Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bernardes
Advisor
Jump to solution

VPN Site-to-Site Peer Route All Traffic Through Check Point

Dear friends,

could you please help me with the following situation:

I am going to establish a tunnel between Site A (Check Point) and Site B (SonicWall), and I need all traffic, including internet browsing from Site B, to pass through Site A.

What is the best option to achieve this?

How should I configure the VPN Domains at gateways options on Sites A and B?

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

In a "route all traffic" scenario, you have to do one of two things:

  • Use Route-Based VPN (where the encryption domains are empty or 0.0.0.0/0), everything is controlled through the routing table.
  • In the relevant VPN community, ensure "One Tunnel Per Gateway Pair" is selected, which I believe means we will negotiate a 0.0.0.0/0 SA with the VPN peer:

image.png

If using domain-based VPN, on the Check Point side, your encryption domain would include the hosts behind it and you define the remote encryption domain as the hosts behind the remote gateway.
Can't speak to the Sonicwall side of the configuration in either case. 

View solution in original post

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

In a "route all traffic" scenario, you have to do one of two things:

  • Use Route-Based VPN (where the encryption domains are empty or 0.0.0.0/0), everything is controlled through the routing table.
  • In the relevant VPN community, ensure "One Tunnel Per Gateway Pair" is selected, which I believe means we will negotiate a 0.0.0.0/0 SA with the VPN peer:

image.png

If using domain-based VPN, on the Check Point side, your encryption domain would include the hosts behind it and you define the remote encryption domain as the hosts behind the remote gateway.
Can't speak to the Sonicwall side of the configuration in either case. 

0 Kudos
Blason_R
Leader
Leader

This is absolutely correct and you must go with route based VPN.

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events