Hello @PhoneBoy, Sure here is the configuration.
AWS Side Configuration
1. Create a Site-to-Site Connection:
- Under Static Route, add your local network CIDR.
- Download the configuration:
- Vendor: Checkpoint
- Platform: Gaia
- Software: R80.10+
- IKE Version: IKEv2
Checkpoint SMB Configuration
1. Connect to the Firewall via SSH and Create a VPN Tunnel (VTI):
- Verify that the VPN tunnel (VTI) is visible under Local Network
![VTP.JPG VTP.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26506i78C46D88C13738A0/image-size/large?v=v2&px=999)
2. Create a VPN Site:
- Navigate to VPN -> VPN Sites -> New.
Remote Site
![T1 Remote Site.JPG T1 Remote Site.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26507iC68DB4CD55BBF5A8/image-size/small?v=v2&px=200)
Encryption
![Encryption.JPG Encryption.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26508i013CA2C5A2F88D10/image-size/small?v=v2&px=200)
Advanced
![Advanced.JPG Advanced.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26509i481DCAF6464DDF3B/image-size/small?v=v2&px=200)
This is the configuration we have done as per the sk111733
Below is the screenshot where you able to see the VPN tunnel us up at both sides.
![AWS Tunnel1.JPG AWS Tunnel1.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26510i1378F4C00FC06ABE/image-size/small?v=v2&px=200)
![CP Tunnel1.JPG CP Tunnel1.JPG](https://community.checkpoint.com/t5/image/serverpage/image-id/26511i7735D27653A11CB2/image-size/small?v=v2&px=200)