Configuring SD-WAN Device
To prevent cyberattacks and enforce the Check Point access control, the traffic from the subnets is tunneled through the Check Point Harmony Connect. You must create two IPsec tunnels for redundancy.
After you create the site at Check PointHarmony Connect, you must configure your branch office on this site to route the traffic through Harmony Connect.
Check Point creates the back-end architecture for tunneling the traffic from the branch device to the Internet.
Example:
Notes:
|
To configure your branch device:
-
On the site thumbnail, click the Configure branch device button:
The Instructions window opens.
-
From the top field, select your SD-WAN branch office device.
-
Follow the instructions on the screen to get the IPsec configuration properties, pre-shared key, tunnel addresses, and the traffic routes.
Example:
Note - For VeloCloud, you must get the IP addresses for the tunnels. Use
nslookup
to find the IP addresses of the two Check Point tunnels. -
Click Close.