Checkpoint FW1/VPN1 training

Checkpoint FW1/VPN1 training

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Checkpoint FW1/VPN1 training MD 10-19-2005
Posted by MD on October 19, 2005, 1:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Following the departure of a staff member, I find myself with minimal
experience of, but responsibility for, a clients' Checkpoint firewall.
This is FP2, but an upgrade to the latest version is planned for 9-12
months time and I need to be able to cope with both.

I have been offered some training by my company, but am trying to
figure out what will best help me both with supporting what we have
now _and_ with what we'll be upgrading to.

Training centres offer courses on NG-AI (I, II & III - I could
probably get the first two, as they seem to be about the firewall and
vpn respectively) and correspondingly NGX I, II & III, with what looks
like an "upgrade" course for parts I & II combined, for CCSE certified
people.

I am not sure how NG-AI mentioned in training brochures relates to
what we have, would it be better to take the courses for NG-AI and try
to get the upgrade course a bit further down the line, or would the
NGX course allow me to get to grips with what we have now.

I should add that the environment is fairly stable, with just a very
few rulechanges required occasionaly (1 every other month?), and no
vpn changes for several months AFAIK. The main reason we're
uncomfortable is if any troubleshooting was required.

--

Regards,

Mark Davies




Posted by Wayne on October 20, 2005, 9:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You're running NG FP2 at the moment, upgrading to NGX in 9-12 months. Your
immediate issue is understanding what you have installed right now. NG AI
Man l and ll use the R55 hfa12 build, a fair bit different from your current
install. A good training centre and instructor will be able to help you with
the differences between the course and your site. I suggest doing those
courses, at this stage the courseware for NGX l and ll are in a state of
flux, new revisions should be out in the new year.
Summing up: sit NG AI Man l and ll *now*, sit the NGX 1 when you upgrade
next year.

Wayne McGlinn
Brisbane, Oz

> Following the departure of a staff member, I find myself with minimal
> experience of, but responsibility for, a clients' Checkpoint firewall.
> This is FP2, but an upgrade to the latest version is planned for 9-12
> months time and I need to be able to cope with both.
>
> I have been offered some training by my company, but am trying to figure
> out what will best help me both with supporting what we have now _and_
> with what we'll be upgrading to.
>
> Training centres offer courses on NG-AI (I, II & III - I could probably
> get the first two, as they seem to be about the firewall and vpn
> respectively) and correspondingly NGX I, II & III, with what looks like an
> "upgrade" course for parts I & II combined, for CCSE certified people.
>
> I am not sure how NG-AI mentioned in training brochures relates to what we
> have, would it be better to take the courses for NG-AI and try to get the
> upgrade course a bit further down the line, or would the NGX course allow
> me to get to grips with what we have now.
>
> I should add that the environment is fairly stable, with just a very few
> rulechanges required occasionaly (1 every other month?), and no vpn
> changes for several months AFAIK. The main reason we're uncomfortable is
> if any troubleshooting was required.
>
> --
>
> Regards,
>
> Mark Davies
>




Posted by ¦ on October 25, 2005, 8:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yeah, agreed. The difference between FP2 and FP3 is huge, but it will take
you a lot of the way to NGX. FP3 -> AI is mostly a feature difference, the
interface is pretty much the same. One of the best things you could do is
open things read-only and poke around. I don't even think FP2 is supported
any more, is it?

You might want to bring someone in and work with them to get you to R55
first. That will get you a lot more familiar with what's going on. R55 is
currently at HFA16, with one additional HFA (hotfix accumulator) to fix a
problem with the worm catcher in HFA16. It's a pretty stable configuration.
if you try to make the jump from FP2 to NGX, you're going to feel lost for
quite awhile.

Ray

> You're running NG FP2 at the moment, upgrading to NGX in 9-12 months. Your
> immediate issue is understanding what you have installed right now. NG AI
> Man l and ll use the R55 hfa12 build, a fair bit different from your
current
> install. A good training centre and instructor will be able to help you
with
> the differences between the course and your site. I suggest doing those
> courses, at this stage the courseware for NGX l and ll are in a state of
> flux, new revisions should be out in the new year.
> Summing up: sit NG AI Man l and ll *now*, sit the NGX 1 when you upgrade
> next year.
>
> Wayne McGlinn
> Brisbane, Oz
>
> > Following the departure of a staff member, I find myself with minimal
> > experience of, but responsibility for, a clients' Checkpoint firewall.
> > This is FP2, but an upgrade to the latest version is planned for 9-12
> > months time and I need to be able to cope with both.
> >
> > I have been offered some training by my company, but am trying to figure
> > out what will best help me both with supporting what we have now _and_
> > with what we'll be upgrading to.
> >
> > Training centres offer courses on NG-AI (I, II & III - I could probably
> > get the first two, as they seem to be about the firewall and vpn
> > respectively) and correspondingly NGX I, II & III, with what looks like
an
> > "upgrade" course for parts I & II combined, for CCSE certified people.
> >
> > I am not sure how NG-AI mentioned in training brochures relates to what
we
> > have, would it be better to take the courses for NG-AI and try to get
the
> > upgrade course a bit further down the line, or would the NGX course
allow
> > me to get to grips with what we have now.
> >
> > I should add that the environment is fairly stable, with just a very few
> > rulechanges required occasionaly (1 every other month?), and no vpn
> > changes for several months AFAIK. The main reason we're uncomfortable is
> > if any troubleshooting was required.
> >
> > --
> >
> > Regards,
> >
> > Mark Davies
> >
>
>




Similar ThreadsPosted
CBT training for Checkpoint? July 26, 2006, 10:13 pm
Good firewall theory training/class in Chicagoland?!? July 28, 2005, 9:17 pm
Checkpoint - Deny traceroute through checkpoint firewall August 10, 2004, 3:27 pm
Checkpoint - NAT Help February 7, 2005, 8:00 am
checkpoint March 17, 2005, 5:12 pm
checkpoint fp1 +ike October 25, 2005, 12:08 am
CheckPoint help on September 15, 2006, 2:37 pm
Checkpoint QoS October 24, 2006, 3:29 pm
PIX to checkpoint VPN August 14, 2007, 1:08 pm
checkpoint and static nat August 3, 2004, 5:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy