<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN between CheckPoint and Prisma Access in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237179#M39643</link>
    <description>&lt;P&gt;See if below post I made about a year ago helps. I know its Azure, but would be very similar. I know Prisma is Palo Alto, if Im not mistaken. I only seen it once myself, apologies, but not familiar with it at all. But, to answer your question about route based, yes, you can follow documents I have in the link, hope it makes sense.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2024 14:41:08 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-30T14:41:08Z</dc:date>
    <item>
      <title>IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237160#M39631</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;I was asked to make a test in which I will route all internet traffic from specific subnet (for example 10.10.10.0/24) to Prisma Access.&lt;/P&gt;&lt;P&gt;I configured the necessary part in Prisma Access Remote Networks IPSec VPN, but what are my options in order to this in checkpoint?&lt;/P&gt;&lt;P&gt;I was thinking to make a VPN community in which the VPN Domain will be 0.0.0.0/0, with excluding RFC1918 addresses and CGNAT address.&lt;/P&gt;&lt;P&gt;Is it even possible? Are there other options?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 12:41:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237160#M39631</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2024-12-30T12:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237178#M39642</link>
      <description>&lt;P&gt;I am thinking that maybe Route Based VPN with PBR will be more appropriate solution, but I am not sure how to implement it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In VTI configuration, what do I configure as remote peer ip address and local ip address? I only have Prisma Access Public IP.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:10:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237178#M39642</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2024-12-30T14:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237179#M39643</link>
      <description>&lt;P&gt;See if below post I made about a year ago helps. I know its Azure, but would be very similar. I know Prisma is Palo Alto, if Im not mistaken. I only seen it once myself, apologies, but not familiar with it at all. But, to answer your question about route based, yes, you can follow documents I have in the link, hope it makes sense.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:41:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237179#M39643</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-30T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237181#M39644</link>
      <description>&lt;P&gt;I understand that I could just "gibberish" the VTI numbered addresses, is this correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237181#M39644</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2024-12-30T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237183#M39646</link>
      <description>&lt;P&gt;Thats right. See below from another post while back example I gave. Message me directly if you need further explanation.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-failover-issue/m-p/155553#M26519" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-failover-issue/m-p/155553#M26519&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 14:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237183#M39646</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-30T14:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237343#M39661</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/120580"&gt;@shauls&lt;/a&gt;&amp;nbsp;, were you able to figure this out?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2024 17:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237343#M39661</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-31T17:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237664#M39721</link>
      <description>&lt;P&gt;I am still not sure about the "Numbered Remote Address" field. I understand that I could come up with any unique IP address for the numbered local address, but what about the remote address? I don't have such address provided to me by Prisma, unlike the AWS example.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 11:33:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237664#M39721</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2025-01-06T11:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237667#M39724</link>
      <description>&lt;P&gt;Does not really matter, as long as its not used on their end.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 11:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/237667#M39724</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T11:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238060#M39786</link>
      <description>&lt;P&gt;IT IS working. I used your text guide along with the AWS guide. I also configured PBR instead of static route.&lt;/P&gt;&lt;P&gt;There is only one thing that is very strange.. in Tunnel Monitoring I see the the tunnel is down, but on the Prisma side it is up and everything is working as expected.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 07:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238060#M39786</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2025-01-09T07:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238061#M39787</link>
      <description>&lt;P&gt;Never mind, I see that I configured the "permanent tunnels" option but it should only work between checkpoint gateways. I disabled it and now I see that the tunnel is up. Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 07:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238061#M39787</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2025-01-09T07:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238075#M39790</link>
      <description>&lt;P&gt;I always more rely on vpn tu or vpn tu tlist.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 12:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/238075#M39790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-09T12:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245607#M41012</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/120580"&gt;@shauls&lt;/a&gt; I have the same issue. We are setting up a VPN tunnel with Palo Alto Prisma Access on VSX level. Only limitation on VSX is that we have to use numbered VPN since the unnumbered is not supported.&lt;BR /&gt;&lt;BR /&gt;What did you do configure as LOCAL and REMOTE IP?&lt;BR /&gt;The local can be whatever you choose? Does it need to be a L3 interface on the FW? Or can it?&lt;BR /&gt;&lt;BR /&gt;For the remote IP, does it need to come from the same subnet?&lt;BR /&gt;I see that &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt; tells us that it doesn't matter? If we route for example 10.1.1.0/24 behind this VPN, the remote IP can't be from this range right?&lt;BR /&gt;&lt;BR /&gt;I also see that Palo Alto can't specify a local and remote address. So at PA side, it's not used?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245607#M41012</guid>
      <dc:creator>koendsp</dc:creator>
      <dc:date>2025-04-03T14:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245608#M41013</link>
      <description>&lt;P&gt;Thats right&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70344"&gt;@koendsp&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:34:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245608#M41013</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T14:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245611#M41014</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you please allow me to summarize/question so I get it 100% correct:&lt;BR /&gt;&lt;BR /&gt;- The Local IP can be a L3 interface on the VSX Virtual FW. &lt;STRONG&gt;Yes, but not needed you can choose another as long as it's routed/ No, it can't be a layer 3 interface.&lt;/STRONG&gt;&lt;BR /&gt;- The local IP &lt;U&gt;cannot&lt;/U&gt; be the PUBLIC IP that I use to setup my PHASE1. &lt;STRONG&gt;YES/NO&lt;/STRONG&gt;&lt;BR /&gt;- The Remote IP at Palo Alto Side can be whatever, as long as it's not in the VPN domain at PA side. For example if we want to reach 10.1.1.0/24 at PA, we can't have a remote IP in this range? &lt;STRONG&gt;YES/NO&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;Koen&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 14:50:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245611#M41014</guid>
      <dc:creator>koendsp</dc:creator>
      <dc:date>2025-04-03T14:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245613#M41015</link>
      <description>&lt;P&gt;Yes to all, but last one, it would supernet, so they better be different, otherwise, certain modifications are needed or nat.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 15:12:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245613#M41015</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T15:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245619#M41021</link>
      <description>&lt;P&gt;Thanks for the help! Very much appreciated! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 15:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245619#M41021</guid>
      <dc:creator>koendsp</dc:creator>
      <dc:date>2025-04-03T15:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245623#M41025</link>
      <description>&lt;P&gt;No problem. FYI, IF supernet happens, make sure below values in Guidbedit are set to FALSE.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_enable_supernet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_use_largest_possible_subnets&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 15:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245623#M41025</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T15:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245839#M41074</link>
      <description>&lt;P&gt;Thanks. We have a /22 routed/used at Palo Alto side.&lt;BR /&gt;Could this be the reason that that we have Phase1 up but Phase 2 is having issues?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In SmartView Monitor we see the state as 'Up'.&lt;BR /&gt;In the 'FW monitor' on VSX we can see that we have Outgoing Encrypted packets, but we don't see them arriving at Palo Alto side.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm also wondering what we have to set at VPN Tunneling Sharing.&lt;BR /&gt;One tunnel per each pair of hots, subnet or gateway pair?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 10:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245839#M41074</guid>
      <dc:creator>koendsp</dc:creator>
      <dc:date>2025-04-07T10:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN between CheckPoint and Prisma Access</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245842#M41076</link>
      <description>&lt;P&gt;Definitely could be. Thats why I would make sure those guidbedit values are set to FALSE.&lt;/P&gt;
&lt;P&gt;Btw, you set per gateway if its route based tunnel or if vpn domain is combo of hosts/subnets.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 10:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-between-CheckPoint-and-Prisma-Access/m-p/245842#M41076</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-07T10:56:35Z</dc:date>
    </item>
  </channel>
</rss>

