Hello,
We have a situation internally I could use help with. We are an energy company, and use private APNs for a lot of our substation and field device connections. We are in the process of moving our Checkpoint firewalls over to these APNs, but have management and traffic issues. Basically we need to manage them through the APN's site to site vpn tunnel with the 3rd party.
I have reviewed some other posts on this, but they dont seem to fit exactly. For example https://community.checkpoint.com/t5/General-Topics/Manage-firewalls-via-IPSec-VPN-tunnel/td-p/53075
and https://support.checkpoint.com/results/sk/sk104582
We need to keep our existing connections working, which are through an APN, but via a 3rd party cisco router (we are trying to migrate from). From what I am reading, if we disable the CPMI in implied rules, it might break a lot of our other locations. We are trying to use site-to-site checkpoint VPNs as well over this APN connection. Is there some way TAC can change the implied rules to allow encryption of that traffic? The option to move the CMPI and many others 'Before Last' is greyed out, which seems like exactly what we want.
Anyone else doing this? I have a case with Diamond started but it hasnt gotten far.