- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
Checkpoint Noob here. Have been tasked with configuring a Spark 1570 running R81.10.10 - Build 945.
Requires:
Third party has 2 IPs so we need two tunnels.
BGP required, therefore VTI required.
I do not have access to SmartConsole (that I know of) or Communities (that I know of - is that an add-on product?)
I feel like the setup is going to be very similar to this:
I used the above guide to setup the tunnels successfully in Gaia but I don't have access to the SmartConsole to configure the Interoperable device (is not a object type in Gaia GUI). I created a normal host object instead - don't know if that's going to work.
I don't have Communities apparently with the license for this device so I cannot setup the communities part. Can that portion be setup using Gaia command line?
Am I going to have to figure out how to add a license to use Communities? Feeling very ignorant at the moment.
Thanks.
VPN Communities and Interoperable Objects are only relevant when managed with a Smart-1, which is not the case for a locally managed device.
You can set up VTIs in Device > Network > Local Network > New > VPN Tunnel (VTIs).
You can set up the peer in VPN > Site to Site > VPN Sites.
Was able to engage Check Point support. It turns out that in our case to use the redundant tunnels we need to use MEP, which can be used with DPD instead of RDP (Check Point proprietary), however, to use MEP with our device requires centrally managed system like SmartConsole. We are going to work with the third party to just use a single tunnel. 😞
You use a loclly managed Spark 1570 running R81.10.10, so you have no SmartConsole and only Embedded GAiA.
Documentation:
Better look here for VPN with AWS: sk111733: How to configure Site-to-Site VPN between Amazon Web Services and locally managed SMB appl...
Besides: Can we move this post to Spark/SMB, @PhoneBoy , @_Val_ ?
Was able to engage Check Point support. It turns out that in our case to use the redundant tunnels we need to use MEP, which can be used with DPD instead of RDP (Check Point proprietary), however, to use MEP with our device requires centrally managed system like SmartConsole. We are going to work with the third party to just use a single tunnel. 😞
VPN Communities and Interoperable Objects are only relevant when managed with a Smart-1, which is not the case for a locally managed device.
You can set up VTIs in Device > Network > Local Network > New > VPN Tunnel (VTIs).
You can set up the peer in VPN > Site to Site > VPN Sites.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY