IPsec Site-to-Site VPN Tunnel
IPsec Site-to-Site tunneling is a security feature that creates a secure communication link between two networks in different locations using the IKE VPN protocol. Use IPsec Site-to-Site to connect your Check Point SASE Gateway to your on-premises network or cloud resources for remote access.
Prerequisites
Make sure your edge device (firewall or router) supports IPsec point to point tunnel using IKEv1 or IKEv2 protocols.
IPSec Handshake
The IPSec Site-2-Site VPN tunnel employs a two-phase handshake. The handshake interval is determined by the tunnel's lifetime values.
Phase I (IKE or Gateway)
This is the security association responsible for the external IP communication between the Check Point SASE network and the remote IP through the port 500/4500. The following information is required for Phase I. This information must match in both Check Point SASE and the remote side of the tunnel:
-
Shared Secret
-
Public IP
-
Remote ID
-
IKE Version
-
IKE Lifetime
-
Encryption (Phase 1)
-
Integrity (Phase 1)
-
Key Exchange Method
|
|
Note - Check Point SASE requires NAT Traversal (NAT-T) to be enabled on the remote peer. IKE negotiation must use UDP ports 500 and 4500. Check Point SASE does not support native ESP (IP protocol 50) through the SASE edge. Tunnels that send raw ESP fail silently. Before you configure the tunnel, make sure NAT-T is enabled on the firewall or router. |
Phase II (ESP or Tunnel):
This is the security association responsible for the internal LAN range or subnet handshake after establishing the IKE SA .
The following information is required for Phase II. This information must match in both Check Point SASE and the remote side of the tunnel:
-
Check Point SASE Gateway Proposal Subnets
-
Remote Gateway Proposal Subnets
-
Tunnel Lifetime
-
Dead Peer Detection (DPD)
-
Encryption (Phase 2)
-
Integrity (Phase 2)
-
Key Exchange Method
Policy-Based and Route-Based IPSec Connection
Policy-based connection is easier to set up but is more vulnerable to IPSec tunnel value mismatch.
Depending on your device, a single missing subnet may cause the Phase 2 negotiation to fail.
Route-based connection is also known as a Tunnel Interface or VTI.
It is a more modern and stable method of IPSec tunneling. Once established, it uses one subnet (0.0.0.0/0) for the handshake, thereby reducing the chances of an error during renegotiation.
Supported Integrations
|
On-premises SD-WAN |
Cloud-based SD-WAN |
|
|---|---|---|
|
Firewall |
Router |
|
|
|
Single Tunnel Redundant Tunnels Other Cloud Options |
|
High-Level Procedure
-
Configure the required Firewall / Router / Cloud Management Portal:
On-premises
Cloud-based Resource
Firewall
Router
Single Tunnel
Redundant Tunnels
Other Cloud Options