<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site-to-Site VPN over 4G Internet for Quantum Spark Appliances in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254121#M12986</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We have nearly 20 Checkpoint appliances at our branches. We currently have an existing PPPoE connection used for both Internet access and a Site-to-Site VPN to our DC, HO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning to set up a backup 4G Internet link for SMB appliances at our branch offices. This is intended to ensure continuous Internet and VPN connectivity for staff in case the primary PPPoE link goes down.&lt;/P&gt;&lt;P&gt;I would like to ask:&lt;BR /&gt;Is it possible to establish a Site-to-Site VPN over this 4G interface?&lt;/P&gt;&lt;P&gt;The 4G connection uses CGNAT, so no public IP is available on the branch side. I'm currently unsure whether Check Point SMB appliances support dial-up VPN mode (where the branch initiates VPN without needing a static public IP).&lt;/P&gt;&lt;P&gt;Does anyone know something about this, please help me.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best regards.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jul 2025 15:53:27 GMT</pubDate>
    <dc:creator>Mk_83</dc:creator>
    <dc:date>2025-07-28T15:53:27Z</dc:date>
    <item>
      <title>Site-to-Site VPN over 4G Internet for Quantum Spark Appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254121#M12986</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;We have nearly 20 Checkpoint appliances at our branches. We currently have an existing PPPoE connection used for both Internet access and a Site-to-Site VPN to our DC, HO.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm planning to set up a backup 4G Internet link for SMB appliances at our branch offices. This is intended to ensure continuous Internet and VPN connectivity for staff in case the primary PPPoE link goes down.&lt;/P&gt;&lt;P&gt;I would like to ask:&lt;BR /&gt;Is it possible to establish a Site-to-Site VPN over this 4G interface?&lt;/P&gt;&lt;P&gt;The 4G connection uses CGNAT, so no public IP is available on the branch side. I'm currently unsure whether Check Point SMB appliances support dial-up VPN mode (where the branch initiates VPN without needing a static public IP).&lt;/P&gt;&lt;P&gt;Does anyone know something about this, please help me.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 15:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254121#M12986</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2025-07-28T15:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN over 4G Internet for Quantum Spark Appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254138#M12987</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/106488"&gt;@Mk_83&lt;/a&gt;&amp;nbsp;How about your DC ? Are there running gateways with a none dynamic public IP address ?&lt;/P&gt;
&lt;P&gt;It‘s normally not a problem with site to site VPN via 4G, 5G, LTE ….. to a central gateway. NAT done by the mobile networks providers are too no problems. IPSEC connection will be using NAT-T and the connection has to be initiate from the branch site to the central DC.&lt;/P&gt;
&lt;P&gt;Monitoring of the state of the branch appliances does not work (the small green sign of the firewall object in SmartConsole). The monitoring connection is initiated from the SMS to the branch appliance and this will fail because of the NAT in the providers network.&lt;/P&gt;
&lt;P&gt;The branch gateway objects must be defined with dynamic external IP. We are running environments with integrated LTE in the appliance and others with external LTE routers, both are working fine.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 20:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254138#M12987</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-07-28T20:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN over 4G Internet for Quantum Spark Appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254164#M12988</link>
      <description>&lt;P&gt;Many thanks for your response.&lt;/P&gt;&lt;P&gt;Yes, Our DC gateway (Sophos) already have public IP (pppoe).&lt;/P&gt;&lt;P&gt;We were add the branch gateways to Smart-1 Cloud (connect through pppoe internet link), and set up VPN S2S to DC using that link. This works well since both sides have public IP addresses.&lt;/P&gt;&lt;P&gt;Do you have any documentation or best practices regarding configuring a VPN tunnel from a 4G/LTE/5G (non-public IP) to a DC gateway with a public IP, could you please share it with me?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Best Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 07:45:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254164#M12988</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2025-07-29T07:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN over 4G Internet for Quantum Spark Appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254165#M12989</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167473" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk167473: FAQ for Security Gateways with Dynamically Assigned IP Address (&lt;STRONG&gt;DAIP&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 07:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-over-4G-Internet-for-Quantum-Spark-Appliances/m-p/254165#M12989</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-29T07:50:09Z</dc:date>
    </item>
  </channel>
</rss>

