Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mitesh
Participant
Jump to solution

IPSec Tunnel Architecture

Hi,

We need your suggestion in IPSec Tunnel Architecture, attaching architectural diagram fro your reference.

In the diagram we have mentioned incoming & outgoing traffic flow. Traffice from Remote Office to DC (ingress traffic) is indicated via Green arrow & Traffic from DC to Remote Office (egress traffic) is indicated via Red arrow.

We have performed below configuration:

For Ingress Traffic:-

1. In CP-3800, created static route to reach DMZ subnet traffic pointed to Palo Alto Interface.

2. In Palo Alto, created static route to reach DMZ subnet traffic pointed to CP-9100 interface.

3. DMZ Subnet Route advertied in CP-9100 via directly connected.

Also we have allowed traffic via security rules.

For Egress Traffic:-

1. In CP-9100, created static route to reach remote office network traffic pointed to Palo Alto Interface.

2. In Palo Alto, created static route to reach remote office network traffic pointed to CP-3800 interface.

 

Is any further configuration is required, need your suggestion.

ipsec_tu.jpg

 

0 Kudos
2 Solutions

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Seems fine to me, are there any specific concerns you have with it?

View solution in original post

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Seems right.

Best,
Andy

View solution in original post

0 Kudos
5 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Your diagram isn't loading for me, seems to be stuck in a virus scan. What's not working for you?

0 Kudos
Mitesh
Participant

attached once again...

0 Kudos
Mitesh
Participant

ipsec_tu.jpg

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Seems fine to me, are there any specific concerns you have with it?

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Seems right.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events