Site-to-site VPN between Fortigate and Checkpoint R81

TigerDao

Administrator
Thành viên BQT
Configure site-to-site VPN

Hardening and checkpointing firewalls


Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png

VPN specifications:


Stage 1:

Encryption: DES

Hash value: MD5

Pre-shared key: 123456

DH group 2

Stage 2:

Encryption: DES

Hash value: SHA256

PFS Group 2






Configuration within checkpoint:

Similar to this post:


FGT side configuration:


1696829408_143_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png


Since there is no place to select a checkpoint in FGT’s web GUI, we can still select Cisco.


1696829408_752_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png



Then go into FGT’s CLI and declare encryption and hashing according to the plan above:


Stage 1:

Configure vpn ipsec phase 1 interface

Edit “to point c”

Set proposal des-md5 des-sha1

setdhgrp2


Stage 2:

Configure vpn ipsec phase 2 interface

Edit “to point c”

Set proposal des-sha256

set pfs enable

setdhgrp2


Next enter the tunnel of the BringUp tunnel


1696829408_728_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png


UP The result is no problem:

1696829408_189_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png


Check again:

Ping between 2 LANs

LAN FGT to LAN checkpoint:


1696829408_933_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png



FGT checkpoint:

1696829408_861_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png


CHECKLOG ON CHECKPOINT: If you don’t see the drop, that’s fine


1696829408_60_Site-to-site-VPN-between-Fortigate-and-Checkpoint-R81.png


Solarwind NTA download link:

Xem tiếp...
 

Thành viên mới

Thành viên trực tuyến

Không có thành viên trực tuyến.
Top