The content is looking good, my biggest comment is about length.
I already find myself breaking half way through the 201 firewall module (Usually just before NAT) to try and keep focus. I feel that 70 slides would just be a little much to absorb for many.
Perhaps we can split VIP, Endpoint Control and some of the more advanced NAT concepts out into another module within the 301, perhaps including the Load Balancing and SSL Offloading capability.
Next, in the labs one thing that we' re missing right now is a " Best Practice" type example showing:
- Splitting out DNS / ICMP into their own policy with logging disabled to save resources
- Creating a specific policy for BYOD with Web Access and E-Mail access with Certificate Inspection enabled.
- Using a " Services" group instead of the All, disuading use of the All service at all.
In the 301, it' d be nice to see a module incorporating Load Balancing, SSL Offloading and IPS in addition to a server / DMZ best practice example. Peraps included with the DoS policy.
David