Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mcguppy
Participant

two VPN connections with the same client

Is it possible to connect a VPN within a VPN with the checkpoint "Check Point Mobile" client?

The problem is as follows: Today to get to the company network, we are using WatchGuard VPN. As soon as I am connected there, I have to open another VPN with the product of Palo Alto to get to the target environment. This is working without problems.

We have decided to replace both firewalls with checkpoint firewalls. Like this, I have to do all with the same client (not with two different products like today).

Is this possible with "Check Point Mobile" client at all?

 

Thanks for helping me.

0 Kudos
3 Replies
_Val_
Admin
Admin

If you want to connect to two separate VPN GWs from the same client at the same time, it is not possible. Event in your current setup, you are using two different clients to open two tunnels.

However, you can do VPN routing that would allow you to connect to the target environment through S2S VPN tunnel between two sites.

What I am saying is, that you connect with your RAS VPN client to GW A and need to reach a server that belongs to GW B VPN domain. This is possible if there is a site-to-site tunnel between GW A and GW B.

 

 

0 Kudos
mcguppy
Participant

Hello Admin

Thank you very much for your help.

The solution for the S2S would work as long as we have only one target environment or if we have different subnets in the different target environments. But we will have multiple target environments (different GW B) always using the same subnets, and so it can't be handled with routing on GW A.

But we will find a solution, either via the VDI environment in the corporate network which is then used as a jumphost where we again use the checkpoint VPN client to connect to the different GW B's or by placing another VPN product in the target environment behind the second checkpoint that terminates the VPN (e.g. openVPN).

I just wanted to make sure it really wasn't possible before designing a workaround, and with your answer it's clear now. 

Thank you very much.

0 Kudos
_Val_
Admin
Admin

No problem

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events