Hello all,
I must confess that I am still completely new to the CheckPoint environment. Please forgive me if some information is missing. This is simply due to my inexperience.
We will soon replace our existing firewall solution (SonicWall Nsa 2650) with a CheckPoint 6600. To take some load off the CheckPoint and make the switch a little easier, we would like to keep our SonicWall cluster running as a client VPN gateway (HomeOffice etc.).
The required networks (i.e. the client VPN network and the internal network to be reached) and access rules have already been created on the CheckPoint side. On the SonicWall side, all rule sets etc. still exist anyway.
For my understanding, it should be sufficient if we simply plug the LAN interface of the SonicWall onto an interface of the CheckPoint and connect the two components (SonicWall as client VPN gateway and the CheckPoint as FireWall) with each other. This way, the VPN gateway (SonicWall) would practically be "in front" of the CheckPoint. The incoming client VPN traffic would then be received on the SonicWall side and routed to the CheckPoint via the target interface.
Are there any possible stumbling blocks here that you can see directly, or how would you proceed if you want to continue to operate an old firwall cluster as a vpn gateway? I am grateful for any help.
Thanks
Felix