<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN terminate on firewall with no public ip address via external firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235347#M45618</link>
    <description>&lt;P&gt;K, thats more clear now. Good question actually...so you dont need S2S between outer and inner fw, just to forward it to inner?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2024 14:15:37 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-11T14:15:37Z</dc:date>
    <item>
      <title>Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235304#M45611</link>
      <description>&lt;P&gt;Hi I need to :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) set up a VPN from AWS to a R81.20&lt;/P&gt;&lt;P&gt;the question is :&lt;/P&gt;&lt;P&gt;can i do a nat of a public ip address to the inner firewalls private ip address.&lt;/P&gt;&lt;P&gt;Using nat t will this allow me to terminate the VPN on the inner firewall &amp;amp; tunnel traffic using ipsec directly to inner ?&lt;/P&gt;&lt;P&gt;The network between the inner &amp;amp; outer are the same /24 network.&lt;/P&gt;&lt;P&gt;I will use sk100726&lt;/P&gt;&lt;P&gt;The documentation suggests this is achievable, has anyone done this&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;This will allow a significant simplification of routing changes on the internal lan that will be required.&lt;/P&gt;&lt;P&gt;any help is appreciated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 11:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235304#M45611</guid>
      <dc:creator>TOM_MORAN</dc:creator>
      <dc:date>2024-12-11T11:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235333#M45613</link>
      <description>&lt;P&gt;Im fairly sure it is possible, you would just need to do static nat in this case and make sure nat is NOT disabled inside vpn community.&lt;/P&gt;
&lt;P&gt;Hey, do you have simple network diagram you can attach? I think that would help us as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 13:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235333#M45613</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-11T13:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235339#M45614</link>
      <description>&lt;P&gt;apologizes i thought i had attached the diagram&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 13:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235339#M45614</guid>
      <dc:creator>TOM_MORAN</dc:creator>
      <dc:date>2024-12-11T13:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235341#M45615</link>
      <description>&lt;P&gt;Got it, yes, np man, we see it now! So essentially, just to make sure, S2S is between AWS and outer CP fw, but connection has to flow all the way to the server itself, which is behind INNER cp fw?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 13:56:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235341#M45615</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-11T13:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235346#M45617</link>
      <description>&lt;P&gt;Hi Andy many thanks.&lt;/P&gt;&lt;P&gt;Normally the VPN would terminate on the physical ip of the outer firewall.&lt;/P&gt;&lt;P&gt;But what i want to do is :&lt;/P&gt;&lt;P&gt;do a static nat public public ip on the outer fw to the inner fw &amp;amp; use that ip as the termination ip site.&lt;/P&gt;&lt;P&gt;If i do that can we tunnel traffic using nat t &amp;amp; ipsec to the inner fw&lt;/P&gt;&lt;P&gt;we don't want to route traffic on the outer fw&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:10:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235346#M45617</guid>
      <dc:creator>TOM_MORAN</dc:creator>
      <dc:date>2024-12-11T14:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235347#M45618</link>
      <description>&lt;P&gt;K, thats more clear now. Good question actually...so you dont need S2S between outer and inner fw, just to forward it to inner?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 14:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235347#M45618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-11T14:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235358#M45621</link>
      <description>&lt;P&gt;correct connect/forward to inner&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 15:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235358#M45621</guid>
      <dc:creator>TOM_MORAN</dc:creator>
      <dc:date>2024-12-11T15:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235359#M45622</link>
      <description>&lt;P&gt;I would say as long as rules allow it and routing is there, no reason not to work, as technically, inner firewall would simply "serve" as passthrough (if you will) to reach the final destination.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 15:12:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235359#M45622</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-11T15:12:55Z</dc:date>
    </item>
    <item>
      <title>Site to Site VPN terminate on firewall with no public ip address via external firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235390#M45628</link>
      <description>&lt;P&gt;&lt;STRONG&gt;This answer is provided by &lt;A href="https://www.checkpoint.com/ai/copilot/" target="_blank"&gt;Infinity AI Copilot&lt;/A&gt; and should be confirmed by reviewing official documentation in &lt;A href="https://support.checkpoint.com" target="blank"&gt;Support Center&lt;/A&gt;.&lt;/STRONG&gt;&lt;/P&gt; &lt;P&gt;Yes, you can set up a VPN from AWS to an R81.20 firewall without a public IP by using NAT to map a public IP to the inner firewall's private IP. Using NAT-T (NAT Traversal) will allow you to terminate the VPN on the inner firewall and tunnel traffic using IPsec directly to the inner firewall. This setup is supported and can simplify routing changes on your internal LAN.&lt;/P&gt; &lt;P&gt;Here are some key steps to consider:&lt;/P&gt; &lt;OL&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;NAT Configuration&lt;/STRONG&gt;: Ensure that the public IP is properly NATed to the private IP of the inner firewall. This will allow the VPN traffic to reach the inner firewall.&lt;/P&gt; &lt;/LI&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;NAT-T Configuration&lt;/STRONG&gt;: Enable NAT Traversal on your VPN settings to handle the NATed traffic correctly.&lt;/P&gt; &lt;/LI&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;VPN Configuration&lt;/STRONG&gt;: Follow the guidelines in &lt;A href="https://support.checkpoint.com/results/sk/sk100726" target="_blank"&gt;sk100726&lt;/A&gt; for configuring IPsec VPN between your Check Point Security Gateway and AWS VPC using static routes and Numbered VTI.&lt;/P&gt; &lt;/LI&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Network Configuration&lt;/STRONG&gt;: Since the network between the inner and outer firewalls is the same /24 network, ensure that routing and firewall rules are correctly set to allow traffic to flow between these networks.&lt;/P&gt; &lt;/LI&gt; &lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Testing and Validation&lt;/STRONG&gt;: After configuration, test the VPN connection to ensure that traffic is correctly routed and encrypted between AWS and your internal network.&lt;/P&gt; &lt;/LI&gt; &lt;/OL&gt; &lt;P&gt;This approach is feasible and has been documented in Check Point's resources, allowing for a streamlined setup. If you encounter any issues, consider revisiting the configuration steps or consulting with Check Point support for further assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 20:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-terminate-on-firewall-with-no-public-ip-address/m-p/235390#M45628</guid>
      <dc:creator>CheckMatesAI</dc:creator>
      <dc:date>2024-12-11T20:51:38Z</dc:date>
    </item>
  </channel>
</rss>

