| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi how to configure and edge behind an adsl router)with no static ip). We want to configure site to site vpn to our main cp vpn-1 firewall. any documentation available? huntsville |
| |||
| Solution 1) Get a UTM-1 Edge ADSL instead and get rid of that ADSL router in front of your Edge. This way your Edge gets the dynamic external IP address on it's external interface and NAT-T is not required. Solution 2) Configure you UTM-1 Edge as a DAIP gateway in SmartDashboard, check permanent tunnels in your VPN community and let NAT-T do the rest. You may not be able to manage your Edge remotely, though. Solution 3) Come to the CPUG CON 2008 Europe. |
| |||
| Hi dantro. first thx for replying. i hope i understood what you mentioned, plz correct if i got it wrong. create a new ext managed adsl object. specify fqdn hostname in link selection create a certificate using an external CA (coz cp says for externally managed gateways, external ca is required) put the gw objects in community and create a security rule. hope i got it right. tomorrow i got to work on a new CA and will update. thanks |
![]() |
| Thread Tools | |
| Display Modes | |
| |