CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-17
Junior Member
 
Join Date: 2005-10-17
Location: England UK
Posts: 1
Rep Power: 0
Mickyvgb has an average reputation (10+)
Send a message via MSN to Mickyvgb
Default Site to Site VPN tunnel using NGX(R50)

Hi all

does anyone have a simple user guide on how to set up a VPN site to site tunnel
We have tried to set one up but it seems the packets are not routing though the tunnel.
The remote system is an Cisco PIX
if you could email me at m.varney@hotmail.com



I know I should go on a training course but getting the money out of the IT manager is a bloody nightmare !! I am sure managers see there budgets as there own private money !! sorry for the moan !! :-(
Reply With Quote
  #2 (permalink)  
Old 2005-10-24
Junior Member
 
Join Date: 2005-09-29
Posts: 7
Rep Power: 0
rasberrystolli has an average reputation (10+)
Default Re: Site to Site VPN tunnel using NGX(R50)

VPN Setup

What you need to know
• Remote site external gateway (ISP)
• What networks they will allow you to get to
• Create a network object for the remote site’s network. If more than one network create a network group.
• Create an interoperable device. Use this because it doesn’t have to be a checkpoint firewall on the other end. If you use checkpoint firewall you have to specify the version. If this version changes the VPN will break.
• Create interoperable device and specify their remote gateway. Manually define the vpn domain. Put in the remote access group you just created for the remote network. Your firewall also has to have vpn domain manually.
• Create a VPN community add participating gateways- your firewall and theirs
• VPN properties
• VPN – advanced- disable NAT (what ever you use it must match theirs)
• Key exchange AES-256 SHA1 (what ever you use it must match theirs)
• Shared secret click and use shared secret for all external members. Click edit. Enter secret xxxxxx (make complicated) must be the same at each site.
• Set up rules
• Source (your network group and theirs) destination (your network group and theirs) VPN add your VPN community Service Any
• Push policy
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0