Check Point Security Administration NGX I (R65)
Check Point Security Administration I NGX (R65) is a foundation course for Check Point’s flagship product, VPN-1 (NGX R65). This course provides an understanding of basic concepts and skills necessary to configure VPN-1. During this course, students will configure a Security Policy, and learn about managing and monitoring a secure network.
Course Objectives
Delegates attending this course will learn:
• How VPN-1 components and Check Point’s three-tier architecture works to secure your network
• How to perform command-line operations using Check Point’s SecurePlatform operating system
• How to back up critical files and directories, for availability and timely recovery of Security Gateways and SmartCenter Servers
• How to create objects and rules and modify a Security Policy’s properties
• How to use monitoring tools to track, monitor, and account for all connections logged by Check Point components
• How to configure network-bandwidth requirements and interpret the results
• How to use Network Address Translation to overcome IP addressing limitations
• How to verify the identity of users logging in to VPN-1 using authentication schemes
• How to implement LDAP, and integrate it with a SmartCenter Server
• How to protect organizations from known network attacks and entire categories of emerging or unknown attacks, using SmartDefense
• How to configure Web-filtering and antivirus settings on a Gateway to ensure traffic content is inspected for specific conditions.
Certification
This course meets the requirements for the Check Point Certified Security Administrator (CCSA) NGX R65 certification. A separate examination is available for those delegates who wish to have a formal qualification.
Target Audience
This course is designed for systems administrators, security managers, and network engineers who manages NGX R65 Security Gateway deployments
Prerequisites
Delegates should have basic networking knowledge, knowledge of Windows Server and/or UNIX, and experience with TCP/IP and the Interney
Topics covered
• Installing and configuring the SmartCenter Server
• Installing SecurePlatform Pro on the Security Gateway
• Configuring the Security Gateway using the WebUI
• Configure an interface as your management connection using the sysconfig utility
• Backing up a current configuration from the command line
• Create network objects
• Establish trust between a Gateway and SmartCenter Server
• Develop a network model using SmartMap
• Create a Policy Package to configure a Rule Base
• Enable Static NAT on a network
• Simulate a malicious network intrusion, and blocking the attack
• Enforce the Suspicious Activity Rule with SmartView monitor
• Create user templates and define users
• Test Client Authentication
• Configure SmartDirectory using Microsoft Active directory to authenticate users
• Configure QoS rules to support traffic-priority requirements
• Configure SmartDefense to detect port scans and successive multiple-connection attempts
• Configure Web Intelligence to detect a simple worm signature
Course duration: 3 Days
Price: £1795 + VAT
Check Point Security Admin Training Inverness, Aberdeen, Glasgow, Edinburgh, Dunfermline and other sites throughout the UK including onsite closed company courses are available.
Check Point Security Admin Training in Ghana, Nigeria and Qatar is also available.
SELECT wp_posts.*, wp_p2p.* FROM wp_posts INNER JOIN wp_postmeta ON ( wp_posts.ID = wp_postmeta.post_id ) INNER JOIN wp_p2p WHERE 1=1 AND ( ( wp_postmeta.meta_key = ‘start_date’ AND CAST(wp_postmeta.meta_value AS DATE) >= ‘2024-01-28’ ) ) AND ((wp_posts.post_type = ‘schedule’ AND (wp_posts.post_status = ‘publish’ OR wp_posts.post_status = ‘acf-disabled’))) AND (wp_p2p.p2p_type = ‘schedule_to_courses’ AND wp_posts.ID = wp_p2p.p2p_from AND wp_p2p.p2p_to IN ( SELECT wp_posts.ID FROM wp_posts WHERE 1=1 AND wp_posts.ID IN (538) AND ((wp_posts.post_type = ‘courses’ AND (wp_posts.post_status = ‘publish’ OR wp_posts.post_status = ‘acf-disabled’))) ORDER BY wp_posts.post_date DESC )) GROUP BY wp_posts.ID ORDER BY CAST(wp_postmeta.meta_value AS DATE) ASC
Checkpoint ngx r65 что такое


Chat
Phone
General
United States 1-800-429-4391
International +972-3-753-4555
Support
24×7 Technical Support
Americas: 1-972-444-6600
International: +972-3-6115100
Toll Free: 1-888-361-5030
Locations
United States
Check Point Software Technologies Inc.
959 Skyway Road
Suite 300
San Carlos, CA 94070
MAP
International
Check Point Software Technologies Ltd.
5 Ha’Solelim Street
Tel Aviv 67897, Israel
MAP
Check Point NGX R65 Security Administration
Read it now on the O’Reilly learning platform with a 10-day free trial.
O’Reilly members get unlimited access to books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.
Book description
- First book to market covering Check Point’s new, flagship NGX R65 Firewall/VPN
- Provides bonus coverage for Check Point’s upcoming NGX R65 Certification exams
- Companion Web site offers customized scripts for managing log files
Show and hide more
Table of contents Product information
Table of contents
- Copyright
- Technical Editor
- Assistant Technical Editor
- Contributing Authors
- 1. NGX R65 Operational Changes
- Introduction
- New SmartPortal Features
- Eventia Correlation Unit and Eventia Analyzer Server
- SmartView Tracker
- IPv6 Reporting
- DNS Implementation
- Remote License Management
- Eventia Reporter on Multiple Versions of SmartCenter Management
- Eventia Reporter and Analyzer Integration
- SmartDefense Profiles
- AMT Support
- Aggressive Aging
- Cooperative Enforcement
- Monitor-Only Deployment Mode
- Handling an Unauthorized Host
- Signature Updates
- Continuous Download
- Scanning Files
- Management Plug-In System
- Connectra Management
- Connectra Tab
- Provider-1 Support
- SmartView Monitor
- Understanding the New VPN Options
- Allowing Directional VPN Rules
- Allowing Backup Links and On-Demand Links
- Allowing Wire Mode VPN Connectivity
- Allowing Route-Based VPNs
- Allowing Permanent Tunnels
- Same Local IP and Cluster IP Address for VTIs
- Antispoofing for Unnumbered Interfaces on IPSO
- Dynamic Routing and VTIs
- Configurable Metrics for Dial-up Routes
- Interoperability between SecurePlatform and IPSO
- Route-Based VPN Improvements
- Customer-Defined Scripts for VPN Peers
- Route-Based VPN and IP Clustering Support
- RIM Performance Improvements on IPSO
- Interface Bonding
- Multicast Routing Failover Support
- New SmartPortal Features
- New FireWall-1/VPN-1 Features
- Edge Support for CLM
- Integrity Advanced Server
- New VPN Features
- ClusterXL
- Introduction
- SmartDashboard
- The SmartDashboard Log-in Dialog Box
- Key Components
- The Object Tree Pane
- The Rule Base Pane
- The Security Tab
- The NAT Tab
- The SmartDefense and SmartDefense Services Tabs
- The Connectra Tab
- Configuring SmartMap Display and Characteristics
- Log View Types
- The Log Tab
- The Active Tab
- The Audit Tab
- Configuring a Filter
- Query
- The SmartView Monitor Interface
- Gateway Status
- The System Information Tab
- The Network Activity Tab
- The Licenses Tab
- License Management
- Package Management
- CPInfo
- How It Works
- GUI and Basic Functionality
- Using the SecurClient Packaging Tool
- Creating an Installation Profile
- Generating the Package
- Installing the Connectra Management Plug-in
- Uninstalling the Connectra Management Plug-in
- cpconfig Configuration Options
- Licenses
- Administrator
- GUI Clients
- SNMP Extension
- Secure Internal Communication (SIC)
- Automatic Start of Check Point Modules
- SmartDashboard
- SmartView Tracker
- SmartView Monitor
- SmartUpdate
- SmartLSM
- The SecureClient Packaging Tool
- Management Plug-ins
- The Check Point Configuration Tool/cpconfig
- Introduction
- SmartCenter Installation
- Basic Configurations
- Installation Paths
- Common Installation Scenarios
- Install
- Uninstall
- Integrity Advanced Server
- Logging In
- The Rulebase Pane
- Security Tab
- Address Translation Tab
- SmartDefense Tab
- Web Intelligence Tab
- VPN Manager Tab
- QoS Tab
- Desktop Security Tab
- Web Access Tab
- Consolidation Rules Tab
- Network Objects
- Services
- Resources
- Servers and OPSEC Applications
- Users and Administrators
- VPN Communities
- FireWall Page
- NAT—Network Address Translation Page
- VPN Page
- VPN-1 Edge/Embedded Page
- Remote Access Page
- SmartDirectory (LDAP) Page
- Stateful Inspection Page
- Security Policy Rule Names and Unique IDs
- Group Object Convention
- Group Hierarchy
- Clone Object
- Session Description
- Tooltips
- Creating Your Administrator Account
- Hooking Up to the Gateway
- Reviewing the Gateway Object
- Defining Your Security Policy
- Policy Design
- Creating Rules
- Network Address Translation
- Installing the Policy
- Working with Security Policy Rules
- Section Titles
- Hiding Rules
- Rule Queries
- Searching Rules
- Object References
- Who Broke That Object?
- Object Queries
- What Would Be Installed?
- What’s Really Installed?
- No Security Please
- For the Anoraks
- Configuring Interspect or Connectra Integration
- SmartDefense Updates
- SmartUpdate Enhancements
- Connectra Tab
- SmartDashboard and SmartDefense Update
- Provider-1 Support
- SmartView Monitor
- SmartPortal Functionality
- Installing SmartPortal
- Tour of SmartPortal
- A Tour of the Dashboard
- New in SmartDashboard NGX
- Your First Security Policy
- Other Useful Controls on the Dashboard
- Managing Connectra and Interspect Gateways
- SmartPortal
- Introduction
- Authentication Overview
- Using Authentication in Your Environment
- Managing Users and Administrators
- Permissions Profiles
- Administrators
- General Tab
- Personal Tab
- Groups
- Admin Auth
- Admin Certificates
- General
- Personal
- Groups
- Authentication
- Location
- Time
- Encryption
- General
- Personal
- Groups
- Authentication
- Location
- Time
- Certificates
- Encryption
- Match by Domain
- Match All Users
- Undefined
- SecurID
- Check Point Password
- RADIUS
- TACACS
- Configuring SmartDirectory
- Account Units
- Accessing the LDAP Server
- LDAP Groups
- Configuring User Authentication in the Rulebase
- Interacting with User Authentication
- Telnet and rlogin
- FTP
- HTTP
- Placing Authentication Rules
- Changing the Banner
- Use Host Header As Destination
- Configuring Client Authentication in the Rulebase
- ClientAuth | Edit Properties | General | Source
- ClientAuth | Edit Properties | General | Destination
- ClientAuth | Edit Properties | General | Apply Rule Only if Desktop Configuration Options are Verified
- ClientAuth | Edit Properties | General | Required Sign-On
- ClientAuth | Edit Properties | General | Sign On Method
- Manual Sign-On
- Partially Automatic Sign-On
- Fully Automatic Sign-On
- Agent Automatic Sign-On
- Single Sign-On
- Check Point Gateway | Authentication
- Enabled Authentication Schemes
- Authentication Settings
- HTTP Security Server
- Failed Authentication Attempts
- Authentication of Users with Certificates
- Brute Force Password-Guessing Protection
- Early Versions Compatibility
- New Interface
- Use Host Header As Destination
- Opening All Client Authentication Rules
- Enabling Encrypted Authentication
- Custom Pages
- Authentication Overview
- Users and Administrators
- SmartDirectory
- User Authentication
- Session Authentication
- Client Authentication
- Introduction
- Encryption Overview
- IKE Overview
- Main Mode and Aggressive Mode
- Configuring Advanced IKE Properties
- IKE Policies
- Priority
- Encryption
- Hash Function
- Authentication Mode
- Digital Certificates (Using RSA Algorithms)
- Preshared Keys
- Diffie-Hellman Group
- Lifetime
- IKE SA Negotiation
- Remote Access Community
- Mesh Topology
- Star Topology
- VPN Routing
- Configuring VPN Routing for Gateways via SmartDashboard
- vpn_route.conf
- Virtual Tunnel Interfaces
- Numbered VTI
- Unnumbered VTI
- Routing
- Encryption Overview
- Configuring SecuRemote/SecureClient VPNs
- VPN Tunnel Interfaces (VTI)
- Introduction
- SecuRemote
- IP Pool NAT
- Desktop Policies
- Office Mode
- Visitor Mode
- Connection Profiles
- Windows L2TP Integration
- Backup Gateways
- Multiple Entry Point VPNs
- Userc.C
- SecuRemote
- SecureClient
- SSL Network Extender
- Introduction
- Configuring SmartDefense
- Updating SmartDefense with the Latest Defenses
- Denial of Service
- Aggressive Aging
- Teardrop Attacks
- The Ping of Death
- LAND Attacks
- Non-TCP Flooding
- Packet Sanity
- Max PING Size
- IP Fragments
- Network Quota
- SYN Attack Configuration
- Small PMTU
- Sequence Verifier
- ISN Spoofing
- TTL
- IP ID
- Retrieve and Block Malicious IPs
- Report to DShield
- Host Port Scan
- Sweep Scan
- Mail
- SMTP Content
- Mail and Recipient Content
- POP3/IMAP Security
- FTP Bounce
- FTP Security Server
- Allowed FTP Commands
- Preventing Port Overflow Checks
- File and Print Sharing
- Kazaa
- Gnutella et al.
- Yahoo!
- ICQ
- MSN over SIP
- Protocol Enforcement
- Domain Black Lists
- Cache Poisoning
- Scrambling
- Dropping Inbound Requests
- Detecting Mismatched Replies
- Important Capabilities
- H.323 Voice Protocol
- SIP Voice Protocol
- MGCP Voice Protocol
- SCCP Voice Protocol
- VoIP Enhancements
- Small IKE Phase II Proposals
- VPN Attack Prevention
- Important Capabilities
- Connectivity Implications of Specific Protections
- Malicious Code
- Application Layer
- Information Disclosure
- HTTP Protocol Inspection
- Monitor-Only Mode
- Protection for Specific Servers
- Variable Security Levels
- Configuring SmartDefense
- Application Intelligence
- Web Intelligence
- Introduction
- ClusterXL Overview
- The Cluster Control Protocol
- Legacy High Availability Mode
- New Mode High Availability Mode
- Load-Sharing Multicast
- Load-Sharing Unicast
- Monitoring the Cluster
- Resilience
- Nokia IPSO Clustering
- Crossbeam
- ClusterXL Overview
- Configuring ClusterXL
- Third-Party Solutions
- ISP Redundancy
- Introduction
- Installation
- Installation Using the NGX R65 CD
- Bootable Floppy and Network Installation
- Web User Interface
- Command Line Configuration
- Sysconfig
- Setting the Host Name
- Setting the Domain Name
- Setting the DNS Servers
- Expert Mode
- Useful Commands
- Backup and Restore
- Backup
- Restore
- Upgrade_export and Upgrade_import
- HFA Installation
- Installation
- Configuration
- SecurePlatform Shell
- Secure Shell
- SecurePlatform Pro
- Hot Fix Accumulators
- Introduction
- NGX Debugging
- SIC Troubleshooting
- snoop
- tcpdump
- fw monitor
- CPethereal and Wireshark
- Encryption failure, decrypted methods did not match rule
- Received notification from peer: no proposal chosen
- Cannot identify peer for encrypted connection
- Encryption failure: packet is dropped as there is no valid SA
- Encryption failure: Clear text packet should be encrypted or clear text packet received within an encrypted packet
- Encryption Failure: Packet was decrypted, but policy says connection should not be decrypted
- NGX Debugging
- Packet Analysis
- Log Troubleshooting
- VPN Analysis
- VPN Client Analysis
- ClusterXL Troubleshooting
Show and hide more
Product information
- Title: Check Point NGX R65 Security Administration
- Author(s): Ralph Bonnell
- Release date: August 2011
- Publisher(s): Syngress
- ISBN: 9780080558677
Check Point NGX R65 Security Administration


Check Point NGX R65 is the next major release of Check Point’s flagship firewall software product, which has over 750,000 registered users. Check Point’s NGX is the underlying security software platform for all of the company’s enterprise firewall, VPN and management solutions. It enables enterprises of all sizes to reduce the cost and complexity of security management and ensure that their security systems can be easily extended to adapt to new and emerging threats. This title is a continuation of Syngress’ best-selling references on Check Point’s market leading Firewall and VPN products. This is the first book in the market covering Check Point’s new, flagship NGX R65 Firewall/VPN. It provides bonus coverage for Check Point’s upcoming NGX R65 Certification exams. A companion website offers customized scripts for managing log files.
Full description
About the book
Full name Check Point NGX R65 Security Administration
Language English
Date of issue 2008
Number of pages 800
EAN 9781597492454
ISBN 1597492450
Libristo code 04241618
Publishers Syngress Media,U.S.
Weight 780
Dimensions 192 x 232 x 23
CategoriesGive this book today
It’s easy 1 Add to cart and choose Deliver as present at the checkout 2 We’ll send you a voucher 3 The book will arrive at the recipient’s address
- Backup and Restore
- Installation Using the NGX R65 CD
- VPN Routing
- IKE Overview
- SmartDefense Updates
- Section Titles
- Gateway Status