Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Explorer

VPN Routing through Center?

We need:

Traffic flow: Satellites GW from branch B、C  need to contact to Remote GW X , the traffic must always pass through Center A.

Example : host (behind branch B or C )=====VPN====>Center A=====VPN=====> Server  (behind Remote GW X)

 

So now the question is How to configure the “Remote GW X “?

 Please share configuration methods and suggestions. Thanks!

0 Kudos
Reply
4 Replies
Champion
Champion

Are all gateways Check Point?
In any case create a new Star topology configure satellite X with the correct VPN Topology, same for each other gateway, only add it's own topology.
In the star set Center A as the center gateway and all other gateways as Satellites. In the routing page set routing through center. Allow the traffic that you want to allow and push policy to all gateways.
Regards, Maarten
Explorer

Thank you so much for your reply and help!

Are all gateways Check Point?
Yes, all gateways are Check Point.

1)、Satellite X (Remote GW X) is Standalone Deployment, It manages by itself.

2)、Center A and satellite B, C, D are managed by the same SMS server

=================================================================================================
Is the following configuration correct on firewall Satellite X?

Create a new VPN Community:Star mode
Set Center A as the center gateway
Set Satellite X as the Satellites gateway
VPN Routing Options:To center and to other satellites through the center
Set Traffic Policy and push policy to Satellite X


Two questions:
1)、Do satellite B and C need to be created on Satellite X and added to the satellites?
2)、The VPN networks from the satellite B and C that need to access resources behind the remote Satellite X,Are these VPN networks added to the VPN Domain of the Center A?(Center A here is the object on Satellite X

-----------------------------------------------------------------------------------------------------------------------


Is the following configuration correct on SMS server Center A and Satellite B、C、D are centralized management )

VPN Community:Star mode
Center A is the center gateway
branch B、C、D are Satellites gateway (add Satellite X as the Satellites gateway )
VPN Routing Options:To center, or through the center to other satellites, to internet and other VPN targetsThis setting cannot be changed
Set Traffic Policy and push policy to Center A and Satellite B、C、D.


Questions:
1)、Does setting different VPN routing options cause problems?


Thanks a lot !

0 Kudos
Reply
Champion
Champion

On the locally managed X you need to add the networks of all other satellites to the VPN domain of the Center A gateway. Do not add any other gateway to the Satellite X.

Changing the VPN routing from the current setting to the route through center to other satellites (NOT Internet) will cause the internet traffic to be direct from the satellites instead of through the center GW.
Regards, Maarten
0 Kudos
Reply
Explorer

Ok, thanks. I'll try.

0 Kudos
Reply