German Website
 





Check Point Security Administration NGX III

Length: 4 days* (recommended)

For schedules and pricing, contact Dom Agostino at 800-818-8070 x4508 or email dagostinoakibia.com.

Prerequisites:

Check Point Security Administration NGX I Rev 1.1 and Check Point Security Administration NGX II Rev 1.1

Take this class if:

  • You are a systems administrator, security manager, or network engineer implementing VPN-1 NGX in an enterprise setting
  • Check Point Certified Security Expert Plus NGX (CCSE Plus NGX) certification

Description

Check Point Security Administration NGX III offers comprehensive training to enhance enterprise knowledge of VPN-1 NGX, network planning, route-based VPN, and troubleshooting procedures.

You Will Learn:

  • Troubleshooting NGX product problems using troubleshooting guidelines
  • Using cpinfo and log files for file management
  • Using protocol analyzers to capture and analyze network traffic
  • Troubleshooting NGX problems using NGX debugging tools
  • Using fw and fw advanced commands for troubleshooting
  • Troubleshooting specific Security Server issues
  • Using VPN log files and vpn debug to troubleshoot VPN connections
  • Capturing traffic flow using ike debug, sr_service debug, and srfw monitor
  • Identifying differences between route- and domain-based VPNs
  • Identifying, debugging, and using relevant commands to troubleshoot Eventia Reporter problems

Exercises:

  • Collecting configuration files from an NGX installation
  • Review and analyzing cpinfo output in InfoView
  • Using GuiDBedit to create services and objects, and modify an object’s global properties
  • Using fw logswitch to switch active and audit logs
  • Using fwm logexport to export logs
  • Comparing client- and server-side NAT using fw monitor
  • Using fwm and cpd debugging to troubleshoot a stand-alone installation problem
  • Generating and interpreting a file containing fw ctl pstat information
  • Using fw stat to verify a Gateway’s Policy installed status
  • Using fw unloadlocal to uninstall a Security Policy
  • Using fwm load to install a Policy
  • Running ike debug on Gateways, and analyzing output using IKEview
  • Observing IKE by running ike debug
  • Running srfw monitor on a SecureClient desktop
  • Configuring route-based VPNs for VPN redundancy
  • Configuring dynamic routing using OSPF through VPN tunnels