Managing VPNs
Remote Access communities in VPN of My Organization are supported only in Office Mode. You can define Internal VPNs, include them in My Organization and exclude them.
-
In SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., click Gateways & Servers and double-click the Security Gateway
Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..The gateway window opens and shows the General Properties page.
-
From the navigation tree, click VPN Clients > Office Mode.
-
Select Perform Anti spoofing on Office Mode addresses.
-
In Additional IP Addresses for Anti-Spoofing, select the applicable network object.
-
Click OK.
-
Publish the SmartConsole session.
-
In SmartConsole, select Security Policies > Shared Policies > DLP and click Open DLP Policy in SmartDashboard.
SmartDashboard
Legacy Check Point GUI client used to create and manage the security settings in versions R77.30 and lower. In versions R80.X and higher is still used to configure specific legacy settings. opens and shows the DLP tab. -
From the navigation tree, click My Organization.
-
In the VPN section, make sure the All VPN traffic is selected.
-
Click Save and then close SmartDashboard.
-
In SmartConsole, click Install Policy.
-
In SmartConsole, click Gateways & Servers, and find the VPN gateway that protects the DLP Gateway.
For an integrated DLP configuration, this is the DLP Gateway itself. The protecting VPN gateway includes the IP address of the DLP Gateway in its encryption domain.
-
Double-click the VPN gateway.
The gateway window opens and shows the General Properties page.
-
From the navigation tree, click IPSec VPN.
The DLP Gateway is aware of the VPN communities that are shown in this page.
-
In SmartConsole, select Security Policies > Shared Policies > DLP and click Open DLP Policy in SmartDashboard.
SmartDashboard opens and shows the DLP tab.
-
From the left tree, click My Organization.
-
In the VPN section, click Exclusions.
The VPN Communities window opens.
-
Select the VPNs that you want to exclude from My Organization and click Add.
Ignore the VPNs that are not relevant to the protecting VPN gateway; they are excluded by default.
-
Click Save and then close SmartDashboard.
-
In SmartConsole, click Install Policy.