Skip to content
TrackPodcasts
educationMay 9, 202625:20pending

Course 32 - Checkpoint CCSA R80 | Episode 9: Advanced Threat Prevention and Secure Site-to-Site Connectivity

About this episode

In this lesson, you’ll learn about: layered security, anti-spoofing, and VPNs in Check Point R801. Layered Security with Policy Packages
  • In Check Point R80, security is built in layers, not just a single rulebase
🔹 Two Main Layers✅ Access Control
  • Controls:
    • Who can access what
  • Uses:
    • URL Filtering
    • Application Control
✅ Threat Prevention
  • Protects against:
    • Malware
    • Exploits
    • Zero-day attacks
🔹 Key Blades
  • IPS (Intrusion Prevention System)
  • Anti-Virus
  • Threat Emulation (sandboxing)
👉 Combined = Prevent + Detect + Control2. Protecting Encrypted Traffic
  • Even encrypted traffic is inspected using:
    • HTTPS Inspection
🔹 Why Important
  • Attacks often hide inside:
    • HTTPS
👉 Ensures full visibility across all traffic3. Anti-Spoofing (Network Integrity)🔹 The Problem
  • Attackers fake source IP addresses
🔹 The Solution
  • Anti-spoofing in Check Point R80
🔹 How It Works
  • Firewall checks:
    • Incoming interface
    • Routing table
🔹 Behavior
  • If mismatch → traffic is dropped
👉 Prevents:
  • IP spoofing attacks
  • Unauthorized access attempts
4. Site-to-Site VPN (Secure Connectivity)🔹 Purpose
  • Secure communication over:
    • Public internet
🔹 Technology Used
  • IPsec
5. VPN Topologies🔹 Mesh Topology
  • Every gateway connects to every other
🔹 Star Topology (Hub-and-Spoke)
  • Central hub connects branches
👉 Defined using:
  • VPN Communities
6. VPN Domains🔹 Definition
  • Networks included in VPN encryption
🔹 Example
  • Internal LAN behind each gateway
👉 Only defined domains are encrypted7. IKE (Internet Key Exchange)
  • Used to automatically build VPN tunnels
🔹 Phase 1 (Management Tunnel)
  • Establishes secure channel
🔹 Phase 2 (Data Tunnel)
  • Encrypts actual traffic
8. HAGGLE ParametersUsed during IKE negotiation:
  • H → Hashing
  • A → Authentication
  • G → Group (Diffie-Hellman)
  • L → Lifetime
  • E → Encryption
👉 Both sides must match these settings9. Perfect Forward Secrecy (PFS)🔹 Concept
  • Generates new encryption keys for sessions
🔹 Benefit
  • Even if one key is compromised:
    • Past sessions remain secure
Key Takeaways
  • Security is layered: Access Control + Threat Prevention
  • HTTPS inspection reveals hidden threats
  • Anti-spoofing protects against fake IP attacks
  • VPNs secure communication over public networks
  • IKE automates secure tunnel creation
  • PFS ensures long-term encryption safety
Big PictureWith these capabilities in Check Point R80, you now control:
  • User access and application behavior
  • Advanced threat detection and prevention
  • Network integrity against spoofing
  • Secure communication between sites
  • Strong encryption with automated key exchange


You can listen and download our episodes for free on more than 10 different platforms:
https://linktr.ee/cybercode_academy

Get every episode summarized

Each time CyberCode Academy publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Course 32 - Checkpoint CCSA R80 | Episode 9: Advanced Threat Prevention and Secure Site-to-Site Connectivity

CyberCode Academy

0:00
25:20

More episodes

More from CyberCode Academy

View all episodes →