版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、Check Point Certified Security AdministratorIntroduction to Check Point TechnologyDeployment PlatformsIntroduction to the Security PolicyMonitoring Traffic and ConnectionsUsing SmartUpdateIntroduction to Check Point VPNs CCSA Course Chapters3 Lab Topology4Introduction to Check Point TechnologyThe Op
2、en Systems Interconnect (OSI) ModelTo better understand the capabilities of the basic firewall, understand the OSI model.8-9Introduction to Check Point TechnologyControlling Network TrafficCheck Point utilizes these technologies to deny or permit traffic, based on defined rules:Packet FilteringAppli
3、cation IntelligenceStateful Inspection10Introduction to Check Point TechnologyPacket FilteringPacket Filtering is a firewall in its most basic form10-11Introduction to Check Point TechnologyStateful InspectionStateful Inspection examinees the context of a packet to monitoring the state of the connec
4、tion:12Introduction to Check Point TechnologyApplication IntelligenceApplication Intelligence works with application-layer defense:13Introduction to Check Point TechnologySecurity Gateway Inspection Architecture13Introduction to Check Point TechnologyINSPECT Engine Packet FlowSample flow of new inbo
5、und packet:14-15Introduction to Check Point TechnologyDeployment ConsiderationsThe Security Gateway must be aware of the layout of the network.16Introduction to Check Point TechnologyThe DMZAll externally accessible servers should be located in the DMZ.17Introduction to Check Point TechnologyBridge
6、ModeBridge mode allows a transparent deployment of a Check Point Security Gateway.18Introduction to Check Point TechnologySecurity Policy ManagementCheck Point provides for security across critical layers of network19Introduction to Check Point TechnologySmartConsole ComponentsSmartConsole is compri
7、sed of several software modules.20Introduction to Check Point TechnologySmartDashboardTabs:FirewallNATIPSApplication ControlAnti Spam & MailMobile AccessDLPAnti Virus & URL FilteringIPSec VPNQoSDesktop20-21Introduction to Check Point TechnologySmartEventEvent correlation for firewall, IPS, DLP, endp
8、oints via a single console.22Introduction to Check Point TechnologySmartEventCentralized Event CorrelationReal-Time Threat Analysis and ProtectionIntelligent Event Management24Introduction to Check Point TechnologySmartEvent ArchitectureSmartEvent has several components that work together to help tr
9、ack down security threats and make your network more secure.24-25Introduction to Check Point TechnologySmartUpdateSmartUpdate is used to manage and maintain a license repository, as well as to facilitate upgrading Check Point software.27Introduction to Check Point TechnologySmartView MonitorSmartVie
10、w Monitor is used to monitor and generate reports for traffic on different Check Point components.27-29Introduction to Check Point TechnologySmartView TrackerSmartView Tracker is used for managing and tracking logs and alerts.30Introduction to Check Point TechnologySecurity Management ServerThe Chec
11、k Point Security Management Architecture (SMART) is a core.31Introduction to Check Point TechnologyManaging Users in Smart DashboardObjects Tree and the Users and Administrators.31Introduction to Check Point TechnologyCreating Administrators in SmartDasboardUsers and Administrators.32-33Introduction
12、 to Check Point TechnologySecuring Channels of CommunicationCommunication must be encryptedCommunication must be authenticatedTransmitted communication should have data integritySIC setup process allowing the munication to take place must be user friendly34Introduction to Check Point TechnologySIC B
13、etween Security Management Servers and Components SIC among Security Management Servers and components36-37Deployment Platforms39Deployment PlatformsGiven network specifications, perform a backup and restore the current Gateway installation from the command line.Identify critical files needed to pur
14、ge or backup, import and export users and groups and add or delete administrators from the command line.Deploy Gateways using sysconfig and cpconfig from the Gateway command line.Learning Objectives39Introduction to Check Point TechnologyIPSO and SecurePlatform are now being replaced with GAiA.GAiAI
15、ntroduction to Check Point TechnologyGAiAIPSOSecurePlatformCore operating systemFreeBSDRed Hat Enterprise LinuxRed Hat Enterprise LinuxConfiguration architectureCentralizedDistributedCentralizedCommand line shellclishcpshellSupershellUser InterfaceVoyagerWeb UIGaia PortalClusteringVRRP andIP Cluster
16、ingClusterXLVRRP and ClusterXLIntroduction to Check Point TechnologySupport all Check Point appliance linesSupport all major open servers in the marketProvide all of SecurePlatforms featuresProvide IPSOs most in-demand featuresUnify multiple distributions into a single software distributionProvide a
17、 foundation for the next decade of appliances and serversGAiA GoalsIntroduction to Check Point TechnologyCoreXL introduces advanced core-level load balancing that increases throughput for the deep inspectionCoreXL54-55Introduction to Check Point TechnologyCoreXL is configured via expert modeWorking
18、with CoreXL57Introduction to the Security Policy61Introduction to the Security PolicyGiven the network topology, create and configure network, host and gateway objects.Verify SIC establishment between the Security Management Server and the Gateway using SmartDashboard.Create a basic Rule Base in Sma
19、rtDashboard that includes permissions for administrative users, external services, and LAN outbound use.Configure NAT rules on Web and Gateway servers.Evaluate existing policies and optimize the rules based on current corporate requirements.Maintain the Security Management Server with scheduled back
20、ups and policy versions to ensure seamless upgrades and minimal downtime.Learning Objectives62Introduction to the Security PolicyThe Security Policy is a set of rules that defines your network security.Security Policy Basics63Introduction to the Security PolicyManaging Objects in SmartDashboard64Int
21、roduction to the Security PolicyNetwork ServicesResourcesServers and OPSEC ApplicationsUsers and AdministratorsVPN Communities Object Types72Introduction to the Security PolicyThe Objects Tree is the main view for managing objectsManaging Objects66Introduction to the Security PolicyClassic ViewGroup
22、 View.Changing Objects Tree View67Introduction to the Security PolicyEach rule in a Rule Base defines the packets that match the rule.Creating the Rule Base69Introduction to the Security PolicyThe Default Rule is added when you add a rule to the Rule Base.Default Rule70Introduction to the Security P
23、olicyTwo basic rules used by nearly all Security Gateway Administrators Cleanup ruleStealth RuleBasic Rules71Introduction to the Security PolicyImplicit/Explicit Rules72Introduction to the Security PolicyControl ConnectionsThere are three types of Control Connections, defined by default rules:Gatewa
24、y specific trafficAcceptance of IKE and RDP traffic Communication with various types of servers73Introduction to the Security PolicyDetecting IP SpoofingSpoofing is where an intruder attempts to gain unauthorized access by altering a packets IP address.74Introduction to the Security PolicyRule Base
25、ManagementBefore creating a rulebase:Which objects are in the network?.Which user permissions and authentication schemes are needed?Which services, including customized services and sessions, are allowed across the network?75Introduction to the Security PolicyRule Base OrderIP spoofing/IP optionsFir
26、stExplicitBefore LastLastImplicit Drop76Introduction to the Security PolicyPolicy Management and Revision Control78-79Introduction to the Security PolicyNetwork Address TranslationHide NAT81-82Introduction to the Security PolicyStatic NATStatic NAT83Introduction to the Security PolicyGlobal Properti
27、esAllow bi-directional NATTranslate Destination on client sideAutomatic ARPMerge manual proxy ARP84-85Introduction to the Security PolicyObject Configuration Hide NAT86Introduction to the Security PolicyObject Configuration Hide NATAddress translation rules are divided into two elementsOriginal Pack
28、etTranslated Packet87Introduction to the Security PolicyObject Configuration Hide NAT88-89Introduction to the Security PolicyManual NATInstances where remote networks only allow specific IP addresses.Situations where translation is desired for some services, and not for others.Environments where mor
29、e granular control of address translation in VPN tunnels is needed.Enterprises where Address Translation Rule Base order must be manipulated.When port address translation is required.Environments where granular control of address translation between internal networks is required.When a range of IP a
30、ddresses, rather than a network, will be translated.90Monitoring Traffic and Connections95Monitoring Traffic and ConnectionsUse Queries in SmartView Tracker to monitor IPS and common network traffic and troubleshoot events using packet data.Using packet data on a given corporate network, generate re
31、ports, troubleshoot system and security issues, and ensure network functionality.Using SmartView Monitor, configure alerts and traffic counters, view a Gateways status, monitor suspicious activity rules, analyze tunnel activity and monitor remote user access based on corporate requirements.Learning
32、Objectives96Monitoring Traffic and ConnectionsSmartView Tracker97Monitoring Traffic and ConnectionsSmartView Tracker Log TypesPredefinedCustom97-98Monitoring Traffic and ConnectionsSmartView Tracker TabsNetwork & EndpointActiveManagement99Monitoring Traffic and ConnectionsSmartView Tracker Action Ic
33、ons100Monitoring Traffic and ConnectionsLog File ManagementOpen Log FileSafe Log File AsSwitch Log FileRemote File ManagementShow or Hide ProgressQuery Options101Monitoring Traffic and ConnectionsAdministrator AuditingAdministrator login and outObject creation, deletion, editsRule Base changes102Mon
34、itoring Traffic and ConnectionsGlobal Logging and AlertingVPN successful key exchangeVPN packet handling errorsVPN configuration and key exchange errorsIP Options dropAdministrative notificationsSLA violationsConnection matched by SAMDynamic Object resolution failureLog every authenticated HTTP conn
35、ectionLog VoIP connection103Monitoring Traffic and ConnectionsGateway StatusStatus Information:Check Point GatewaysOPSEC GatewaysCheck Point Software Blades117Monitoring Traffic and ConnectionsOverall Status / Blade StatusOK Working properly Attention Minor problemProblem - MalfunctionWaiting 30 sec
36、ond connection periodDisconnected no communicationUntrusted SIC failed119-120Monitoring Traffic and ConnectionsSmartView Tracker vs. SmartView MonitorSmartView TrackerEnsure network components are operating properlyTroubleshoot system and security issuesGather information for legal or audit purposes
37、Generate reports to analyze network-traffic patternsTerminate connections from specific IP addressesSmartView MonitorCentrally monitor Check Point & OPSEC devisesPresent a complete picture of changes to Gateways, tunnels, remote users, security activitiesMaintain high network availabilityImprove eff
38、iciency of bandwidth useTack SLA compliance121Using SmartUpdate123Using SmartUpdateMonitor remote Gateways using SmartUpdate to evaluate the need for upgrades, new installations, and license modifications.Use SmartUpdate to apply upgrade packages to single or multiple VPN-1 Gateways.Upgrade and atta
39、ch product licenses using SmartUpdate.Learning Objectives124Using SmartUpdateSmartUpdate and Managing Licenses125Using SmartUpdateSmartUpdate Architecture126Using SmartUpdateSmartUpdate Introduction128-129Using SmartUpdateOverview of Managing Licenses130Using SmartUpdateAddAttachCertificate KeyCPLIC
40、DetachedLicense TerminologyUpgrade StatusGetLicense ExpirationMulti-License FileFeatures131-132Using SmartUpdateAttachedUnattachedRequires UpgradeLicense StateAssignedNo NGX LicenseObsolete License132Using SmartUpdateNew Licenses need to be attached when:Existing license expiresExisting license is u
41、pgradedLocal license replaced with central licenseIP address changesUpgrading Licenses133Using SmartUpdateService Contracts138Using SmartUpdateFrom CDFrom FileFrom Download CenterLicensing SmartEvent142Introduction to Check Point VPNs185Introduction to Check Point VPNsConfigure a pre-shared secret s
42、ite-to-site VPN with partner sites.Configure permanent tunnels for remote access to corporate resources.Configure VPN tunnel sharing, given the difference between host-based, subunit-based and gateway-based tunnels.Learning Objectives186Introduction to Check Point VPNsThe Check Point VPN187Introduct
43、ion to Check Point VPNsVPN encrypted tunnels to exchange dataUses IKE and IPSec protocolsIKE creates the tunnelIPSec encodes the dataThe VPN187Introduction to Check Point VPNsSite-to-Site VPNStrong encryptionReliableScalable188Introduction to Check Point VPNsRemote-Access VPNStrong authenticationCen
44、tralized ManagementScalable189Introduction to Check Point VPNsVPN Implementation190Introduction to Check Point VPNsUnderstanding VPN DeploymentCheck Point VPN management modelAdministrators directly define a VPN on group of GatewaysGateway in group = VPN siteEach VPN site performs encryption for VPN
45、 Domain, LAN, NetworksGrouped VPN sites = VPN Community191Introduction to Check Point VPNsVPN CommunitiesVPN Community memberVPN DomainVPN siteVPN CommunityDomain-based VPNRoute-based VPNVPN DomainVPN SiteVPN CommunityVPN MembersVPN Tunnel192Introduction to Check Point VPNsRemote Access CommunitySpe
46、cifically for remote usersSecures communication between users and corporate LAN193Introduction to Check Point VPNsMeshed VPN Community194Introduction to Check Point VPNsStar VPN Community195Introduction to Check Point VPNsChoosing A TopologyMeshed CommunityAppropriate for IntranetParticipating Gatew
47、ays part of internally managed networkStar CommunityAppropriate for exchange with external partnersCentral and satellite Gateways195Introduction to Check Point VPNsCombination VPN196Introduction Check Point VPNsTopology and Encryption Issues197Introduction Check Point VPNsSpecial VPN Gateway Conditi
48、ons198Introduction Check Point VPNsSpecial VPN Gateway Conditions199Introduction to Check Point VPNsAuthentication Between Community MembersBefore exchanging keys and building tunnels, Gateways must authenticate one of two ways.CertificatesPre-shared secret199Introduction to Check Point VPNsDomain a
49、nd Route-Based VPNsTwo ways to direct VPN traffic:Domain-based VPNRoute-based VPN200Introduction to Check Point VPNsAccess Control and VPN Communities201Introduction to Check Point VPNsAccess Control and VPN CommunitiesUsing the VPN column of the Rule Base, you can create access control rules that apply only to members of a VPN community:201Introduction to Check Point VPNsAccess Control and VPN CommunitiesYou can also create rules that are relevant for both VPN Communities and host machines not in the Community:201Introduction to Check Point VPN
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 红岩测试题及详细答案
- 财务主管个人年终述职报告(3篇)
- 光谱培训练习题及详细答案解读
- 餐饮员工收银知识试题及对应答案
- 2025-2026学年开封市通许县三年级数学第二学期期末试题含答案解析
- 2025-2026学年广西壮族来宾市三下数学期末检测模拟试题(含答案解析)
- 幼儿园保育员考试提升题目及答案
- 初中政治下册模拟试题及答案
- 乐理专项试题及详细答案
- 宋诗考试题目与答案解析
- 新二升三暑假英语26个字母每日一练过关练22天
- 2026年高校行政管理岗招聘笔试典型试题及要点含答案
- 光伏施工方案范文模板
- 2026年危险化学品生产单位安全生产管理人员安全生产模拟考试题库及答案
- 高标准农田建设技术工作手册
- 魏家凉皮考勤制度
- 无刷电机培训
- 临床医学大三《急性脑梗塞合并一氧化碳中毒》教学设计
- 全口吸附性义齿知情同意书
- 《大明太祖高皇帝实录》(点校标注版1-30卷)
- 人大换届选举培训课件
评论
0/150
提交评论