Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LazarusG
Contributor
Contributor
Jump to solution

How to steer web browsing traffic through an ipsec tunnel to Netskope

Hi

If you implement the Netskope IPsec tunnel option for traffic steering: the documentation states that you can use PBR;

https://docs.netskope.com/en/netskope-help/traffic-steering/ipsec/

"Configure the IPSec tunnels for your vendor’s source identity devices. Use policy-based routing to steer HTTP/HTTPS traffic on ports 80 and 443 through the IPSec tunnels. If you have the Cloud Firewall license, you can also steer non-HTTP(s) traffic like TCP, UDP, and ICMP through the tunnels. To see vendor specific integration guides: IPSec and GRE."

If you follow the hyperlink for the vendor-specific integration guide Checkpoint isnt listed;

https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/

How can we leverage sk167135 to steer http and https traffic through a Netskope tunnel?

It sounds like an ideal solution for ABR, but it also sounds like PBR can't be used with route based vpns so this would need to be a domain based VPN(?).

 

Thanks

 

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

The table suggests should be possible from R80.40 and above with VTI / route based?

Whether that's what's required / supported by Netskope I couldn't say.

CCSM R77/R80/ELITE

View solution in original post

0 Kudos
4 Replies
Chris_Atkinson
Employee Employee
Employee

Regarding sk167135 and the table therein which version is your gateway?

CCSM R77/R80/ELITE
0 Kudos
LazarusG
Contributor
Contributor

Hi

 

Product Name: SVN Foundation
SVN Foundation Version String: R81.10
SVN Foundation Build Number: 996000057
SVN Foundation Status: OK
OS Name: Gaia
OS Major Version: 3
OS Minor Version: 10
OS Build Number: -
OS SP Major: -
OS SP Minor: -
OS Version Level:
Appliance SN:
Appliance Name: PowerEdge R730
Appliance Manufacturer: Other

This is Check Point CPinfo Build 914000234 for GAIA
[FW1]
HOTFIX_R81_10_JUMBO_HF_MAIN Take: 94
HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE
HOTFIX_GOT_TPCONF_AUTOUPDATE
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE

FW1 build number:
This is Check Point's software version R81.10 - Build 035
kernel: R81.10 - Build 036

route based vpn with PBR or even application based routing might make sense but from SK167135 I understand VTI and PBR isnt supported?

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

The table suggests should be possible from R80.40 and above with VTI / route based?

Whether that's what's required / supported by Netskope I couldn't say.

CCSM R77/R80/ELITE
0 Kudos
LazarusG
Contributor
Contributor

thanks - I think it would be really nice to use PBR/ABR with route based vpn and maybe unnumbered vti but I found there is a solution published since 2022;

Configuring Site-to-Site VPN between a Check Point Gateway and Netskope

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events