<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: checkpoint 3600 query on ipsec vpn and ssl vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103078#M8124</link>
    <description>&lt;P&gt;Only way to do Site2Site VPN with a dynamic IP is with certificate-based authentication.&lt;BR /&gt;Not sure how Mobile Access Blade would handle the dynamic IP.&lt;BR /&gt;It might be better to use something like our new Corporate Access solution (Formerly known as Odo), which will definitely work with a dynamic IP:&amp;nbsp;&lt;A href="https://www.checkpoint.com/odo/" target="_blank"&gt;https://www.checkpoint.com/odo/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 04:47:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-24T04:47:14Z</dc:date>
    <item>
      <title>checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103072#M8121</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have a question on Checkpoint model 3600 ( Gaia R80.30)&lt;/P&gt;&lt;P&gt;Checkpoint Interface connected to the internet don't have a static ip and it is dynamic.&lt;/P&gt;&lt;P&gt;Need to achieve an Ipsec site to site VPN with fortinet firewall and also ssl vpn also should be configured with duo authentication. Is the above requirement possible with dynamic public ip for the checkpoint interface connected to internet?&lt;/P&gt;&lt;P&gt;Customer is planning of&amp;nbsp; subscribing to one of the DynDNS service so that the CP firewall can keep updating the DynDNS with the latest IP that the firewall hold.&lt;/P&gt;&lt;P&gt;Also consider creating a CNAME for their company domain that points to the dyndns domain for VPN requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jijo Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 03:05:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103072#M8121</guid>
      <dc:creator>jijotms0511</dc:creator>
      <dc:date>2020-11-24T03:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103078#M8124</link>
      <description>&lt;P&gt;Only way to do Site2Site VPN with a dynamic IP is with certificate-based authentication.&lt;BR /&gt;Not sure how Mobile Access Blade would handle the dynamic IP.&lt;BR /&gt;It might be better to use something like our new Corporate Access solution (Formerly known as Odo), which will definitely work with a dynamic IP:&amp;nbsp;&lt;A href="https://www.checkpoint.com/odo/" target="_blank"&gt;https://www.checkpoint.com/odo/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 04:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103078#M8124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T04:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103079#M8125</link>
      <description>&lt;P&gt;Thank you so much..let me check on the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 05:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103079#M8125</guid>
      <dc:creator>jijotms0511</dc:creator>
      <dc:date>2020-11-24T05:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103116#M8127</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi , the plan for the user us like below for mobile users with dynamic ip&lt;/P&gt;&lt;P&gt;User -&amp;gt; vpn.customerdomain.com&lt;/P&gt;&lt;P&gt;vpn.customerdomain.com CNAME to XX.dyndns.org&lt;/P&gt;&lt;P&gt;XX.dyndns.org is on dynamic IP that CP will keep updating based on it WAN IP.&lt;/P&gt;&lt;P&gt;Please help to confirm&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 09:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103116#M8127</guid>
      <dc:creator>jijotms0511</dc:creator>
      <dc:date>2020-11-24T09:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103188#M8140</link>
      <description>&lt;P&gt;Mobile Access requires a fixed IP address to operate.&lt;BR /&gt;If you configure the gateway with a Dynamic IP address, Mobile Access Blade is not available (see screenshot below).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-11-24 at 11.42.24 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9241iF53F674957962CCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-11-24 at 11.42.24 AM.png" alt="Screen Shot 2020-11-24 at 11.42.24 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Even with traditional IPsec VPN, the gateway IP is ultimately what is resolved in the local configuration.&lt;BR /&gt;When that IP changes, your clients will not be able to connect.&lt;/P&gt;
&lt;P&gt;If the IP rarely changes, you can configure the gateway with a static IP and update the configuration when the local IP changes.&lt;BR /&gt;However, this will require manual intervention when the IP does change.&lt;/P&gt;
&lt;P&gt;The Odo solution I mentioned previously has none of these issues.&lt;BR /&gt;An on-premise agent runs in an on-premise Docker container that initiates an outbound connection with the Check Point cloud.&lt;BR /&gt;Access to on-premise resources is mediated through a controller that operates in the cloud, where your end users connect.&lt;BR /&gt;No inbound access is needed (thus no need for remote users to know your local IP).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-11-24 at 11.48.00 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9242iFAE959AEC3654E79/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-11-24 at 11.48.00 AM.png" alt="Screen Shot 2020-11-24 at 11.48.00 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you're interested in the above solution, I recommend connecting with your local Check Point office.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 19:54:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103188#M8140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T19:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: checkpoint 3600 query on ipsec vpn and ssl vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103220#M8142</link>
      <description>&lt;P&gt;Thank you so much for the explanation!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 06:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/checkpoint-3600-query-on-ipsec-vpn-and-ssl-vpn/m-p/103220#M8142</guid>
      <dc:creator>jijotms0511</dc:creator>
      <dc:date>2020-11-25T06:08:50Z</dc:date>
    </item>
  </channel>
</rss>

