Configuring a Third-Party Gateway using a CheckPoint with a SonicWall SSL-VPN appliance

Description

Configuring a Third-Party Gateway using a CheckPoint with a SonicWall SSL-VPN appliance

Resolution

Setting up a SonicWall SSL-VPN with Check Point AIR 55

The first thing necessary to do is define a host-based network object. This is done under the file menu “Manage” and “Network Objects”.

The object is defined as existing on the internal network. Should you decide to locate the SonicWall SSL-VPN on a secure segment (sometimes known as a demilitarized zone) then subsequent firewall rules will have to pass the necessary traffic from the secure segment to the internal network.

Next, select the NAT tab for the object you have created.

Here you will enter the external IP address (if it is not the existing external IP address of the firewall). The translation method to be selected is static. Clicking OK will automatically create the necessary NAT rule shown below.

Static Route

Most installations of Check Point AIR55 require a static route. This route will send all traffic from the public IP address for the SonicWall SSL-VPN to the internal IP address.

#route add 64.41.140.167 netmask 255.255.255.255 192.168.100.2


ARP

Check Point AIR55 contains a feature called auto-ARP creation. This feature will automatically add an ARP entry for a secondary external IP address (the public IP address of the SonicWall SSL-VPN). If running Check Point on a Nokia security platform, Nokia recommends that users disable this feature. As a result, the ARP entry for the external IP address must be added manually within the Nokia Voyager interface.

Finally, a traffic or policy rule is required for all traffic to flow from the Internet to the SonicWall SSL-VPN.

Again, should the SonicWall SSL-VPN be located on a secure segment of the Check Point firewall, a second rule allowing the relevant traffic to flow from the SonicWall SSL-VPN to the internal network will be necessary.

Excerpted from SSL-VPN 2.1 Administrator’s Guide

Related Articles

  • How to Provision SMA1000 in Monthly Billing (MSSP Program)
    Read More
  • SMA 1000 Series Support Matrix
    Read More
  • How to Configure SAML 2.0 SSO with Microsoft Entra ID for SonicWall SMA 1000 Series
    Read More
not finding your answers?