SonicWALL TZ170 User Manual

Page of 22
 
 
SonicOS 
Hub and Spoke TZ170 VPNs with Checkpoint NG 
 
 
 
 
Introduction 
This technote will detail all steps to get a Hub and Spoke setup between the SonicWALL SonicOS Enhanced and the 
Checkpoint NG. Within this setup the Checkpoint NG will be the HUB and 2 TZ170 units will be the Spokes. 
Versions Used 
ƒ  SonicOS 2.5.0.2 Enhanced on both TZ170 units 
ƒ  Checkpoint FW-1 NGAI 
Sample Diagram 
 
 
Tasklist 
On the SonicWALL units: 
 
ƒ  Create new network objects and groups 
ƒ  Create new VPN Policy for the Check Point FW-1 NG 
ƒ  Specify Destination Network(s), IKE Phase 1 and Phase 2 properties 
 
On FireWall-1 NG: 
ƒ  Create local(Check Point) LAN network objects and group 
ƒ  Create remote(SonicWALL's) LAN network objects 
ƒ  Create new Interoperable Device objects 
ƒ  Edit the Check Point Gateway object 
ƒ  Verify the Topology 
ƒ  Manually define VPN Domain 
ƒ  Create new VPN Star Community 
ƒ  Edit VPN Star community properties 
ƒ Verify Security Rules 
ƒ  Verify Address Translation Rules 
 
Testing 
ƒ  Verify that traffic flows through the tunnel. 
ƒ  Verify that applications function properly through the tunnel. 
ƒ  Verify that the tunnel can reestablish if either side is disconnected. 
ƒ  Verify that the network map and documentation match the running configuration.