CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-26
Junior Member
 
Join Date: 2006-02-26
Posts: 8
Rep Power: 0
ohanes has an average reputation (10+)
Default IPSec VPN using certificates between Checkpoint and Pix

Greetings All,

I'm trying to find out if there is any papers or posting regarding
IPSec VPNs using certificates and internal certificate authority between
Checkpoint and Pix.

The assumption is to use Checkpoint's SmartCenter as the internal
certificates authority.

Anyone who done this before or know about any publication regarding
this subject would be appreciated and many thanks in advance.

Cheers
Ohanes
Reply With Quote
  #2 (permalink)  
Old 2006-02-27
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: IPSec VPN using certificates between Checkpoint and Pix

Document from CP site "How to configure IKE VPNs with Cisco PIX" - https://downloads.checkpoint.com/dc/...ad.htm?ID=5912
May be it will be helpful
Reply With Quote
  #3 (permalink)  
Old 2006-02-27
Junior Member
 
Join Date: 2006-02-26
Posts: 8
Rep Power: 0
ohanes has an average reputation (10+)
Default Re: IPSec VPN using certificates between Checkpoint and Pix

Thanks for the reply, that document is about using shared key and I what I'm looking is using smartcenter server as certificates authority to issue certificates for the IKE peer authentication.

Regards
Ohanes
Reply With Quote
  #4 (permalink)  
Old 2006-02-28
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: IPSec VPN using certificates between Checkpoint and Pix

Hi,

I guess this is a less common scenario, due to most of the site-to-site CheckPoint-PIX VPN's being of the Shared Secret type (all the ones I've done have been shared secret for example).

Also I guess that if really they want to use Certificates, organisations might choose to use a trusted third party Certificate Authority.

At any rate, as you've already discovered, there's not a huge amount of doucmentation on this.

I'll give it a go if you like, from which we should be able to generate a guide of some sort.

Post back or reply off thread if you want me to go ahead.
Reply With Quote
  #5 (permalink)  
Old 2006-02-28
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: IPSec VPN using certificates between Checkpoint and Pix

Some time ago I found that CheckPoint CA have a Web Gui. I cant remember right now what are the functions and options of the GUI.
Try to find it, may be this will help you to issue certificate to PIX.

Last edited by Sergej; 2006-03-04 at 10:28.
Reply With Quote
  #6 (permalink)  
Old 2006-03-02
Junior Member
 
Join Date: 2006-02-26
Posts: 8
Rep Power: 0
ohanes has an average reputation (10+)
Default Re: IPSec VPN using certificates between Checkpoint and Pix

many thanks for the tip, I'll investigate the web GUI for the CA and find out if it is possible to use it to issue certificate to PIX


Best Regards
Ohanes Semerjian
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0