Hi All
I would like to create a VPN between my Cisco ASA and Checkpoint Firewalls.
There is a limitation on the Checkpoints whereby they have a vpn domain, which is the source subnet to build the tunnels.
However that means to build a tunnel, you always have to use the same source addresses, which is not flexible at all, the ASA can propose any source you want.
Does anyone know a way around this, more so on the Checkpoint side? I believe we can create route based vpn's using VTI tunnels on the Checkpoint, however I believe they will propose the 0.0.0.0 network in the phase 2 negotiation, which is no good as it will break other tunnels on my ASA.
Anyone got any info on this?
cheers