Course Description
This two-day course provides an understanding of basic concepts and skills necessary to configure VPN-1. During this course, you will configure a Security Policy, and learn about managing and monitoring a secure network.
Certification
Check Point Certified Security Administrator (CCSA) NGX R65 - exam #156-215.65
Who Should Take This Course?
- This course is designed for systems administrator, security manager, or network engineer who manages NGX R65 Security Gateway deployments
- If you want to earn Check Point Certified Security Administrator (CCSA) NGX R65 certification
Course Fee: $1,995
Course Prerequisites
- Basic networking knowledge
- Knowledge of Windows Server and/or Unix
- Experience with TCP/IP and the Internet
Course Objectives
After completion of this course, participants will learn
- How to use NGX tools to upgrade to VPN-1 NGX, from VPN-1/FireWall-1 NG or VPN-1 NG with Application Intelligence
- How to use NGX tools to install VPN-1 NGX on Windows Server 2003 and SecurePlatform
- How to work with Security Policy rules and NGX objects, using NGX object cloning and Database Revision Control features
- How to use monitoring tools to track, monitor, and account for all connections logged by Check Point components
- How to implement LDAP, and integrate it with an NGX SmartCenter Server
- How to allocate bandwidth, given a variety of Check Point QoS configurations
- How to identify the features and limitations of Check Point High Availability solutions
Course Outline
Chapter 1: VPN-1 Overview
- VPN-1 Fundamentals
- Check Point's Security Gateway
- Security Policy Management
- VPN-1 SmartCenter Server
- Lab 1: VPN-1 Distributed Installation
Chapter 2: Introduction to SecurePlatform
- SecurePlatform Hardware Requirements and Setup
- Using the Command Line
- Managing Your SecurePlatform System
- SecurePlatform Command Shell
- Lab 2: Configuring VPN-1 Using the CLI
Chapter 3: Introduction to the Security Policy
- Security Policy Basics
- Managing Objects in SmartDashboard
- Lab 3
- Creating Objects, Establishing Trust and Configuring SmartMap
- Creating the Rule Base
- Completing the Rule Base
- Rule Base Management
- Policy Management and Revision Control
- Policy-Management Overview
- Database Revision Control
- Lab 4: Configuring the Security Policy
- Network Address Translation
- Lab 5: Configuring Statis NAT
- Enabling VoIP Traffic
- Detecting IP Spoofing
- Multicasting
Chapter 4: Monitoring Traffic and Connections
- SmartView Tracker
- Blocking Connections
- SmartView Monitor
- Eventia Reporter
- Lab 6: Blocking Intruder Connections
- Lab 7: Configuring Suspicious Activity Rule in Smart View Monitor
Chapter 5: User Management and Authentication
- Creating Users and Groups in SmartDashboard
- Introduction to VPN-1 Authentication
- Authentication Methods
- LDAP User Management with SmartDirectory
- Lab 8: Configuring Client Authentication
- Lab 9: Configuring LDAP Authentication with SmartDirectory
Chapter 6: Check Point QoS
- Check Point QoS Overview
- Check Point QoS Architecture
- Deploying QoS
- Check Point QoS Rule Base
- Differentiated Services
- Low Latency Queuing
- Monitoring QoS Policy
- Optimizing Check Point QoS
- Lab 10: Configuring Check Point QoS Policy
Chapter 7: Basic SmartDefense and Content Inspection
- Introducing SmartDefense
- Network Security
- Application Intelligence
- Web Intelligence
- SmartDefense Services
- Content Inspection
- Lab 11: Configuring SmartDefense
- Lab 12: Configuring Web-Filtering and Antivirus Settings