:59Let me minimize that by clicking this bad boy right here.
1:02And what version am I running?
1:04I'm running 7.0 Update 2 on this ESXi host.
1:08And it doesn't have to be version 7.
1:10You can run 6.0, or 5.5, or 6.7, or 7.x.
1:15So the interface may change slightly,
1:17based on the flavor of ESXi you're using,
1:19but the concepts are going to be the same.
1:21And I'm logged in now to this ESXi host called ESXi-2.
1:25So in the navigation panel over here on the left,
1:27let's click on Networking.
1:28And let's start by looking at what we have.
1:31So let's click on Virtual switches up here.
1:33So I've got networking selected over here,
1:35Virtual switches, and vSwitch0 is
1:38what we get by default when we deploy a brand new ESXi host.
1:41So if we open that up--
1:43and it shows me over here my port groups on the left.
1:45And so there's a default management port
1:47group for a VMkernel adapter.
1:49This is how the ESXi host, with its manageable IP address,
1:53how it communicates out on the real network
1:54to talk to other devices.
1:56So I've got this port group for VMkernel adapters.
1:58And then by default, we're going to have
2:00a port group called VMnetwork.
2:02And what I did was I just clicked
2:03on the little edit pencil here, and I changed it,
2:06calling it Mgmt Network 192, so that when I see it,
2:09I'll know what this port group represents.
2:11And regarding security for this port group,
2:14I went and I specifically specified everything
2:16for accept, because I don't want the hypervisor
2:19in the background with any of its security settings
2:22to cause a problem for anything that we're
2:24implementing in the lab.
2:25So here, I want the hypervisor and the virtualized
2:27switch not to get in the way, but simply
2:29to provide basic networking.
2:31So I'm not going to make any changes there.
2:33So I'll click on Cancel.
2:35And then over here, it's showing us
2:36that these two port groups are logically
2:40connected out to the physical world on vmnic0.
2:43So that's my one physical network card
2:45that is connected to the 192.168.1 network, my home
2:49network that I'm currently sitting at right here.
2:51So this is the port group that we're
2:53going to use if we need to connect anything,
2:55like the Firepower Management Center,
2:57or the management interfaces of our Firepower Threat Defense
3:00Appliances.
3:00Any devices we need to connect to the management network,
3:03we'll simply associate with this port group called Mgmt Network
3:06192, and then they'll have that uplink that puts them
3:09on that same network with everybody
3:10else on that same network.
3:13So that's one switch down and a bunch to go.
3:16So let's go back to Networking.
3:18We'll click on Virtual switches.
3:19And based on our game plan, we need a virtual switch
3:22for headquarters, for site 3, for site 4, for the internet,
3:26and for the parking lot.
3:27So we'll start by going to Virtual switches,
3:29clicking on add standard virtual switch right here.
3:31Let's create the network for the headquarters site.
3:34So we'll call this switch HQ, and we'll call it 10.1.0.0.
3:39And the thing about the switch is we're not
3:41going to give it any uplinks.
3:42So here where it says Uplink, I'm
3:44going to click on the little x here.
3:45And I want a switch with no directly connected uplinks,
3:48because when we're done, we'll be
3:50using the FTD to forward traffic off of the local network
3:53to our pseudo-internet.
3:55And then for security here, also,
3:56in all the new switches I'm going to create,
3:58I'm going to make sure that they Accept--
4:00meaning, not Reject-- the Accept is selected on all these
4:04switches that we're creating so that the switching on the ESXi
4:08hosts and the forwarding there doesn't
4:10get in the way of anything we're doing in the lab itself.
4:13So with that set, we'll click on Add.
4:15So here's what I propose we do.
4:16Let's create all of our switches first, and then we'll go back
4:19and we'll create the port groups,
4:20associate them with those switches
4:22to support the networking.
4:23So our next one, let's do site number 3.
4:26So we'll click on Add virtual switch.
4:28We'll call this site 3 Net 10.3.0.0,
4:33just so that when we see it, we'll know exactly what it is.
4:36I'm not going to give it any physical uplinks.
4:38And for security, I'm going to say Accept, Accept,
4:40Accept, and click on Add.
4:43We have HQ.
4:44We have site 3.
4:45Let's create another switch for site 4.
4:48So we'll name it Site 4 Net 10.4.0.0.
4:55And no Uplink for you.
4:56And Security, wide open.
5:00And add.
5:01So let's take a look.
5:02We've got the management port group,
5:04which is on vSwitch0, which is already done.
5:06We've got the switch for headquarters site 10.1.
5:09We've got Site 3, Site 4.
5:11Let's also create one for our pseudo-internet.
5:14So we'll click on Add virtual switch.
5:16We'll call this Lab internet.
5:20And we'll put a number on it there
5:22so we remember what it is.
5:24No Uplinks, and then Security is wide open, and Add.
5:29And let's also create a switch as a parking
5:31lot for any interfaces that we're not using.
5:33So one more switch.
5:34Add standard virtual switch.
5:37We'll call this Parking Lot Not Used.
5:39No Uplinks.
5:40And for Security-- I guess security on this one
5:42won't matter because we're not expecting traffic to move.
5:45But I'm going to say Accept everywhere here.
5:47Click on Add.
5:48And let's do a quick check.
5:49So vSwitch0 for management, HQ, Site 3, Site 4, Lab Internet,
5:54Parking Lot.
5:55Fantastic.
5:56Next, let's create port groups for those brand new
6:00switches that we just created.
6:01So with Networking on the left selected on the ESXi host,
6:04we'll click on the Port groups tab, and we'll click on Add.
6:08And let's create one for HQ.
6:10We'll call it HQ 10 Net.
6:13I'll just put PG there for Port Group.
6:16And we're going to associate that with the switch called HQ.
6:19And the security, it'll inherit from the parent switch,
6:22which we already opened up.
6:23So we'll click on Add.
6:26Let's create another port group.
6:27So with Port groups still selected,
6:28we'll click on Add port group.
6:29We'll call this Site 3 Net 10.3.0.0 PG-- for Port Group,
6:38just so we can see what it is.
6:39And then we'll associate this with our Site 3 switch.
6:44So think of a port group like a section of ports
6:47that are associated with this switch,
6:48because that's what they are.
6:49And then because there's a section of ports,
6:51we can also describe or setup certain attributes
6:54for that group of ports, such as,
6:56what security do we want to use?
6:58What VLAN do they belong to?
6:59And so forth.
7:01So that looks good.
7:01We'll click on Add.
7:02Well, let's create another port group for site 4.
7:07So we'll call this Site 4 Net 10.4.
7:14And we'll associate this with Site 4 switch, and Add.
7:19And let's see, what else do we need?
7:21Oh the pseudo-internet-- we need some port groups there
7:23so we can connect to that switch.
7:25So we'll click on Add port group.
7:26And we'll call this Lab Internet 23.1.2.0 PG.
7:32And we're going to associate that with the Lab Internet
7:34switch right there, and Add.
7:37And let's also create a port group for the Parking Lot.
7:41Add port group.
7:43We'll call it Not Used Parking Lot PG.
7:46And then we'll associate it with our Parking Lot switch,
7:50and click on Add.
7:51And I think we've got all the networking in place.
7:53Let's just do a quick check.
7:54So we've got a switch and a port group supporting our management
7:57network, which is vSwitch0 and the Mgmt Port Group there.
8:01We've got a switch and port group
8:03for the 10.1 network, A switch and a port group
8:05for site 3, a switch and a port group for site 4.
8:08We've got a switch and a port group for the lab internet.
8:12And we also have one for the parking lot.
8:14That's it.
8:14We've done it.
8:15So now we've done a huge chunk towards our infrastructure
8:18on the ESXi host portion to support our lab environment.
8:21One other thing I'd like to do-- and let's do it the next
8:23video--
8:24is I'd like to inject into this topology,
8:26as part of the infrastructure, another router that's
8:29going to be able to route between the pseudo-lab
8:32internet, and the production internet.
8:34So we'll do all that, including the design
8:35and where that fits in, in the next video.
8:37So I'll see you there in just a moment.
8:39Meanwhile, I hope this has been informative for you,
8:42and I'd like to thank you for viewing.
Vyos Router VM Configuration
0:06Setting up a lab environment can be a little bit
0:08of work on the frontend.
0:09But it's so worth it, because once it's
0:11installed and working, we can practice
0:13with it and the technology, and bring stuff up and tear stuff
0:16down.
0:16We're not messing with the production environment.
0:18It's a lot of fun and a lot of good practice.
0:21One of the aspects that I absolutely
0:22love about a lab environment is that whenever we can,
0:25if we can connect it or integrate it
0:27with the live internet, oh, my gosh.
0:29It's so good.
0:30So in this video, we get to do exactly that.
0:31I'd like to walk you through the step-by-step process
0:34for deploying a tiny little VM as a router
0:37to support that integration between our lab environment
0:40and the real internet.
0:41And here's our game plan to pull that off.
0:43We already have some virtualized switches and port groups
0:46to support the lab internet, which
0:48is the 23.1 network address space, and also
0:51the 192.161 network.
0:53And on my 192.161 network-- let me change the color here--
0:56I've got a default gateway of .1 that
0:59leads off to the real internet.
1:01So this device is doing PAT.
1:03And there's probably one or two other devices
1:05in the line that are doing NAT PAT.
1:06But eventually, it gets to the internet,
1:08based on the 192.168.1 network and the default gateway at .1.
1:13So if we want to have our pseudo-lab internet connect
1:16to the real lab internet, here's what I propose we do.
1:19Let's add another virtual appliance-- a VM, really--
1:22running VyOS, V-Y-O-S. And I'm going to be using version
1:251.2.1.
1:26It's free.
1:27It doesn't cost a dime.
1:28And we're going to do that by logically connecting it
1:30to ethernet0 interface to the port group associated
1:33with the 23.1.2 network.
1:35So it's going to have a leg or a Ethernet connection.
1:38And we'll give it the IP address of .1.
1:39So anybody who's on this pseudo-internet,
1:42if they use 23.1.2.1, they're going
1:44to be pointing to this router interface.
1:46And then this router can have connectivity
1:48over to our management network.
1:50So this would be ethernet1.
1:52And over here, we could just use an IP address that's available.
1:56In my lab environment, I have .80.
1:58But you can also configure this interface
1:59to be a DHCP client if you wanted to.
2:01And then we configure routing.
2:03If we're doing it statically, we'd
2:05configure this router to use .1 as a default gateway.
2:08And then we can also setup network address translation.
2:11Or more likely, we'll go ahead and do PAT--
2:13Port Address Translation.
2:14So the traffic source from the 23.1.2 network,
2:18if it's using .1 as the next hop,
2:20this router can not only forward to the live internet,
2:22but it also can provide port address translation
2:25to swap out this address with the address it's
2:28using on this interface, which has then connectivity
2:30through a few more PAT devices out to the real internet.
2:33But long story short is that this one little VM
2:36can be the link between our lab internet and the live internet.
2:40And so what I'd like to do is walk you
2:41through deploying this virtual machine on the ESXi host.
2:45And I'm going to be using VyOS 1.2.1.
2:48And you can download this little VyOS virtual appliance
2:50from the VMware Marketplace.
2:52It's available other places online, as well.
2:54It's open source.
2:55It's free.
2:56And it's super easy to configure.
2:59So what we get to do right now is
3:00I'm going to walk you through the steps
3:02for both deploying and configuring
3:03this beautiful little VyOS router.
3:05So here, back at our ESXi host, using the GUI to manage it,
3:09I'm going to go to Host, right click,
3:11and we're going to Create/Register a Virtual
3:14Machine.
3:15So we'll click there.
3:16And it's asking me, do you want to create new virtual machine
3:18the hard way, or you do want to deploy it from an OVF
3:21or on OVA file format?
3:24From the VMware Marketplace, I downloaded the VyOS appliance,
3:28which is the VyOS router.
3:30So if you have an ISO port, you could do a new virtual machine
3:32and deploy it that way.
3:33But because it's already packaged for me
3:35and ready to go, I'm just going to select this option,
3:37and click on Next.
3:39Then it's asking us, what we want to name it?
3:41I'm going to call this Vyos Router.
3:44That way, when I see it in the inventory here in my ESXi host,
3:46I'll remember what it is.
3:48And then I'm going to click here to select the files for it.
3:51So prior to this demonstration, I
3:52googled, found, and downloaded the VyOS appliance.
3:56And here it is-- vyos-1.2.1.ova, which is a format that VMware,
4:02both VMware Workstation and vSphere,
4:04recognize for deployment of a VM.
4:06So with it selected here, I'm going to click on Open.
4:09And then click on Next to continue.
4:11It's asking me what datastore on this ESXi host
4:14do we want to use.
4:15And on the ESXi host, it has a datastore that's
4:19on top of a non-flash drive.
4:21And then I've got one that's SSD, which is faster.
4:24So I'm going to put everything on the ESXi host--
4:26as far as virtual machines, I'm going to put it all on the SSD.
4:29So I'm going to select that datastore on the ESXi host
4:32as a storage location for the files supporting this VM,
4:35and click on Next.
4:37It's asking me here about the network mappings.
4:39Effectively, it's saying, OK, I've
4:40got two interfaces, LAN and WAN.
4:42And where do you want to connect those?
4:43So the way I have it setup, the LAN interface
4:45is going to go to the 23 network.
4:47That's going to end up being ethernet0.
4:49So I want to grab the port group associated
4:52with our pseudo-internet, which is right here, Lab Internet 23.
4:55And the WAN connection which leads up to the real internet
4:58is our management network.
5:00So I want to choose the port group that supports that,
5:02which is Mgmt Network 192.
5:05So LAN is going to be the ethernet0 adapter.
5:08WAN is going to be our ethernet1 adapter
5:11on the virtual appliance.
5:12It's next asking what kind of resources
5:14do we want to throw at this.
5:15In a lab environment, we don't need a ton of CPU
5:18and we don't need a ton of RAM.
5:19So we'll select Small, which is going to give it 1 virtual CPU
5:22and 512 megabytes of RAM.
5:24We're going to do the Thin provisioning.
5:25And what that means, if it allocates like 5 gigs of space
5:29or 1 gig of space for a virtual disk drive,
5:32it won't actually use the full amount
5:33unless it's really using it.
5:35So we could allocate it like a 10-gig drive.
5:37If it's thin provisioned and we're only using 500 megabytes,
5:40it's only going to really tie up 500 megabytes on the datastore.
5:44So we'll choose thin.
5:45And then it says, do you want to this on automatically?
5:48And I'm going to say no to that, because I
5:50want to check my work.
5:51And we'll click on Next.
5:53Because it's an OVA and it's all been packaged,
5:55that gave us the opportunity to put in information such as what
5:57password do we want to use.
5:59I'm going to use my lab password here.
6:01And that way, when we log into this little virtual router,
6:03we're going to login with the username of vyos--
6:05V-Y-O-S-- and then whatever password we specified here.
6:09And then for its IP addresses, it's asking me about-- oh,
6:12it's just one IP address.
6:13So this is going to be the IP address on the LAN interface.
6:16In our case, that's the 23 network.
6:18So I'm going to give it 23.1.2.1,
6:22and the mask is going to be a 24-bit mask.
6:25That's how we spell 24 bits in dotted decimal.
6:28It's not going to have a Default Gateway for this interface.
6:32So what I'll do is I'm going to hold off on the Default Gateway
6:35until I configure the 192.168 address.
6:38And for DNS servers, I'm going to give it 8.8.8.8.
6:43Also, you know what?
6:44Let's give it a default gateway of 192.168.1.1.
6:48And until we configure the other interface, ethernet1,
6:51with an IP address, it really won't
6:53be able to use that default gateway,
6:55because it can't reach it with only one interface.
6:58So we'll just play it by ear and see how that comes up,
7:01and I'll walk you through any problems if they arise.
7:03So with that in place, we'll click on Next.
7:05We'll confirm our settings.
7:06That looks good.
7:07And we'll click on Finish.
7:08So if we bring up the task by clicking on Recent tasks
7:11down here, it's now showing us the deployment
7:14of that virtual machine, which is our little VyOS router.
7:17It says it's done deploying.
7:19And so if we click up here on Virtual Machines,
7:22and there's our VyOS router.
7:23If we click on it, the first interface
7:25is connected to the port group for the pseudo-internet,
7:28and the second adapter, which is ethernet1,
7:30is connected to our management network.
7:33So that looks good to me.
7:35Let's power it on.
7:36So with this selected, we can just click on Power on here,
7:39or Power on here, or right click and Power on here.
7:42There's a whole bunch of options to power that bad boy up.
7:44He is up and running, or will be here in a moment.
7:47And I'm going to open up a console to him.
7:49So based on the flavor of ESXi you're
7:51using, if you just click here, you
7:53can open up a console there.
7:55Or if you have the VMware Remote Console installed
7:58on your computer, you could right click and hover
8:01over Console.
8:02And from here, you could just click on Launch remote console.
8:05Either way, you want a console to this device
8:07so we can look at it, configure it, and work with it.
8:10So here is that console that it just brought up.
8:13And it wants me to log in, so I will as vyos and the password I
8:18specified during the setup.
8:22Then we'll do a show configuration.
8:25There we go.
8:26And there's also context-sensitive help, too.
8:28So if you don't know exactly what to type in,
8:29do a question mark.
8:30So we'll do show configuration.
8:32So this shows us that ethernet0 has the address of 23.1.2.1
8:37with a 24-bit mask.
8:38ethernet1 has no IP address at the moment.
8:41We'll configure that.
8:42It's got a default route with a next hop of 192.168.1.1.
8:45That's great.
8:46Once we do configure ethernet1 with the 192.168.1 address,
8:50it'll be able to reach that next hop for the default gateway
8:52and actually work.
8:53And we'll press Enter to go down one line at a time.
8:56There's the name-server using a Google DNS server.
9:00So to configure this VyOS router, one of the best things
9:03to do would be to find a quick start guide.
9:05So I'm just going to type VyOS--
9:08I did this about 10 minutes ago--
9:09VyOS quick start.
9:10And I'm going to just use this option right here, which
9:13is going to walk us through the basic configuration for VyOS.
9:16So right here, it says, type in configure
9:19to go into configuration.
9:21Once you make changes, type in commit to commit those.
9:24And then if you want to save those
9:25so it reboots with those settings, click on Save.
9:27All right, awesome.
9:29So I'm going to scroll down to where
9:30it says how to set an IP address, right here.
9:34So if we type in configure-- and I just typed in conf for short,
9:37and it accepted that.
9:39The prompt changes to a pound symbol
9:40to tell us that we're in configuration mode,
9:43if you will.
9:43On a Cisco router, that's what we would call it.
9:45And then from here, we can do a set interfaces and ethernet.
9:50And we want to configure ethernet1.
9:53And that's the interface facing our 192.168.1.1 network.
9:57And we want to configure an address.
9:59And the address we want to use is 192.168.1.80.
10:04That address, the .80, I'm not using on my home network,
10:07so it's safe.
10:07And I'll just make sure I'm not using the same address on two
10:10different devices.
10:11And we'll give it a 24-bit mask.
10:14That looks good.
10:14And then the other thing we're going to need eventually,
10:17too, is we're going to need port address translation or NAT.
10:20And so in the startup guide, If we go to the startup guide
10:22and just scroll down a little bit,
10:24here it has information on setting up NAT.
10:27So this is the router.
10:28This is ethernet0 that's on the 23 network.
10:31And we're in the process of configuring ethernet1.
10:33Once we do a commit, it'll be real.
10:36And ethernet1 is going to our 192.168.1 network.
10:40And it's using .80, based on this command right here.
10:43And what we want to do is set up NAT, so anybody who
10:45sends a packet this way, if their source address is coming
10:48from the 23.1.2 network, we want to do PAT.
10:53Effectively, you want to translate
10:54it using whatever IP address is on this interface
10:56and then forward it along its way.
10:58So to pull that off, the commands are right over here
11:00on the right.
11:00So let me leave the drawings up there and let's
11:02set nat source rule.
11:07And I'm going to use 100.
11:08And the outbound interface is going
11:09to be eth1, based on our diagram right there.
11:13And as far as who can be translated,
11:14set nat source rule 100 source address.
11:21Anybody coming from the 23.1.2 network with a 24-bit mask--
11:26if that's your source address, I am willing to translate you.
11:28That's what this rule says.
11:30And then third, we need to specify
11:32what we're going to translate that address into.
11:35And if we want to overload on that .80 address,
11:38we're going to use the command set nat source rule
11:41100 translation address masquerade, like that.
11:48And that basically means we're doing PAT against that .80
11:51address on that e1 interface.
11:54So to make this real, to put it in action,
11:56we'll type in commit.
11:57And good, no errors.
11:58Then if we want to make sure this comes up
12:00this way next time we reboot this VM, we'll type in save.
12:03Perfect.
12:05And then we'll type in exit.
12:06If everything's working, we should
12:08be able to ping our default gateway, 192.168.1.1.
12:13Then we'll do a Control-C. Because we
12:15have an interface, e1, and because our routing
12:18is in place with the default route,
12:20we should be able to ping an internet address, like 8.8.8.8.
12:24That works.
12:25And also, because we specified a name server
12:27in our installation of this VM, we
12:29should also be able to do name resolution.
12:31So if we typed in ping www.cisco.com--
12:35yeah, sure enough.
12:38I'm always surprised when it works the first time.
12:40So that just shows us that DNS is working,
12:42and name resolution and internet connectivity is there.
12:44And this is going to be part of our infrastructure as part
12:47of our lab.
12:48And here's how it fits in.
12:49If we have a Firepower Threat Defense appliance,
12:52and we have a client back here who's
12:53using the Firepower Threat Defense as the default gateway
12:56to get traffic out to the internet,
12:57this FTD can do its magic of inspection and filtering,
13:01and things like NAT and PAT.
13:04So from the FTD's perspective and the client's perspective
13:07here, they're just sending traffic from
13:09and RFC 1918 address space, who's then, by the FTDs,
13:12doing translation once we have policies applied.
13:15Does the translation, forwards it,
13:16and if the traffic is going to the internet,
13:18the next hop will be .1 on this router, who can then
13:22do port address translation itself
13:25and forward the packet onto the real internet.
13:27So this router has now become part
13:29of our infrastructure for our home-based lab,
13:32all sitting within one beautiful system called an ESXi host.
13:37So let's do a quick inventory check.
13:39We did the networking on the ESXi host
13:40in the previous two videos.
13:42We now implemented the VyOS router
13:44as a part of our integration for our home lab
13:47to connect to the internet.
13:48And in the next video, I'd like to take a look
13:50at another resource that we very well may
13:52want as part of our infrastructure
13:54for a home-based lab.
13:55And we'll take a look at that in more detail in the next video.
13:58I'll see you there in just a moment.
14:00Meanwhile, I hope this has been informative for you,
14:03and I'd like to thank you for viewing.
Windows Server VM
0:06As part of our infrastructure for the lab,
0:08it's often handy to have a server that
0:10can do things like NTP--
0:11Network Time Protocol-- or Active Directory
0:14integration, or DNS.
0:16So guess what kind of a server that's going to be?
0:18Well, in the lab, I'd like to walk you through setting up
0:21a virtualized Windows Server-- again,
0:23you can use an eval copy, no worries there--
0:25as part of our lab infrastructure.
0:28And that way, if we're doing labs
0:29and you think, oh, I want to practice with something
0:31like Active Directory integration,
0:33you have a server sitting there in your lab environment
0:36that you can use to actually practice that and verify
0:38that it works.
0:39So in this video, I'd like to walk you
0:40through the integration of a Windows Server
0:42into our lab environment.
0:44And let's talk about where we're going to put this.
0:46We're going to create a new virtual machine, the Windows
0:48Server.
0:49And logically, we're going to place its network interface
0:51card into a port group associated with our management
0:55network.
0:56And then for this VM server, which
0:58is going to give be on 192.168.1,
1:00I'm going to give it the IP address of .100,
1:02because two reasons.
1:04One is it's easy to remember that address if we
1:06need to point to that server.
1:07And secondly, it's also not used currently on my home network
1:11of 192.168.1.
1:13So let's take a look at how to deploy a Windows
1:16Server as a VM on the ESXi host and then connect it
1:19to this network.
1:21So back here at the ESXi host, let's right click on Host.
1:25And from the dropdown, we'll select Create/Register VM.
1:29If you have an OVF or an OVA for a Windows Server, fantastic.
1:32Use it.
1:32It'll be much easier to deploy.
1:34I currently just downloaded an ISO for an evaluation
1:37version of Windows Server, and so that's
1:39what I'm going to use.
1:40I'm going to choose the slightly longer process
1:42by clicking on Create a new virtual machine,
1:44clicking on Next.
1:45I'm going to name this Win Lab Server.
1:48And I'm going to use the latest version
1:50of the virtualized hardware in the EXSi.
1:54And I"m going to specify this is for Windows.
1:56And I'm going to specify that the Windows version is Windows
1:59Server 2019, just like that.
2:02So this part right here does not cause Windows Server 2019
2:05to be installed.
2:06But instead, it's just giving VMware
2:07an idea of what type of guest operating system
2:10is going to be running in the VM.
2:12So that way, VMware, when we deploy this VM,
2:14it can make some guesstimates regarding how much RAM and CPU
2:17it should give it.
2:18And we can tweak those, as well.
2:19So we'll click on Next to continue.
2:22It's asking me, where do I want to store this VM's files?
2:24I'm going to use the datastore called ESXi-2-SSD-1.
2:28Click on Next.
2:29It's now giving me the recommendations.
2:31So because I've got plenty of CPU and RAM,
2:33I'm going to give it more than what it's asking for.
2:36So VMware's going to do a great job
2:37of managing all the resources.
2:38And one change I am going to make, also,
2:40is I'm going to go to under Hard disk.
2:42And so what I'm going to do here is by specifying
2:44Thin provisioning, I'm asking ESXi,
2:46please, even though we're provisioning 90 gigs of disk
2:49space for this virtual machine, don't tie all that space up
2:52unless it's actually needed.
2:54So if the VM is only using like 10 or 20 gigs of disk storage,
2:58it's only going to tie up that much physical disk
3:00storage on the ESXi host.
3:02So in a lab environment, whenever possible,
3:04which is almost always with ESXi, choose thin provisioning.
3:09And that way, you can conserve the physical disk space
3:11on the ESXi host.
3:13So with that done, we'll scroll down just a little bit.
3:16And for the Network Adapter right
3:18here, I want to plug that into our management 192.
3:20And that way, it's going to be connected to the right network.
3:23And for the Drive, I want to tell this virtual machine when
3:27it boots up, I want it to boot up to an ISO file
3:30that I currently have on the ESXi host.
3:32So previously, I did some browsing on the datastore
3:34on this ESXi host.
3:36I created a folder.
3:37I called that folder Images and Files.
3:39And in that folder, I uploaded a couple files.
3:42I upload an ISO for a version of Linux.
3:45I also uploaded a Windows Server ISO image.
3:48So I'm going to select it there from the datastore.
3:50Click on Select.
3:51And I'm going to expand that and make sure
3:53that the check is there for Connect,
3:54and also Connect at power on.
3:56So that way when it boots up, I can hit key and boot off
3:58of that CD to start the install of Windows Server.
4:02So that looks good.
4:03We'll click on next.
4:04Here's a summary.
4:06That looks good to me.
4:07Click on Finish.
4:09And then if we click on VMs, we have our Windows Lab Server
4:12right there.
4:12So I'm going to click on that.
4:13And I'm going to right click here and hover over Console,
4:18and say I want to Launch a remote console.
4:19And you might say, Keith, it's not even running yet.
4:22How come you're bringing up a remote console?
4:24And the answer is I want to be able to press Space bar when
4:27this thing first boots up so I can boot to the CD-ROM
4:30that it believes it has connected to it.
4:32So right here in the remote console, I'll click on Go,
4:37and then put my mouse in there and hit Space.
4:40There we go.
4:40And what I just did is told it to boot.
4:43Oh, I missed it.
4:44I forgot to click inside.
4:46All right, I'm going to cancel that.
4:47Power it off.
4:49Yes, nothing's installed yet.
4:51And let's do that one more time.
4:53Let me do that one more time.
4:54I'm going to bring up a console again.
4:57So here's the remote console.
4:58I'll start it up.
5:00I'm going to click in the space this time and hit Space.
5:03There we go.
5:04Now it's loading from the ISO.
5:05We can also tweak those settings to give us a few more minutes
5:08to choose to boot from CD.
5:10But now that it's installing, we'll
5:11just follow the install process for Windows.
5:13I'll click Next a few times.
5:15Click on Install now.
5:17I'll select I want a Desktop Experience,
5:20because we want a graphical user interface to play with.
5:22So I'm going to choose the Windows Server 2019 Evaluation
5:26(Desktop Experience).
5:27Click on Next, and accept.
5:29Next.
5:31Custom Install.
5:33Choose the drive.
5:34This is the 90-gig drive from this VM's perspective.
5:36Click on Next, and it's off to the races.
5:40So I'm going to let that finish.
5:42Once it's done, I'll configure its only interface
5:44that we gave it to have the IP address of 192.168.1.100
5:48with the default gateway of .1.
5:49And then this guy is connected directly on the management
5:52network and we can use it then.
5:54So if we want to install Active Directory, or Certificate
5:56Services, or anything else on this Windows Server,
5:59those services can then be leveraged by our Firepower
6:03environment.
6:04So we'll let this install continue in the background.
6:06And in the next video, as we put the components together
6:08for our lab environment, I'd like
6:09to walk you through the initial placement
6:11and deployment of the Firepower Management Center device
6:14as a VM in EXSi.
6:16We'll do that in the next video.
6:18See you there in just a moment.
6:20Meanwhile, I hope this has been informative for you,
6:22and I'd like to thank you for viewing.
Deploy the FMC
0:00[MUSIC PLAYING]
0:06And welcome back.
0:08In this video, we're going to deploy
0:09in our lab environment, the FMC, the Firepower Management
0:12Center.
0:13Think of it like the single place
0:15to go if we need to manage our entire Firepower
0:18environment, through the Firepower Management Center,
0:20the FMC.
0:21This is going to be run as a VM.
0:23And although in this video we're not
0:25going to walk through all the details for how
0:27to configure policies and push them out and so forth,
0:29we'll save that for the other sets of videos.
0:31In this video, I'd like to walk you to the deployment,
0:34up to the point where we have a functional working Firepower
0:37Management Center that we can then
0:39use in our lab environment.
0:41So let's take a look at where this Firepower Management
0:43Center is going to sit in our lab topology,
0:46and then we'll deploy it together.
0:47So for our Firepower Management Center,
0:49we're going to deploy it as a VM on the ESXi host,
0:52and so we're going to deploy it from a template.
0:54And I'll show you that here in a moment.
0:56And we are going to associate it single interface
0:59with the management network.
1:01So when it ask us for this VM, where
1:03do you want to plug this into, for Networking,
1:05we're going to choose the port group associated
1:07with the 192.168.1 management network.
1:10So let's go to our ESXi hosts and deploy this VM.
1:14So here we're sitting at the ESXi host
1:15that we're using for the lab.
1:17I'm going to right-click on the host from the dropdown.
1:21We're going to select Create/Register VM.
1:23And it's asking us, do we want to create
1:25a new virtual machine, or do you want
1:27to deploy a new virtual machine from an OVF and OVA file.
1:30Now the actual appliance that we get
1:32from Cisco for the Firepower Management Center,
1:35they package it for us all ready to go.
1:37So I'm going to select this deploy
1:38a virtual machine from an OVF or OVA, click on Next.
1:43Now it's asking me to name it.
1:44So let's call this FMC for the Firepower Management Center,
1:48and then we're going to click here to select the files,
1:50or if we had another window open,
1:51we could drag and drop them from our computer.
1:53So I also downloaded the files for the FMC,
1:55the virtual appliance.
1:57And we could drag them over here, or just
1:59click here and select them.
2:00So after some extraction of the files,
2:02I extracted some VMDKs, which are hard disks, some OVFs,
2:06which are the information for the virtual machines,
2:08and then the MF is the hashes.
2:10It's a manifest file.
2:11So there's two sets of files.
2:12There's one option here, and I'll
2:14go ahead and highlight them.
2:16And that's if we're going to be deploying these on an ESXi host
2:19stand only, which we're doing right now.
2:21And the other option here with the Vi,
2:23is if we are going to deploy the virtual machine
2:26in a vSphere environment using vCenter.
2:28So because we're on a standalone ESXi host,
2:31I'm going to go ahead and select the disk,
2:33hold down my Control key, grab the OVF for ESXi.
2:37And we don't need the manifest file, but if you do select it,
2:39it won't even care.
2:40So I'm going to select the very top one here, VMDK, hold down
2:43the Shift, and select these three,
2:44with the two specific options for ESXi.
2:47Click on Open, and it's just brought
2:49in the disk and the OVF.
2:51And the MF is just for validation of the files.
2:54It doesn't actually get included as part of the deployed VM.
2:57So with the name specified and the OVF information,
3:01the hard disk specified that I got from Cisco,
3:03we'll go ahead and click on Next.
3:05I'm going to store these virtual machines files on the same SSD
3:08data store.
3:09Click on Next.
3:10I want to do thin provisioning and I
3:12want to plug this guy into the management network, management
3:15network 192.
3:17And it's going to power automatically,
3:19and we'll click on Next, and that all looks good.
3:21So we'll go ahead and click on Finish.
3:23And if we bring up recent tasks, it's
3:25going to show us deploying that virtual machine, this FMC.
3:28So this deployment of the virtual machine, this part
3:31of it where we're deploying the VM to ESXi,
3:34they'll take a few minutes, not a big deal.
3:36But what takes a little bit longer is, once this
3:39is deployed and then we power it up-- and we told it
3:42to power up automatically-- that powering up,
3:44that initial power up of the FMC,
3:47that could take 20 to 30 minutes for it to go
3:50through all of its gyrations.
3:52So I just wanted to be aware of that, because the first time
3:55we deploy this in any virtualized environment,
3:57it took so long I thought, it's failing, it's failing,
3:59it's not continuing.
4:00When in reality, I just wasn't patient enough
4:02after the VM was up and running for it to fully initialize.
4:06And the reason I tell you that is
4:07I don't want you to make the same mistake of just
4:09getting impatient, thinking, oh, it's not working, what's wrong.
4:12Just give it some time.
4:13All right, so from an ESXi host perspective, it's deployed
4:16and it is powering up.
4:18Let me go ahead and minimize the tasks there.
4:20Let's go to virtual machines here on the left.
4:22There's our FMC right here.
4:24I'll go ahead and click on it.
4:25And then we can click right here to go ahead and open up
4:28a console to it.
4:29So it's right here that we need to be patient and wait
4:32for it to finish.
4:32And when it's done with all of its magic
4:34about the initialization of the database
4:35and everything else getting set up,
4:37it'll prompt us for a login.
4:39And it's at that point we're going to log in as admin,
4:42with a default password for a Firepower Management Center
4:44server.
4:45And that is capital A-D-M-I-N-1-2-3 for the initial
4:50log in, after it's ready for us.
4:53And so here's what I propose we do.
4:54I'll let this go ahead and run for 20, 30,
4:5640 minutes as it does all its initial setup.
4:58And while it does that, let's you and I go to the next video.
5:02And in the next video, we'll walk through
5:03the deployment of our FTDs, the Firepower Threat
5:07Defense appliances, also as VMs in our virtualized lab
5:11environment.
5:12So I'll see you in that next video in just a moment
5:14for the deployment of the FTDs.
5:16Meanwhile, I hope this has been informative for you,
5:18and I'd like to thank you for viewing.
Deploy the FTDs
0:06And welcome back.
0:08If we had a manager that had nobody to manage,
0:10what do we call that manager?
0:11I think maybe lonely?
0:13Well, with a Firepower environment,
0:15we want to have a Firepower Management
0:17Center to manage what?
0:18To manage our Firepower Threat Defense appliances.
0:21So in this video, I'd like to walk you
0:23through deploying three VMs, which
0:26are going to represent our three FTDs, one at headquarters site,
0:30and then FTD number 3 at site 3, and FTD 4 at site 4.
0:34And that way, we'll have them available and ready
0:36for us in our lab environment, so we
0:38can go to work in creating policies and doing
0:40all the magic that Firepower brings to the table.
0:42So let's take a look at the big picture as far as
0:44where they fit in.
0:45Then I'll walk you through the deployment of our FTDs.
0:48And so in our topology, we've got FTD-1, FTD-3, and FTD-4.
0:53And if you're thinking, Keith, where's FTD-2?
0:57Later on in the videos, we'll deploy FTD-2
1:00with high availability for FTD.
1:02And that's why I'm going to leave that little FTD-2
1:05spot open for our HA discussions, which are coming
1:08up in separate sets of videos.
1:09So far the deployment of this virtualized lab
1:12inside of an ESXi host, when we deploy these three FTDs,
1:15they are going to need to have one connection that goes out
1:18here to the lab internet, which is our port group representing
1:22that.
1:22So there'll be one on each of them there.
1:24And they're also going to need a connection over
1:26to the HQ network for FTD-1, and to site 3 for FTD-3,
1:31and for site 4, and their respective port
1:33group there for site 4.
1:36And because we're putting each of these FTDs
1:38also on the management network of 192.168 for management
1:41purposes, we're also going to want to connect the management
1:44interface or interfaces to that network,
1:47as well, in that port group.
1:48So as we go through the deployment of these three FTDs,
1:52what I'll do is I'll walk you through those interface
1:54assignments as they come up, so you can see exactly
1:57which interfaces need to go to which port groups to make
2:00this topology happen.
2:02So back at our ESXi host, which is
2:04providing all the magic for this lab, let's right click on Host.
2:08From the dropdown, we'll select Create/Register VM.
2:11And then we'll select Deploy a machine
2:13from an OVF or OVA file.
2:14Cisco, when they provide the virtualized images for the FMC,
2:19as well as the FTD, they are going
2:21to be packaged in this virtualization format.
2:24So it makes it very easy to deploy.
2:26So I've downloaded, from Cisco, the files
2:29for the virtual edition of an FTD.
2:31And that's what I'm going to point to when it asks me,
2:33hey, where are the files?
2:35So we'll click on Next.
2:36So we'll call this FTD-1.
2:38And them I'm going to here in this big section
2:40so I can browse for the actual files for this.
2:45So I'll click here to select files.
2:47And then under a folder called FTD, Extracted,
2:51I've got the Firepower Threat Defense appliance
2:53VM files, which are these three right here.
2:57And the ones with VI, that's if we were going
2:59to deploy them using vCenter.
3:01But in our case, we're just using a standalone ESXi host.
3:04So the VMDK is the hard disk file.
3:07The MF is the Manifest File, which
3:10includes some hashes for validation of the files.
3:12And then the OVF is the configuration file.
3:16So with those selected, we'll click on Open.
3:18And it's going to use the VMDK and the OVF,
3:20and we'll click on Next.
3:22And then I'm going to store this on the ESXi host
3:24on this datastore with the SSD drive.
3:26Click on Next.
3:28And now here's where it gets interesting.
3:29Look at this.
3:30We've got-- that's a whole bunch of interfaces.
3:33So from the perspective of getting the right interfaces
3:36into the right port groups, let me walk you
3:38through where we're going to want to put these.
3:40And I also want to tell you that the first time I did this,
3:42I didn't get this all correct.
3:45So after a couple of goes and looking
3:48at the documentation, which is always a great solution,
3:50let me share with you information
3:52about these interfaces.
3:53So I see the FTDV interface in a Google search,
3:57and I found this document from Cisco
3:59regarding the Firepower Threat Defense Virtual,
4:02which is the virtual appliance.
4:03And I scrolled down to Interfaces.
4:07And here in table 4--
4:08let me make a little bit bigger here, as well.
4:10Here in this table, it's showing us the interfaces.
4:12So effectively, what we want to do is we want to take the first
4:14two interfaces-- these are in order--
4:17which they're calling adapter 1 and adapter 2.
4:19And in our hypervisor environment,
4:21that's literally what it's going to be called.
4:23And we're going to want to put both of those
4:24into our management network.
4:26So we'll take interface 1 and 2 and associate those
4:29with the 192 network for management.
4:31And also in our topology, because I want gig 0/0
4:34to be connected to our pseudo-internet,
4:36I'm going to specify that adapter 3 should
4:38connect to the 23 network port group
4:41for our pseudo-lab internet.
4:42And then network adapter 4 on our ESXi host, which
4:45is going to be gigabit-ethernet 0/1,
4:47I want that to go to my local network.
4:50So that would go-- on FTD-1, it would be the HQ network.
4:53On FTD-3, it would be the site 3 network.
4:56And on FTD-4, it would be the site 4 port group to put those
5:02interfaces-- in this case, it's going to be gig0/1--
5:04from the FTD's perspective, in the correct network.
5:08So that's our game plan.
5:10And all the other interfaces, including adapter 5 and beyond,
5:13we'll just put all of those in the parking lot,
5:16meaning the port group associated with our parking lot
5:19switch.
5:20And then if we need them in the future for things
5:22like high availability or more interfaces,
5:24we can bring them out of the parking lot
5:26and put them into our production lab environment.
5:29But initially, we want to set them up like this.
5:32So the first two, we want to put in our management network.
5:36So I'll select those port groups.
5:38The next one is our outside interface,
5:40and so that outside interface is going
5:42to be our lab pseudo-internet.
5:44So I'll switch the port group there.
5:45And then 0-1, and this is FTD-1, is going to be on HQ Net.
5:50And then for FTD-3 and FTD-4, they
5:54would actually choose Site 3 and Site 4, respectively.
5:56So I'm going to choose the correct port group here.
5:58And then for the rest of these interfaces,
6:01I'm going to say, Not Used Parking lot, Not Used Parking
6:04Lot, Not Used Parking Lot, et cetera, all the way down.
6:09And with those correctly selected-- let
6:11me just check my work.
6:12Mgmt Network, the pseudo internet for Gig0-0,
6:15and 0-1 will be the HQ 10 network for FTD-1.
6:18Fantastic.
6:19And the rest, we're not using at the moment.
6:20And then for the Deployment type,
6:22we can select how much we want to throw at this.
6:24If you have 128 gig, or 256 gig, or a terabyte server of RAM,
6:29just go crazy.
6:30But for a lab environment, if you don't have a ton,
6:33you might want to choose lower is better.
6:35For my lab environment, I have a whole bunch of cores
6:38and a whole bunch of RAM.
6:39So I'm going to say for this FTD,
6:41just go hog wild with 12 cores and 24 gigabytes of RAM.
6:45And the cool thing is, with a hypervisor like ESXi,
6:49if those devices--
6:50if this VM is not using those resources,
6:53it's not going to tie up those resources.
6:54So there's not a lot of harm to give it a little more than what
6:57it might actually need.
6:59Then I'm going to do Thin provisioning,
7:01and I'm going to tell it to Power on automatically.
7:04And we'll click on Next.
7:05I'll confirm my work here.
7:07That all looks good.
7:08And we'll click on Finish.
7:09And if we click on Recent tasks, it
7:11can show us the deployment of that virtual machine, which
7:14in our case is FTD-1.
7:16And the process for doing FTD-3 and FTD-4
7:20is exactly the same as for FTD-1.
7:21So we don't need to walk through that whole process again.
7:24The big difference would be for the deployment of the VM
7:27for FTD-3, we'd want the 0/1 interface
7:30to connect to the site 3 inside network of 10.3.
7:33And for the FTD-4, that 0/1 interface
7:37would connect to the site 4 switch and port group
7:40to put it in the right network.
7:42So the process is the same for those two,
7:44so I'll do that off-camera, because it's
7:45identical to FTD-1, with the exception of that one port
7:47group.
7:48So to complete our lab environment, in the next video,
7:51I'd like to walk through just the basic connectivity
7:54and integration of the Firepower Management Center,
7:56from the previous video, and the Firepower Threat Defense
7:59appliances from this video.
8:01And that'll give us a basic foundation
8:02for a working Firepower lab that we can then play with and work
8:05with going forward.
8:07So I'll see you in the next video for that integration.
8:09Meanwhile, I hope this has been informative for you,
8:11and I'd like to thank you for viewing.
Add FTDs to the FMC for Mgmt
0:07In the previous video, we deployed our FTDs--
0:09the Firepower Threat Defense Appliances-- as VMs.
0:13Before that, we deployed the FMC as a VM.
0:15To integrate those so we can have the FMC manage the FTDs,
0:19we need to do a few things, including give everybody
0:22an IP address on the management network,
0:25and then also associate the FTDs that they
0:27should be managed by our FMC.
0:30So to verify that we have a functional lab on our hands,
0:32what we're going to do in this video
0:34is integrate the FTDs with the FMC.
0:37And then once that's in place, boom.
0:39We now have a great framework for a lab environment
0:41that we can use to practice going forward.
0:44So what we'll want to do on these FTDs
0:46is in the initial config, which I'll walk you
0:48through, we're going to want to configure this guy with an IP
0:51address of .11 on its management interface, and this guy, .13,
0:55and this guy, .14.
0:56And on the Firepower Management Center, we want to give it .10.
0:59And then we want to tell the FTDs
1:01that they're going to be managed by this Firepower Management
1:04Center, like that.
1:05So let me bring in the players.
1:07Here's FTD-1.
1:08There's the console for it.
1:10And here is FTD-3.
1:13And I'll size them up here in a bit.
1:15And here's FTD-4.
1:18And here is the FMC.
1:20And that way, they're in a similar position
1:21as they were in the diagram.
1:23And I'll see if I can make these a little bit bigger, as well.
1:26Let's go and start up here on FTD-1.
1:30And the reason why we're going to start on FTD-1
1:32is because the Firepower Management Center is still
1:35initializing.
1:36So let's start with FTD-1.
1:38So the default username and password on an FTD,
1:40as well as on the FMC, is admin as the user,
1:44and the password is Admin123.
1:48Press Enter.
1:49And we are now logged into FTD-1.
1:51And here, I'm going to press Enter to accept the end user
1:54license agreement.
1:55Hit Space bar a few times to go all the way down to the bottom.
1:58And then press Enter to agree to the end user license agreement.
2:01In fact, let me minimize the other windows just
2:05for a moment.
2:07And that way, we can focus on the initial config for FTD-1.
2:11So let me bring that down to the middle
2:13and make that a little bit bigger.
2:15There we go, much better.
2:17Now it's asking for a new password.
2:18So we can set the password to whatever you
2:20want in your lab environment.
2:21I'm going to set mine.
2:23Press Enter.
2:24Confirm the password.
2:27Press Enter.
2:28Do I want to configure IPv4?
2:30Yes, I do.
2:30If it's in brackets, you can just press Enter.
2:32That'll accept it.
2:33And do I want to configure IPv6?
2:35There's an n in brackets, so we can press Enter to select that.
2:38And then how do we want to configure IPv4?
2:40We're going to do it manually based on our plan.
2:43And we are going to use--
2:44this is FTD-1-- 192.168.1.11, based on our plan,
2:50with a 24-bit mask.
2:52Enter.
2:52And a default gateway of 192.168.1.1.
2:56And that's my default gateway on my home network.
2:59And press Enter.
3:00And we'll call this FTD-1.
3:02I'm going to call it nuggetlab.com.
3:05So if you have DNS in your home lab, as well,
3:08you can set all that up for name resolution.
3:10And then it's asking for a comma-separated list
3:12of DNS servers.
3:13If you have a DNS server in your home lab,
3:15you could point to it.
3:16Right here, it's pointing to the OpenDNS or the Umbrella servers
3:19on the internet, which is fine.
3:20Press Enter.
3:21I'm not going to provide any search domains.
3:23Next it's asking, do you want to manage this Firepower Threat
3:26Defense appliance locally?
3:27Meaning, do you want to connect to it directly and manage it
3:30by yourself?
3:31Or if we say no, do we want to use the FMC, the Firepower
3:34Management Center?
3:35Which we do.
3:36So we're going say no to being managed locally.
3:38Press Enter.
3:39Then it's asking us, do you want this to be a routed layer 3
3:42routing firewall, or do you want to be
3:44like a bridge in the night, like a bump in the wire--
3:46transparent mode?
3:47And the default is routed.
3:48I'll press Enter to accept that.
3:51And we'll have further discussions
3:52in our configuration videos about routed
3:54versus transparent, but we're going to start off with routed.
3:57And then it's giving us instructions
3:59for how to allow this Firepower Threat Defense
4:01Appliance to be managed by a Firepower Management Center.
4:05And we're going to use the command configure manager add,
4:08and then the hostname, if it's resolvable, or the IP
4:11address, followed by the key that the manager would also
4:14have to supply in order for it to work.
4:16So for us, we're going to type in configure manager
4:22and then add.
4:23And the manager's address is 192.168.1.10.
4:27That's our Firepower Management Center.
4:29And then we just specify a key that we want to use.
4:32So it doesn't really matter too much
4:33about the key we use right here, as long as we
4:35use the same key at the FMC when we try to bring this FTD along
4:39with us as a managed device.
4:41So we'll press Enter.
4:42It says it was successfully configured.
4:44We can also do a show managers.
4:46Press Enter just to verify.
4:48So here it says the FMC is at 192.168.1.10,
4:52that we have a key specified, and it's pending,
4:55meaning we haven't had that manager reach out to us yet.
4:58But hey, we're willing.
4:59And we're going to repeat this process on FTD-3 and FTD-4.
5:03We'll assign the IP address of .13 to FTD-3 and .14 to FTD-4.
5:10And we'll configure each of them to be
5:12willing to be managed by the FMC.
5:14So in the background right now, I'm
5:16going to configure FTD-3 and FTD-4 with their respective IP
5:20addresses, and also telling them to wait for the FMC
5:24to contact them so they can be managed by the Firepower
5:27Management Center.
5:28OK, so finally, the FMC has also finished its initial bootup
5:32and installation of the database and everything else.
5:35So on the FMC, we're going to do the initial bootstrap
5:38by logging in as Admin with the default password of Admin123.
5:44Press Enter.
5:45And again, this is on the FMC.
5:47We'll press Enter.
5:48Hit Space bar a few times.
5:49Press Enter to accept the end user license agreement.
5:52And then we'll specify a password,
5:54and then we'll confirm the password.
5:59Press Enter.
6:00And we'll call this fmc.nuggetlab.com.
6:06Press Enter.
6:07We're going to do a manual configuration of the management
6:09interface on the FMC.
6:11And it is going to be 192.168.1.10,
6:15based on our plan, with a 24-bit mask.
6:17Looks good.
6:18Default gateway of .1 looks good.
6:20DNS servers using OpenDNS, which is now Umbrella.
6:23Press Enter.
6:25It's going to resolve these NTP servers and use that for NTP.
6:28That's fine.
6:29And if we had a lab environment where
6:30we had a Windows Server acting as a time server, as well,
6:33we could all point to that specific IP address in your lab
6:36environment, if you desire.
6:38So I'm going to hit a y for yes.
6:39Press Enter.
6:40And then to integrate the three FTD appliances
6:44with this Management Center, we're
6:46simply going to open up a browser to 192.168.1.10
6:49and finished the configuration from there.
6:51So here from my computer that I use every day, right
6:53here on the 192.168.1 network--
6:55so I have reachability to the whole management
6:57network from my computer--
6:59I'm going to https://192.168.1.10 and press
7:05Enter.
7:06So because FMC is currently using
7:08a certificate that's self-signed,
7:09my browser doesn't trust it.
7:11That's OK.
7:11I'll click on Advanced and Proceed.
7:14And here, we're going to login as admin.
7:16I'll supply the password, and we'll click on Log In.
7:19So here, with 6.7, this is the first pop-up that comes up.
7:22And it's giving us the opportunity of licensing it,
7:24or check this out.
7:25We'll click this radio button to start the 90-day evaluation
7:29period right here.
7:30So we'll start the evaluation, and we'll click on Save.
7:33And then if we want to bring in the three FTDs,
7:35we go to Devices.
7:37And from the dropdown here, we click on Device Management.
7:41And that was the screen that we were currently looking at,
7:43but I want to show you how to get there.
7:44And then over here on the right, we'll simply click on Add.
7:47And from the dropdown, we'll click on Device.
7:50And then we'll bring in those three amigos.
7:52So the first one's at 192.168.1.11.
7:55That's FTD-1.
7:56We'll give the name of FTD-1.
7:58And if you have local DNS services all setup and working,
8:01you could resolve it by name.
8:03And the key that we're going to use
8:04is the key we specified on the FTD, which is Cisco123.
8:09And then we're using the same password here.
8:11It's going to require an initial access control policy.
8:13There is none by default. So from the dropdown,
8:16we'll say Create new policy.
8:18Let's call this Starter ACP, for Access Control Policy.
8:22And regarding this policy, instead of blocking traffic
8:25or doing IPS, let's tell it just to do Network Discovery, which
8:28is pretty darn cool.
8:29That way, it can tell us what's going on.
8:31And we'll click on Save.
8:32So now that it knows what policy to use for access control,
8:35let's also enable Malware, Threat, and URL Filtering,
8:38because, hey, we got a 90-day license.
8:40Let's use it.
8:41And we'll click on Register.
8:43And then what we'll do is we'll do the same exact process
8:46to bring in FTD-3 at .13 and FTD-4 at .14.
8:51So FTD-1 is on its way.
8:53Let's bring in FTD-3 and 4.
8:55So we'll click on Add, and we'll put in the IP address
8:59192.168.1.13 for FTD-3.
9:03And for the display name, we'll call it FTD-3.
9:07And we use the same key over there, as well.
9:11So I'll supply that key.
9:12And we'll use the same policy--
9:13the same Starter policy we just created.
9:15And we'll enable Malware, Threat, and URL Filtering.
9:18And we'll click on Register.
9:21So FTD-3 is on its way in, and let's bring in FTD-4, as well.
9:26So here under Devices, with Device Management,
9:29we'll click on Add up in the upper right-hand corner.
9:31Click on Device.
9:32And we'll specify it's 192.168.1.14 for FTD-4.
9:38Display Name-- we'll give it as FTD-4.
9:41That will be for site 4.
9:43We'll put in the Key that we used over there
9:47for registration.
9:48We'll use the Starter Access Control Policy.
9:50We'll enable Malware, Threat, and URL Filtering services,
9:52and click on Register.
9:54So now FTD-4 is in place, and we now
9:57have a base infrastructure for practicing, playing,
10:00and working with a Firepower environment.
10:03So using the ESXi host is one way of doing it.
10:06And as we've demonstrated, that's
10:07my intent as we go forward to the other sets of videos.
10:10As we take a look at configuring Firepower and working with it,
10:13I'm going to be using this ESXi host-based lab.
10:15But it's not the only option.
10:17So if you don't have a host with a whole bunch of RAM
10:20that can support it, and you have a couple of computers
10:22laying around, there's also an option with VMware Workstation
10:25to build a lab.
10:26And I've got a separate set of videos
10:28just on how to put it together with VMware Workstation.
10:30Or if you want to use EvE-NG, I've also got a set of videos
10:34on that, as well.
10:35So I would encourage you, even if you're only going to use one
10:38lab environment-- you don't need all three--
10:40I would encourage you to take a peek at those other ones,
10:42as well, because you'll get some more ideas and a better
10:45reference point on where things are.
10:46And then once we have a lab environment in place
10:48that we can practice with, I'd like
10:50to walk you through how it works-- the logic, access
10:52control policies, intrusion policies, malware policies,
10:56file inspection policies, SSL-intercept, and how that
10:59works and why we would do it.
11:00And having the lab available to you to practice with
11:04is a big part of reinforcing all those skills.
11:06So I would encourage you to choose one of the three options
11:09for a lab environment--
11:10ESXi host, multiple machines with VMware Workstation,
11:13or using EvE-NG--
11:15and then following along with me as we
11:16continue through the rest of the videos.
11:18So that's it for this set of videos regarding building
11:21a lab with one ESXi host.
11:23I appreciate you joining me, and I'll see you
11:25in the next set of videos.
11:26Until then, I hope this has been informative for you,
11:29and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year