4. NGFW for small businesses. VPN





Continuing our series of articles on NGFW for small businesses, let me remind you that we are considering a new model range of the 1500 series. In part 1 of the series, I mentioned one of the most useful options when buying an SMB device - the delivery of gateways with built-in Mobile Access licenses (from 100 to 200 users, depending on the model). In this article we will walk you through VPN configuration for 1500 series gateways that come with Gaia 80.20 Embedded preinstalled. Here's a quick summary:



  1. VPN capabilities for SMB.
  2. Organization of Remote Access for a small office.
  3. Available clients to connect.


1. VPN capabilities for SMB



c , R80.20.05 ( — ). , VPN Gaia 80.20 Embedded :



  1. Site-To-Site. VPN- , , “” .





  2. Remote Access. (, ..). SSL Network Extender, Java Applet, SSL. : c Mobile Access Portal ( Gaia Embedded ).







In addition, I highly recommend the author's course TS Solution - Check Point Remote Access VPN, it discloses Check Point technologies in the VPN part, touches on licensing issues and contains detailed instructions for setting up.



2. Remote Access for small office



We will start organizing a remote connection to your office:



  1. In order for users to build a VPN tunnel with a gateway, you need to have a public IP address. If you have already passed the initial setup ( article 2 from the cycle), then as a rule - External Link is already active. Information can be found by going to Gaia Portal: Device → Network → Internet







    , IP-, Dynamic DNS. Device DDNS & Device Access









    : DynDns no-ip.com. (, ).

  2. , : VPN → Remote Access → Remote Access Users







    ( : remoteaccess) , . , , Remote Access permissions.









    , : , .





  3. VPN → Remote Access → Blade Control. .



  4. * , Remote Access. , , VPN → Remote Access → Advanced







    , IP- 172.16.11.0/24, Office Mode. 200 ( 1590 NGFW heck Point).



    «Route Internet traffic from connected clients through this gateway» ( ). .

  5. * Remote Access

    Remote Access, Firewall, : Access Policy → Firewall → Policy







    , , , “Incoming, Internal and VPN traffic”. VPN- , “Outgoing access to the Internet”.

  6. , , VPN- NGFW . VPN- , . ( IP- ). GIF







    , IP- CMD: ipconfig







    IP- Office Mode NGFW, . Gaia Portal: VPN → Remote Access → Connected Remote Users









    “ntuser” , , Logs & Monitoring → Security Logs









    , IP-: 172.16.10.1 — , Office Mode.



    3. Remote Access



    , c NGFW heck Point SMB, :





    , NGFW . “How to connect”







    , , .



    : , VPN NGFW Check Point SMB. Remote Access, , . Remote Access. , VPN-, .



    Check Point TS Solution. (Telegram, Facebook, VK, TS Solution Blog, .).



All Articles