Site-to-Site VPN
Last updated
Was this helpful?
Last updated
Was this helpful?
All users on the network are unaware of the VPN connection between the two Gateways
Two options for VPN topologies
Hub and Spoke:
Full Mesh:
The Security Gateway uses the IPsec suite to encrypt and decrypt traffic to and from other Security Gateways. The protocols must match between the SGWs
IKE and Deffie-hellman are used for the key exchange (public keys); IKEv1 is the default version, Check Point Remote VPNs can only use this version.
Phase 1
Establish a Control Tunnel between the two SGWs
Protocols must match on both ends
This is initiated using certificates or a PSK
Phase 2
Establish the Data Tunnel between the two SGWs
Again protocols must match on both ends