# Course 32 - Checkpoint CCSA R80 | Episode 9: Advanced Threat Prevention and Secure Site-to-Site Connectivity Page: https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity Text version: https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity.md Podcast: [CyberCode Academy](https://stenobird.com/podcast/cybercode-academy-7578615) Published: 2026-05-09T06:00:02+00:00 Episode link: https://www.spreaker.com/episode/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity--71508403 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/71508403/how_firewalls_and_vpn_tunnels_work.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity Duration seconds: 1520 ## Resource In this lesson, youโ€™ll learn about: layered security, anti-spoofing, and VPNs in Check Point R801. Layered Security with Policy Packages In Check Point R80, security is built in layers, not just a single rulebase ๐Ÿ”น Two Main Layersโœ… Access Control Controls: Who can access what Uses: URL Filtering Application Control โœ… Threat Prevention Protects against: Malware Exploits Zero-day attacks ๐Ÿ”น Key Blades IPS (Intrusion Prevention System) Anti-Virus Threat Emulation (sandboxing) ๐Ÿ‘‰ Combined = Prevent + Detect + Control2. Protecting Encrypted Traffic Even encrypted traffic is inspected using: HTTPS Inspection ๐Ÿ”น Why Important Attacks often hide inside: HTTPS ๐Ÿ‘‰ Ensures full visibility across all traffic3. Anti-Spoofing (Network Integrity)๐Ÿ”น The Problem Attackers fake source IP addresses ๐Ÿ”น The Solution Anti-spoofing in Check Point R80 ๐Ÿ”น How It Works Firewall checks: Incoming interface Routing table ๐Ÿ”น Behavior If mismatch โ†’ traffic is dropped ๐Ÿ‘‰ Prevents: IP spoofing attacks Unauthorized access attempts 4. Site-to-Site VPN (Secure Connectivity)๐Ÿ”น Purpose Secure communication over: Public internet ๐Ÿ”น Technology Used IPsec 5. VPN Topologies๐Ÿ”น Mesh Topology Every gateway connects to every other ๐Ÿ”น Star Topology (Hub-and-Spoke) Central hub connects branches ๐Ÿ‘‰ Defined using: VPN Communities 6. VPN Domains๐Ÿ”น Definition Networks included in VPN encryption ๐Ÿ”น Example Internal LAN behind each gateway ๐Ÿ‘‰ Only defined domains are encrypted7. IKE (Internet Key Exchange) Used to automatically build VPN tunnels ๐Ÿ”น Phase 1 (Management Tunnel) Establishes secure channel ๐Ÿ”น Phase 2 (Data Tunnel) Encrypts actual traffic 8. HAGGLE ParametersUsed during IKE negotiation: H โ†’ Hashing A โ†’ Authentication G โ†’ Group (Diffie-Hellman) L โ†’ Lifetime E โ†’ Encryption ๐Ÿ‘‰ Both sides must match these settings9. Perfect Forward Sโ€ฆ ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity/transcription-requests` โ€” Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-9-advanced-threat-prevention-and-secure-site-to-site-connectivity.md` โ€” Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.