
Set up EVE-NG in Google Cloud by creating a project, building a nested image, launching a VM, and installing EVE-NG, using Google Cloud credits for hands-on practice.
Install the checkpoint firewall in a three-tier setup with a management server and gateway, and create a checkpoint user center account to access a 30-day product evaluation.
Create the directory and establish an association connection, then upload the downloaded checkpoint image via Forcillo to the designated location, forming a three-tier topology with a management server and gateways.
Rename the uploaded checkpoint ISO, set up separate management and gateway directories, and copy the image for a three-tier checkpoint firewall topology, then prepare a Windows 10 image for deployment.
Learn to add a management checkpoint for CheckPoint CCSA R80 by creating a virtual hard disk, installing GUYA OS, and configuring the management interface IP.
Connect to the management server and install the smart console on windows, then centrally configure and manage checkpoint gateways from a single interface, including siac setup and password reset.
Publish your configuration to share changes with admins and enable policy installation on gateway gw1. Monitor installation status and cpu usage as the gateway applies updates.
Add a second gateway and switch, configure CBW interfaces with 10.1.0/24 and management IPs, save the configuration, and verify connectivity while noting that ping is blocked by default.
Learn to enable https by creating a security policy that permits management traffic from the management host to the gateway, install the policy, and access the web GUI.
Configure the topology to access firewall two by adding a Windows device, set new IP addresses and a static route, and update the firewall security policy to permit traffic.
Learn to configure a default route on a checkpoint gateway to forward traffic from the 10.1.2.0/24 network to gateway 20, including editing static routes and verifying with ip config.
Learn to create security policies by defining network and host objects, using the smart console, publishing and installing rules, and validating logs for stateful traffic.
this lecture demonstrates adding a second checkpoint gateway to the management server, configuring the default gateway and static routes, and publishing an updated security policy via the smart console.
Explore security zones and how to implement zone-based policies in Check Point, including inside, outside, and DMZ configurations, interface assignment, and logging of zone-to-zone traffic.
Create time objects and apply them to a security policy to permit traffic only within defined daily windows, such as midnight to noon and noon to midnight.
Organize firewall rules with sections and inline layers, creating management, headquarters, and cleanup policies. Define parent and child inline sub-policies to control and log traffic between checkpoints.
Explore how multiple smart console users collaborate on a checkpoint firewall. Use publish and lock indicators to manage concurrent edits, create user accounts, and publish changes to the management server.
Publish and install firewall policies across gateway devices by using policy targets, attach interfaces to zones, and verify inside and outside traffic rules on multiple gateways.
Explore how checkpoint firewall uses nat to map private addresses to a public ip, including static one-to-one and hide nat with icmp verification.
How to Add Linux Ubuntu Webmin:
https://www.eve-ng.net/index.php/documentation/howtos/howto-create-own-linux-host-image/
How to change Linux Ubuntu Webmin Port Number:
https://www.iodocs.com/change-webmin-port-using-terminal/
Configure static one-to-one nat on a Linux server via a checkpoint gateway, set inbound policies, and verify public-to-private translation using the smart console.
DMZ is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted, usually larger, network such as the Internet. The purpose of a DMZ is to add an additional layer of security to an organization's local area network (LAN): an external network node can access only what is exposed in the DMZ, while the rest of the organization's network is firewalled
Configure a site-to-site IPsec VPN between two checkpoint firewalls by enabling IPsec, creating a mesh VPN community, defining encryption and integrity settings, and applying site-to-site policies.
Verify a secure vpn connection by ensuring icmp is allowed in global properties, set to before last, then monitor vpn status and tunnels via SmartView using logs and keys.
Explore the vpn tunnel utility to view IP security associations between Checkpoint firewalls, delete IP security associations, and rebuild tunnels by generating traffic.
Configure and enable SCDP inspection on checkpoint gateways, create a certificate, and apply inbound and outbound HTTPS inspection policies to test traffic from a device to a Linux server.
Explore high availability (HA) concepts for management servers and security gateways, including multi-domain server HA with active/standby roles and ClusterXL with virtual IP and state synchronization.
Explore how bot infections use attachments, websites, and command-and-control networks to steal data, spawn spam, or launch denial-of-service, and how checkpoint threat prevention detects them.
Explore how Check Point antivirus inspects internet traffic, scans downloads and files in real time, blocks malware, and uses threat cloud, binary signatures, and file types.
Explore the checkpoint firewall command line interface with show commands and tab completion to view interfaces, their state and IP addresses, then configure with set interface and save config.
Understand how the command line interface enforces a single configuration lock on a checkpoint firewall, who holds it, and how to acquire, override, or release it.
Explore how to use the Sepi view to monitor cpu usage, view historic data by timestamp, and inspect cpu, memory, network, and disk space stats for pinpointing performance spikes.
CheckPoint CCSA R80 Complete Course will start from scratch by teaching student how to deploy Check Point firewall and Management Servers in EVE-NG and Google Cloud Services. By completing this training, network administrators will be better prepared to advance into roles that lead to higher-level network administrator and security positions. This course is intended for anyone who manages a company’s Check Point or security training, this CCSA R80 training can be used for 156-215.80 exam prep, for on-boarding new network administrators, or as part of a team training plan.