
Welcome to the 7th lesson, where we will begin working with security policies. Today, we will install a policy on our gateway for the first time, meaning we will finally perform an ‘install policy’. After this step, traffic will start flowing through the gateway!
In general, policies from Check Point's perspective are quite a broad concept. Security Policies can be divided into three types:
- Access Control. This includes blades such as: Firewall, Application Control, URL Filtering, Content Awareness, Mobile Access, VPN. That is, everything concerning the permission or restriction of traffic.
- Threat Prevention. Here, blades used include: IPS, Anti-Virus, Anti-Bot, Threat Emulation, Threat Extraction. These are functions that check the content of traffic or content that has already passed through Access Control.
- Desktop Security. This involves policies managing Endpoint agents (i.e., protecting workstations). We won't cover this topic within the scope of the course.
In this lesson, we will start discussing Access Control policies.
Access Control Composition
Access Control is the first policy that must be set on the gateway. Without this policy, others (Threat Prevention, Desktop Security) simply will not be established. As mentioned earlier, Access Control policies include multiple blades:
- Firewall;
- Application & URL Filtering;
- Content Awareness;
- Mobile Access;
- NAT.
Initially, we will review only one — the Firewall.
Four Steps to Configure the Firewall
To install a policy on the gateway, we MUST complete the following steps:
- Define the gateway interfaces corresponding to the security zone (whether Internal, External, DMZ, etc.)
- Set up Anti-Spoofing;
- Create network objects (Networks, Hosts, Servers , etc.) This is important! As I mentioned, Check Point only works with objects. You cannot simply insert an IP address into the access list;
- Create Access-Lists— at least one.
Without these settings, the policies simply will not be established!
Video lesson
As usual, we are attaching a video lesson where we will carry out the procedure for basic Access Control configuration and form recommended access lists.

Stay tuned for more and join our 🙂
Source: habr.com
