
Learn how assets—data, intellectual property, tangible property, and hardware—face vulnerabilities and exploits, and how threats and risk drive the need for countermeasures in ongoing security protection.
Explore firewall technologies and types—from packet-filtering to next-generation firewalls—covering stateful and stateless filtering, proxies, application control, deep packet inspection, cloud and UTM solutions.
Learn how a web application firewall protects web and mobile apps from injection attacks and cross-site scripting, beyond next-generation firewalls.
Explore how the next-generation firewall adds application ID, user ID, and content ID for application-level inspection and intrusion prevention. Enable user/group policies and content scanning to enforce security.
Explore Check Point's next generation firewall, the Chitwan Security Gateway, delivering network, cloud, and data security with features like application control, integrated management, and logging.
Explore the Check Point CCSA R80 certificate, covering installation of security gateways, distributed and standalone deployment, and configuring rules and policy. Also learn to manage administrators, permissions, and monitor activity.
Explore Check Point terminology: three-tier architecture with a security gateway, security management server, and smart console. Learn deployment options like distributed and stand-alone, plus routed or bridge modes and saic-based policy.
Install Check Point firewall on vmware workstation by downloading Gaia, creating a multi-interface VM (management, internet, LAN) with proper IP settings, and completing the first-time configuration wizard.
Download and install smart console (gui client) from the dashboard or checkpoint website, then connect to the firewall and configure blades from the centralized, graphical interface.
Demonstrates uploading the checkpoint firewall ISO to Eve Energy, creating a shared folder, copying and renaming the image, and performing the Gaia installation with the first-time configuration.
Upload the ready-made Check Point firewall image to eve-ng, drag it into the khemu folder, apply the fixed permission, and configure eth0 with your management subnet for first-time configuration.
Gaia unites Nokia IBS/IPS and Secure Platform into a linux-based operating system. It separates system settings (web UI) from security settings (smart console).
Log in to the Gaia portal via HTTPS to configure network, system settings, and blades. Use the search tool, navigation tree, and basic versus advanced modes for efficient management.
Explore smart console GUI client for Windows to manage security gateway and security management server, configure access control, threat prevention, and logs through an integrated policy and monitoring workflow.
Explore the architecture of checkpoint: security gateway, security management software, and smart console, and learn how policies are created in SMS on Gaia and pushed to gateways via SAIC.
Explore various Check Point deployment options, including distributed deployment, stand-alone deployment, routing, and bridge mode, plus clusterXL and management high availability for secure, scalable networks.
Demonstrate a standalone deployment topology for a Check Point firewall, detailing the dmz, lan, and management networks, and concrete interface IP schemes.
Perform the first time configuration for a standalone deployment by accessing the management IP, running the wizard, and setting IP, DNS, and time zone before using the Gaia portal.
Configure and enable four network interfaces—management, LAN, WAN, and DMZ—by assigning IPv4 addresses and verifying connectivity with show interfaces commands in the topology.
Configure a static default route by updating the gateway to 172.29.129.254 in the Gaia portal, then verify the route via CLI and ensure traffic routes to the internet.
Configure hosts in a standalone deployment by assigning IPs to servers and clients in the topology, including DMZ, and set gateway, DNS, and startup config in Docker.
Download and install smart console from Gaia Portal or Chitwan site. Log in, verify fingerprints, and manage blades, NAD, and access policies from smart console and Gaia Portal.
Configure a security policy in standalone deployment to let LAN and DMZ access the internet, publish and install the rule, and monitor logs for traffic.
Configure NAT policy in standalone deployment by creating LAN and DMZ network objects (192.168.1.0/24 and 192.168.2.0/24), enable hide NAT, and publish and install the policy.
perform testing and verification of the standalone deployment, validating topology, interfaces, hosts, and relevant policies; verify logs and internet access to google and facebook.
Configure a distributed deployment topology with a security gateway, a security management server, and a smart console across a three-tier LAN, DMZ, and management network, and follow the ip schema.
Configure a security gateway in a distributed deployment, guiding first-time setup, management IP assignment, and activation key entry, with security gateway only installation and browser-based access.
Configure security management in a distributed deployment by changing the sms IP, running the first-time configuration wizard, and accessing the gateway and sms via the smart console.
Implement a distributed deployment by configuring the security gateway’s four interfaces: lan, dmz, internet, and management. Assign static IPs, set the correct gateway, and validate connectivity with ping.
Configure distributed deployments with the smart console for Check Point firewall, install the smart console on Windows, access security management, and configure blades, ACLs, and policies.
Add security gateway to HMS in a distributed deployment, configure via smart console, establish trusted communication, and push the policy from the SMS to the gateway.
In distributed deployment part-7, configure security policy to allow LAN and DMZ traffic to the internet, create net objects, enable logs, and publish to the gateway.
Configure hosts on LAN and BMC by assigning management IPs—1.10 and 1.20 for LAN dockers, 2.10 and 2.20 for DMs—set DNS and gateways, then enable the firewall.
Test and verify distributed deployment in a Check Point firewall lab by validating PCIe one, DMZ, and internet connectivity, gateway reachability, DNS access, and policy logs.
Configure three vlans 10 20 30 in a lab topology with a security gateway and switches. Allocate subnets 192.168.10.0/24, 192.168.20.0/24, 192.168.30.0/24 and verify traffic via smart console.
Configure the first time setup for a standalone security gateway using the first time configuration wizard, set management IP, DNS, time zone, admin access, and security management.
Configure and enable interfaces in Gaia portal, create three vlan interfaces (10, 20, 30) with 192.168.1.1/24, 192.168.2.1/24, 192.168.3.1/24, and leave the physical interface without an IP.
Configure a static default route in the network management portal, set the gateway to 172.29.129.254, enable pings, save, and verify that traffic is routed to site B.
Configure three hosts for VLAN deployment across subnets 10, 20, and 30, assign IPs and gateways, and save configurations. Verify connectivity with ifconfig and route on each host.
Configure the switch for vlan deployment by creating three vlans, assigning interfaces 0/1, 0/2, and 0/3 to vlans 10, 20, and 30, and enabling trunking; verify with show commands.
Download and install the SmartConsole, log in to the security gateway and management server, and configure access rules, NAD rules, and security policies via the SmartConsole GUI.
Configure a security policy in vlan deployment part 8 to allow traffic by creating an access policy, enabling logs, and installing it to the security gateway, then ping to verify.
configure the nat policy by creating three network objects for vlan 10, 20, and 30 with their subnets, publish and install the policy to enable internet access.
Perform testing and verification in VLAN deployment part-10, inspect gateway logs, validate traffic, and confirm policy and net rules while accessing sites like Facebook and Wikipedia.
Explore bridge mode for checkpoint firewall, configuring two interfaces as a transparent layer 2 bridge within the same subnet, with lab setup, IP planning, and policy deployment.
Explore bond interfaces on Check Point devices, where multiple physical interfaces form a single virtual bond with a shared IP, enabling link aggregation via LCP and dynamic load balancing.
Learn to request a one-month evaluation license for Check Point security management and gateway. Create a user center account, enter the management IP, and download the license file.
Request and import an extended evaluation license in SG using smart console, smart upgrade, and licenses and contracts, then verify the license status in the portal.
Configure banner messages and the message of the day on Gaia Portal and Clia, understanding before login versus after login, default states, and how to enable or disable them.
Learn how the command line interface (cli) provides device control via console or smart console, alongside graphical access, and how to save configurations and use glitch shell and expert mode.
Learn the Check Point firewall command line interface basics, including four core operations—set, show, delete, and edit—plus saving, rebooting, and navigating command history and tab-completion for efficient management.
Learn command line interface keystrokes and feature commands, including ctrl navigation, word deletion, line movement, and using show command feature to access ARP, BGP, and dynamic URL options.
Learn the Check Point firewall clish command line interface by using show commands and feature keywords to locate backup, dns, clock, interface, and routing commands with status and logs.
Explore advanced cli commands for backup, snapshot, user creation, export, system shutdown, restart, rollback, and restoring local backups, plus configuring date/time, dhcp server, dns, interface ip, hostname, and timeouts.
Acquire the configuration lock to gain read/write access to the configuration database via Gaia portal or CLI; use log database and unlock database commands to switch access.
Explore expert mode in the command line to move from the restricted shell to a linux-based environment and run advanced firewall and system commands.
Explore how network address translation lets private ip addresses share a single public ip via source nat and destination nat, with static and automatic nat rules.
Explore automatic NAT versus manual NAT in the Check Point firewall, including hide net and static net configurations with original and translated sources, destinations, and services.
Describe the net lab topology with a dmz and lan, featuring live servers, an ftp server, and docker-based servers, plus a security gateway and smart console for distributed deployment.
Configure and verify automatic hide NAT to translate multiple internal addresses to a single external IP, with automatic rules and security policy, then test connectivity and review logs.
Configure automatic static NAT to publish a DMZ server using a public IP, create NAT rules and objects, publish policies, and verify bi-directional reachability.
Configure and verify manual hide NAT on a firewall by creating LAN and host objects, translating the LAN to a single IP, enabling manual proxy ARP, and deploying the policy.
Configure manual static NAT in the firewall by creating a DMZ server object and a public IP object. Set a bi-directional translation to the DMZ server and enable proxy ARP.
Learn how hairpin NAT enables internal users to reach internal DMZ servers via public IPs through a security gateway, with the top NAT rule applied first.
Configure and verify hairpin NAT in the firewall by routing a public IP through the DMZ to DMZ server 2, creating DMZ objects and security policies, and testing with logs.
Configure a no-net rule to prevent translation between LAN and DMZ when using private ranges, preserving original source and destination and reducing overhead.
Become a skilled Check Point Security Administrator by mastering the installation, configuration, management, and troubleshooting of Check Point Security Gateways through practical, hands-on labs.
This comprehensive course is designed for IT administrators, network engineers, cybersecurity professionals, and anyone preparing for the Check Point Certified Security Administrator (CCSA) certification. Starting with the fundamentals, you will progressively build the knowledge and practical skills required to deploy and manage enterprise Check Point security environments.
Throughout the course, you will learn how to install, configure, secure, monitor, and troubleshoot Check Point Security Gateway and Security Management Server using real-world enterprise scenarios and laboratory demonstrations.
What You'll Learn
Understand Check Point architecture and core security concepts
Install and configure Check Point Security Gateway
Deploy Check Point Security Management Server
Build a complete Check Point lab using EVE-NG
Configure Security Policies and Access Control Rules
Create and manage Network Objects, Hosts, Networks, and Services
Configure NAT Policies
Manage Users, Groups, and Administrator Accounts
Configure Role-Based Administration and Permission Profiles
Integrate Check Point with enterprise environments
Configure Site-to-Site IPsec VPNs
Configure High Availability (ClusterXL) and Load Sharing
Monitor security events and system health
Configure Threat Prevention policies
Understand Application Control and URL Filtering
Generate logs, reports, and security audits
Perform system backup and restore
Troubleshoot common firewall and VPN issues
Apply security best practices for enterprise deployments
This Course Includes
Complete Check Point installation from scratch
Step-by-step configuration demonstrations
Hands-on enterprise lab exercises
Real-world deployment scenarios
Firewall policy configuration
NAT implementation
User and administrator management
VPN configuration
High Availability (HA) deployment
Threat Prevention configuration
Monitoring and logging
Backup and recovery
Troubleshooting labs
Downloadable lab resources and configuration examples
Course Curriculum
Introduction to Check Point Technology
Building the Lab Environment using EVE-NG
Check Point Architecture
Installing Security Gateway and Management Server
SmartConsole Overview
Objects Management
Security Policies
NAT Configuration
Administrator Accounts
Users and Groups
Identity Awareness
Site-to-Site VPN
ClusterXL High Availability
Load Sharing
Monitoring and Logging
Threat Prevention
System Backup and Restore
Troubleshooting Enterprise Deployments
Why Learn Check Point?
Check Point is one of the world's leading enterprise cybersecurity platforms, trusted by governments, financial institutions, healthcare organizations, service providers, and global enterprises to protect their networks, cloud environments, endpoints, and users.
Organizations rely on Check Point solutions to secure:
Enterprise Firewalls
Network Security
Cloud Security
Threat Prevention
Endpoint Security
Remote Access VPN
Data Security
IoT Security
Mobile Security
Advanced Malware Protection
Security Management and Compliance
Learning Check Point security technologies will help you develop highly sought-after enterprise firewall and network security skills.
Who This Course Is For
Network Engineers
Security Engineers
Firewall Administrators
System Administrators
SOC Analysts
IT Support Professionals
Cybersecurity Professionals
Check Point CCSA Certification Candidates
Anyone interested in enterprise firewall administration
Prerequisites
To get the most from this course, you should have:
Basic knowledge of computer networking
Basic understanding of TCP/IP and IP addressing
Familiarity with switching and routing concepts
Basic firewall knowledge is helpful but not mandatory
No prior Check Point experience is required, as every concept is explained from the ground up.
By the End of This Course
By completing this course, you will be able to confidently deploy, configure, administer, monitor, and troubleshoot Check Point Security Gateway and Security Management Server in enterprise environments. You will understand how to build secure firewall policies, implement VPNs, manage administrators and users, configure High Availability, monitor threats, and maintain secure production networks.
Whether your goal is to pass the Check Point Certified Security Administrator (CCSA) certification or to advance your career as a network security professional, this course provides the practical knowledge and hands-on experience needed to succeed.