Course Description
This two-day accelerated course is an in-depth class designed to give you the critical knowledge and hands-on experience that you need to implement the NGX R65 platform. The purpose of this course is to assist the participants in upgrading their current Check Point Security Expert (CCSE) certificate to CCSE - R65.
Certification
Exam #156-915.65
If you hold a current CCSE certification, passing exam #156-915 earns you Check Point Certified Security Expert NGX R65 (CCSE NGX R65) certification
Who Should Take This Course?
- You are a Check Point CCSE NG, or CCSE NG with Application Intelligence professional
- Want to earn Check Point Certified Security Expert (CCSE NGX R65) certification
Course Fee: $1,995
Course Prerequisites
- Check Point CCSA and CCSE - pre R65
- Knowledge of TCP/IP, Windows and or UNIX
- Knowledge of network technology and Internet
Course Objectives
After completion of this course, participants will learn
- How VPN-1 components and Check Point's three-tier architecture works to secure your network
- How to perform command-line operations using Check Point's SecurePlatform operating system
- How to use monitoring tools to track, monitor, and account for all connections logged by Check Point components
- How to configure network-bandwith requirements and interpret the results
- How to use Network Address Translation to overcome IP addressing limitations
- How to protect organizations from known network attacks and entire categories of emerging or unknown attacks, using SmartDefense
- How to configure Web-filtering and antivirus settings on a Gateway to ensure traffic content is inspected for specific conditions
- How to use SmartUpdate to add a package to an NGX Installation
- How to establish a VPN between two networks, encrypting traffic
- How to configure a Security Gateway for hybrid IKE SecuRemote connections
- How to test VPN-1 SecuRemote and Secure Server using the IKE encryption scheme
- How to configure an Office Mode IP pool
- How to connect and authenticate via Office Mode IP addressing using SecureClient
- How to deploy and test ClusterXL
- How to implement Office Mode
Course Outline
Chapter 1: Installing and Upgrading VPN-1
- Preinstallation Configuration
- Distributed Installation
- Upgrading to VPN-1 NGX R65
- VPN-1 Backward Compatibility
- Licensing VPN-1
- Performing License Upgrade
- Pre-Upgrade Considerations
- Upgrading SmartCenter Server
- Gateway Upgrade
- Lab 1: VPN-1 Distributed Installation
Chapter 2: Introduction to SecurePlatform
- SecurePlatform Hardware Requirements and Setup
- Using the Command Line
- Managing Your SecurePlatform System
- SecurePlatform Command Shell
- Lab 2: Configuring VPN-1 Using the CLI
Chapter 3: SmartUpdate
- Upgrading Packages
- Managing Licenses
- Lab 3: Creating Objects, Establishing Trust and Configuring SmartMap
- Lab 4: Configuring the Security Policy
Chapter 4: Monitoring Traffic and Connections
- SmartView Tracker
- Blocking Connections
- SmartView Monitor
- Eventia Reporter
- Lab 5: Blocking Intruder Connections
- Lab 6: Configuring Suspicious Activity Rule in Smart View Monitor
Chapter 5: Basic SmartDefense and Content Inspection
- Network Security
- Application Intelligence
- Web Intelligence
- SmartDefense Services
- Content Inspection
- Lab 7: Configuring SmartDefense
- Lab 8: Configuring Web-Filtering and Antivirus Settings
Chapter 6: Site-to-Site VPNs
- Site-to-Site VPN
- VPN Tunnel Management
- Wire Mode
- Directional VPN Enforcement
- Multiple Entry Point VPNs
- Traditional Mode VPNs
- Lab 9: Two-Gateway IKE Encryption (Shared Secret)
Chapter 7: Remote Access VPNs
- Remote Access VPN
- Office Mode
- Office Mode Planning
- Desktop Security Policy
- VPN Routing - Remote Access
- SSL Network Extender
- Clientless VPN
- Lab 10: Configuring Remote Access in an IKE VPN
- Lab 11: Remote Access and Office Mode
Chapter 8: High Availability and Cluster XL
- Management High Availability
- ClusterXL
- ClusterXL Modes
- Synchronizing Cluster
- Sticky Connections
- CPHA Commands
- Debugging ClusterXL Issues
- Lab 12: Deploying New Mode HA