Вы находитесь на странице: 1из 4

CCSA / CCSE Training Outline

CCSA
 Introduction to Check Point Technology
o Check Point Security Management Architecture(SMART)
o The Check Point Firewall
o Security Gateway Inspection Architecture
o Deployment Considerations
o Check Point Smart Console Clients
o Security Management Server
o Securing Channels of Communication
 Deployment Platforms & Introduction to the Security Policy
o Check Point Deployment Platforms
o Check Point Gaia
o Security Policy Basics
o Managing Objects
o Creating the Rule Base
o Rule Base Management
o Policy Management and Revision Control

 Monitoring Traffic and Connections


o Smart View Tracker
o Smart View Monitor
o Monitoring Suspicious Activity Rules
o Smart View Tracker vs. Smart View Monitor

 Network Address Translation


o Introduction to NAT
o Hid NAT
o Choosing the Hide Address in Hide NAT
o Static NAT
o Original Packet
o Reply Packet
o NAT Global Properties
o Object Configuration – Hid NAT
o Hide NAT Using Another Interface
o Static NAT
o Configuring Manual NAT

 Using Smart Update


o Smart Update Architecture
o Smart Update Introduction
o Overview of Managing Licenses
o License Terminology
o Upgrading Licenses
o Retrieving License Data from Security Gateways
o Adding New Licenses to the License & Contract Repository
o Importing License Files
o Adding License Details Manually
o Attaching Licenses
o Detaching Licenses
o Deleting Licenses From License & Contract Repository
CCSA / CCSE Training Outline

o Installation Process

 User Management and Authentication


o Creating Users and Groups
o Security Gateway Authentication
o User Authentication
o Session Authentication
o Client Authentication
o LDAP User Management with User Directory
 Introduction to Check Point VPNs
o VPN Deployments and Implementation
o VPN Topologies
o Special VPN Gateway Conditions
o Access Control and VPN Communities
o Integrating VPNs into a Rule Base
o Remote Access VPNs
CCSA / CCSE Training Outline

CCSE

 Lab Environment Setup


o Build the Management Server
o Build Gateways
o Install and configure NTP
o Upgrade to R70.1
o Establish SIC

 Management Portal
o Configure Management Portal on corporate site
o Test Management Portal access
o Configure Management Portal access on partner site
o Test Management Portal

 SmartWorkflow
o Create New Administrators
o Configure SmartWorkflow
o Open and Submit a Session for Approval
o Disapprove the Session and Request a Modification
o Approve the Session and Install the Policy
o Disable SmartWorkflow

 SmartProvisioning
o Enable SmartProvisioning
o Create New Profile
o Assign Profile to Gateways
o Verify Profile Changes

 SSL VPN
o Configure Connectra R66 Gateway
o Enable Connectra Gateway in SmartDashboard
o Create a file-share application in the SSL VPN tab
o Create an Internal User
o Assign file-share access to User Group
o Update Rule Base for DMZ traffic
o Verify file-share access through the User Portal
o Configure embedded RDP
o Shutdown and remove Connectra Server

 SecureXL
o Enable and Configure SecureXL on the Gateway
o Open connections and verify acceleration

 Deploying New Mode HA


o Create and configure a secondary cluster member
o Configure Gateway-Cluster object
o Configure ClusterXL properties
o Modify the Rule Base
o Pass traffic through the cluster
o Observe cluster status in SmartView Monitor
CCSA / CCSE Training Outline

o Perform test failovers

 Load Sharing Modes


o Configure Load Sharing Unicast mode
o Test Load Sharing Unicast mode
o Configure Load Sharing Multicast mode
o Test Load Sharing Multicast mode

 VPN with Sticky Decision Function


o Configure VPN in a Cluster
o View a packet capture of FTP connections without Sticky Decision function
o View a packet capture of FTP connections with Sticky Decision function

 Configure Check Point QoS Policy


o Enable and Configure Check Point QoS
o Create Check Point QoS Rules and adjust Rule weights
o Verify and install Policy
o Test QoS Policy

 Route-based VPNs with Static Routes


o Configure Gateway and VPN Community objects
o Add participating Gateway to Community
o Configure VTI’s on participating Gateways
o Add Static Routes for internal networks

 Eventia Analyzer
o Install the Eventia Suite on CG_Corporate
o Configure the network object in SmartDashboard
o Configure Eventia
o Monitor events with Eventia

Вам также может понравиться