Configuring a Third-Party Gateway using a CheckPoint with a SonicWall SSL-VPN appliance

Description

Configuring a Third-Party Gateway using a CheckPoint with a SonicWall SSL-VPN appliance

Resolution

Setting up a SonicWall SSL-VPN with Check Point AIR 55

The first thing necessary to do is define a host-based network object. This is done under the file menu “Manage” and “Network Objects”.

The object is defined as existing on the internal network. Should you decide to locate the SonicWall SSL-VPN on a secure segment (sometimes known as a demilitarized zone) then subsequent firewall rules will have to pass the necessary traffic from the secure segment to the internal network.

Next, select the NAT tab for the object you have created.

Here you will enter the external IP address (if it is not the existing external IP address of the firewall). The translation method to be selected is static. Clicking OK will automatically create the necessary NAT rule shown below.

Static Route

Most installations of Check Point AIR55 require a static route. This route will send all traffic from the public IP address for the SonicWall SSL-VPN to the internal IP address.

#route add 64.41.140.167 netmask 255.255.255.255 192.168.100.2


ARP

Check Point AIR55 contains a feature called auto-ARP creation. This feature will automatically add an ARP entry for a secondary external IP address (the public IP address of the SonicWall SSL-VPN). If running Check Point on a Nokia security platform, Nokia recommends that users disable this feature. As a result, the ARP entry for the external IP address must be added manually within the Nokia Voyager interface.

Finally, a traffic or policy rule is required for all traffic to flow from the Internet to the SonicWall SSL-VPN.

Again, should the SonicWall SSL-VPN be located on a secure segment of the Check Point firewall, a second rule allowing the relevant traffic to flow from the SonicWall SSL-VPN to the internal network will be necessary.

Excerpted from SSL-VPN 2.1 Administrator’s Guide

Related Articles

  • SMA100 End of Support No-Charge Replacement FAQ
    Read More
  • SMA1000: Post upgrade to 12.5.0 on AWS and Azure, we show the error Could not retrieve the DNS settings once we log in to AMC/CMS console
    Read More
  • Firmware version required to upgrade to version 12.5.0.
    Read More
not finding your answers?