Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Herold
Contributor

IPSec VPN with Zscaler

Hi,

Is there any integration guide to implement IPSec VPN with Zscaler ? I'm trying to establish a IPSec Tunnel to forward all port 80 and 443 traffic from a Checkpoint Firewall to Zscaler. Please advise.

Thanks,

 

 

0 Kudos
Reply
3 Replies
PhoneBoy
Admin
Admin

Why would you do that when we do all the same functionality or better on the gateway itself using the various NGTX blades? 🙂

Personally, I haven't seen an integration guide myself.
Historically, they've wanted to use GRE, which is something we don't support.
Here's what Zscaler has to say: https://help.zscaler.com/zia/configuring-ipsec-vpn-tunnel
Part of what they say here isn't true because:
1. From R80.30, we can support MEP with DPD with third party peers.
2. What is sent down the tunnel is "all ports and protocols."

What is true is that it would require some complex configuration to send only 80/443 traffic down the VPN tunnel.
My guess is that involves NON_VPN_TRAFFIC_RULES.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

And I guess you have to disable NAT-T support, as their document says.
0 Kudos
Reply
vijayakumar_M
Explorer

i too have the same requirement can you help us.

 

0 Kudos
Reply
jrinns
Explorer

Hi did anyone get the IPSEC tunnels created to Zscaler?

 

0 Kudos
Reply