- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: IPSec VPN between CheckPoint and Prisma Access
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSec VPN between CheckPoint and Prisma Access
Hey guys,
I was asked to make a test in which I will route all internet traffic from specific subnet (for example 10.10.10.0/24) to Prisma Access.
I configured the necessary part in Prisma Access Remote Networks IPSec VPN, but what are my options in order to this in checkpoint?
I was thinking to make a VPN community in which the VPN Domain will be 0.0.0.0/0, with excluding RFC1918 addresses and CGNAT address.
Is it even possible? Are there other options?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am thinking that maybe Route Based VPN with PBR will be more appropriate solution, but I am not sure how to implement it.
In VTI configuration, what do I configure as remote peer ip address and local ip address? I only have Prisma Access Public IP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See if below post I made about a year ago helps. I know its Azure, but would be very similar. I know Prisma is Palo Alto, if Im not mistaken. I only seen it once myself, apologies, but not familiar with it at all. But, to answer your question about route based, yes, you can follow documents I have in the link, hope it makes sense.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I understand that I could just "gibberish" the VTI numbered addresses, is this correct?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats right. See below from another post while back example I gave. Message me directly if you need further explanation.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @shauls , were you able to figure this out?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am still not sure about the "Numbered Remote Address" field. I understand that I could come up with any unique IP address for the numbered local address, but what about the remote address? I don't have such address provided to me by Prisma, unlike the AWS example.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does not really matter, as long as its not used on their end.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IT IS working. I used your text guide along with the AWS guide. I also configured PBR instead of static route.
There is only one thing that is very strange.. in Tunnel Monitoring I see the the tunnel is down, but on the Prisma side it is up and everything is working as expected.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Never mind, I see that I configured the "permanent tunnels" option but it should only work between checkpoint gateways. I disabled it and now I see that the tunnel is up. Thanks for the help!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I always more rely on vpn tu or vpn tu tlist.
Andy
