Skip links

Check Point | Learning

Training: CCSE, Check Point Certified Security Expert R81, preparation for certification

This training will allow you to acquire all the techniques and methodologies necessary to pass the exam for obtaining the CCSE R81 certification. You will learn to set up advanced mechanisms of clustering, high availability and service quality (QoS).
Upon completion of the training, the participant will be able to:
  • Make updates
  • Solve user access problems detected during implementation with Identity Awareness
  • Implement a high availability cluster and Load Sharing
  • Prepare the formal exam leading to CCSE certification

Technician, administrator and system/network/security engineer.

Good knowledge of TCP/IP, the security of SIs and the main functions of Check Point or having completed the internship "CCSA, Check Point Certified Security Administrator R81" (Ref. CPQ).

Advanced Gaia & API

  • Gaia on the command line.
  • Presentation of API.
  • Create objects and rules via API.
Practical work
Installation of SMS and GWs in R81. Using API to create basic objects and rules.
 

Gaia upgrade

  • Gaia upgrade methods.
  • Centralized bridge upgrade/level.
Practical work
Gaia upgrade methods. Centralized bridge upgrade/level.
 

Check Point processes

  • Main Check Point processes.
  • Orders to view Check Point processes.
  • Scripts and « SmartTasks ».
Practical work
Configure SmartTasks.
 

Installation of security policy

  • Security policy installation process.
  • Installation Accelerated.
  • Policy Packages & Layers.
  • Dynamic objects.
  • Updable Objects.
Practical work
Checking installation files. Creating dynamic objects.
 

Kernel operations & Traffic flow

  • Circulation of packages inside the gateway.
  • Module chains.
  • Tool « fw monitor ».
  • Management Data Plane Separation (MDPS).
Practical work
Use of tool « fw monitor ».
 

SecureXL & CoreXL

  • SecureXL acceleration and its templates.
  • SecureXL commands.
  • CoreXL and SND (Secure Network Distributor).
  • CoreXL Affinity.
  • Dynamic Balancing.
  • Multi-Quue.
  • CoreXL Dynamic Dispatcher.
  • Priority Queues (PrioQ).
 

VPN IPSEC site to site

  • VPN architecture. The basics of encryption.
  • Introduction to IKE and IPSec.
  • The Certification Authority (CA). The Domain-Based VPN.
  • Simplified mode. Configuration of VPN communities.
  • VPN routing.
Practical work
VPN-IPSec Inter-sites (Shared Secret). VPN-IPSec Inter-sites (Certificates).
 

Remote access

  • The SSL VPN and the IPSec VPN.
  • The Blade Mobile Access.
  • Mobile Access type: « Remote Access ».
  • Mobile Access SSL : Clientless Applications & Native Applications. SSL Network Extender (SNX).
  • Portal « Check Point Mobile ».
  • VPN clients layer 3.
Practical work
Setting up a VPN connection of type « Remote Access » via the customer « Check Point Mobile ». Setting up a VPN connection of type « Mobile Access SSL ».
 

Logs & monitor

  • Presentation of the Logs & Monitor tab.
  • SmartEvent.
  • Compliance.
  • SmartEvent GUI Client.
  • Suspicious Activity Monitoring (SAM).
Practical work
Configuration of SmartEvent.
 

The clustering

  • Redundancy of firewalls.
  • The ClusterXL High Availability.
  • ClusterXL Load Sharing.
  • Load Sharing Multicast.
  • The ClusterXL High Availability.
  • VMAC and ARP issues.
  • High availability of Management Server.
Practical work
Implementation of ClusterXL in High Availability mode.

To pass the certification exam, simply register on the Check Point website. You can then take the exam directly online or in an approved centre. CCSA certification will be required.

The trainer evaluates the educational progress of the participant throughout the training through QCM, situations, practical work...
The participant also completes an upstream and downstream positioning test to validate the acquired skills.
This website uses cookies to improve your web experience.
EnglishenEnglishEnglish
0