- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good morning, dear friends,
I am deploying the checkpoint spark equipment in 5 remote locations, managed from smart cloud, which I will link to the client's main location through a site-to-site tunnel, at the end of the main location the firewall is a fortigate. The requirement of this tunnel is that each remote location has communication only and exclusively to the central location, in this case would I use a meshed or start community?
Another question I have is at the end of the remote locations where the spark checkpoint gateways will be, the internet router provides a netted IP (192.168.1.0/24), the WAN interface of the Gateway has an IP of this segment; at the end of the main location the Foritgate does have public IPs in its WAN interface. In this case, with other firewalls I would have to configure a Peer ID at each end but in checkpoint I do not identify how to configure this Peer ID.
Best regards
I think simple net diagram would help us here. Question 1 ) Yes, sounds like star community is fine, since you can use central location as central gw and other ones as sateelites
Question 2) I never ever heard of peer ID on CP side, so not sure if that setting even exists. Though, it might be somehwere in smb gui page, cant confirm, as I literally ever work on those devices, but in regular Gaia, I had never seen it, unless you use VTIs, but even in such case, it ONLY asks to enter peer name, which is essentially name of interoperable object you configure representing other side
Andy
This is what I was referring to.
Andy
Hi, thanks for your reply,
I don't know where to add this, please help me
Regards
Just working on some Fortinet stuff, will spin up quick demo smb lab and see if option is there. Otherwise, we can do remote tomorrow if you are allowed to, let me know.
Btw, that option I pasted is on regular Gaia, plus, may not apply to you, as its mostly used for ROUTE based vpn tunnels, not domain based ones.
Andy
While Im waiting for customer/Fortinet guy to finish what they need to finish, I spun up the lab in the meantime and this is what Im referencing from the screenshot. BUT, again, if you are going to build domain based vpn, none of this is relevant. Howveer, if it will be route based (which I always recommend to people now days), then it matters. Anyway, message me directly tomorrow if you can do remote and happy to go through it together.
Andy
See my post abour route based tunnels.
Hi, I wrote to you directly. Thanks
Responded...just send me your email, lets connect offline, easier.
Best,
Andy
Hey Gerardo,
Thanks for your time on the remote today and apologies for my abysmal Spanish :(. Anyway, we agreed you would configure route-based VPN tunnel and test it out. If any issues mate, just text me or email and we can do another zoom meeting.
Best,
Andy
And here is Spanish translation 🙂
***********************************
Gracias por tu tiempo en el control remoto hoy y disculpas por mi pésimo español :(. De todos modos, acordamos que configurarías un túnel VPN basado en rutas y lo probarías. Si tienes algún problema, amigo, envíame un mensaje de texto o un correo electrónico y podemos hacer otro zoom. reunión.
Hey bro,
I waited 10 mins in zoom, but no one showed up, so I closed it. Im good for another 30 mins.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 6 | |
| 2 | |
| 2 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY