Here is an example how this works with Azure.
Instead of Azure, this can also be any other VPN destination.
1) Create VPN Tunnel Interface (VTI)
NOTE:
THE PEER NAME MUST MATCH THE SMARTDASHBOARD OBJECT NAME OTHERWISE THE VTI WILL NOT WORK
2) Add Static Route for Azure VPN Peer BGP IP:
3) Setup BGP in GAIA WebUI
WARNING:
Without “ALL” of these configurations completed BGP will not be successful
4) Add Azure Gateway BGP Information:
Fill in information based on Azure Gateway BGP Settings:
NOTE:
Without Multihop enabled the BGP session will not be established
5) Set BGP Inbound route filters
NOTE:
For the purpose of this documentation the inbound filter has been set to accept all routes – this will vary in each environment
6) Set inbound route filter settings
7) Create an empty VPN group which will represent the Azure VPN Gateway’s vpn domain:
8 ) Next create Azure VPN Gateway object:
9) Create VPN Community
10) Create VPN ruleset
...
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips