MicroNugget: How to Build a Check Point Network

Video Statistics and Information

Video
Captions Word Cloud
Reddit Comments
Captions
building a checkpoint network starting with the infrastructure our objective for this micro- really simple we want to put the infrastructure in place for our checkpoint network here's how we're going to start we're going to install the operating system called Gaia on this server and this server this will be our management server once we tell it that and this one will be our gateway now the question is Keith well once you install the operating system called Gaia how do you tell these devices that you're a manager and you're a firewall the way we do that is once we have the operating system installed we're going to connect via HTTP and that's where we tell this guy hey your manager and you are a gateway now this is called a distributed deployment we could also install the manager and Gateway on the same physical blocks and that would be considered a standalone Check Point deployment in most networks we're going to have distributed roles manager on one box and Gateway on a separate box also from HTTPS we're going to configure the interfaces to make sure that if we have additional interfaces we need to configure or static routes or routing we're going to configure all that as well right from HTTPS then the last step is to download these smart console clients primarily we're after a smart dashboard and we sit right here at this windows computer using smart dashboard which is connected to the manager where we create all of our policies and rules and then when we're ready we tell the manager to push those policies out to the Gateway for enforcement so our first step is going to be to install the Gaia operating system so I simply booted the management server from a cd-rom I'm going to press ENTER to say please install Gaia on this system we get a confirmation saying do we want to proceed we'll press ENTER for okay we'll pick the u.s. keyboard we'll accept the defaults for the allocation of the disk space we'll provide a password for the admin account and press ok and then we'll give this management server its IP address of 1000 - with a default gateway of the IP address that the Gateway will have after we configure it and we'll select ok then we're going to select ok one more time to confirm and it's going to install and now that the Gaia operating system is installed on the device that will be our manager we are going to do a reboot so here on the device that will be our gateway we're going to do the exact same thing we boot from the gaia CD and provide the basic information such as the IP address the password for the administrator and a default gateway so we have a confirmation message will press ok will accept the keyboard will supply a password for the admin account on the device that will be our gateway which is firewall 1 we'll press ok it sees that we have two interfaces easy ro goes out to the outside II won goes the inside I want to configure II one first because it's on the e1 interface that the manager is going to communicate with that firewall so with E one selected we'll go ahead and press ok we'll put in the correct IP address for e 1 interface we can add the IP address of easy ro and the default gateway that it should use once we connect via HTTPS we'll press ok to confirm that we're ready to continue and now the install is going to complete so on this device that will be our gateway is telling us to reboot and to come back using HTTPS to this IP address to finish off the configuration and assign its roles so we'll press ENTER to reboot that so now guy is installed on both the device that will be the manager and the device that will be our gateway and now we're going to connect via HTTP to specify their roles well specify to this guy hey you're going to be a manager and we'll tell this guy hey you're going to be a gateway we can also configure that any additional interfaces or static routes or routing that we need to while we're connected via HTTP so I've connected to 1000 - and because this device has a self-signed certificate my browser saying oh there will Robinson are you sure you want to continue in our case I do will login using the password that we configured on that box 1000 - click login and from here we're simply going to click Next to follow the wizard we can set the date and time we can configure an NTP server we can give this guy a name I'm going to call him manager he's already got his IP address at 1000 - which is perfect his default gateway is perfect I'm going to click on next Ed's on this screen or we get to say hey you are a security management server with this checkbox selected and the security gateway deselected so it's just doing dedicated management responsibilities we'll click on next we'll create an administrative account for this management server we'll click on next we can specify restrictions as far as who's allowed to connect to this management server click on next and then click on finish and then a final confirmation and it does it's magic meanwhile while that's cooking let's also go with HTTP over to the IP address of the gateway so over at 10.00 an eleven is saying hey the self signed certificate is entrusted by your browser either that's okay in this case because we just installed it we'll put in the credentials to login and we'll run through the wizard now keep in mind this is the gateway device or the device that is about to be the gateway so we have a time page we have the name page I'm going to go ahead and call this gateway and click on next its IP address is 1000 111 we'll leave that as is we'll click on next and this is where we're going to tell it that we want it to be a security gateway and it will be managed by that other box over at 10.00 to will click on next it's not going to have a dynamically assigned IP and we're going to specify an activation key now this activation key is just a phrase that we're going to use initially when the manager checks in and says I want to take total control of you mr. gateway so it's just an initial way to confirm that the right manager is talking to the right gateway and then once the manager talks to the Gateway initializes the communications they're going to use digital certificates to authenticate each other based on name so this activation key is like a one-time use so we'll click on next and we'll click on finish and a yes to confirm now at the end of our installation on this gateway is saying you must restart the system in order to finish the configuration so we'll click on ok so the reboot is completed on this gateway it's automatically asking us to reconnect so we'll supply the admin username and password and click login and so from here with network interfaces if we want to configure the other interface for example the outside interface Ethernet 0 so we double click on it go ahead and click on the check box to enable it and then specify the IP address you want to use so in my test lab this is the IP address I'm using on that outside interface I'll click on OK and we'll also go ahead and configure a static route so on the static routes option on the Left we'll simply double click on the default route and so let me add a gateway for the default route and that's going to be 192 168 1.1 and will click on OK and then we'll save that this is also where we can configure the details for example as a DHCP server additional network interfaces and so forth but now that this is done let's go ahead and close this in fact I'm going to log out of the Gateway so now we're sitting at the manager via HTTP and we have very sim our options for example if we needed to configure static routes on this manager and he has this default route pointing to the Gateway or if we needed to configure DNS information on this device here's where we do all of that but the really important part we need to do right here is under overview is there's this big green button says please download the smart console smart console is a suite of applications that we're going to use on our windows computer that lets us manage the checkpoint environment and the primary tool that we're going to use is smart dashboard so we're going to click download now so that is downloading as we speak in the bottom left-hand corner of my browser and now that it's downloaded we'll go ahead and install it meanwhile while this program is installing our local Windows computer I can go ahead and sign out and close the browser session that we have over to the manager so I have a little overview page for a smart console for r76 we'll click on next and we can select to install everything or simply certain clients because you never know what we might want to try or use I'm going to install everything by clicking next and in just a few moments those tools will all be available on this Windows computer so now that the installation is complete we'll click on finish it's automatically going to launch smart dashboard we'll put in the username we'll put in the IP address of that management server and we'll click login and then we have smart dashboard running we also can get to our other smart client utilities by using this drop-down right here to get the Smart View tracker Smart View monitor and the other really smart tools that checkpoint provides for us you know one last step since we're here we really need to make sure this manager can communicate and manage that gateway and to do that we're going to go to our network objects and right-click on checkpoint and say I want to add a new gateway we'll go ahead and use the classic mode we'll put in the IP address we'll specify what features we want enabled on that gateway they refer to these as software blades so for the moment we'll just say that we want firewall services on that gateway and then we'll click on communication it says what's that one time password we need to get the ball rolling with this device so we'll put that password in that's one we configured on the Gateway will click on initialize and if but mrs. trust established which is great we'll click on OK in the background it just went out looked at the topology information for that gateway this is just an overview of that information right here we'll the kind close will click on okay so now the manager has generated and installed a certificate on that gateway so now we can create policies right here and then push those policies out to the gateway for enforcement in this video you and I have taken a look at implementing a basic infrastructure for checkpoint I've got another micro nugget on how to create and push out a policy that you also might be interested in if you'd like even more checkpoint training hey come and check out our courses at CBT Nuggets I'd love to see you there meanwhile I hope this has been informative for you and I'd like to thank you for viewing
Info
Channel: CBT Nuggets
Views: 22,024
Rating: undefined out of 5
Keywords: cyber security, cyber security jobs, cyber security certifications, cyber security degree, cyber security training, cyber security analyst, ccna security, cyber security engineer, cyber security course, ccna training, cyber security training for beginners, ccna training course, ccna training video for beginners, ccna training video, ccna training videos 2019
Id: B5dynSHp3RQ
Channel Id: undefined
Length: 9min 34sec (574 seconds)
Published: Fri Nov 29 2013
Related Videos
Note
Please note that this website is currently a work in progress! Lots of interesting data and statistics to come.