Module 1: Introduction to Check Point R81 Architecture
Overview of Check Point products.
New features in version R81.
Module 2: Gaia Deployment: Installing Check Point Appliances
Introduction to the Gaia system.
Three-tier architecture elements.
Modular architecture of Software Blades.
Check Point Infinity.
Distributed and standalone architecture.
Management server. SIC protocol.
Hands-on exercises: Installation of Check Point R81.
Module 3: Security Management Server Management
Getting started with SmartConsole R81.
Security policy. Rule management.
Unified Policies.
Packet inspection.
Inline Policies (sub-rules).
Hands-on exercises: Installation of SmartConsole. Creating objects. Creating a security policy. Activating anti-spoofing.
Module 4: Network Address Translation (NAT)
Address translation rules with IPv4 and IPv6.
Static NAT (One To One NAT) and dynamic NAT (Many To One NAT)/PAT.
Manual NAT.
ARP and routing issues.
Hands-on exercises: Implementing automatic NAT of static type, Hide, and manual transaction rules.
Module 5: Visibility: Log Management, Monitoring, and Reporting
Log management policy.
Tracking connections with Logs & Monitor (formerly SmartView Tracker).
SmartView Monitor, features, and alert thresholds.
Hands-on exercises: Activating monitoring, using the Suspicious Activity Monitoring Protocol, traffic visualization, monitoring the security policy state.
Module 6: License and Multi-Site Management
License structure.
License management in SmartUpdate and SmartConsole.
Types of licenses.
Contract and service management.
Monitoring license status.
Policy Packages definition.
Policy Packages management.
Layer definition and types.
Packet inspection in an Ordered Layer.
Layer sharing (Policy Layers Sharing).
Module 7: Administrator Management
Permission Profiles.
Limiting administrators' scope of action.
Concurrent user management.
Session management.
Hands-on exercises: Creating a new Permission Profile with limited permissions.
Module 8: HTTPS Decryption
Rule creation.
Certificate management.
Server Name Indications (SNI).
Hands-on exercises: Implementing HTTPS inspection.
Module 9: Application Control / URL Filtering
Limitations of a traditional firewall by IP and port.
Access control.
AppWiki. URL Filtering.
User Check.
Hands-on exercises: Web and Application filtering: creating and sharing Web and Application Filtering policy as Inline Layer and Ordered Layer.
Module 10: User-based Policy / Threat Prevention
Need to retrieve user identity.
Identity Awareness R81 authentication methods.
Access Role objects.
Threat Prevention policy and its Software Blades.
Rule management.
Security profiles.
Autonomous Threat Prevention.