The ticket
You trained Check Point. The job is Palo Alto. They ask for User-ID. If you say “Access Role” without mapping it, you sound lost. If you map it, you sound like an engineer.
Every NGFW has a manager, a box that forwards, identity, NAT, decrypt, IPS, and HA. Names change. First match is almost universal. I will use your words on day one and keep the same proof habit: log, then path, then change.
SMS sms-lab 10.10.10.5 · cluster VIP 10.10.10.1 (cp-gw-01 10.10.10.2 / cp-gw-02 10.10.10.3) · external 203.0.113.25 · internal LAN 10.20.30.0/24 · HR PC 10.20.30.80 TECHCLICK\priya.hr · HR app 10.20.30.41 hr.techclick-lab.in. Not a live customer.
Translation table
| Idea | Check Point | Palo Alto | FortiGate |
|---|---|---|---|
| Manager | SMS + SmartConsole | Panorama / local GUI | FortiManager / local |
| Forwarding box | Security Gateway / Gaia | PA-series / PAN-OS | FortiGate / FortiOS |
| Policy | Layers + first match | Security rules + profiles | IPv4 policy + VDOM |
| Identity | Identity Awareness / Access Role | User-ID / Source User | FSSO / groups |
| Decrypt | HTTPS Inspection | SSL Decryption | SSL Inspection |
| IPS/AV | Threat Prevention | Security profiles | UTM profiles / IPS |
| HA | ClusterXL | Active/Passive HA | FGCP HA |
| Accel | SecureXL / CoreXL | Session offload / DP | NPU / session helpers |
| Site VPN | Community | IKE crypto + proxy IDs | IPsec phase1/2 + selectors |
When each language bites
| Trap | Check Point | PA | Forti |
|---|---|---|---|
| Identity empty | pdp / Access Role | ip-user-mapping | diagnose firewall auth |
| HA lie | cphaprob | show high-availability state | get sys ha status |
| Accel hide | fwaccel / fw monitor -F | fastpath / offload | npu / flow offload |
How to answer in interview
Side A — their word
“User-ID is your name. On Check Point I did Identity Awareness. Same IP→user table.”
Side B — one proof command
Name theirs if you know it; say you will learn the exact CLI on day one.
Side C — one failure
Empty user, shadowed rule, or HA split-brain. Same story every vendor.
Four mix-up failures
1 · Calling Panorama “SMS” in the interview
Use their word after one translation.
2 · Thinking PA zones = CP layers
Zones are interfaces/trust. Layers are policy stacks. Different idea.
3 · “Forti has no first match”
It does. VDOM is closer to virtual systems than to layers.
4 · Brand war
Interviewers hire operators, not fans.
Say it out loud
Check Point splits manager and gateway and uses layers plus Access Roles. Palo Alto uses App-ID and User-ID on a single rule with profiles. FortiGate is often one box plus VDOMs and UTM profiles. I troubleshoot with logs first on all three.
Traps
| They say | You think | You say |
|---|---|---|
| Source User empty | Access Role empty | “Identity mapping is missing” |
| Security profile | TP + App layer | “Attached inspection” |
| Proxy-ID | Encryption domain | “Phase-2 selectors” |
Knowledge check
Judgment items. One best answer. Reasons send you back to the matching section.
Check Point class series: Architecture · Gaia first day · SIC reset · Objects + first match · Policy layers · Hide vs Static NAT · Identity Awareness · HTTPS Inspection · Threat Prevention · Find the drop · fw monitor · SecureXL · ClusterXL · VPN Community · Policy install lock · vs PA vs Forti · CCSA / CCSE interview
Sources
- This series lessons 1, 5, 7, 13, 14 plus Techclick Palo Alto User-ID and FortiGate policy lessons for the other two columns.
- Vendor admin guides for official names only — do not invent menus.
Related: Check Point evidence desk · session factory · next lesson in the series above.