SonicWALL SonicOS Hub and Spoke TZ170 VPNs with Checkpoint NG TZ170 Manuale Utente

Pagina di 22
 
 
SonicOS 
Hub and Spoke TZ170 VPNs with Checkpoint NG 
 
 
 
 
Introduction 
This technote will detail all steps to get a Hub and Spoke setup between the SonicWALL SonicOS Enhanced and the 
Checkpoint NG. Within this setup the Checkpoint NG will be the HUB and 2 TZ170 units will be the Spokes. 
Versions Used 
ƒ  SonicOS 2.5.0.2 Enhanced on both TZ170 units 
ƒ  Checkpoint FW-1 NGAI 
Sample Diagram 
 
 
Tasklist 
On the SonicWALL units: 
 
ƒ  Create new network objects and groups 
ƒ  Create new VPN Policy for the Check Point FW-1 NG 
ƒ  Specify Destination Network(s), IKE Phase 1 and Phase 2 properties 
 
On FireWall-1 NG: 
ƒ  Create local(Check Point) LAN network objects and group 
ƒ  Create remote(SonicWALL's) LAN network objects 
ƒ  Create new Interoperable Device objects 
ƒ  Edit the Check Point Gateway object 
ƒ  Verify the Topology 
ƒ  Manually define VPN Domain 
ƒ  Create new VPN Star Community 
ƒ  Edit VPN Star community properties 
ƒ Verify Security Rules 
ƒ  Verify Address Translation Rules 
 
Testing 
ƒ  Verify that traffic flows through the tunnel. 
ƒ  Verify that applications function properly through the tunnel. 
ƒ  Verify that the tunnel can reestablish if either side is disconnected. 
ƒ  Verify that the network map and documentation match the running configuration.