CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Certifications And Exams > CCSE (Check Point Certified Security Expert) > CCSE NGX Exam 156-315.1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-01
Junior Member
 
Join Date: 2006-09-18
Posts: 7
Rep Power: 0
Afontanilla has an average reputation (10+)
Default August CCSE 315.1 passed

Ok guys, just passed with an 85 but I thought I would get higher...they really do try to screw you up with hidden qualifiers and details. It is true that the CCSA test is wider in scope and may ask you some obscure questions. But then again, so is the NGX I student manual when compared to the NGX II manual. I suggest you get two or 3 Checkpoint servers...(2 nokias (gateways) and a 1 secureplatform as a smartserver) and practice most if not all of the labs in the NGX II student manual. This should take about 6 hours(un-interupted) if your experienced with the product. (I got some nokias if anyone wants any...) then you can get drunk..and then take the test ..8) just watch out for: 1. When you set up a HA cluster....take a look at the actual IP addresses of the individual members that you use on the cluster interfaces. Does the IP address on those interfaces have to be on the same subnet as the virtual HA IP addressed that they form...................I say no....you can have the ip addresses be rfc1918 but still form a virtual HA address that is routable on the internet..... the question you get, sort of tests you on this but changes some details...ie outside vs inside. 2. Know the difference between SIP and SIP any in relation to rulebase..Checkpoint documentation is very unclear about this...they use some confusing language to explain this... ie SIP-If you use source or destination to be any in the rulebase any is not allowed to redirect traffic unless its a proxy. sip-any if you use the source or destination as any, any is not allowed to be a sip proxy... Thats great but what happens if you dont use any and actually use a network object? I guess the less restrictive use would be sip-any?????(used in proxy to proxy communications, call handoff, or for you Cisco guys secure routing)? Can we debate this? 3. Know the difference between advanced upgrade and and a normal upgrade when it comes to HA smartcenter servers...whats the proper order to upgrade high availability Smartcenter servers. 4. Whats the difference between Diff services and low latency classes...is there a special tag that goes with either of these..... 5. Do the URI blocked access list lab in the NGX II manual...just so you can get a feel of creating a URI resource (just a net or filter or IP pool for you cisco guys) and blocking sites by importing a properly formatted bad-web txt file. The question they ask however involves using a CVP to do the same thing..slighly different then using just a plain URI resource. I'll post more once I remember them.. Good luck all!!!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:10.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0