|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/checkpoint-firewall-administration/
课程评论:没有评论
课程名称:检查点认证安全管理员 课程概述:检查点安全管理课程提供了有关配置检查点安全网关所需的基本概念和技能的理解,配置安全策略,并学习管理和监控安全网络。本课程涵盖以下主题: - 描述检查点的统一网络管理方法及其架构的关键元素。 - 设计课程拓扑中详细编写的分布式环境。 - 在分布式环境中安装R77版本的安全网关。 - 根据网络规格,从命令行执行备份和还原当前网关安装。 - 识别所需的重要文件,以清除或备份,导入和导出用户及组,并从命令行添加或删除管理员。 - 使用sysconfig和cpconfig从网关命令行部署网关。 - 根据网络拓扑创建和配置网络、主机和网关对象。 - 使用SmartDashboard验证安全管理服务器与网关之间的SIC建立情况。 - 在SmartDashboard中创建基本的规则库,包括对管理用户、外部服务和局域网出站使用的权限。 - 评估现有策略并根据当前企业要求优化规则。 - 维护安全管理服务器,定期备份和版本策略,以确保无缝升级和最小停机时间。 - 在Web和网关服务器上配置NAT规则。 - 使用SmartView Tracker中的查询监控IPS和常见网络流量,并使用数据包数据排除事件。 - 在给定企业网络上使用数据包数据生成报告,排除系统和安全问题,确保网络功能。 - 使用SmartView Monitor配置警报和流量计数器,查看网关状态,监控可疑活动规则,分析隧道活动和基于企业要求监控远程用户访问。 - 使用SmartUpdate监控远程网关,评估升级、新安装和许可证修改的需求。 - 使用SmartUpdate将升级包应用于单个或多个VPN-1网关。 - 升级并使用SmartUpdate附加产品许可证。 - 集中管理用户,确保仅有经过身份验证的用户安全访问企业网络,无论是本地还是远程。 - 使用外部数据库管理用户访问本地局域网。 - 使用身份感知提供网络资源的细粒度访问。 - 获取安全网关控制访问所需的用户信息。 - 定义身份感知规则中使用的访问角色。 - 在防火墙规则库中实施身份感知。 - 配置具有合作方站点的预共享密钥点对点VPN。 - 为远程访问企业资源配置永久隧道。 - 配置VPN隧道共享,给出主机基础、子单元基础和网关基础的隧道之间的区别。
The Check Point Security Administration course provides an understanding of basic concepts andskills necessary to configure the Check Point Security Gateway, configure Security Policies, andlearn about managing and monitoring secure networks. This Course covers the following topics: Describe Check Point's unified approach to network management, and the key elements of this architecture. Design a distributed environment using the network detailed in the course topology. Install the Security Gateway version R77 in a distributed environment using the network detailed in the course topology. Given network specifications, perform a backup and restore the current Gateway installationfrom the command line. Identify critical files needed to purge or backup, import and export users and groups and add or delete administrators from the command line. Deploy Gateways using sysconfig and cpconfig from the Gateway command line. Given the network topology, create and configure network, host and gateway objects Verify SIC establishment between the Security Management Server and the Gateway usingSmartDashboard. Create a basic Rule Base in SmartDashboard that includes permissions for administrative users, external services, and LAN outbound use. Evaluate existing policies and optimize the rules based on current corporate requirements. Maintain the Security Management Server with scheduled backups and policy versions to ensure seamless upgrades and minimal downtime. Configure NAT rules on Web and Gateway servers. Use Queries in SmartView Tracker to monitor IPS and common network traffic and troubleshoot events using packet data. Using packet data on a given corporate network, generate reports, troubleshoot system and security issues, and ensure network functionality. Using SmartView Monitor, configure alerts and traffic counters, view a Gateway's status, monitor suspicious activity rules, analyze tunnel activity and monitor remote user access based on corporate requirements. Monitor remote Gateways using SmartUpdate to evaluate the need for upgrades, new installations, and license modifications. Use SmartUpdate to apply upgrade packages to single or multiple VPN-1 Gateways. Upgrade and attach product licenses using SmartUpdate. Centrally manage users to ensure only authenticated users securely access the corporate network either locally or remotely. Manage users to access to the corporate LAN by using external databases. Use Identity Awareness to provide granular level access to network resources. Acquire user information used by the Security Gateway to control access. Define Access Roles for use in an Identity Awareness rule. Implementing Identity Awareness in the Firewall Rule Base. Configure a pre-shared secret site-to-site VPN with partner sites Configure permanent tunnels for remote access to corporate resources. Configure VPN tunnel sharing, given the difference between host-based, subunit-based and gateway-based tunnels.