Check Point VPN-1/FireWall-1

Connecting to other Products with VPN


AERAsec Network Services and Security GmbH


Sometimes it's heard, that building a VPN between Check Point VPN-1 and other products is difficult. Yes, if the administrators don't exchange basic information like protocols, encryption and hash algorithms as well as other parameters, it's quite impossible.
But if the necessary information is provided, it works in most cases...

So here are some links for building VPN's to other VPN endpoints as from Check Point.

Connecting a VPN from Check Point VPN-1 to...

Bintec / Funkwerk

Hints for configuring a VPN between a Bintec Router and a VPN-1 4.1 on Nokia have been published by Funkwerk (ex Bintec). The configuration file has been publishe,too. AERAsec has published hints for configuring a VPN between a BinTec IPsec enabled router and VPN-1 Pro NG AI.

Cisco ASA A VPN between Cisco ASA (Adaptive Security Appliance) 7.0 and Check Point NGX R61 is described in the MediaWiki
Cisco PIX

Cisco (PDF) and Check Point provide a step-by-step how-to connect Check Point 4.1. 
Connecting Cisco PIX 6.2.1 with Check Point NG is described by Cisco (PDF). 

Cisco Router

For a VPN to a router some information is provided by Cisco (PDF) and by Check Point using version 4.1. A VPN from VPN-1 4.1 to Cisco VPN 3000 Concentrator (PDF) and Cisco VPN 5000 Concentrator (PDF) has been published by Cisco. 
A VPN between Check Point NG and a Cisco VPN 3000 Concentrator can be set up too. 
Cisco provides information how to build up a VPN between Check Point NG and a Cisco VPN Router 1751 (PDF). 

DrayTek DSL Router How to build a VPN between a Vigor DrayTek 2600 and a Check Point VPN-1 is described in the CPUG. Further on, a detailed description how to set up a VPN between a Vigor2200 series and Check Point 4.1 is available. 
Fortinet How to set up a VPN between Check Point NGX and FortiGate 3.x is described by Fortinet.
FreeBSD

How to build an IKE VPN with pre-shared secrets between Check Point 4.1 on Debian and FreeBSD with Racoon has been published by Neil Camara (local copy), including hints for firewall-rules. In earlier times you could have downloaded it also from from Obiwankenobi's site.

Juniper Configuring a VPN between Juniper SSG5 and Safe@Office 500 can be found in the kb of Juniper.
The Juniper Info Center provides suggestions about building a VPN between NG and NetScreen Routers.
Mac OSX Several hints about using SecureClient with Leopard is described in a special report.
FreeS/Wan

A step-by-step NG FP2 documentation VPN with FreeS/WAN published by AERAsec. Connecting a Linux client to VPN-1 4.1 is also described by Check Point.

NAI PGP VPN-Client

A document hosted by The Shmoo Group describes the configuration for a VPN between Check Point VPN-1 4.x and PGP Version 6.5.1. Additionally, Wittys hosts a document how to connect PGP Version 7.0 with Check Point VPN-1 4.x deploying an Entrust PKI. 

NetScreen 5XP

Check Point has published a document how to set up a VPN using IKE and preshared secrets between Next Generation FP1 and Netscreen with ScreenOS 3.0. If you cannot download this document, please contact your support partner. 

Nortel Contivity How to configure a VPN between a Check Point VPN-1 4.1 and a Nortel Contivity 600 Switch has been described by Check Point.
Racoon under Linux

A 'work in progress' document by AERAsec describes in its first version the support matrix for a VPN between Check Point NG AI and Racoon under Linux.

SonicWALL A VPN tunnel between a SonicWALL TZ 170 SP SonicOS 3.1.0.11 Enhanced with NGX R60 is possible, also here.
Watchguard

This manufacturer gives information how to set up a VPN from Check Point to SOHO and Firebox II. A VPN between NG FP2 and Firebox II 6.0 is described by Cossy Cosmas.

ZyXEL

ZyXEL provides some documents how to configure VPNs to Check Point VPN-1. They are about the systems of the ZyWALL series.

Check Point has published a troublehooting document about VPN-1 Interoperability, based on NGX (sign in to Check Point UserCenter required, if still no download possible, please contact your support partner)


We are not responsible for any content shown when following these links above.

No warranty at all, your Feedback is welcome!
© 2002-2011 AERAsec Network Services and Security GmbH, last change 2011-07-28
back to http://www.vpn-1.de/aerasec/