Jump to main content
Device Inventory
Installing SASE on Chromebook
SASE Agent - Optimized Performance with Minimal Resource Impact
Prerequisites
Multi user and User Switching on Shared Devices (Windows only)
macOS
Uninstall the agent on macOS and complete the protected uninstall process if prompted for an uninstallation code.
Linux Ubuntu
This topic explains how to uninstall the SASE Agent application on Ubuntu Linux systems.
Android / iOS
This topic explains how to uninstall the agent on Android and iOS devices.
Regions and Point-of-Presence
Gateways
Tunnels
Dynamic IP Tunnels
Prerequisites
Configuring the Tunnel in the Check Point SASE Administrator Portal
Configuring Route-Based VPN between Check Point SASE (DAIP) and Check Point Spark Appliance (Locally Managed)
This task explains how to configure a route-based IPSec VPN tunnel between Check Point SASE and a locally managed Check Point Spark appliance and add the required route configuration.
Moving the Spark Appliance from Centralized Management to Locally Managed
Switch a Spark appliance from centralized management by the Security Management Server to locally managed mode using the Spark Appliance WebUI console.
Creating a VPN Site
Configure and create a VPN site by defining remote site settings, encryption parameters, and advanced VPN options.
Adding a VPN Tunnel Interface for Route-Based VPN
Configure a VPN Tunnel Interface (VTI) for a route-based VPN connection. The procedure explains how to create and configure the VTI settings.
Creating Static Routing to the SASE Network through VTI
Configuring the IKEv2 Key Type
Configure the IKEv2 key type setting in the Advanced Settings section. This procedure explains how to locate and select the FQDN option.
Configuring the Remote ID
Configure the Remote ID (FQDN) in clish and verify the configuration for the VPN site. The procedure also explains how to confirm the tunnel status.
Configuration Steps
This task explains how to create an Interoperable Device object in the Check Point SmartConsole. It includes the required configuration details and gateway public IP lookup steps.
Adding SASE Gateway IP Address and Remote Subnet To The Interoperable Device Object
Creating VPN Start Community
Additional settings in Check Point SmartConsole
FortiGate Next Generation Firewall
Juniper Networks ScreenOS Firewall
Juniper (JunOS) SRX Firewall
Palo Alto Firewall
pfSense Firewall
SonicWall Firewall
Sophos XG Firewall
UniFi USG Firewall
WatchGuard Firewall
Step 1 - Configurations in Alibaba Cloud
This task explains how to configure an IPsec VPN tunnel, security group access rules, and routes in Alibaba Cloud.
Step 2 - Creating the Tunnel in the Check Point SASE Administrator Portal
Prerequisites
Configuring a Virtual Private Gateway
Configure a virtual private gateway in AWS and attach it to a VPC. This procedure explains how to create the gateway from the AWS Management Console.
Creating a Virtual Private Network Connection
Create a Site-to-Site VPN connection in the AWS Management Console using a virtual private gateway and customer gateway configuration.
Configuring the Routing Rules to the Default Gateway
Configure routing rules in the AWS Management Console for the VPN Gateway associated with your VPC tunnel. This procedure explains how to edit route tables and add static routes for the required subnets.
Configuring the Tunnel
Configure the VPN tunnel settings in the AWS Management Console and download the VPN configuration file for use with Strongswan.
Step 2 - Creating the Tunnel in the Check Point SASE Administrator Portal
Step 1 - Configurations in the AWS Management Console
This task explains how to create an AWS Transit Gateway and Transit Gateway Attachments in the AWS Management Console. It also explains how to create Transit Gateway VPC Attachments.
Creating the Transit Gateway VPN Attachment
Create a Transit Gateway VPN attachment in the AWS Management Console and configure the required VPN settings.
Configuring the Tunnel
Configure the AWS Transit Gateway VPN tunnel and download the VPN configuration for a Strongswan deployment. The procedure explains how to access the VPN connection and specify the required download parameters.
Configuring the Routing
Configure routing settings in AWS Transit Gateway Route Tables and VPC Route Tables. The procedure explains how to verify propagations, associations, and routes for Transit Gateway attachments.
Step 2 - Creating the Tunnel in the Check Point SASE Administrator Portal
Azure Virtual WAN Redundant Tunnels
This topic describes the prerequisites for configuring Azure Virtual WAN Redundant Tunnels. It includes required accounts, applications, administrative access, and gateway deployment requirements.
Step 1 - Configurations in the Azure Management Portal
Configure a virtual WAN in the Azure Management Portal. This task explains how to create the WAN and define the required basic settings.
Creating a Virtual Hub
Use the Azure Management Portal to create a virtual hub and configure the required settings for Virtual WAN connectivity.
Creating a Site
Create a VPN site in the Azure Management Portal for a Virtual WAN deployment. The procedure explains how to configure site details and link settings for gateways.
Connecting the Site to your Virtual Hub
Connect a site to an Azure Virtual WAN hub and configure VPN gateway settings and parameters. The procedure includes configuring VPN connectivity, IPsec settings, and downloading the VPN configuration.
Step 2 - Creating the Tunnels in the Check Point SASE Administrator Portal
Google Cloud VPC Peering
Heroku Enterprise
Verifying the Setup
SaaS API
General Settings
Google Services
Before opting for Google Services instead of the Google SAML application to log in with your Google Workspace account, evaluate the potential cost implications for using Google Services.
Step 1 - Enabling Active Directory/LDAP Connection
Step 2 - Link to SASE and LDAP
Troubleshooting LDAPS
Test the LDAPS port and verify the LDAPS connection with LDP on the connector server. These procedures help confirm connectivity to the domain controller over SSL.
Appendix A - Removing Microsoft Entra ID (formerly Azure AD) API Permissions
Changing DNS Settings in Mac
Changing Region and Language for Accurate Google Search Results
Troubleshooting Common Errors in IPsec Site-to-Site Connection Setup
Configuring Active-Standby BGP for Site-to-Site Through SASE (Quantum and Maestro)
This procedure explains when and how to configure active-standby BGP for site-to-site traffic through redundant VTI tunnels with SASE and Maestro deployments. It also describes prerequisites and primary-region selection considerations.
BGP Configuration in Gaia Clish
Configure BGP settings in Gaia Clish by defining placeholders, AS information, and router ID values.
Step 2 - Configure Inbound Route Maps
Configure inbound route maps to prefer the primary region for return traffic. Set lower preference values for routes learned from the primary peer.
Step 3 - Configure Outbound Route Maps
Configure outbound route maps to advertise the LAN and prepend the AS path on the secondary path. Set the matched protocol according to how the LAN prefix exists on the gateway.
Step 4 - Configure BGP Peering and Bindings
This task explains how to configure BGP peering and route map bindings for primary and secondary peers. It includes the required commands for remote AS and peer configuration.
Step 5 - Save the Configuration
This task explains how to save the configuration and provides important notes about route maps and AS prepend configuration.
Verify on the Gateway
Verify BGP configuration, peer status, route advertisements, and failover behavior on the active cluster member.
Validated Example
This example shows sample BGP configuration values and commands for a lab environment. Replace the sample values with values from your environment before deployment.