CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-08-31
Junior Member
 
Join Date: 2007-11-25
Posts: 5
Rep Power: 0
huntsville has an average reputation (10+)
Default How to configure Edge behind an ADSL router-no fixed ip

Hi

how to configure and edge behind an adsl router)with no static ip).

We want to configure site to site vpn to our main cp vpn-1 firewall.
any documentation available?

huntsville
Reply With Quote
  #2 (permalink)  
Old 2008-08-31
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: How to configure Edge behind an ADSL router-no fixed ip

Solution 1) Get a UTM-1 Edge ADSL instead and get rid of that ADSL router in front of your Edge. This way your Edge gets the dynamic external IP address on it's external interface and NAT-T is not required.

Solution 2) Configure you UTM-1 Edge as a DAIP gateway in SmartDashboard, check permanent tunnels in your VPN community and let NAT-T do the rest. You may not be able to manage your Edge remotely, though.

Solution 3) Come to the CPUG CON 2008 Europe.
Reply With Quote
  #3 (permalink)  
Old 2008-09-02
Junior Member
 
Join Date: 2007-11-25
Posts: 5
Rep Power: 0
huntsville has an average reputation (10+)
Default Re: How to configure Edge behind an ADSL router-no fixed ip

Hi dantro.

first thx for replying.

i hope i understood what you mentioned, plz correct if i got it wrong.
create a new ext managed adsl object.
specify fqdn hostname in link selection
create a certificate using an external CA (coz cp says for externally managed gateways, external ca is required)

put the gw objects in community and create a security rule.
hope i got it right. tomorrow i got to work on a new CA and will update. thanks
Reply With Quote
  #4 (permalink)  
Old 4 Weeks Ago
Member
 
Join Date: 2007-03-09
Location: Singapore
Posts: 31
Rep Power: 0
wicked has an average reputation (10+)
Default Re: How to configure Edge behind an ADSL router-no fixed ip

why do most people not come back & update when they promise to do so?
__________________
CEH, CCSE, CISSP
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:16.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0