Check Point VPN-1/FireWall-1

Connecting to other Products with VPN


AERAsec Network Services and Security GmbH


Sometimes it's heard, that building a VPN between Check Point VPN-1 and other products is difficult. Yes, if the administrators don't exchange basic information like protocols, encryption and hash algorithms as well as other parameters, it's quite impossible.
But if the necessary information is provided, it works in most cases...

So here are some links for building VPN's to other VPN endpoints as from Check Point.

Connecting a VPN from Check Point VPN-1 to...

Bintec / Funkwerk

Hints for configuring a VPN between a Bintec Router and a VPN-1 4.1 on Nokia have been published by Funkwerk (ex Bintec). AERAsec has published hints for configuring a VPN between a BinTec IPsec enabled router and VPN-1 Pro NG AI.

Cisco ASA A VPN between Cisco ASA (Adaptive Security Appliance) 7.0 and Check Point NGX R61 is described in the MediaWiki
Cisco PIX

Cisco (PDF) and Check Point provide a step-by-step how-to connect Check Point 4.1. 
Connecting Cisco PIX 6.2.1 with Check Point NG is described by Cisco (PDF), a VPN between Cisco PIX 501 and NG FP3 is possible, too. 

Cisco Router

For a VPN to a router some information is provided by Cisco (PDF) and by Check Point using version 4.1. A VPN from VPN-1 4.1 to Cisco VPN 3000 Concentrator (PDF) and Cisco VPN 5000 Concentrator (PDF) has been published by Cisco. 
A VPN between NG and a Cisco VPN 3000 Concentrator (PDF) can be set up too. 
Obiwankenobi has published how to build a VPN deploying manual IPSec from Check Point to Cisco 1605 (no more supported by Check Point).
A document describing how to build a VPN between Cisco PIX 501 - Cisco 806 Router with Check Point Next Generation NG FP3 has been published here.
Cisco provides information how to build up a VPN between Check Point NG and a Cisco VPN Router 1751 (PDF). 

DrayTek DSL Router How to build a VPN between a Vigor DrayTek 2600 and a Check Point VPN-1 is described in the CPUG. Further on, a detailed description how to set up a VPN between a Vigor2200 series and Check Point 4.1 is available. 
Fortinet How to set up a VPN between Check Point NGX and FortiGate 3.x is described by Fortinet.
FreeBSD

How to build an IKE VPN with pre-shared secrets between Check Point 4.1 on Debian and FreeBSD with Racoon has been published by Neil Camara (local copy), including hints for firewall-rules. You can download this paper from Obiwankenobi's site also.

FreeS/Wan

A step-by-step NG FP2 documentation VPN with FreeS/WAN published by AERAsec. Connecting a Linux client to VPN-1 4.1 is also described by Check Point.

NAI Gauntlet Firewall

Phoneboy has published documents by Junaid Syed and Andrew Caird & Kip Cranford describing a VPN between Gauntlet 5.x and Check Point VPN-1 4.1.

NAI PGP VPN-Client

A document hosted by The Shmoo Group describes the configuration for a VPN between Check Point VPN-1 4.x and PGP Version 6.5.1 (not reachable as mid of october, 2007). Additionally, Wittys hosts a document how to connect PGP Version 7.0 with Check Point VPN-1 4.x deploying an Entrust PKI. 

NetScreen 5XP

Check Point has published a document how to set up a VPN using IKE and preshared secrets between Next Generation FP1 and Netscreen with ScreenOS 3.0. If you cannot download this document, please contact your support partner. 

Nortel Contivity How to configure a VPN between a Check Point VPN-1 4.1 and a Nortel Contivity 600 Switch has been described by Check Point.
Raptor Firewall

Information about building a VPN between Raptor and Check Point 4.1 by Obiwankenobi.

Racoon under Linux

A 'work in progress' document by AERAsec describes in its first version the support matrix for a VPN between Check Point NG AI and Racoon under Linux.

SonicWALL A VPN tunnel between a SonicWALL TZ 170 SP SonicOS 3.1.0.11 Enhanced with NGX R60 is possible, also here.
Watchguard

This manufacturer gives information how to set up a VPN from Check Point to SOHO and Firebox II. A VPN between NG FP2 and Firebox II 6.0 is described by Cossy Cosmas.

ZyXEL

ZyXEL provides some documents how to configure VPNs to Check Point VPN-1. They are about the systems of the ZyWALL series.

Check Point has published a troublehooting document about VPN-1 Interoperability, based on NGX R60 (sign in to Check Point UserCenter required, if still no download possible, please contact your support partner)


We are not responsible for any content shown when following these links above.

No warranty at all, your Feedback is welcome!
© 2002-2010 AERAsec Network Services and Security GmbH, last change 2009-11-16
back to http://www.vpn-1.de/aerasec/