- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Does it possible to HOST_B access to internet through Checkpoint firewall by using IPSEC vpn tunnel.?
If yes, how to configure this.
Then we need to consult Site to Site VPN Administration Guide R80.20 p.72 :
Configuring VPN Routing in Domain Based VPN
Configure most common VPN routing scenarios through a VPN star community in SmartConsole.
You can only configure VPN routing between Security Gateways that belong to a VPN community.
Configuring VPN Routing for Security Gateways in SmartConsole
To configure a VPN Routing in a star community in SmartConsole:
1. On the Star Community window, in the:
a) Center Gateways section, select the Security Gateway that functions as the "Hub".
b) Satellite Gateways section, select Security Gateways as the "spokes", or satellites.
2. On the VPN Routing page, Enable VPN routing for satellites section, select one of these options:
• To center and to other Satellites through center - This allows connectivity between the Security Gateways, for example if the spoke Security Gateways have dynamically assigned IP addresses, and the Hub is a Security Gateway with a static IP address.
• To center, or through the center to other satellites, to internet and other VPN targets - This allows connectivity between the Security Gateways as well as the ability to inspect all communication passing through the Hub to the Internet.
3. Create an appropriate Access Control Policy rule. Remember: one rule must cover traffic in both directions.
4. NAT the satellite Security Gateways on the Hub if the Hub is used to route connections from Satellites to the Internet.
Sound like Hub Mode - see sk101239: Routealltrafficfrom Remote Access clients, including internet traffic, through Security Ga... ! Internat networks can be excluded, see sk130832: "Do not routetrafficfor local network to the gateway" is grayed out on Endpoint Security C...
Then we need to consult Site to Site VPN Administration Guide R80.20 p.72 :
Configuring VPN Routing in Domain Based VPN
Configure most common VPN routing scenarios through a VPN star community in SmartConsole.
You can only configure VPN routing between Security Gateways that belong to a VPN community.
Configuring VPN Routing for Security Gateways in SmartConsole
To configure a VPN Routing in a star community in SmartConsole:
1. On the Star Community window, in the:
a) Center Gateways section, select the Security Gateway that functions as the "Hub".
b) Satellite Gateways section, select Security Gateways as the "spokes", or satellites.
2. On the VPN Routing page, Enable VPN routing for satellites section, select one of these options:
• To center and to other Satellites through center - This allows connectivity between the Security Gateways, for example if the spoke Security Gateways have dynamically assigned IP addresses, and the Hub is a Security Gateway with a static IP address.
• To center, or through the center to other satellites, to internet and other VPN targets - This allows connectivity between the Security Gateways as well as the ability to inspect all communication passing through the Hub to the Internet.
3. Create an appropriate Access Control Policy rule. Remember: one rule must cover traffic in both directions.
4. NAT the satellite Security Gateways on the Hub if the Hub is used to route connections from Satellites to the Internet.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY