Checkpoint CCSA 4.XCramsession

Definition of Firewall

Comparing Different Firewall Technologies

Packet Filtering
Application Layer Gateway
Stateful Inspection

6 Major Modules of Firewall-1

Checkpoint uses OPSEC Open Platform for Secure Enterprise Connectivity architecture, which provides a scalable framework for security implementation by means of separating the firewall product into different modules.
Inspection Module enforces security by providing the following capabilities:
Firewall Module enforces security by providing the following capabilities:
Encryption Module supports Firewall to Firewall / Client to Firewall encryption using thefollowing encryption schemes:
The Encryption module can be classified into DES Encryption Module, which is for use in North America, and FWZ1 Module, which is for world wide export
Connect Control Modules provide automatic server load balancing
Router Security Module uses Access Control List to control 3com, Bay and Cisco Routers

The Complete Firewall-1 Architecture

Figure 0 - Firewall - 1 as a service in Control Panel - Services


Administrator Access


Figure 1 - Log in


  1. Monitor Only - Read Only access to the log viewer and system status tool
  2. Read Only - includes Monitor Only rights, plus Read Only rights to the Security Policy Editor
  3. User Access - administrator can modify user information, but nothing else
  4. Read/Write Access - administrator can do everything. Only one administrator at at time can log in using this mode
Figure 2 - Administrators access mode

Security Policy

  1. Anti Spoofing
  2. Any properties marked FIRST in the Security Policy Properties
  3. Rule base order (except for the last rule)
  4. Any properties marked BEFORE LAST in the SecurityPolicy Properties
  5. Rule Bases last rule
  6. Any properties marked LAST in the SecurityPolicy Properties
  7. Implicit Drop Rule (drop everything not mentioned above)
Figure 3 - Sample Rule Base

Figure 4 - Security Policy Properties

Figure 5 - Possible Rule Base Actions

System Status Tool

Log Viewer

Content Security

Anti - Spoofing


Network Address Translation NAT

Figure 6 - Defining NAT

Figure 7 - NAT in the Rule Base


Solving SYN Flood Problem

SYN Relay
SYN Gateway
Passive SYN Gateway

Special Thanks to Michael Yu for contributing material for this Cramsession.