View Single Post
  #10 (permalink)  
Old 2008-04-21
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Check Point VPN design

This is a typical design for an enterprise.

The reason that most companies go with VPN Concentrator for remote access
and IOS routers for L2L VPN is because the flexibilities with IOS routers and
VPN concentrators to be able to do GRE/IPSec and dynamic routing protocols
within the IPSec tunnel. NAT on checkpoint is the best because it is
so flexible.

Just abpit every place I work uses this design.
Reply With Quote