<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Route based VPN tunnel to Azure in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/206179#M38950</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Since I had seen lots of posts about this, figured would post couple of docs I created in hopes it helps others who may have issues with it. It has screenshots and also a text file with how you would set up things on Azure side and the word doc is for CP end. Im fairly experienced in this, as I had done lots of testing in the lab for this kind of config.&lt;/P&gt;
&lt;P&gt;If any questions, as always, be free to reach out directly, I always respond to everyone.&lt;/P&gt;
&lt;P&gt;Best and happy weekend!&lt;/P&gt;
&lt;P&gt;Woohooo, weekend &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WooHooWillSmithGIF.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24516i65E3864DE9A8BF0A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WooHooWillSmithGIF.gif" alt="WooHooWillSmithGIF.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; Andy&lt;/P&gt;</description>
    <pubDate>Thu, 15 Feb 2024 13:49:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-15T13:49:40Z</dc:date>
    <item>
      <title>Route based VPN tunnel to Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/206179#M38950</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Since I had seen lots of posts about this, figured would post couple of docs I created in hopes it helps others who may have issues with it. It has screenshots and also a text file with how you would set up things on Azure side and the word doc is for CP end. Im fairly experienced in this, as I had done lots of testing in the lab for this kind of config.&lt;/P&gt;
&lt;P&gt;If any questions, as always, be free to reach out directly, I always respond to everyone.&lt;/P&gt;
&lt;P&gt;Best and happy weekend!&lt;/P&gt;
&lt;P&gt;Woohooo, weekend &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WooHooWillSmithGIF.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24516i65E3864DE9A8BF0A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WooHooWillSmithGIF.gif" alt="WooHooWillSmithGIF.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 13:49:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/206179#M38950</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-15T13:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Route based VPN tunnel to Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/256554#M50251</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Is it possible to re-upload the azure part (the txt) it seems I'm not able to see that part&lt;BR /&gt;&lt;BR /&gt;Thank you for your work!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 06:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/256554#M50251</guid>
      <dc:creator>nkfs</dc:creator>
      <dc:date>2025-09-04T06:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Route based VPN tunnel to Azure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/256585#M50259</link>
      <description>&lt;P&gt;There you go &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;*************&lt;/P&gt;
&lt;P&gt;VPN CONFIG EXAMPLE:&lt;/P&gt;
&lt;P&gt;Steps to build the route based VPN tunnel&lt;/P&gt;
&lt;P&gt;Azure portal:&lt;/P&gt;
&lt;P&gt;Create new VNG&lt;/P&gt;
&lt;P&gt;SK Basic (100 Mbps Limit)&lt;/P&gt;
&lt;P&gt;Route Based&lt;/P&gt;
&lt;P&gt;No BGP/Active to Active (because basic SK)&lt;/P&gt;
&lt;P&gt;New Resource Group&lt;/P&gt;
&lt;P&gt;New VNET&lt;/P&gt;
&lt;P&gt;10.0.0.0/16&lt;/P&gt;
&lt;P&gt;New Public IP&lt;/P&gt;
&lt;P&gt;VIP = x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;New Local Network Gateway (This is a reference object for the Checkpoint Cluster/Lab Checkpoint)&lt;BR /&gt;DEVCheckpoint&lt;/P&gt;
&lt;P&gt;IP address: x.x.x.x&lt;/P&gt;
&lt;P&gt;Address space: 172.16.10.0/24, x.x.x.x/x, 192.168.10.0/24 (Must include internal/local subnets and the external WAN facing subnets)&lt;/P&gt;
&lt;P&gt;Click , click Add Connection&lt;/P&gt;
&lt;P&gt;Type: Site to Site&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PSK Pleasework1!&lt;/P&gt;
&lt;P&gt;IKEv2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Click the connection&lt;/P&gt;
&lt;P&gt;Download Config (Cisco &amp;gt; IOS &amp;gt; IKEv2)&lt;/P&gt;
&lt;P&gt;Verify Default Settings/VTI IPs&lt;/P&gt;
&lt;P&gt;IKE aes-cbc-256, sha1, DH 2, SA lifetime 3600S&lt;/P&gt;
&lt;P&gt;IPSec esp-aes 256, esp-sha256-hmac, SA lifetime 3600s, SA lifetime 102400000 KB&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Configure an APIPA (169.254.x.x) address that does NOT overlap with any&lt;/P&gt;
&lt;P&gt;! other address on this device. This is not visible from the Azure gateway.&lt;/P&gt;
&lt;P&gt;Local on Checkpoint Side VTI IP 169.254.0.1/32&lt;/P&gt;
&lt;P&gt;Remote (Azure) 169.254.0.2/32&lt;/P&gt;
&lt;P&gt;If there is another tunnel use DIFFERENT IPs that DO NOT OVERLAP WITH PREVIOUS RouteBASED TUNNEL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-------&lt;/P&gt;
&lt;P&gt;Access to Lab Checkpoint&lt;/P&gt;
&lt;P&gt;SmartConsole x.x.x.x&lt;/P&gt;
&lt;P&gt;SmartConsole Settings&lt;/P&gt;
&lt;P&gt;Global Properties &amp;gt; VPN &amp;gt; Advanced &amp;gt; Enable VPN Directional Match&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add Interoperable Object for Azure GW with configured VIP&lt;/P&gt;
&lt;P&gt;"AzureLabGW"&lt;BR /&gt;Topology &amp;gt; VPN Domain &amp;gt; Add an Empty Group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Publish &amp;amp; Install&lt;/P&gt;
&lt;P&gt;Go to Gaia WebUi (172.16.10.189:4434)&lt;/P&gt;
&lt;P&gt;Network Interface&lt;/P&gt;
&lt;P&gt;Add VPN-Tunnel&lt;/P&gt;
&lt;P&gt;vpnt1&lt;/P&gt;
&lt;P&gt;Peer Name should be EXACT SAME AS INTEROPERABLE DEVICE NAME&lt;/P&gt;
&lt;P&gt;Local IP 169.254.0.5 (Not used anywhere else)&lt;/P&gt;
&lt;P&gt;Remote IP 169.254.0.6 (Not used anywhere else)&lt;/P&gt;
&lt;P&gt;Add Static Route&lt;/P&gt;
&lt;P&gt;Local IP/Subnet of Azure GW (Virtual Network = 10.0.0.0/16)&lt;/P&gt;
&lt;P&gt;Gateway (IP) of Remote IP from VTI configured previously (169.254.0.6)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Go back to SmartConsole&lt;/P&gt;
&lt;P&gt;Open Gateway Object/Cluster&lt;/P&gt;
&lt;P&gt;Network Management &amp;gt; Topology &amp;gt; Get Interfaces WITHOUT Topology&lt;/P&gt;
&lt;P&gt;Make sure VTI interface shows up, may need to set up vip obj for vpnt tunnel in cluster (make sure no overlap)&lt;/P&gt;
&lt;P&gt;Install Policy&lt;/P&gt;
&lt;P&gt;Create a new VPN Community (Star Topology)&lt;/P&gt;
&lt;P&gt;Ensure both gateways use an EMPTY group for domain&lt;/P&gt;
&lt;P&gt;Encryption (IKEv2 Only)&lt;/P&gt;
&lt;P&gt;AES256, SHA1, Group2&lt;/P&gt;
&lt;P&gt;AES 256, SHA256&lt;/P&gt;
&lt;P&gt;Tunnel Management&lt;/P&gt;
&lt;P&gt;Set perm tunnels on all tunnels in the community&lt;/P&gt;
&lt;P&gt;One tunnel per gateway pair&lt;/P&gt;
&lt;P&gt;VPN Routing&lt;/P&gt;
&lt;P&gt;To center only&lt;/P&gt;
&lt;P&gt;SharedSecret&lt;/P&gt;
&lt;P&gt;Pleasework1!&lt;/P&gt;
&lt;P&gt;Advanced&lt;/P&gt;
&lt;P&gt;IKE Phase 1 480 Min&lt;/P&gt;
&lt;P&gt;IPSec Phase 2 27000 seconds&lt;/P&gt;
&lt;P&gt;Disable NAT inside VPN Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policies&lt;/P&gt;
&lt;P&gt;Source &amp;amp; Destination&lt;/P&gt;
&lt;P&gt;- Local Subnets included in the Local Gateway Object Config/Applicable Subnets&lt;/P&gt;
&lt;P&gt;- Remote (AzureNetwork 10.0.0.0/16)&lt;/P&gt;
&lt;P&gt;- RServ (Radius Server used for testing)&lt;/P&gt;
&lt;P&gt;VPN &amp;gt; Directional Match&lt;/P&gt;
&lt;P&gt;Internal to Community&lt;/P&gt;
&lt;P&gt;Community to Internal&lt;/P&gt;
&lt;P&gt;Community to Community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Publish &amp;amp; Install&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GUIDBEdit DPD Enabled (Tunnel Test Settings)&lt;/P&gt;
&lt;P&gt;Reset Connection on Azure Side&lt;/P&gt;
&lt;P&gt;MAY NOT BE NEEDED REFRESH AND CHECK IF CONNECTED&lt;/P&gt;
&lt;P&gt;Test&lt;/P&gt;
&lt;P&gt;Create VM LabUbuntu&lt;/P&gt;
&lt;P&gt;VIP x.x.x.x&lt;/P&gt;
&lt;P&gt;Private IP 10.0.0.4&lt;/P&gt;
&lt;P&gt;Enable Rule to allow Pings &amp;amp; SSH traffic in&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 13:58:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-tunnel-to-Azure/m-p/256585#M50259</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-04T13:58:41Z</dc:date>
    </item>
  </channel>
</rss>

