
Learn checkpoint licensing for sandblast, including njt x versus njt licenses, cloud vs physical appliances, and how threat simulation, threat extraction, and api use hinge on the license.
Explore the three-tier checkpoint architecture (management server, gateway, sandblast) and identify essential ports for internal communication, web ui access, and ssh/https between components.
Explore deployment scenarios for checkpoint sandblast palmtop, mta https pennel, and inline https mail last—configure span interfaces on routers to inspect https and smtp traffic with threat extraction and emulation.
outline of topology for three labs shows a three-interface checkpoint gateway linking a 192.168.1.0 dns server and a 172.16.0.0 mail server, with static routes and cloud sandblast deployment.
Learn how to deploy checkpoint sandblast to protect web traffic with threat emulation and threat extraction, enable https inspection, configure threat prevention policy, and review logs and user checks.
Install a DNS server on a Windows server to resolve mail traffic addresses for the Sandblast lab, using a straightforward role-based installation via Server Manager with admin privileges.
Enable the mail transfer agent on the perimeter firewall and configure domain routing to a separate mail server, using threat emulation and threat extraction blades to protect mail traffic.
Configure sandblast mail threat prevention policy with MTA traffic, enabling threat emulation and extraction, manage infected mail handling, headers, notifications, and digital signature behavior.
Configure DNS for sandblast domain by creating a primary zone, mapping users to IP addresses, and setting a mail exchanger to route SMTP mail.
Set up a mail server and domain for sandblast on a Windows lab, enable smtp receiving and sending, and IMAP and POP3, then test threat extraction with Check Point logs.
Explore hybrid mode in Sandblast, splitting traffic between cloud and a private on-prem appliance to protect private files, with threat emulation analysis defaulting to cloud and customizable file-type locations.
Explore emulation connection handling in threat prevention, detailing background and hold modes, custom mode for web and email traffic, and the threat extraction safe copy via TX overthinks.
Deploy the Check Point endpoint client and Sandblast agent to understand threat extraction, emulation, full disk encryption, endpoint policy management, and the licensing and deployment workflow.
Deploy endpoint client using the initial 25 MB package, then configure Sandblast blades via a deployment policy. The process includes a 30-second heartbeat and remote access VPN licensing notes.
In this Sandblast course, we cover everything to start working with Check Point sandbox technology. The course includes detailed Lectures and 3 Labs that will fully cover SANDBLAST technology.
The following course includes lectures on how Check Point features work and the walk-through of the configuration in the lab/production environment. From the very beginning following step-by-step approach you will be able to grasp advanced concepts and step on the next level.
Lecture:
What is a Sandbox?
Types of Deployment
Licensing
Sandblast Appliances
Required Ports between Check Point components
How to PoC (Proof of Concept)
Lab1 Sandblast [WEB] :
Downloading ISO
Getting Evaluation license and installing it
Protecting Web Traffic with Sandblast (TE + TX + HTTPs inspection)
Lab2 Sandblast [Mail] :
Protecting MAIL traffic with Sandblast (TE+TX)
Hybrid Mode
(Includes the installation of DNS server, Mail Server, E-mail clients and MTA on Check Point device)
Lab3 Sandblast [Endpoint Security] :
Installing Endpoint Security [Part 1]
Installing Endpoint Security [Part 2]
IN THIS COURSE:
You are NOT learning disconnected skills
You learn how to stack your security sandboxing knowledge together in a single, unified whole
You get to see and learn how Sandbox (sandblast) is set up on real devices in various examples
I have applied the streamlined, step-by-step method to excel as a security professional in less time than you ever thought possible. I'm going to walk you through the main challenges in sandboxing, so you can step on the next level.