- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi everyone,
I have a CheckPoint 3000 Application running R80.10 software.
I have been attempting to create a simple VPN setup for the last few weeks and failing miserably.
What I want to achieve.
I want to be able to have clients use the CheckPoint VPN client software, to connect to my CheckPoint appliance and access the local LAN.
I have followed a number of guides to no avail, I'm hoping someone has set this up on their appliance and can point me in the right direction.
Cheers
Hi @RyanJohnson,
I think the GAIA portal on port 443 is active on the management server. This means that the site information cannot be loaded over port 443.
More to used check Point ports read here: R80.x Ports Used for Communication by Various Check Point Modules
Solution:
Put the GAIA portal to a different port for example 4434.
Thanks for your reply.
The guide was as follows; This one (Getting started with Remote Access)
When I try to connect to the external IP that I have set on the Link Selection on the Checkpoint IpSecVPN, it states that the target isn't responding.
I assume that I've set something up wrong somewhere, but from what I can see, I have followed the guide.
Steps that I have taken so far;
With the above setting, I assumed I'd be able to establish a connection with my NAT IP and then fail on user login, however I cannot connect to the Checkpoint from an external IP.
I get this error using the Checkpoint software to connect;
Any pointers would be great, is there a different way I should be creating this, is there another guide I can follow.
Checkpoint is super new to me!
1. Do you permit HTTPS connections from the Internet to the external interface of your Check Point appliance? If not, enable it.
2. Do you refer to the appliance by its name or IP address? if name, is it publicly resolvable?
3. When you are connecting to the appliance, are you prompted to accept the self-signed certificate? If so and you are accepting it, please examine it to see what it is issued to and if your connection properties on the client actually matching those presented in the cert.
4. Since you are mentioning manually specifying the "Statically NATed IP" in the link selection, this to me indicates that the CP device itself has RFC1918 addresses on its external interface. Do you have that interface defined as "External" in topology? Are you using "Zones" in your rulebase? Does the upstream device filtering the inbound traffic at all (i.e. it is another firewall or a VPN capable device)? If it does, have you configured it to forward IPSec related traffic to the actual private IP of the CP's external interface?
For times when we see such Site creation failed ! error we can look into sk128652: Troubleshooting "site is not responding" Issues
Did you follow Remote Access VPN Administration Guide R80.10 ? Because usually it is rather an easy task (using internal users defined in Dashboard, do a Database install and emacs!)...
Hiya,
I did, well I think I did, I must be missing something somewhere.
Checkpoint is rather new to me, but Firewalls and VPN aren't so I'm a tad baffled.
Hi @RyanJohnson,
I think the GAIA portal on port 443 is active on the management server. This means that the site information cannot be loaded over port 443.
More to used check Point ports read here: R80.x Ports Used for Communication by Various Check Point Modules
Solution:
Put the GAIA portal to a different port for example 4434.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
5 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY