<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11291#M93976</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the info are great! Just another question: If I'm not using VTI, I just set up a regular loopback with the 10.2.92.2/30 address, right? And that with the NAT mode set to hide should work, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jul 2018 18:43:57 GMT</pubDate>
    <dc:creator>Cesar_Caballero</dc:creator>
    <dc:date>2018-07-19T18:43:57Z</dc:date>
    <item>
      <title>Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11285#M93970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello to everyone,&lt;/P&gt;&lt;P&gt;I'm currently facing a scenario where we have two Check Point 4200s working in standalone HA and taking care of my internet connection and a simple VPN. Next to it, there is a Cisco 2811 router whose only duty is to keep an IPsec VPN established with another Cisco that we don't manage. I've been asked to migrate that IPsec VPN from the Cisco to the Check Point, and I don't know how to do that. Can anybody help me?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Network Topology" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/67139_CP &amp;amp; Cisco.png" /&gt;&lt;/P&gt;&lt;P&gt;The IPsec VPN conditions are:&lt;/P&gt;&lt;P&gt;- The IPsec VPN must be established between the Check Point standalone in HA with a cluster IP 10.15.128.130/30 and a 3rd party appliance (Cisco) that we don't manage with an IP 10.15.128.2/30. So the Cluster IP address is going to be in a diferent subnet than it's members.&lt;/P&gt;&lt;P&gt;- Trafic within the IPsec VPN must be routed by NATing all IPs with a loopback with an IP 10.2.92.2 and another loopback with an IP 10.1.92.2.&lt;/P&gt;&lt;P&gt;- I've uploaded a modified config of the Cisco 2811 to protect privacy. It is attached to this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly apreciated.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 14:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11285#M93970</guid>
      <dc:creator>Cesar_Caballero</dc:creator>
      <dc:date>2018-07-19T14:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11286#M93971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would start by making sure you have all the necessary information to create a VPN.&lt;/P&gt;&lt;P&gt;Here's a nice worksheet for that:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/5863"&gt;what information do we need from the remote site customer when creating site to site VPN?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you can follow the steps in the documentation for creating a VPN with a third-party site:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm"&gt;Site to Site VPN R80.10 Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;VPN Site-to-Site with 3rd party&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 15:24:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11286#M93971</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-19T15:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11287#M93972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌ for the quick response. Yes, we allready have all the necessary information to create the VPN. Regarding the documentation for creating a VPN, we're running R77.30, and yes I'd had access to that documentation as well. My main question is how do I create the policy after configuring all the VPN parameters and how do I get the traffic to be NATed trough the loopback?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 15:45:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11287#M93972</guid>
      <dc:creator>Cesar_Caballero</dc:creator>
      <dc:date>2018-07-19T15:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11288#M93973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something like the following for the VPN rules:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67138_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For NAT, something like:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67142_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 16:21:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11288#M93973</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-19T16:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11289#M93974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks once again for the info! And that loopback is configured as what kind of object in the SmartDashboard? Do I need a loopback interface in the GAiA firewall as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:48:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11289#M93974</guid>
      <dc:creator>Cesar_Caballero</dc:creator>
      <dc:date>2018-07-19T17:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11290#M93975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You create a regular host object for it.&lt;/P&gt;&lt;P&gt;You will need to right-click on it in the NAT rulebase to change the NAT mode to Hide (versus Static).&lt;/P&gt;&lt;P&gt;If you are using VPN tunnel interfaces, you configure the IP on the tunnel interface.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11290#M93975</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-19T18:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11291#M93976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the info are great! Just another question: If I'm not using VTI, I just set up a regular loopback with the 10.2.92.2/30 address, right? And that with the NAT mode set to hide should work, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11291#M93976</guid>
      <dc:creator>Cesar_Caballero</dc:creator>
      <dc:date>2018-07-19T18:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing a Cisco 2811 router duty with a Check Point standalone HA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11292#M93977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need to set up a loopback in this case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:18:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-a-Cisco-2811-router-duty-with-a-Check-Point-standalone/m-p/11292#M93977</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-19T19:18:31Z</dc:date>
    </item>
  </channel>
</rss>

