- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
TASK-1:
Establish the VPN between FW5 PC3 and Site1-FW3 PC1
Verification:
Ping from PC3 to PC1
Ping reply should be come and packet should be encrypted in Smart view Tracker.
TASK-2:
Establish the VPN between FW5 PC3 and Site1-FW4 PC2
Verification:
Ping from PC3 to PC2
Ping reply should be come and packet should be encrypted in Smart view Tracker.
TASK-3:
Establish the VPN between FW5 PC3 and Site1-FW6 PC4
Verification:
Ping from PC3 to PC4
Ping reply should be come and packet should be encrypted in Smart view Tracker.
Note:
i tried as shown below youtube video link but not worked
https://www.youtube.com/watch?v=mYgOztne_Gg&t=13s
please help me someone on this i am trying from last one week
Version/JHF of components in question?
What is the precise configuration on each gateway in terms of the encryption domain?
Are all gateways in the same VPN community?
What precise errors are you seeing in SmartView?
Version r77 and all gateways are in same vpn community,
Task are mentioned in the question and when i try as shown in the YouTube video link , i am able to ping pc3 to pc1 but i am not getting logs in pc3 and the ping should encrypt with vpn
Can you please tell me how will you able to ping pc3 to pc1
You can use vpn admin guide and follow info to set up vpn tunnel. Once up, then if traffic is not going through, more debugs can be done
vpn debug trunc
vpn debug ikeon
vpn debug ikeoff
get $FWDIR.log ike.elg and vpnd files
Andy
What does it mean can you explain more clearly?
What about the YouTube video is that correct
Can you complete this task? If you complete then please help me how will you do this
Please start with the following guide to setup simple Site to Site VPN:
Check Point for Beginners > Network Security
Or use Site to Site VPN R81.20 Administration Guide:
As outside firewall have same network it will be treated as private network so we have to do natting. But i didn't understand how to do natting. And after natting the private network will be known by public ip address so in console site which ip address is used to create vpn external gateway and which ip address is used to create other side network for vpn domain
Local encryption domain should always include local addresses (without NAT) of systems that will communicate over VPN tunnels.
Remote encryption domain will include the NAT addresses needed by the local systems to reach the remote systems.
Hello sir,
I understand what you want to say but i didn't understand how to do this so can you please explain more what wiil be the steps to make vpn end to end connectivity by using natting.
Its exactly how it works with any firewall vendor when it comes to VPN S2S tunnels...so you put LOCAL addresses as @PhoneBoy said in your CP fw enc. domain and as far as remote, that VPN domain needs to included NAT-ed IPs required to communicate.
Andy
Sir can u explain how you achieve this and i am beginner i should finish this task can you plz provide some u tube source link or can u explain what to do in each phase and how many server and firewall(two - tier ) should to be installed
Aside from official documentation, we have something in Check Point for Beginners that might be useful: https://community.checkpoint.com/t5/Check-Point-for-Beginners/Site-to-Site-VPN-in-R80-x-Tutorial-for...
I would say what @PhoneBoy linked is good start. Setting us the tunnel is easy, but if it does not work, then you would need to troubleshoot (run debugs, examine the config, check logs, etc)
Check Point | 3rd Party Site to Site VPN - YouTube
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY