VeloCloud Version 3.x and Lower
These procedures are for versions of VeloCloud prior to version 4.0.
To establish connection through Check Point, you must attach the new IPsec tunnels to the SD-WAN on your Site.
To configure VeloCloud on your SD-WAN Device:
-
Integrate with Check Point through the two Check PointIPsec Tunnels that you created and configured on the VeloCloud Orchestrator.
-
Go back to the Check Point Infinity Portal and edit the site. Update the random external IP addresses with the real IP addresses that VeloCloud provided.
-
Route the traffic from your branch office to Check PointHarmony Connect and test your configuration.
See Routing the Traffic through the Check PointHarmony Connect IPsec Tunnels.
-
Test your configuration.
Configuring VeloCloud Orchestrator
To establish connection through Check Point, you must configure two new IPsec tunnels from the SD-WAN on your Site, and then route the traffic from your branch office to Check Point Harmony Connect.
In VeloCloud terminology it means to create a non VeloCloud site.
To create a WAN Edge IPsec tunnel:
-
From the SD-WAN VeloCloud Orchestrator user interface, go to Configure > Network Services.
Example:
-
Scroll down to Non-VeloCloud Sites.
The Add or Edit CheckPoint_IPSec pop-up window opens.
-
Click New.
A New Non-VeloCloud Site pop-up window opens.
Example:
-
Edit these parameters:
-
Name must be an alias for this tunnel. In this case, to_check_point.
-
Type must be set to Generic IKEv1 Router (route based).
-
Primary VPN Gateway must be set to current IP address of your first tunnel.
-
Secondary VPN Gateway must be set to current IP address of your second tunnel.
-
-
Click Next.
-
Configure additional settings.
-
Enable Tunnel(s) must be checked.
-
Authentication must be set to None.
-
Disable Site Subnets must be checked. It indicates that the Internes access is protected by Check Point.
Example:
-
-
Click Save Changes.
-
Click Advanced.
The Advanced window opens.
Example:
-
Configure the advanced settings for the Check Point Service.
Procedure-
Set the Tunnel Settings for Primary VPN Gateway:
-
PSK must be set to Pre-Shared Key. See Configuring SD-WAN Device.
-
Encryption must be set to AES 256.
-
DH Group should be set to 2.
-
FPS must be set to disabled.
-
-
Set the Tunnel Settings for Secondary VPN Gateway:
-
PSK must be set to the Pre-Shared Key from the Check Point instructions at the previous steps.
-
Encryption must be set to AES 256.
-
DH Group must be set to 2.
-
FPS must be set to disabled.
-
Best Practice - The Redundant VeloCloud Cloud VPN option must be selected.
-
-
Click Save Changes.
-
Extract VeloCloudgateway IP addresses from the configuration template.
ProcedureNote - You will use this IP addresses in these steps as an external IP addresses for integration with Harmony Connect.
-
Click View IKE/IPsec Template and view your created settings in the command-line description.
-
Go to Tunnel Interface > Outside IP Addresses > SD-WAN Gateway.
-
Copy the IP addresses of the VeloCloud Gateway and use them in the Check Point Infinity Portal in the next configuration steps.
Example:
Note - In real environments, the highlighted IP addresses are two different IP addresses.
-
-
Click Close.
-
Activate the Check Point Site at VeloCloud Orchestrator.
Procedure-
In VeloCloud Orchestrator user interface, go to Configure > Profiles.
-
On Device tab, click Profiles
-
Select the profile you want to connect to Check PointHarmony Connect.
-
Go to Device > Cloud VPN > Branch to non-VeloCloud Site.
-
Select the Check Point Non-VeloCloud Site that you configured in the previous sections and edit these parameters:
-
Enable must be checked.
-
Cloud VPN must be checked.
Example:
-
-
Click Save Changes.
-
Updating the IP Address at Check PointInfinity Portal
To update the IP addresses of the VeloCloudGateway in the Check PointInfinity Portal:
-
Go back to Check PointInfinity Portal.
-
Go to Sites and select a site you want to connect.
-
Click Edit Site on your Check Point Site.
Example:
-
Go to Connection Details > External IP Addresses.
-
Set the External IP Addresses to the VeloCloudGateway IP Address (see Configuring VeloCloud Orchestrator - Extract VeloCloudgateway IP addresses from the configuration template.).
Example:
-
Click Apply.
Note - It can take several minutes for Check Point to update the external IP addresses of the site.
-
Test the Tunnel Status.
Procedure-
Go to Monitor > Network Services > Non-VeloCloud Sites.
-
Locate your Check Point tunnels and make sure that they are up. They must show the amount of traffic that is sent and received. Both tunnels must be connected and show up as green.
Note - It can take significant time to apply the changes and represent the current status.
-
Green- Connected
-
Red - Disconnected
Example:
Note - In this example, primary tunnel is connected / established, while the secondary tunnel is disconnected.
-
-
Optional: In the Events column, click View next to the relevant tunnel status and view the events.
Example:
-
Routing the Traffic through the Check PointHarmony Connect IPsec Tunnels
You must define routes for the traffic from your branch office IPsec tunnels to Check Point Harmony Connect.
To define routes for the traffic from your branch office to Check PointHarmony Connect:
-
On the VeloCloud Orchestrator user interface, go to Configure > Profiles.
-
Select the Profile configured for the VeloCloud Edges.
-
Go to Business Policy > New Rule.
Example:
-
Configure the Business Policy Rule.
Procedure-
Name must be a short description of the rule, such as "Traffic to Check Point".
-
Destination must be set to Internet or scroll down to the Action section.
-
Network Service must be set to Internet Backhaul.
-
Non-VeloCloud Site must be selected.
-
Non-VeloCloud Site must be selected and set for the Check Point Site that you defined in the previous steps.
-
NAT must be disabled.
Example:
-
-
Click OK.
Example:
-
Click Save Changes.
Testing the VeloCloud Configuration
To work with the VeloCloud configuration, you must check its activity on your branch office device.
To test the overall configuration at VeloCloud Orchestrator:
-
Route the traffic from behind your Site to the Internet and test the browsing function.
-
Go to Monitor > Edges.
-
Click the Edge that sends the traffic.
-
Locate your Check Point tunnels and make sure that they are up. They must show the amount of traffic that is sent and received.
Now you can go to the Check Point Infinity Portal and monitor Cybersecurity Events. See Monitoring Cybersecurity Events.