cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
496
Views
15
Helpful
5
Replies

Tunnel PIX-CheckPoint

pslavkovsky
Level 1
Level 1

Hi,

I would create a VPN Tunnel between PIX and CheckPoint.

Exists some recommendations or do you have some experience with this situation ?

Thank you very much for your tips.

Peter

5 Replies 5

Follow the instruction in the post before and take care of the point bellow:

1.) The SA Lifetime time is diffrent in the Cisco to CheckPoint implementation. Both have to be equal

2.) Some Checkpoint version are just able communicate with a PIX in DH Group 1, I don't know why. Same for PFS Perfect forward Secret if you use that.

3.) Define the PIX as an embedded device in the CP config tab.

4.) Take care of your VPN access-list in the PIX and the VPN Domain on your CheckPoint FW definition.

Hope that helps

Patrick

Thanks,

But I do not clear understand point 4.

Please, explain it.

Thanks

Peter

The VPN access-list defines the interesting traffic, as used for ISDN configs for example, this defines which internal traffic is encrypted.

PIX(config)# access-list VPN permit ip Internalnet ISubnet Externalnet ESubnet

PIX(config)# crypto map REMOTE 10 match address VPN

This is the same thing as the encryption domain in CheckPoints language.

Be sure that they are identical, otherwise the policy is not accepted by the PIX.

sincerely

Patrick

Patrick,

Thank you very much for your help.

Peter

Review Cisco Networking for a $25 gift card