
Kindly download Step by step workbook for this course attached under this video Resources also the require Lab EVE-NG Images and topology .
Configure administrator accounts on the check point firewall, assign roles and authentication methods, and manage permissions with predefined roles like read only, read write, and superuser.
Configure administrator advanced options to lock out after three failed logins and unlock accounts. Restrict trusted clients by IP, range, or subnet, and set authentication, password length, and idle timeout.
Demonstrates certificate-based administrator login in the smart console by creating a cert admin, configuring a certificate, and logging in via certificate or certificate file without a password.
Explore https inspection by decrypting tls/ssl traffic with a local certificate, enabling forwarding and reverse proxies to act as a man-in-the-middle and inspect and block outbound and inbound traffic.
Perform a hands-on HTTPS inspection lab to configure the gateway, create and export a certificate, enable application control and URL filtering, and install the policy for verification.
Test and verify https inspection by using the test.local certificate on the PC, visiting Facebook and Twitter, and reviewing logs to confirm https inspection and bypass for financial sites.
Create and assign security zone objects (LAN, DMZ, WAN, management) to gateway interfaces, then build zone-based policies to simplify traffic between LAN, DMZ, and WAN.
discover how unified access control policy in Check Point firewall consolidates application, service, vpn, content awareness, and identity awareness rules into a single console, enabling centralized management and data control.
Apply explicit, stealth, cleanup, and management rules to control firewall traffic: explicitly configured allow/deny rules, top-placement stealth protections, default cleanup denial, and restricted management access.
Enable net, application control, and URL filtering, then design an access control policy with management, stealth, DNS, LAN to WAN, and DMZ rules, culminating in publishing and installing the policy.
Organize firewall rules by creating and naming sections to group them for easier management and filtering, then publish and install the policy to push changes from SMS to the gateway.
Explore how the user check feature enforces the organization security policy with banners and redirects, guiding users through inform, ask, notification, and approval actions across apps and blades.
Divide policies into order layers, network, application and URL, and content awareness, to simplify management and improve performance, with top-to-bottom rule evaluation and explicit and implicit cleanup at each layer.
Explore inline layers in firewall policy design, creating parent rules with sub rules and independent cleanup rules to organize management, stealth, DNS, and DMZ traffic for improved performance.
Enable threat prevention blades (ips, anti bot, antivirus) on the security gateway, publish the policy, and test with Nmap and necto using the default optimized policy.
Explore how cryptography protects network traffic in transit, explaining encryption and decryption, plaintext and ciphertext, encryption algorithms and keys, and symmetric vs asymmetric methods for confidentiality, integrity, and authentication.
Learn how hashing produces a fixed-size digest from data, using md5 or sha and hmac for integrity and authentication, with digests that reveal any modification.
Diffie-Hellman key exchange lets two parties derive a shared secret without sending the key. It enables secure site-to-site vpn, ipsec, ssh, and tls/ssl with elliptic curve and other groups.
Explore ipsec protocols for site-to-site and remote access vpn, covering confidentiality, integrity, authentication, anti-replay, and the differences between esp and authentication header, transport and tunnel modes.
Learn how IKE enables IPsec peers to negotiate security associations through ISAKMP, Oakley, and phases, with IKEv1 main mode and quick mode, and IKEv2 improvements.
Explore how virtual private networks create secure tunnels over the internet to protect private network traffic with IPsec and SSL, including site-to-site and remote access VPN.
Enable ipsec vpn blades on multiple security gateways to create encrypted site to site tunnels, using domain-based or route-based deployments and star or mesh topologies.
Configure the security management server in a site-to-site vpn topology using the first-time wizard, update the sms ip, dns, and time zone, then log in to finish setup.
Log in to the Gaia portal, edit network interfaces in network management, configure the HQ security gateway external and LAN interfaces, set the IPv4 static route, enable ping, and save.
Configure the BR-SG branch gateway ethernet and internal interfaces with IPs and masks, add comments and enable ping, then set the IPv4 default static route to 2.2.2.1 and save.
Download and install the smart console from the Gaia portal to manage software blades, such as ACL Net and VPN, then access the SMS from the management PC.
Add security gateways to SMS by configuring HQ and branch gateways in the smart console, entering IP addresses and activation keys, enabling monitoring blade, and publishing changes to install policy.
Configure hosts and the ISP router by setting static IPs, DNS, and gateways on PCs and servers. Establish router interfaces, enable internet access, and verify connectivity with pings.
Explore clustering and high availability concepts for gateways, emphasizing redundancy, failover, and fault tolerance across links and devices, with automatic switchovers using CCP heartbeat and cluster control protocol.
Explore load sharing and high availability with checkpoint cluster xl, examining new and legacy modes, multicast and unicast distributions, virtual ip and virtual mac, pivot roles, and ccp-based failover.
Perform sg-2 first time wizard to configure the security gateway, set ethernet zero ipv4 address with /24, adjust dns and time zone, and enable clustering before restart.
Configure SMS with time wizard by setting Ethernet zero IPv4 address and mask, log in, uncheck security gateway, and apply DNS (8.8.8.8 and 1.1.1.1) with Riyadh time, enable security management.
Configure three interfaces on the security gateway—ethernet one, ethernet two, and ethernet three—with their IPs and subnet masks. Set a static route to 172.29.129.254 and verify connectivity with ping.
Download the smart console from the Gaia portal to access the SMS, then log in with the SMS management IP 192.168.170. Check API status and start services to enable login.
Configure a two-gateway cluster in the smart console with high availability, add cluster members and interfaces, assign a virtual IP, enable net, verify interfaces, and install the policy.
Configure hosts pc1 and pc2 with the network manager, assign static IPs, set gateway and DNS, then connect and verify with ipconfig for the virtual IP.
Test high availability in a cluster xl setup between two security gateways by simulating failover and validating traffic reroutes when an interface goes down.
Become a skilled Check Point Security Administrator by mastering the installation, configuration, management, and troubleshooting of Check Point Security Gateways through practical, hands-on labs.
This comprehensive course is designed for IT administrators, network engineers, cybersecurity professionals, and anyone preparing for the Check Point Certified Security Administrator (CCSA) certification. Starting with the fundamentals, you will progressively build the knowledge and practical skills required to deploy and manage enterprise Check Point security environments.
Throughout the course, you will learn how to install, configure, secure, monitor, and troubleshoot Check Point Security Gateway and Security Management Server using real-world enterprise scenarios and laboratory demonstrations.
What You'll Learn
Understand Check Point architecture and core security concepts
Install and configure Check Point Security Gateway
Deploy Check Point Security Management Server
Build a complete Check Point lab using EVE-NG
Configure Security Policies and Access Control Rules
Create and manage Network Objects, Hosts, Networks, and Services
Configure NAT Policies
Manage Users, Groups, and Administrator Accounts
Configure Role-Based Administration and Permission Profiles
Integrate Check Point with enterprise environments
Configure Site-to-Site IPsec VPNs
Configure High Availability (ClusterXL) and Load Sharing
Monitor security events and system health
Configure Threat Prevention policies
Understand Application Control and URL Filtering
Generate logs, reports, and security audits
Perform system backup and restore
Troubleshoot common firewall and VPN issues
Apply security best practices for enterprise deployments
This Course Includes
Complete Check Point installation from scratch
Step-by-step configuration demonstrations
Hands-on enterprise lab exercises
Real-world deployment scenarios
Firewall policy configuration
NAT implementation
User and administrator management
VPN configuration
High Availability (HA) deployment
Threat Prevention configuration
Monitoring and logging
Backup and recovery
Troubleshooting labs
Downloadable lab resources and configuration examples
Course Curriculum
Introduction to Check Point Technology
Building the Lab Environment using EVE-NG
Check Point Architecture
Installing Security Gateway and Management Server
SmartConsole Overview
Objects Management
Security Policies
NAT Configuration
Administrator Accounts
Users and Groups
Identity Awareness
Site-to-Site VPN
ClusterXL High Availability
Load Sharing
Monitoring and Logging
Threat Prevention
System Backup and Restore
Troubleshooting Enterprise Deployments
Why Learn Check Point?
Check Point is one of the world's leading enterprise cybersecurity platforms, trusted by governments, financial institutions, healthcare organizations, service providers, and global enterprises to protect their networks, cloud environments, endpoints, and users.
Organizations rely on Check Point solutions to secure:
Enterprise Firewalls
Network Security
Cloud Security
Threat Prevention
Endpoint Security
Remote Access VPN
Data Security
IoT Security
Mobile Security
Advanced Malware Protection
Security Management and Compliance
Learning Check Point security technologies will help you develop highly sought-after enterprise firewall and network security skills.
Who This Course Is For
Network Engineers
Security Engineers
Firewall Administrators
System Administrators
SOC Analysts
IT Support Professionals
Cybersecurity Professionals
Check Point CCSA Certification Candidates
Anyone interested in enterprise firewall administration
Prerequisites
To get the most from this course, you should have:
Basic knowledge of computer networking
Basic understanding of TCP/IP and IP addressing
Familiarity with switching and routing concepts
Basic firewall knowledge is helpful but not mandatory
No prior Check Point experience is required, as every concept is explained from the ground up.
By the End of This Course
By completing this course, you will be able to confidently deploy, configure, administer, monitor, and troubleshoot Check Point Security Gateway and Security Management Server in enterprise environments. You will understand how to build secure firewall policies, implement VPNs, manage administrators and users, configure High Availability, monitor threats, and maintain secure production networks.
Whether your goal is to pass the Check Point Certified Security Administrator (CCSA) certification or to advance your career as a network security professional, this course provides the practical knowledge and hands-on experience needed to succeed.