<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating checkpoint to fortigate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208987#M39591</link>
    <description>&lt;P&gt;Then explain to the customer that bridge mode is best here 8)&lt;/img&gt; Or suggest to pay for CP Professional Services to make this setup work without issues...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2024 10:11:15 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2024-03-18T10:11:15Z</dc:date>
    <item>
      <title>Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208944#M39574</link>
      <description>&lt;P&gt;10.x.x.x/24 ---&amp;gt; FortiGate ---&amp;gt;Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;current setup with vip configured on fortigate&lt;/P&gt;&lt;P&gt;10.x.x.x/24 --&amp;gt; CheckPoint--&amp;gt;Fortigate ---&amp;gt; Internet.&lt;/P&gt;&lt;P&gt;We want to maintain same configuration on the fortigate ie Nat, vip and VPN with checkpoint doing filtering.&lt;/P&gt;&lt;P&gt;PS checkpoint will not be in transparent mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 21:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208944#M39574</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-17T21:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208957#M39576</link>
      <description>&lt;P&gt;Not sure I understand. Are you adding a second layer with Check Point?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 07:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208957#M39576</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-18T07:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208962#M39577</link>
      <description>&lt;P&gt;YES additional layer of checkpoint behind fortigate. But fortigate has vip and vpns configured. Is there a way of configuring the checkpoint for just filtering and the vips and vpn works on the fortigate.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:10:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208962#M39577</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-18T08:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208969#M39580</link>
      <description>&lt;P&gt;Actually, bridge mode would be the most reasonable way to approach this, as it will help you avoid massive network changes. Why don't you want to use it, then?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208969#M39580</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-18T08:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208972#M39582</link>
      <description>&lt;P&gt;With that there is the drawback that the Check Point firewall will be blissfully unaware of what ever threath is lurking inside the VPN traffic.&lt;/P&gt;
&lt;P&gt;So apart from good sales figures and crossing the "Different vendor firewalls in cascade" tickbox I don't understand the added value here. It does not add real security to the design.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208972#M39582</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2024-03-18T08:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208973#M39583</link>
      <description>&lt;P&gt;YES bridge mode is the best approach but customer wants this setup instead. And they are ready for any network changes. Can you suggest the best approach for this set.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 08:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208973#M39583</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-18T08:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208977#M39584</link>
      <description>&lt;P&gt;Adding Check Point in any mode will improve security. But I understand your point, it seems too be too complex this way.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208977#M39584</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-18T09:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208979#M39585</link>
      <description>&lt;P&gt;So you need to add a different default route to your internal network pointing to CP, while CP GW will have Forti as a DG. A networking exercise, starting from the drawing board.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208979#M39585</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-18T09:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208980#M39586</link>
      <description>&lt;P&gt;Routing is not a problem&amp;nbsp; but the vips on the fortigate will it work with CP in place without any config changes??.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:25:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208980#M39586</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-18T09:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208981#M39587</link>
      <description>&lt;P&gt;Yes complex but customer wants this setup for additional protection.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208981#M39587</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-18T09:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208982#M39588</link>
      <description>&lt;P&gt;The internal traffic is cleartext. VPN tunnels are terminated on Forti. The domain has not changed. It is essentially a Forti question, but I don't see a reason for VPNs to fail after an internal routing change&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208982#M39588</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-18T09:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208985#M39590</link>
      <description>&lt;P&gt;OK noted. what about the vips do we have to do natting on CP ??.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:38:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208985#M39590</guid>
      <dc:creator>wac</dc:creator>
      <dc:date>2024-03-18T09:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208987#M39591</link>
      <description>&lt;P&gt;Then explain to the customer that bridge mode is best here 8)&lt;/img&gt; Or suggest to pay for CP Professional Services to make this setup work without issues...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 10:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/208987#M39591</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-18T10:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating checkpoint to fortigate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/209053#M39610</link>
      <description>&lt;P&gt;Not sure what relevance the VIPs have on the Check Point configuration except maybe as a default route.&lt;BR /&gt;Assuming the networking is set up correctly, it should not be required to perform any NAT on the Check Point device.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 16:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Integrating-checkpoint-to-fortigate/m-p/209053#M39610</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-03-18T16:59:46Z</dc:date>
    </item>
  </channel>
</rss>

