
Explore Check Point ccsa firewall training r81, covering installation, management server setup, firewall deployment, security policies, nat, advanced features, authentication, vpn, and cli essentials.
Learn about Check Point certificates, including Security Administrator, Security Expert, and Security Master, along with CCSA and CCSE pathways, exam codes, fees, and upcoming R81 updates.
Explore the example lab topology, install the management server and firewall, and add the firewall to the management server in the distributed deployment model using vmware workstations.
Install the management server in a vmware lab, configure vm settings and network, install Gaia, then set up web access and install the smart console to connect to the server.
Install a checkpoint r81 firewall in VMware ESXi and configure Istanbul Firewall VM with wan, lan, and dmz vlans; access Gaia at 172.16.0.254 to set interfaces and the default route.
Add the Istanbul Firewall to the management server using wizard mode, set 172.16.0.254 and the secure internal communication password, then publish changes and install the policy.
Set up a home lab in VMware Workstation to practice Check Point CCSA R81, configuring standalone or distributed deployments, VM nets, and firewall with a management server.
Create and publish a security policy rule in the smart console to allow Admin PC 172.16.0.144 access to Istanbul Firewall and management server on http, https, and ssh (version 2).
Create zone-based security policies by defining security zones and network objects, then apply zone-based rules to map wan and multiple lan interfaces to inside, outside, and dmz zones.
Design and publish a time based security policy to block 08:00–18:00 traffic between inside and outside zones, while placing the time rule above the allow rule to enforce it.
Organize firewall rules with section titles and inline layers, using parent and child rules to create distinct policy layers and per-layer clean-up rules for precise traffic control.
Configure dynamic NAT to translate private 172.16.0.0 and 10.1.0.0 subnets to the firewall's public IP 44.34.0.1, enabling internet access and logging traffic from Istanbul firewall.
Configure static NAT to map external 44.34.0.100 to internal 10.1.0.100 for a web server. Create a host object, set a destination NAT rule, publish, install policy, and verify traffic logs.
Configure manual nat to forward requests from the firewall wan ip 44.34.0.1 port 80 to the web server 10.1.0.100. Create and publish the nat rule, install policy, and verify logs.
Discover Check Point features and software blades, modular firewall components activated with a click to tailor firewall, VPN, IPS, application control, URL filtering, antivirus, and identity-based policies.
Enable https inspection to decrypt and inspect tls traffic using a certificate as an intermediary. Configure bypass rules by category, publish changes, install certificates, and monitor https inspection logs.
Enable the URL filtering blade, publish and install policies. Create rules to block sites by categories and custom apps, including adult content, with HTTPS inspection and regex support.
Enable the application control blade, publish and test a policy to block specific apps like Skype and Facebook video, review logs, and fine-tune access control on the firewall.
Enable anti-spoofing on the firewall to prevent IP address manipulations, DHCP snooping, and man-in-the-middle attacks. Default mode is prevent, with options to exclude specific IPs, subnets, or hosts from anti-spoofing.
Add an Ankara firewall to the management server by configuring static NAT and access rules, publish policies to Istanbul and Ankara, and verify internet access for Ankara users.
Create and manage multiple policy packages for separate firewalls, assigning installation targets to Ankara and Istanbul, and upload and install DNS and internet rules across them.
Explore Check Point's ClusterXL high availability to achieve redundancy and load sharing for security gateways and VPN connections, with active/passive or active/active setups, state synchronization, and a virtual IP.
Learn to add an LDAP server to your Check Point firewall, create an LDAP account unit, configure Active Directory details, and publish policy updates to enable user-based security policies.
Activate the identity awareness blade, configure browser-based captive portal authentication with Active Directory, enforce user-based policies, and verify detailed logs of user access.
Enable Identity Awareness with the agent software through Captive Portal, download and install the Identity Agent, authenticate users to access the internet, and review logs to verify policy deployment.
Manage users and roles on the management server web interface by creating users, assigning admin, monitor, or junior roles, and restricting access via IP addresses and password policies.
Explore how IPsec VPN enables site-to-site connections with security gateways, encrypting traffic, using VPN communities with star or mesh topologies and features like privacy, authentication, data integrity, and anti-replay.
Configure IPsec site-to-site VPN across firewalls by enabling IPsec blades, defining VPN domains and subnets, setting VPN peers, and creating a mesh VPN community.
Monitor vpn tunnels with Smart View after configuring site-to-site IPsec, verify tunnel status across Izmir, Istanbul, Ankara, and Malatya, and observe encrypted IPsec traffic and tunnels up.
Learn to configure firewall or management server interface IPs via the command line, connecting with Open Shell or SSH, viewing interfaces, and saving changes to implement IPv4 addresses and masks.
Learn to change the firewall's secure internal communication password via CLI and smart console on Izmir, then remove and reinstall a policy package using CLI and management server.
Change the web ui port using the command line, verify with show web sslport, set web ssl-port 4443, save, install policy, and test access via https with port 4443.
Learn to back up and restore firewall configurations using the command line interface and web user interface, create backups with the add backup local command, and restore from backups.
!!! YOU CAN GET DISCOUNT CODES FOR ALL MY TRAININGS FROM MY WEBSITE !!!
Check Point Certified Security Administrator | In the CCSA R81 training, you will learn the installation and management of Check Point Management Server and Security Gateway (Firewall) with step-by-step lab applications over the sample topology.
By taking this course, you will be able to pass the Check Point Certified Security Administrator CCSA exam easily.
To attend the training, you must have basic system and network knowledge. I recommend that you have received Cisco CCNA training. If you have not received Cisco CCNA training, I recommend that you take this training first among my trainings.
In this training, we have a total of 8 sections and 33 lessons. In the first part of the training, we will talk about the training content and Check Point certificates. In the second part, we will cover the installation and basic settings issues. In the third part, we will make examples for security policies. In the fourth chapter, we will cover Network Address Translations. In the fifth chapter, we will cover topics such as URL Filtering, Application Control, Anti Spoofing, Multiple Policy creation and High Availability. In the sixth chapter, I will tell you about the identity control issues. In this section, I will explain how to add LDAP Server, Captive Portal and Agent software and how to do limit control. In the seventh chapter, we will deal with Virtual Private Network (VPN). In the last section, we will cover device management and maintenance. We will finish our course by explaining topics such as making Interface settings using CLI, changing the Secure Internal Communication password using CLI, Backup and Restore.
I tried to convey this training to you in the best way with my 24 years of experience in the sector. I had a lot of fun while preparing the training, I have no doubt that you will enjoy watching it too.
In order to provide you with the best sound and image quality, I used a quality microphone and HD camera while shooting.