IPSEC S2S configuration between Cisco and CHECKPOINT R81

TigerDao

Administrator
Thành viên BQT
Configure IPSEC S2S between Cisco and Checkpoint

IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png

VPN parameters


Stage 1:


Encryption method: 3des

Hash MD5

Authentication: Pre-shared key: 123456

Group 2

Stage 2:

Encryption: AES 256

Hash sha1



Configuration: On Cisco R4 Router



encryption isakmp policy 1

coding3des

Hash MD5

Certified pre-shared

Group 2

Encryption isakmp key 123456 address 10.1.3.1

!

Encryption ipsec transform set TS esp-aes 256 esp-sha-hmac

!

crypto map CM 10 ipsec-isakmp

Set peer 10.1.3.1

Set transformation set TS

Match address 100

!

Access list 100 allows ip 192.168.5.0 0.0.0.255 192.168.200.0 0.0.0.255

!

Interface Ethernet 0/1

IP address 10.3.4.4 255.255.255.0

CryptomapCM















Configure on CHECKPOINT FW

Claim the remote Cisco router:


1696833273_785_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


Declare R4 parameters:

1696833273_4_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



1696833274_601_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



Declared specifically internally

1696833274_780_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


===========

External:



1696833274_108_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


=================

1696833274_64_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


=================

1696833274_769_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


===============

Statement VPN Community


1696833274_49_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


===============

Statement VPN Community


1696833275_222_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



Select Gateway Checkpoint and Cisco

1696833275_744_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



Fill in the parameters that match Cisco

1696833275_745_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



1696833276_539_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


1696833276_479_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



===================

Create policy rules for mutual VPN connection between both parties


1696833276_36_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



=================

Try pinging each other


1696833276_478_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



Checkpoint LAN ping Cisco LAN OK

1696833276_986_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png



Viewing the logs on Checkpoint shows that there is no problem with encryption and no drop errors:

1696833276_241_IPSEC-S2S-configuration-between-Cisco-and-CHECKPOINT-R81.png


Xem tiếp...
 
Top