Checkpoint FW1/VPN1 training

Following the departure of a staff member, I find myself with minimal experience of, but responsibility for, a clients' Checkpoint firewall. This is FP2, but an upgrade to the latest version is planned for 9-12 months time and I need to be able to cope with both.

I have been offered some training by my company, but am trying to figure out what will best help me both with supporting what we have now _and_ with what we'll be upgrading to.

Training centres offer courses on NG-AI (I, II & III - I could probably get the first two, as they seem to be about the firewall and vpn respectively) and correspondingly NGX I, II & III, with what looks like an "upgrade" course for parts I & II combined, for CCSE certified people.

I am not sure how NG-AI mentioned in training brochures relates to what we have, would it be better to take the courses for NG-AI and try to get the upgrade course a bit further down the line, or would the NGX course allow me to get to grips with what we have now.

I should add that the environment is fairly stable, with just a very few rulechanges required occasionaly (1 every other month?), and no vpn changes for several months AFAIK. The main reason we're uncomfortable is if any troubleshooting was required.

Reply to
MD
Loading thread data ...

You're running NG FP2 at the moment, upgrading to NGX in 9-12 months. Your immediate issue is understanding what you have installed right now. NG AI Man l and ll use the R55 hfa12 build, a fair bit different from your current install. A good training centre and instructor will be able to help you with the differences between the course and your site. I suggest doing those courses, at this stage the courseware for NGX l and ll are in a state of flux, new revisions should be out in the new year. Summing up: sit NG AI Man l and ll *now*, sit the NGX 1 when you upgrade next year.

Wayne McGlinn Brisbane, Oz

Reply to
Wayne

Yeah, agreed. The difference between FP2 and FP3 is huge, but it will take you a lot of the way to NGX. FP3 -> AI is mostly a feature difference, the interface is pretty much the same. One of the best things you could do is open things read-only and poke around. I don't even think FP2 is supported any more, is it?

You might want to bring someone in and work with them to get you to R55 first. That will get you a lot more familiar with what's going on. R55 is currently at HFA16, with one additional HFA (hotfix accumulator) to fix a problem with the worm catcher in HFA16. It's a pretty stable configuration. if you try to make the jump from FP2 to NGX, you're going to feel lost for quite awhile.

Ray

Reply to
¦

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.