This online instructor-led training course provides the basic concepts and skills necessary to configure Check Point Security Gateway and Management Software Blades.In this course students will learn how to configure a security policy and learn about managing and monitoring a secure network, upgrading and configuring a security gateway, and implementing a virtual private network (VPN), and more! This course provides the underlying material required to prepare candidates for the CCSA R80 certification exam.Exam #156-215.80: Check Point Certified Security Administrator R80
Curriculum
1 Section
0 Lessons
9 Hours
Expand all sectionsCollapse all sections
Course Outline
01. Next Generation Firewalls
The difference between packet filtering and modern features: App Control, URL Filtering, AV, AB, VPN, and HTTPS Inspection
Understanding Deep Packet Inspection (DPI)
02. In-line versus Host-based Firewalls
In-line appliances vs. host-based solutions (AEP, Guardicore, Illumio, etc.)
03. Check Point Architecture
3-Tiered Architecture: SmartConsole, Security Management, and Security Gateway
Security Management Server (SMS) and Gateways
Deployment Modes: Standalone, Distributed, and Bridge
04. Configuration Tools
SmartConsole: Centralized Management and Blade Activation
Secure Internal Communication (SIC) and Clustering
Global Parameters, Rules, and NATing Policies
Web User Interface (WebUI): Network Interfaces, ARP, System Time, and Backup/Restore
Command Line Interface (CLI): Tcpdump, FW Monitor, and Zdebug basics
05. SMS-Gateway Communication
Secure Internal Communication (SIC) Mechanics
Communication Channels for Policy Installation and Logs
Internal Certificate Authority (ICA) for SIC, VPN, and Users
06. Configuration and Commands
WebUI Overview: Widgets, Traffic Stats, and Blade Status
Network Interface Config, DHCP Server, and IPv4 Static Routes
Advanced Routing: BGP, OSPF, IGMP, and Route Redistribution
User Management: Roles and Password Policies
High Availability: VRRP and License Status
Snapshot Management and CPUSE Software Updates
CLI Shells: CLISH (Check Point specific) vs. Expert Mode (Bash)
07. Security Policies & Rulebase
Policy Overview and Attributes
Rulebase Best Practices and Management
08. Software Blades
Firewall and IPSec VPN
Mobile Access, Application Control, and URL Filtering
Data Loss Prevention (DLP) and IPS
Anti-Bot, Anti-Virus, Threat Emulation, and Threat Extraction
Identity Awareness, Content Awareness, and QoS
09. & 10. Logging, Tracing, and Clustering
Logs & Monitor and Tracing Tools
Imaging and ClusterXL Operations
11. VIPs & VMACs
Clustering local and SMS configurations
Understanding Virtual IP (VIP) and Virtual MAC (VMAC) addressing