- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello all,
I am actually completely new to Checkpoint. I have done same thing on different vendors but first time tried to make on CP but failed. Unfortunately I cannot find enough resources for solving my problem that is why I write here.
We are building new branch office and installing gateway there. I want all traffic to be router to central office through VPN because for AWS resources I need to have Public IP connection from Central office. The problem is SP cannot install fiber optics in time and now we are using 4G router in front CP for couple weeks. So the connection is as below:
LAN-CP(15000S)-192.168.1.0/24-4G-Reserved Public IP.
Central Office side is completely okay and have already a lot VPN tunnel configured previous to me.
I am doing All TCP_UDP ports forwarded from 4G router to checkpoint external Private IP which is static.
What I need to enable beside basic Domain Based VPN configuration on Checkpoint Firewalls? Any help is appreciated.
How Can I enable NAT-T on both gateways for this connection?
What is "Hide this gateway behind another gateway" on Advanced->NAT section? Do i need to enable it?
Is putting Public IP of 4G router in Link selection enough?
@OrkhanRustamli , take a look at this thread that was discussing this same issue some time ago: https://community.checkpoint.com/t5/General-Topics/Gateway-behind-NAT-What-limitations-am-I-to-be-aw...
Hello @Vladimir,
I have seen this document but it does not answer all my question. Have you been able to solve this problem in your scenario? If yes, amy you please share what you have accomplished?
As far as I recall, this option should be enabled on the gateway you are working on :
"Hide this gateway behind another gateway" on Advanced->NAT
Have to take another look at the "Link selection" options.
Please specify the version you are running on both sides.
My lab is down at the moment, but I'll see if either I can spin it up to verify or poke someone in the forum to take a look at this question.
P.S. How is the gateway behind 4G router is managed? Does it have an independent management server, is it all-in-one, or are you planning to manage it from the main site via the VPN?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY