19 Kasım 2015 Perşembe

Checkpoint - Fortigate Site-to-Site VPN Example

Hi Fellas,

Checkpoint Subnet Range : 10.0.0.0/24
Fortigate Subnet Range : 172.23.54.0/24

Public IP address of Check Point : 192.168.1.111/24
Public IP address of Fortigate : 192.168.1.223/24

Nat is not configured for fortigate
Nat is only configured for internal side of checkpoint. (Also disabled into VPN > Advanced Settings > Advanced VPN properties by checking -disable NAT inside the VPN community.

For Checkpoint :

Star VPN connection is identified by defining Center is CP, Satellite is Fortigate




Also don't forget to create pre-shared key for fortigate on above vpn page (>Shared Secret)

For Fortigate:



Pre-shared key field is required to fill.


Autokey Keep Alive is checked
Auto Negotiate is checked

And of couse : you have to define the source / destination subnet fields for sites.
Above: Source is : 172.23.54.0/24  Destination is : 10.1.1.0/24

And..