Job title- :Checkpoint Firewall Engineer Location- Woodbury, MN
1. The candidate should have design and consulting experience around Checkpoint firewall. 2. Should have proficiency around seamless migration from one firewall to other. 3. The candidate Should have versed with troubleshooting steps during implementation. 4. Check Point certified resource (CCSA and CCSE) who will report to the Client Firewall Team Leader, and will reside in Woodbury, MN. Check Point technical resource will: a. Be current Check Point CCSA and CCSE (Certified on r75 or r77 within the last 2 years) b. Be experienced in Firewall sizing and configuration c. Be experience moving OSPF routing from Cisco Core to UTM (Also known as inline) d. 5 Years hands-on troubleshooting (not just creating and deploying firewall rules) with Check Point UTM (GAiA-based) firewalls and be very proficient with: i. The patience and understanding necessary to walk/talk someone through a 1st time config for a remote firewall (for firewalls drop shipped to EMEA and APAC) ii. Upgrading firewalls out of a cardboard box and updating them to a specific revision of code iii. Application of Check Point HFA and rpm’s iv. Configuration of the firewall using Check Point WEBui interface v. Creating and modification of Check Point configuration files from within Check Point CLI (Expert and Clish shells) vi. Understanding Dynamic Routing (OSPF) with Check Point’s OS vii. Understanding of TCPDUmp, fw monitor, and zdebug as troubleshooting tools viii. Strong understanding how DHCP-Relay and DHCP Server are configured on a firewall. ix. Understanding of Check Point High Availability using ClusterXL x. Understanding of HA Bonded interfaces xi. Strong understanding of all Check Point SmartConsole applications and their use; creating Security, Network Address Translation, and Application Control rules xii. Understanding of Check Point licensing; how to configure and deploy xiii. How to determine and initiate an RMA for a defective firewall e. Receive firewalls spec’d for the site from shipping or: i. Walk a remote resource through the 1st time config such that connectivity can be possible for further configuration f. Unbox and upgrade the firewall to Gold Code (which contains the necessary levels of software and patches required for NAC) g. Configure the firewall specifically for the site based on the logical and switch interconnect drawings from the Access Layer Team h. Document the hardware in on-line Libraries (CIRM, GSM) i. Obtain and properly license the firewalls, burn-in the new hardware, and test. j. Repack, add necessary cables w/instructions for the local eyes/hands, and ship to a domestic site k. Work with other NAC Team and local resources to install, cable, and power-up the hardware l. Game Day Activity: Work with a current Client Firewall Resource to review and deploy the NAC Security Policy m. Work with other NAC Team and local resources to finish UTM installation (establish routing, fail-over testing, simulated hardware failures) n. Test and Troubleshoot NAC, routing, dhcp, rules as required with other NAC Team Member *Ranjeet Majumdar* | SYSMIND, LLC *Technical Recruiter* [image: https://newoldstamp.com/editor/profilePictures/profile-b15c8fc3ea4630e2ca604f11e3e951c7-41898.png] Phone: 609-897-9670 x 2152 Email: r <shes...@sysmind.com>anjeet.sysm...@gmail.com Website: sysmind.com Address: 38 Washington Road, Princeton Junction, NJ 08550 -- You received this message because you are subscribed to the Google Groups "SAP ABAP" group. To unsubscribe from this group and stop receiving emails from it, send an email to sap-abap+unsubscr...@googlegroups.com. To post to this group, send email to sap-abap@googlegroups.com. Visit this group at https://groups.google.com/group/sap-abap. For more options, visit https://groups.google.com/d/optout.