cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
955
Views
0
Helpful
0
Replies

Route based VPN between Cisco ASA and Checkpoint Firewall

carl_townshend
Spotlight
Spotlight

Hi All

I would like to create a VPN between my Cisco ASA and Checkpoint Firewalls.

There is a limitation on the Checkpoints whereby they have a vpn domain, which is the source subnet to build the tunnels.

However that means to build a tunnel, you always have to use the same source addresses, which is not flexible at all, the ASA can propose any source you want.

Does anyone know a way around this, more so on the Checkpoint side? I believe we can create route based vpn's using VTI tunnels on the Checkpoint, however I believe they will propose the 0.0.0.0 network in the phase 2 negotiation, which is no good as it will break other tunnels on my ASA.

Anyone got any info on this?

cheers

 

0 Replies 0