This example will show you how to create a certificate based VPN between 2 Check Point firewalls which are managed via different Smart Centre Servers.
Please note that simplified mode VPN was used along with the Check Point version being R65.
Site A
Create VPN Community
- Within your Gateway Object add you local domain to “Topology | VPN Domain | Manually Defined“
- Within Network Objects create a Externally Managed VPN gateway (For Site B) and add its local domain.
- Goto the VPN communities Tab and Right Click “Site To Site” and select “New” then “Mesh“.
- Give your Community a name
- Select “Accept all encrypted traffic“
- Within Participates add your Gateways.
- Click Ok.
Export the Certificate
- Within the Servers and OPSEC applications tab right click “Servers > Trusted CAs > Internal CA” and select “New > CA > Trusted > New CA > Trusted.“
- Enter a name for your Certificate (such as VPN-CERT)
- Under the Certificate Authority Type choose “External Check Point CA“
- Click the External Check Point CA tab and select “Save As“.
- Save the Certificate
Site B
Create VPN Community
- Within your Gateway Object add you local domain to “Topology | VPN Domain | Manually Defined“.
- Within Network Objects create a Externally Managed VPN gateway (For Site A) and add its local domain.
- Goto the VPN communities Tab and Right Click “Site To Site” and select “New” then “Mesh“.
- Give your Community a name
- Select “Accept all encrypted traffic“
- Within Participates add your Gateways.
- Click Ok.
Import the Certificate
- Within the Servers and OPSEC applications tab right click Servers and select “New > CA > Trusted“
- Enter a name such as VPN-CERT.
- Under the Certificate Authority Type choose “External Check Point CA“.
- Click the External Check Point CA tab and select “Get“.
- Import the previously saved certificate from Site A.
Latest posts by Rick Donato (see all)
- How to Configure a BIND Server on Ubuntu - March 15, 2018
- What is a BGP Confederation? - March 6, 2018
- Cisco – What is BGP ORF (Outbound Route Filtering)? - March 5, 2018
Want to become an IT Security expert?
Here is our hand-picked selection of the best courses you can find online:
Internet Security Deep Dive course
Complete Cyber Security Course – Hackers Exposed
CompTIA Security+ (SY0-601) Certification Complete course
and our recommended certification practice exams:
AlphaPrep Practice Tests - Free Trial