
Define a lab topology by creating four virtual machines with two network interfaces for a standalone gateway and two for encryption-domain machines, connected via LAN segments.
Learn how to obtain a checkpoint evaluation license from the support center, choose central licensing, attach it to your management server IP, and download the .link file for import.
We talk over what is a VPN, what is Site-to-Site and Client-to-Site types of connection and basic terminology of VPN world.
We discuss how the tunnel is being built, what is the Phase 1 and the Phase 2.
Full mesh Routing
Star Routing
Mixed Routing
We talk about what's Permanent tunnel.
The difference between Tunnel Test and Dead Peer Detection (DPD)
Also we discuss what's Active DPD and Passive DPD
What happens behind the scenes when you uncheck "Disable NAT inside VPN"
We talk over what is SA (Security Association) and what is SA lifetime.
What is NAT-T and where it lies in the 1st phase (IKE).
Configure .htdocs and httpd.conf in this Check Point VPN course lesson to master essential configuration practices.
Downloading and installing VPN agent
Configuring Remote Access in SmartConsole
Connecting to the External interface via our VPN agent
Issue:
I'm able to reach my internal interface of the Gateway. Traffic reaches the Ubuntu server, but I have no reply back to my Gateway.
Fix:
Using tcpdump on linux server and on Check Point gateway to figure out where the problem is.
A brief summary for your reference on the steps you have to take to set up Remote Access Client-to-Site connection.
Discover hub mode, which routes all client traffic through the gateway for encryption and inspection by checkpoint blades like application control, url filtering, and threat prevention.
Learn hub mode on a gateway, enable many-to-one hide nat for the 10.10.10.0 subnet, and implement automatic address translation on the external interface to reach the internet, verified by logs.
Discover SSL-based mobile access that lets you securely reach internal resources from any device via a browser, without installing a client, using web portals and network extender.
Connect to mobile access via browser with an external IP and VPN, using the same first-time config as capsule, and browse an internal workspace app.
Explore ipassignment.conf in mobile access office mode, learn the syntax to assign a gateway address as addr with a single ip or a range, and apply policy on the gateway.
Deploy a site-to-site IPsec VPN between two checkpoint gateways managed by separate management servers, define matching encryption domains and a mesh VPN, and enable perfect forward secrecy to establish tunnel.
Explore essential ipsec troubleshooting tools for checkpoint, including logs with filters to verify encrypted VPN traffic, tunnel status, packet-level diagnostics with IQ and VPN debug trunk, and winscp transfers.
Diagnose a vpn issue between separately managed gateways by using vpn debug trunk, collecting Ik logs, and verifying authentication (certificate or pre-shared secret) on both sides, then reconfigure and test.
The course is fully focused on VPN and contains 7 sections that fully cover IPsec and SSL . I show you how to build a lab in VMware workstation + in VPS
Also, you will learn a method, I've used over the years on how to troubleshoot VPN related connection issues
Expand your CCSA and CCSE knowledge
And even better, all subtopics build on top of each other
Which means if you work on them in the right order, you can shave years off of your learning curve.
And that’s exactly what we show you how to do inside Check Point VPN course
Also, instead of bogging you down with a bunch of boring and out-of-context lectures, I include a coherent step-by-step approach, which will lead you from the very beginning to the very essence of Check Point and VPN to get you start in that promising field
We will cover building Check Point lab in VMware and in a private VPS.
IPsec is explained and showed in great detail. Includes a lab on how to deploy IPsec from scratch between two firewalls. You will grasp concepts of Encryption Domain, IPsec Phase 1 and Phase 2, IPsec Routing, Permanent Tunnel (Tunnel Test and DPD), NAT inside VPN, SA lifetime, NAT-T
We install a great web application designed intentionally vulnerable, so security enthusiasts can pentest and hack the web application in order to gain knowledge.
Also we install XAMPP and I show you required configuration for your web application to work.
Includes: build VPN managed by 1 Management Server + build VPN managed by separate Management Servers !!!
Includes Mobile Access overview + SNX + Mobile Access Lab
Troubleshooting [Technique Overview and Practice] - You will Learn unique techniques to troubleshoot Check Point VPN connections like a PRO. ,Each packet of phase 1 and 2 is explained. Hone your troubleshooting skills on real examples.