- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Check Point Firewall Administration R81.10+
After six months on the market, with the feedback from the readers two new updates for Check Point Firewall Administration R81.10+ are now released:
Both are available in the book’s GitHub repository.
Tremendous thanks to @Timothy_Hall , who has pointed out some of the pertinent additional information and few mistakes, and to Seth Holcomb (@SecNetEng) , who has meticulously documented and shared with me his experience and encountered issues with the book and its labs.
#Book #Administration
Always grateful for all your contributions @Vladimir 💪👍
Thanks!
Thank you Danny!
FYI: GitHub resources are free for use, so if anyone is simply interested in building the lab using VirtualBox, all the necessary resources are there (with links to ISOs and software).
Welcome to the hamster wheel of keeping your published content updated Vladimir. 😀 But seriously, nice work!
Thank you Tim!
Yeah, didn't expect to sink this much time into update so soon, but it was needed.
Hi, after I build the Lab as indicated on book i can't reach the external CPGW Secure Gateway from VM Console to complete FTW regardless of Vyos router and FWs are up and running
from LOG on Smart Console i can see CPCM1 allow https but i receive timeout from browser.
Ping from CPGW and CPCM FW to Router interface doesn't work too, seems to be something wrong on router conf i think...can you help me to understand?
Thanks
Maybe best if you start new thread on this, as its not really related to this post : - ). Also, if you could send us basic network diagram, it always helps. Some things to check...run fw stat on the fw, as well as ip r g command to see if it shows right path.
example -> ip r g 8.8.8.8
Andy
Thanks a lot, this is the datagram
So i can't connect from 10.0.0.20 to 200.200.0.1 to complete FTW about CPGW, with telnet on 443 i obtain timeout and ping doesn't work too.
Policy on CPCM is matched and traffic is accepted, on tcpdump i can see only syn, tried to dump on router with this command but i can't see arrive nothing from firewall
vyos@router:~$ monitor traffic interface eth1
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), snapshot length 262144 bytes
^C
0 packets captured
0 packets received by filter
0 packets dropped by kernel
vyos@router:~$ show interfaces
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface IP Address S/L Description
--------- ---------- --- -----------
eth0 192.168.178.60/24 u/u OUTSIDE
eth1 200.100.0.254/24 u/u Net_200.100.0.0
eth2 200.200.0.254/24 u/u Net_200.200.0.0
lo 127.0.0.1/8 u/u
::1/128
vyos@router:~$ monitor traffic interface eth1
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), snapshot length 262144 bytes
this is CPCM side
[Expert@CPCM1:0]# fw stat
HOST POLICY DATE
localhost Standard 2Apr2023 16:20:35 : [>eth0] [<eth0] [>eth2] [<eth2] [>eth3] [<eth4]
[Expert@CPCM1:0]# ip r g 8.8.8.8
8.8.8.8 via 200.100.0.254 dev eth4 src 200.100.0.2
[Expert@CPCM1:0]# netstat -nr
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
0.0.0.0 200.100.0.254 0.0.0.0 UG 0 0 0 eth4
10.0.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
10.10.10.0 0.0.0.0 255.255.255.0 U 0 0 0 eth1
10.20.20.0 0.0.0.0 255.255.255.0 U 0 0 0 eth2
10.30.30.0 0.0.0.0 255.255.255.0 U 0 0 0 eth5
192.168.255.0 0.0.0.0 255.255.255.0 U 0 0 0 eth3
200.100.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth4
[Expert@CPCM1:0]#
@Millo , check the presence of the default route on CPCM1 and CPCM2 as well as if your SmartConsole_VM object has NATR hide behind static IP configured.
Also, please check the eth0 and eth1 on CPGW and let me know which IPs you have assigned to each of the interfaces.
Cheers,
Vladimir
Hi, problem solved. The issue is that the names of the network adapter of the VM of the Router and VM of the FWs was different (case sensitive)
Thanks to all
As of May 2024 VMWare Workstation Pro is free for personal use. As of November 11th, 2024 VMWare Workstation Pro is now also free for commercial use; this would include for utilization by Check Point ATCs such as Shadow Peak. This software would be a viable alternative to VirtualBox for the lab environment used by the book.
Guess Broadcom/VMWare is way too busy fleecing existing big enterprise customers to even bother to collect licensing fees from the little guys. 🙂
While I like the VMware ESXi for serious lab modeling, there are few reasons why I've picked Virtual Box:
1. An issue with VMware Virtual networking in general- it is reshuffling virtual interfaces based on their PCI IDs. I.e. If you've created a VM and assigned the interfaces to the Bridged, NATed or Virtual Segments and then added another few interfaces, their assigments will shift.
2. VMware Workstation does not have Management CLI suitable for native scripted VM configuration and deployment. It must be coupled with Terraform to achieve same outcomes that are possible with simple VirtualBox scripting.
This said, once the lab is created manually and snapshotted, It'll probably be more convenient for a lot of folks to use.
Cheers!
Vladimir
Even if VMware Workstation Pro is “free” now, the change in licensing model for Enterprise customers has left a bad taste in a lot of people’s mouth.
As for the bare-metal ESXi Hypervisor…I’ve found Promox to be a lot easier to keep up to date.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
12 | |
11 | |
9 | |
8 | |
7 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY