Site-to-Site VPN
Last updated
Was this helpful?
Last updated
Was this helpful?
Two options for VPN topologies
Hub and Spoke:
Full Mesh:
The Security Gateway uses the IPsec suite to encrypt and decrypt traffic to and from other Security Gateways. The protocols must match between the SGWs
IKE and Deffie-hellman are used for the key exchange (public keys); IKEv1 is the default version, Check Point Remote VPNs can only use this version.
Phase 1
Establish a Control Tunnel between the two SGWs
Protocols must match on both ends
This is initiated using certificates or a PSK
Phase 2
Establish the Data Tunnel between the two SGWs
Again protocols must match on both ends