| Foreword | p. xxiii |
| Introduction to Check Point Next Generation with Application Intelligence | p. 1 |
| Introduction | p. 2 |
| Introducing the Check Point Next Generation with Application Intelligence Suite of Products | p. 2 |
| Understanding VPN-1/FireWall-1 SVN Components | p. 18 |
| Looking at Firewall Technology | p. 30 |
| Complete SVN Concept | p. 37 |
| Summary | p. 39 |
| Solutions Fast Track | p. 41 |
| Frequently Asked Questions | p. 44 |
| Installing and Configuring VPN-1/FireWall-1 Next Generation with Application Intelligence | p. 47 |
| Introduction | p. 48 |
| Before You Begin | p. 48 |
| Installing Check Point VPN-1/FireWall-1 NG AI on Windows | p. 68 |
| Uninstalling Check Point VPN-1/FireWall-1 NG on Windows | p. 97 |
| Installing Check Point VPN-1/FireWall-1 NG AI on Solaris | p. 104 |
| Uninstalling Check Point VPN-1/FireWall-1 NG AI on Solaris | p. 129 |
| Installing Check Point VPN-1/FireWall-1 NG AI on Nokia | p. 138 |
| Installing Check Point VPN-1/FireWall-1 NG AI on SecurePlatform | p. 146 |
| Summary | p. 152 |
| Solutions Fast Track | p. 153 |
| Frequently Asked Questions | p. 157 |
| Using the Graphical Interface | p. 159 |
| Introduction | p. 160 |
| Managing Objects | p. 160 |
| Services | p. 179 |
| Resources | p. 187 |
| Open Platform for Security Applications | p. 188 |
| Servers | p. 189 |
| Internal Users | p. 192 |
| Time | p. 193 |
| Virtual Link | p. 194 |
| Adding Rules | p. 195 |
| Global Properties | p. 200 |
| SmartUpdate | p. 205 |
| SmartView Tracker | p. 209 |
| SmartView Status | p. 211 |
| Summary | p. 213 |
| Solutions Fast Track | p. 213 |
| Frequently Asked Questions | p. 215 |
| Creating a Security Policy | p. 217 |
| Introduction | p. 218 |
| Reasons for a Security Policy | p. 218 |
| How to Write a Security Policy | p. 219 |
| Implementing a Security Policy | p. 228 |
| Installing a Security Policy | p. 249 |
| Policy Files | p. 251 |
| Summary | p. 253 |
| Solutions Fast Track | p. 253 |
| Frequently Asked Questions | p. 256 |
| Applying Network Address Translation | p. 259 |
| Introduction | p. 260 |
| Hiding Network Objects | p. 260 |
| Configuring Static Address Translation | p. 266 |
| Automatic NAT Rules | p. 272 |
| NAT Global Properties | p. 276 |
| Summary | p. 279 |
| Solutions Fast Track | p. 279 |
| Frequently Asked Questions | p. 281 |
| Authenticating Users | p. 285 |
| Introduction | p. 286 |
| Fire Wall-1 Authentication Schemes | p. 286 |
| Defining Users | p. 292 |
| User Authentication | p. 298 |
| Client Authentication | p. 303 |
| Session Authentication | p. 306 |
| LDAP Authentication | p. 309 |
| Summary | p. 314 |
| Solutions Fast Track | p. 315 |
| Frequently Asked Questions | p. 316 |
| Open Security (OPSEC) and Content Filtering | p. 319 |
| Introduction | p. 320 |
| OPSEC Applications | p. 320 |
| Content Vectoring Protocol | p. 322 |
| URI Filtering Protocol | p. 331 |
| Application Monitoring | p. 339 |
| Client Side OPSEC Applications | p. 341 |
| Other Resource Options | p. 344 |
| Summary | p. 362 |
| Solutions Fast Track | p. 363 |
| Frequently Asked Questions | p. 366 |
| Managing Policies and Logs | p. 371 |
| Introduction | p. 372 |
| Administering Check Point VPN-1/FW-1 NG AI for Performance | p. 373 |
| Administering Check Point VPN-1/FW-1 NG AI for Effectiveness | p. 386 |
| Administering Check Point VPN-1/FW-1 NG for Recoverability | p. 401 |
| Performing Advanced Administration Tasks | p. 402 |
| Summary | p. 408 |
| Solutions Fast Track | p. 408 |
| Frequently Asked Questions | p. 410 |
| Tracking and Alerts | p. 413 |
| Introduction | p. 414 |
| Alerts Commands | p. 414 |
| User-Defined Tracking | p. 420 |
| Suspicious Activities Monitoring Protocol (SAMP) | p. 424 |
| Summary | p. 430 |
| Solutions Fast Track | p. 430 |
| Frequently Asked Questions | p. 431 |
| Configuring Virtual Private Networks | p. 433 |
| Introduction | p. 434 |
| Encryption Schemes | p. 434 |
| Simplified-Mode vs. Traditional-Mode VPNs | p. 441 |
| Configuring an IKE VPN in Traditional Mode | p. 441 |
| Configuring an IKE VPN in Simplified Mode | p. 447 |
| Configuring a SecuRemote VPN | p. 457 |
| Installing SecuRemote Client Software | p. 462 |
| Using SecuRemote Client Software | p. 464 |
| Summary | p. 470 |
| Solutions Fast Track | p. 470 |
| Frequently Asked Questions | p. 472 |
| Securing Remote Clients | p. 475 |
| Introduction | p. 476 |
| Installing and Configuring a Policy Server | p. 476 |
| Desktop Security Options | p. 479 |
| Installing SecureClient Software | p. 495 |
| Logging into the Policy Server | p. 510 |
| Summary | p. 511 |
| Solutions Fast Track | p. 511 |
| Frequently Asked Questions | p. 513 |
| Advanced VPN Configurations | p. 515 |
| Introduction | p. 516 |
| Check Point High Availability and Check Point Load Sharing | p. 517 |
| Single Entry Point VPN Configurations | p. 528 |
| Multiple Entry Point VPN Configurations | p. 533 |
| Other High Availability Methods | p. 543 |
| Summary | p. 546 |
| Solutions Fast Track | p. 546 |
| Frequently Asked Questions | p. 547 |
| SmartDefense | p. 549 |
| Introduction | p. 550 |
| Understanding the Theory of SmartDefense | p. 550 |
| Using SmartDefense | p. 551 |
| Understanding Network Security | p. 553 |
| Understanding Application Intelligence | p. 560 |
| Updating SmartDefense | p. 565 |
| Summary | p. 567 |
| Solutions Fast Track | p. 567 |
| Frequently Asked Questions | p. 569 |
| Class C Subnet Mask Cheat Sheet | p. 571 |
| Index | p. 579 |
| Table of Contents provided by Rittenhouse. All Rights Reserved. |