- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: My first VPN with checkpoint technology
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My first VPN with checkpoint technology
Good afternoon. I'm trying to configure my first VPN with checkpoint technology, but I can't do it.
I want to enter my local home network through the internet through a VPN Check Point 600 Appliance Version:R77.20.80
I wrote my Public IP address assigned by my ISP,
Select option Route all traffic through this site.
When I do the VPN connection test, it does not pass, what is the reason why the test does not pass?
What am I doing wrong?
can you help me please ❤️
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The "site" you are attempting to create is the remote end of a site-to-site VPN.
Which means you wouldn't be entering your public IP here, but the public IP of the remote end.
What is the remote end of the VPN in this case?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Excuse me but I did not understand you, I want to connect to my local network with an VPN from my computer using internet, through Check Point 600 Device version: R77.20.80... I looked in the documentation but I don't see any manual for R77.20.80. that you configure the equipment, in addition the pdf documentation is done through executable software or from the terminal, but there is a manual from the web UI.
Can you please guide me, in which menu is the VPN configured? Am I in the wrong menu? What is the menu to configure the VPN?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If I get it right, what you need to configure is Remote Access and you are trying to configure Site-to-Site VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank for reply
I am following this guide
SMB Appliances - How to connect to the office using Check Point Remote Access (VPN) clients?
Download and Install
- Download and run the latest installation file. Refer to the Remote Access (VPN) Clients product page.
For more information on Check Point Remote Access Solutions, see sk67820. - During installation, select Endpoint Security VPN
- Complete installation and reboot.
- For more operating systems and versions, go to Remote Access (VPN) Clients product page.
Configure
- Right-click the product notification icon and click on VPN Options.
- On the Sites tab, click New - the Site Wizard will start.
- Click Next.
- Enter the IP address of the SMB Appliance in your organization, given to you by your administrator, and click Next.
- Choose Authentication method Username and Password.
Connect
- Right-click the product notification icon and click on Connect.
- Enter username and password (consult your administrator if you do not know them) and click Connect
USER
Client on Windows:
what am I doing wrong ? please help me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try to open in a browser - https://10.20.30.40
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I entered that IP address in the browser.
The checkpoint Firewall Next Generation Check Point 600 Appliance device page opens
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is the admin interface and not remote access one. It does seem like the appliance does not have static Internet address?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Shouldn’t you use the public address (the 200 one) here?
The 10 address is a private address that won’t be reachable from the Internet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, currently my ISP (Internet service provider) does not offer me a static Internet address, but a dynamic IP address is not a problem, I will pay for a DNS service with my own domain
Before purchasing a DNS service I want to configure my Firewall with VPN.
I am not an expert in networks and computer security, but I have basic knowledge, I know a little about this topic.
I am in the menu, device> Routing.
I don't understand what this routing table works for, or what it does
Routing: View the routing table and configure manual routing rules
IPv4 Routing Table
To see my public IP address I enter the website whatismyip.com I currently have "190.1.145.22"
When I type this IP address in the browser, I can enter my ISP's rounter.
PS: for security measures this is not my real ip, it is an example. is 190.xx.xx.xx
I am thinking that the device has a bad configuration?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You seem to have private IP (10.20.30.1) assigned to the Internet connection at the moment. That will not work for remote access. You need to reconfigure your WAN interface so that it is assigned public IP either statically or dynamically. Then you can use some free DDNS service to always have the current public IP assigned to a hostname. Your own DNS will likely not help because you will need to update that IP manually every time it changes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm so sorry. I did not want to put the real IP addresses for security measures but I need to configure this device.
I don't know if the correct term is private ip but this address is from my DHCP ISP's rounter 10.10.10.1
ISP's Rounter
DHCP
10.10.10.1
CheckPoint
DHCP
10.0.0.1
This is the network diagram, how my network is structured
Do I need to reconfigure my WAN interface?
PD: Post Edited press F5 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to either assign public IP on the CheckPoint device or setup NAT from your border router to CheckPoint appliance (TCP/443 and UDP/4500).
