Security Policy & Identity Awareness
Check Point's layered policy model and Identity Awareness are hard to practice without a management server and a gateway running side by side. This lab gives you both, pre-connected, so you can build policy the way SmartConsole actually expects.
The problem
A user-based security rule should match a specific logged-in user, but their traffic keeps hitting a fallback rule instead, as if Check Point doesn't know who they are.
What you'll practice
- Build ordered security policy layers in SmartConsole
- Configure NAT rules on a Gaia gateway
- Enable and test Identity Awareness for user-based policy
- Push policy from the management server to the gateway
- Read SmartConsole logs to verify policy hits
The topology
A Gaia security gateway managed from a SmartConsole management server, with hosts on both sides, the standard Check Point management/gateway split you'll work with in any real deployment.
Topology diagram
Frequently asked
Do I need a Check Point license to use this lab?
No. The management server and gateway are already licensed and paired. You build policy, not infrastructure.
Does this cover CCSE-level topics?
Layered policy, NAT and Identity Awareness are core CCSE topics. This lab is scoped to practice them hands-on.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.