Check Point Firewall Administration R81.10+: A practical guide to Check Point firewall deployment and administration
Book information
Description
Improve your organization's security posture by performing routine administration tasks flawlessly Key FeaturesGet a gradual and practical introduction to Check Point firewallsAcquire the knowledge and skills necessary for effective firewall administration, maintenance, and troubleshootingCreate and operate a lab environment with gradually increasing complexity to practice firewall administration skillsBook Description Check Point firewalls are the premiere firewalls, access control, and threat prevention appliances for physical and virtual infrastructures. With Check Point's superior security, administrators can help maintain confidentiality, integrity, and the availability of their resources protected by firewalls and threat prevention devices. This hands-on guide covers everything you need to be fluent in using Check Point firewalls for your operations. This book familiarizes you with Check Point firewalls and their most common implementation scenarios, showing you how to deploy them from scratch. You will begin by following the deployment and configuration of Check Point products and advance to their administration for an organization. Once you've learned how to plan, prepare, and implement Check Point infrastructure components and grasped the fundamental principles of their operation, you'll be guided through the creation and modification of access control policies of increasing complexity, as well as the inclusion of additional features. To run your routine operations infallibly, you'll also learn how to monitor security logs and dashboards. Generating reports detailing current or historical traffic patterns and security incidents is also covered. By the end of this book, you'll have gained the knowledge necessary to implement and comfortably operate Check Point firewalls. What you will learnUnderstand various Check Point implementation scenarios in different infrastructure topologiesPerform initial installation and configuration tasks using Web UI and the CLICreate objects of different categories and typesConfigure different NAT optionsWork with access control policies and rulesUse identity awareness to create highly granular rulesOperate high-availability clustersWho this book is for Whether you're new to Check Point firewalls or looking to catch up with the latest R81.10++ releases, this book is for you. Although intended for information/cybersecurity professionals with some experience in network or IT infrastructure security, IT professionals looking to shift their career focus to cybersecurity will also find this firewall book useful. Familiarity with Linux and bash scripting is a plus. Table of ContentsIntroduction to Check Point Firewalls and Threat Prevention ProductsCommon Deployment Scenarios and Network SegmentationBuilding a Check Point Lab Environment – Part 1Building a Check Point Lab Environment – Part 2Gaia OS, the First Time Configuration Wizard, and an Introduction to the Gaia Portal (WebUI)Check Point Gaia Command-Line Interface; Backup and Recovery Methods; CPUSESmartConsole – Familiarization and NavigationIntroduction to Policies, Layers, and RulesWorking with Objects – ICA, SIC, Managed, Static, and Variable ObjectsWorking with Network Address TranslationBuilding Your First PolicyConfiguring Site-to-Site and Remote Access VPNsIntroduction to Logging and SmartEventWorking with ClusterXL High AvailabilityPerforming Basic Troubleshooting Cover Copyright Foreword Contributors Table of Contents Preface Part 1: Introduction to Check Point, Network Topology, and Firewalls in Your Infrastructure and Lab Chapter 1: Introduction to Check Point Firewalls and Threat Prevention Products Technical requirements Learning about Check Point's history and the current state of the technology "In the beginning, there was FireWall-1" Check Point today Understanding the Check Point product lineup and coverage Introducing the Unified Management concepts and the advantages of security product consolidation Familiarization with the Security Management Architecture (SMART) Determining how we learn Navigating the Check Point User Center Summary Further reading Chapter 2: Common Deployment Scenarios and Network Segmentation Technical requirements Understanding your network topology Common topology scenarios and exercises Learning about network segmentation User network segmentation North-South and East-West Protecting the core Protecting the perimeter Sizing appliances for new implementations and determining load on current systems Summary Further reading Chapter 3: Building a Check Point Lab Environment – Part 1 Technical requirements Lab topology and components Lab topology Lab components Downloading the prerequisites Downloading Oracle VirtualBox and the VirtualBox extension pack Downloading the Windows Server ISO Installing Oracle VirtualBox Installing the VirtualBox extension pack Deploying the VyOS router Summary Chapter 4: Building a Check Point Lab Environment – Part 2 Technical requirements Creating a Windows base VM Creating a Windows Server base VM in the GUI Windows Server base image scripted Finalizing the Windows Server base VM installation Creating a Check Point base VM Check Point base image scripted Finalizing the Check Point base VM installation Creating linked clones Preparing cloned Windows hosts Preparing cloned Check Point hosts Summary Part 2: Introduction to Gaia, Check Point Management Interfaces, Objects, and NAT Chapter 5: Gaia OS, the First Time Configuration Wizard, and an Introduction to the Gaia Portal (WebUI) Technical requirements Learning about Gaia's roots – a historical note Using the First Time Configuration Wizard Using the FTW for the primary management server First Time Configuration Wizard for gateways First-time configuration using the CLI Rerunning the FTW Introduction to the Gaia Portal (WebUI) Toolbar Navigation tree Widgets and status bar Summary Chapter 6: Check Point Gaia Command-Line Interface; Backup and Recovery Methods; CPUSE Learning about the Check Point Gaia CLI Introduction to Expert mode Configuring Gaia using CLISH Saving Gaia configuration, backups, snapshots, and migration tools Gaia OS-level configuration backup System backup Snapshots Server migration tools Saving and loading the configuration Saving the configuration to a file Loading the configuration Offline configuration editing and comparison Using CPUSE CPUSE in WebUI CPUSE in the CLI CPUSE in offline mode Summary Chapter 7: SmartConsole – Familiarization and Navigation Technical requirements Introduction to the SmartConsole application and Demo Mode Installing the SmartConsole application Initializing Demo Mode SmartConsole components, capabilities, and navigation Global toolbar Session management toolbar Objects bar and the Validations and Session panes Logged-in administrator's pending changes or publish status Management server(s) status and actions Task information area The WHAT'S NEW popup recall and management script CLI and API Summary Chapter 8: Introduction to Policies, Layers, and Rules Access Control policies, layers, and rules Policies Layers Rules Packet flows and acceleration Inspection chains Content inspection Best practices for Access Control rules Threat prevention exemptions Column-based matching APCL/URLF layer structure Actions and user interactions (UserCheck) Content Awareness Logs, tracking depth, and oddities Oddities – CPEarlyDrop and insufficient data passed Summary Chapter 9: Working with Objects – ICA, SIC, Managed, Static, and Variable Objects Working with objects Object categories Static and variable object categories Introduction to Internal Certificate Authority and Secure Internal Communication Internal Certificate Authority Secure Internal Communication Gateways and servers Activation keys Creating a gateway cluster Anti-Spoofing Creating networks and Host objects Networks Hosts Variable objects Dynamic objects Zones (conditional) Domains Updatable objects Access roles Variable objects in DevOps and DevSecOps Summary Chapter 10: Working with Network Address Translation The need for NAT NAT policies, rules, and processing orders Automatic NAT Automatic static NAT Automatic dynamic NAT Preventing unnecessary NAT When NAT is not enough Many-to-less Manual static NAT NAT pools Bells and whistles NAT logging Summary Part 3: Introduction to Practical Administration for Achieving Common Objectives Chapter 11: Building Your First Policy Defining the access control policy structure Creating rules for the firewall/networking layer Defining hosts for broadcast addresses Creating rules for DHCP traffic Configuring rules for noise suppression Configuring rules for core services Configuring rules for privileged access Rules that have corresponding entries with an empty threat prevention profile Configuring internal access rules Configuring DMZ access rules Configuring rules for access to updatable objects Configuring rules for probes Non-optimized rules Creating the APCL/URLF layer and rules Enabling APCL/URLF in the properties of the cluster Creating an outbound CA certificate for HTTPS inspection and enabling HTTPS Inspection in the properties of the cluster Configuring the HTTPS Inspection policy Distributing and installing the outbound CA and ICA certificates to the client machines Changing the website categorization to Hold mode Using Identity Awareness and access roles Preparing Active Directory for integration with Identity Awareness Enabling Identity Awareness and browser-based authentication Creating and using access roles Testing access role-based rules Summary Chapter 12: Configuring Site-to-Site and Remote Access VPNs An introduction to site-to-site VPN capabilities Configuring a remote gateway and creating its policy Building a site-to-site VPN using gateways managed by the same management server Star community – To center only Star community – To center or through the center to other satellites, to Internet and other VPN targets Changing portals’ URLs and renewing a gateway cluster certificate An introduction to Check Point remote access VPN solutions Configuring a remote access IPSec VPN Cloning a policy Creating local user templates, groups, users, and access roles Configuring a gateway or cluster for remote access Configuring global properties for remote access Configuring a VPN community for remote access Configuring access control policy rules for remote access Configuring a DHCP server for a remote access Office Mode IP range Preparing remote client Testing a remote access VPN Summary Chapter 13: Introduction to Logging and SmartEvent Logging into a single security domain Configuring logging on gateways or clusters Security management servers or log servers Logging with management high availability or log servers Strategies for the effective use of management high availability and log servers Smart-1 Cloud Introduction to SmartEvent Initial configuration Views Events Security incidents Reports Automatic reactions Summary Chapter 14: Working with ClusterXL High Availability ClusterXL in HA mode Virtual MAC Cluster member priority Network interfaces Critical devices Cluster Control Protocol, Full Sync, and routing synchronization Cluster member states Failover Edge cases Recovery ClusterXL HA failover simulations Manual failover test Catastrophic failure and recovery simulation Conclusion Alternative preferred HA options Summary Chapter 15: Performing Basic Troubleshooting Troubleshooting constraints and your actions Typical issues and the tools to solve them Troubleshooting prerequisites Stability issue troubleshooting example Troubleshooting intermittent issues Troubleshooting connectivity issues Service Requests – getting them right every time TAC and JHFAs Community resources and engagements Postmortems and lessons learned Summary Appendix: Licensing Licensing Containers and blades Licensing for gateways Licensing for management servers Central and local licenses License activation Offline activation Licensing options for hardware appliances Evaluation licenses for the lab SmartUpdate and additional information Other Books You May Enjoy
Similar books
Check Point Firewall Administration R81.10+: A practical guide to Check Point firewall deployment and administration
2022 · EPUB
OKB Sukhoi. A History of the Design Bureau and its Aircraft
1996 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF