{"course":{"productid":26300,"modality":1,"active":true,"language":"de","title":"Juniper Service Provider Edge Security","productcode":"JSPES","vendorcode":"JP","vendorname":"Juniper Networks","fullproductcode":"JP-JSPES","courseware":{"has_ekit":true,"has_printkit":false,"language":""},"url":"https:\/\/portal.flane.ch\/course\/juniper-jspes","objective":"<ul>\n<li>Define the general security architecture for 4G and 5G networks.<\/li><li>Configure data plane security protections.<\/li><li>Explain DoS and DDoS attacks.<\/li><li>Describe BGP Flowspec in protecting against DDoS attacks.<\/li><li>Explain the Corero solution for DDoS attacks.<\/li><li>Describe the use of stateful firewalls.<\/li><li>Explain the use of ALGs in stateful security firewalls.<\/li><li>Explain how to secure BGP on Junos devices.<\/li><li>Describe how to use IPsec to secure traffic.<\/li><li>Explain the new IoT threat to networks.<\/li><li>Describe AutoVPN IPsec architectures.<\/li><li>Explain the use and configuration of CGNAT on SRX Series devices<\/li><\/ul>","essentials":"<ul>\n<li>Intermediate level of TCP\/IP networking and security knowledge<\/li><li>Attend the Introduction to Juniper Security (IJSEC) course before attending this class<\/li><\/ul>","audience":"<p>This course benefits those responsible for\nimplementing, monitoring, and troubleshooting Juniper\nsecurity components.<\/p>","outline":"<p><strong>DAY 1<\/strong><\/p>\n<p><strong>1 Course Introduction<\/strong><\/p>\n<p><strong>2 Security Challenges for Service Providers<\/strong>\n<\/p>\n<ul>\n<li>Describe limitations of security devices<\/li><li>Describe DDoS attack threats<\/li><li>Describe BGP security threats<\/li><li>Explain IP address depletion challenges<\/li><li>Describe 5G security challenges<\/li><\/ul><p><strong>3 Juniper Networks Solutions for Service Providers<\/strong>\n<\/p>\n<ul>\n<li>Describe Juniper Networks&rsquo; security solutions for the service provider challenges<\/li><\/ul><p><strong>4 Stateful Firewalls<\/strong>\n<\/p>\n<ul>\n<li>Describe stateless firewall filters<\/li><li>Describe stateful firewall policies<\/li><li>Describe screens and ALGs<\/li><li>Explain asymmetrical routing<\/li><\/ul><p><strong>Lab 1: Configure Stateful Firewalls<\/strong><\/p>\n<p><strong>5G Architecture using SRX Series Devices<\/strong>\n<\/p>\n<ul>\n<li>Describe security insertion points<\/li><li>Describe 5G network evolution<\/li><\/ul><p>\n<strong>6 DDoS Protection<\/strong>\n<\/p>\n<ul>\n<li>Explain DDoS history and common protections<\/li><li>Describe SRX DDoS protection<\/li><li>Describe BGP FlowSpec<\/li><li>Describe Corero with MX DDoS protection<\/li><\/ul><p><strong>Lab 2: DDoS Protection<\/strong><\/p>\n<p><strong>DAY 2<\/strong><\/p>\n<p><strong>7 Carrier-Grade NAT<\/strong>\n<\/p>\n<ul>\n<li>Explain IPv4 address exhaustion<\/li><li>Describe Source NAT<\/li><li>Describe CGNAT<\/li><li>Describe NAT64<\/li><\/ul><p><strong>Lab 3: CGNAT<\/strong><\/p>\n<p><strong>8 Juniper Connected Security for Service Providers<\/strong>\n<\/p>\n<ul>\n<li>Explain Juniper Connected Security<\/li><li>Describe SecIntel feeds<\/li><li>Describe a use case for IoT protection<\/li><\/ul><p><strong>Lab 4: Implementing Juniper Connected Security<\/strong><\/p>\n<p><strong>9 IPsec Overview<\/strong>\n<\/p>\n<ul>\n<li>Describe the IPsec and IKE protocols<\/li><li>Configure site-to-site IPsec VPNs<\/li><li>Describe and configure Proxy IDs and Traffic selectors<\/li><li>Monitor site-to-site IPsec VPNs<\/li><li>Describe IPsec use with gNodeB devices<\/li><\/ul><p>\n<strong>Lab 5: Site-to-Site IPsec VPN<\/strong><\/p>\n<p>\n<strong>10 Scaling IPsec<\/strong>\n<\/p>\n<ul>\n<li>Describe and implement PKI certificates in Junos OS<\/li><li>Describe AutoVPN<\/li><li>Describe SecGW firewall use case for scaling IPsec<\/li><\/ul><p>\n<strong>Lab 6: Configuring AutoVPN<\/strong><\/p>\n<p><strong>DAY 3<\/strong><\/p>\n<p><strong>11 GPRS and GTP<\/strong>\n<\/p>\n<ul>\n<li>Describe how to secure GTP tunnels<\/li><li>Describe the GPRS protocol<\/li><li>Describe the GTP<\/li><li>Explain how Roaming Firewall secures GTP<\/li><\/ul><p>\n<strong>12 SCTP<\/strong>\n<\/p>\n<ul>\n<li>Describe the SCTP<\/li><\/ul><p><strong>Lab 7: Video about Implementing the Roaming Firewall (Demo)<\/strong><\/p>\n<p><strong>13 Securing the Control Plane<\/strong>\n<\/p>\n<ul>\n<li>Explain how to secure the control plane on Junos devices<\/li><li>Describe how the loopback filter works to secure the control plane<\/li><li>Explain how to protect the control plane from DDoS attacks<\/li><li>Describe how to secure the IGP against attacks<\/li><\/ul><p><strong>Lab 8: Configure Control Plane Protections<\/strong><\/p>\n<p><strong>14 Securing the BGP<\/strong>\n<\/p>\n<ul>\n<li>Describe how to secure the BGP<\/li><li>Describe BGP security features<\/li><li>Describe BGP dampening<\/li><\/ul><p><strong>Lab 9: Configure BGP protections<\/strong><\/p>","summary":"<p>This three-day course discusses edge security concepts for the service provider network. It discusses security for 5G networks on the main GPRS\ninterfaces. Key topics include deploying an SRX Series device in different parts of the service provider network, implementing CGNAT, DDoS,\nmalware inspection, command-and-control prevention, IPsec tunnels, 5G security, control plane hardening, and BGP hardening.\nStudents will gain experience in configuring, testing, and troubleshooting the Junos OS through demonstrations and hands-on labs. This course is\nbased on Junos OS 21.1R1.11.<\/p>","objective_plain":"- Define the general security architecture for 4G and 5G networks.\n- Configure data plane security protections.\n- Explain DoS and DDoS attacks.\n- Describe BGP Flowspec in protecting against DDoS attacks.\n- Explain the Corero solution for DDoS attacks.\n- Describe the use of stateful firewalls.\n- Explain the use of ALGs in stateful security firewalls.\n- Explain how to secure BGP on Junos devices.\n- Describe how to use IPsec to secure traffic.\n- Explain the new IoT threat to networks.\n- Describe AutoVPN IPsec architectures.\n- Explain the use and configuration of CGNAT on SRX Series devices","essentials_plain":"- Intermediate level of TCP\/IP networking and security knowledge\n- Attend the Introduction to Juniper Security (IJSEC) course before attending this class","audience_plain":"This course benefits those responsible for\nimplementing, monitoring, and troubleshooting Juniper\nsecurity components.","outline_plain":"DAY 1\n\n1 Course Introduction\n\n2 Security Challenges for Service Providers\n\n\n\n- Describe limitations of security devices\n- Describe DDoS attack threats\n- Describe BGP security threats\n- Explain IP address depletion challenges\n- Describe 5G security challenges\n3 Juniper Networks Solutions for Service Providers\n\n\n\n- Describe Juniper Networks\u2019 security solutions for the service provider challenges\n4 Stateful Firewalls\n\n\n\n- Describe stateless firewall filters\n- Describe stateful firewall policies\n- Describe screens and ALGs\n- Explain asymmetrical routing\nLab 1: Configure Stateful Firewalls\n\n5G Architecture using SRX Series Devices\n\n\n\n- Describe security insertion points\n- Describe 5G network evolution\n\n6 DDoS Protection\n\n\n\n- Explain DDoS history and common protections\n- Describe SRX DDoS protection\n- Describe BGP FlowSpec\n- Describe Corero with MX DDoS protection\nLab 2: DDoS Protection\n\nDAY 2\n\n7 Carrier-Grade NAT\n\n\n\n- Explain IPv4 address exhaustion\n- Describe Source NAT\n- Describe CGNAT\n- Describe NAT64\nLab 3: CGNAT\n\n8 Juniper Connected Security for Service Providers\n\n\n\n- Explain Juniper Connected Security\n- Describe SecIntel feeds\n- Describe a use case for IoT protection\nLab 4: Implementing Juniper Connected Security\n\n9 IPsec Overview\n\n\n\n- Describe the IPsec and IKE protocols\n- Configure site-to-site IPsec VPNs\n- Describe and configure Proxy IDs and Traffic selectors\n- Monitor site-to-site IPsec VPNs\n- Describe IPsec use with gNodeB devices\n\nLab 5: Site-to-Site IPsec VPN\n\n\n10 Scaling IPsec\n\n\n\n- Describe and implement PKI certificates in Junos OS\n- Describe AutoVPN\n- Describe SecGW firewall use case for scaling IPsec\n\nLab 6: Configuring AutoVPN\n\nDAY 3\n\n11 GPRS and GTP\n\n\n\n- Describe how to secure GTP tunnels\n- Describe the GPRS protocol\n- Describe the GTP\n- Explain how Roaming Firewall secures GTP\n\n12 SCTP\n\n\n\n- Describe the SCTP\nLab 7: Video about Implementing the Roaming Firewall (Demo)\n\n13 Securing the Control Plane\n\n\n\n- Explain how to secure the control plane on Junos devices\n- Describe how the loopback filter works to secure the control plane\n- Explain how to protect the control plane from DDoS attacks\n- Describe how to secure the IGP against attacks\nLab 8: Configure Control Plane Protections\n\n14 Securing the BGP\n\n\n\n- Describe how to secure the BGP\n- Describe BGP security features\n- Describe BGP dampening\nLab 9: Configure BGP protections","summary_plain":"This three-day course discusses edge security concepts for the service provider network. It discusses security for 5G networks on the main GPRS\ninterfaces. Key topics include deploying an SRX Series device in different parts of the service provider network, implementing CGNAT, DDoS,\nmalware inspection, command-and-control prevention, IPsec tunnels, 5G security, control plane hardening, and BGP hardening.\nStudents will gain experience in configuring, testing, and troubleshooting the Junos OS through demonstrations and hands-on labs. This course is\nbased on Junos OS 21.1R1.11.","skill_level":"Intermediate","version":"21.1R1.11","duration":{"unit":"d","value":3,"formatted":"3 Tage"},"pricelist":{"List Price":{"DE":{"country":"DE","currency":"USD","taxrate":19,"price":2850},"IL":{"country":"IL","currency":"USD","taxrate":17,"price":2850},"UA":{"country":"UA","currency":"USD","taxrate":20,"price":2850},"CH":{"country":"CH","currency":"CHF","taxrate":8.1,"price":2850},"AT":{"country":"AT","currency":"EUR","taxrate":20,"price":2850}}},"lastchanged":"2026-01-13T14:28:40+01:00","parenturl":"https:\/\/portal.flane.ch\/swisscom\/json-courses","nexturl_course_schedule":"https:\/\/portal.flane.ch\/swisscom\/json-course-schedule\/26300","source_lang":"de","source":"https:\/\/portal.flane.ch\/swisscom\/json-course\/juniper-jspes"}}