- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Definition of remote Gateway behind NAT
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definition of remote Gateway behind NAT
Hi,
do you know how centrally managed the CP1430 behind a NAT router? I have nat-ed all the required ports from the Router Public IP to the Firewall. We have some isue on the VPN establishing (invalid ID Identifier).
How I should configure the gateway on the SMS?
172.16.0.1/24 -> CheckpointGateway -> 192.168.1.1/24 -> Router ->PublicIP ---> CheckPointGateway ---> SMS
I hope is clear.... I can establish a SIC and push policy correcly. I also receve the log on the SMS
Luigi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The gateway object IP on the SMS would be the public IP.
You said you configured NAT for the required ports--which ones specifically?
Also, when you try to either push policy, fetch policy, etc, what specific behavior do you see?
Error messages? Screen shots? Other information?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My environment is like the SK 101469 but the 1430 is Centrally Managed...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume you want a VPN to 3rd party VPN as explained here: sk108600: VPN Site-to-Site with 3rd party - maybe you should set the ID Type not to IP address but something else...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nope, the both side are checkpoint gateways centrally managed
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please read sk108600 - maybe you should set the ID Type not to IP address but something else as i think it does send a wrong IP address... But you can analyze that using VPN Debug!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a similar setup but it fails on the SIC allready. In the SIC I see the LAN side IP adres in reverse notation and the match can't be made.
The hostname equals the object name in the policy for the Central firewall.
(SecurityPeer sent wrong DN: 1.255.168.192** Reset SIC from peer, and establish trust again. **)
