# IPSec Tunnel Between CheckPoint Firewall and PaloAlto Firewall

Hello everyone, today I’d like to share step by step guide for configuration ipsec tunnel between CheckPoint Firewall and PaloAlto firewall using eve-ng.

**LAB Diagram**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728358297261/3edc0a73-b435-4ec4-9be6-99c7fd628867.png align="center")

**CheckPoint Side Configuration**

**For WAN Interface**

**Network Management &gt;&gt; Network Interfaces &gt;&gt; Click eth1 &gt;&gt; Edit  &gt;&gt; Comment (optional) &gt;&gt; Checked Enabled &gt;&gt; Assign ip address manually &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728358357748/4a53d216-0eb4-41a6-b116-fcf9b6c88273.png align="center")

**For LAN interface**

**Network Management &gt;&gt; Network Interfaces &gt;&gt; Click eth2 &gt;&gt; Edit  &gt;&gt; Comment (optional) &gt;&gt; Checked Enabled &gt;&gt; Assign ip address manually &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728360070480/c7b6f433-689e-46e9-900d-1a953df7bc65.png align="center")

**Static Route Configuration**

**Network Management &gt;&gt; IPv4 Static Routes &gt;&gt; Click Default &gt;&gt; Edit &gt;&gt; Click Gateway &gt;&gt; Edit &gt;&gt; add the gateway ip address &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728360092487/12019da4-6aea-45a6-a56c-930b3c0f34b0.png align="center")

**Login to the Smart Console &gt;&gt; navigate to the right side and Click New &gt;&gt; Network**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728360112932/feacb130-edc9-407a-99d5-4ab124b33f06.png align="center")

**Checkpoint Internal Network Creation**

**Give a suitable name &gt;&gt; Click General &gt;&gt; Add Network Address and Subnet Mask**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728360136972/807311f5-a9c9-4adf-a6a9-13555434d0c3.png align="center")

**Click NAT &gt;&gt; Checked Add Automatic address translation rules (for SNAT translation behind checkpoint firewall) &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728360152114/6ac6ad8b-1171-4699-89c0-0176a4d8b5f0.png align="center")

**For PA Network Creation**

**Repeat Same Step likes checkpoint network creation**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728364362499/a453ec1d-4ce6-4335-98ec-19ad154d5fdb.png align="center")

**PA Network Creation**

**Give a suitable name &gt;&gt; Click General &gt;&gt; Add Network Address and Subnet Mask**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728364388395/18656c16-b319-4f1c-8c0a-cb5ce7d3fe6d.png align="center")

**Adding PA firewall object in checkpoint for ipsec tunnel**

**Click On right Navigation bar &gt;&gt; New &gt;&gt; More &gt;&gt; Network Object &gt;&gt; More &gt;&gt; Interoperable Device**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728373905835/df6f99a9-9ba2-4b64-a6a7-b205b3177c72.png align="center")

**Configure the public ip address of PA firewall**

**General Properties &gt;&gt; Name (Suitable Name) &gt;&gt;**

**IPv4 Address (Public IP address of PA firewall)**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375512659/6df006aa-5cf9-4a2f-8a76-621ee4a5d0f2.png align="center")

**Configuration External Network for PA firewall**

**Topology &gt;. New &gt;&gt; General &gt;&gt; Name (External) &gt;&gt; IP Address  &gt;&gt; Subnet Mask &gt;&gt; Topology &gt;&gt; Checked External &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375542608/4d750b91-11c2-4aeb-b6da-7c5681858d94.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375551154/0f3b9f04-9019-4cf5-be7b-cb000fd81811.png align="center")

**Configuration VPN Domain for PA firewall’s Network**

**Topology &gt;&gt; VPN Domain &gt;&gt; Check User defined &gt;&gt;**

**Click PA\_Network (the network you created before)**

**\&gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375580398/d6f5fdc9-f388-4472-a825-67ba5490bfef.png align="center")

**IPSec VPN &gt;&gt; Link Selection &gt;&gt; Check Selected address from topology table**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375601947/c0bfb538-ea44-45e5-83b4-c1d7ec1152bc.png align="center")

**VPN Domain for CheckPoint**

**In Smart Console Maing Menu &gt;&gt; Click SMS &gt;&gt;**

**Network Management &gt;&gt; VPN Domain &gt;&gt;**

**User Defined &gt;&gt; Selected Pre defined Network**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375643227/d892fd6c-7a59-4f27-a098-42f4cbc60dde.png align="center")

**Configuration IPSec Peer**

**Select IPSec VPN &gt;&gt; Link Selection &gt;&gt;**

**Check Selected address from topology table**

**\&gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375672189/5d7f33f9-216f-47c7-b1b9-699defbfb33a.png align="center")

**Configuration VPN community**

**On the Smart Console Main Menu &gt;&gt; Navigate to the left panel &gt;&gt; Select Security Policies &gt;&gt; Click VPN Communities &gt;&gt;**

 **Create Meshed Community**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375699381/7175c986-1f32-4e55-a98c-3481cce2c2cd.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375719276/e901c794-f699-4cab-a456-62e90baf412c.png align="center")

**Firewall Policy for IPSec VPN**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375740046/e9ba4765-711c-441a-9762-1aefa1238e50.png align="center")

**Click Install Policy &gt;&gt; Click Publish and Install on pop up box**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375756532/106b5d40-c1e7-43eb-ad89-9bf8133d51f2.png align="center")

**Click Install IPSEC VPN preparation for CheckPoint Side is Done**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375774122/9e64272e-15bc-407b-b68d-af873d5c07c4.png align="center")

**PaloAlto Side Configuration**

**Zone Configuration Trust , Untrust and IPSec Zones**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375813934/d02fcf96-7692-45cc-9cd7-1f16b48a6321.png align="center")

**IP Assign Interface  (WAN and LAN )**

**Click &gt;&gt; Network &gt;&gt; Interfaces &gt;&gt; Ethernet &gt;&gt; ethernet 1/1 &gt;&gt; interface type &gt;&gt; Virtual Router &gt;&gt; Security Zone &gt;&gt;**

 **IPv4 &gt;&gt; Advanced &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375836769/7b10014d-ccc0-4ce3-8a7e-3399d15fdee3.png align="center")

**Tunnel Interface configuration for IPSec Tunnel**

**Network &gt;&gt; interfaces &gt;&gt; Tunnel &gt;&gt; Add &gt;&gt; Tunnel id &gt;&gt; Virtual Router &gt;&gt; Security Zone &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375856822/ca3251f7-1051-42c6-a677-686e1cf212f0.png align="center")

**Creation of Security Rule for local network to access internet**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375875535/1dd8873c-6b84-4442-9144-b44966eeab31.png align="center")

**Security Rule Parameter**

**For local network to access**

**internet**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375899370/dd3158e8-572d-48c3-ac36-112ca995e3f6.png align="center")

**IPSec Security Rule Creation**

**Click Policies &gt;&gt; General &gt;&gt; Name &gt;&gt; Source &gt;&gt; Destination**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375925630/bf9e874a-8c2a-4ef9-b178-39ed2ed90408.png align="center")

**Security Rule Parameter for**

**Ipsec Tunnel**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375943440/9d5f2b7c-da04-4593-a4f6-01c444c3336c.png align="center")

**SNAT Configuration**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375958385/81156521-f3ad-40c8-afdf-911ec3e37c30.png align="center")

**SNAT Parameter**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375974361/7ec45db8-f62f-478c-8a8f-a41b9619a7ea.png align="center")

**Default Route Configuration**

**Network &gt;&gt; Virtual Routers &gt;&gt; Click default &gt;&gt; Click Static Routes &gt;&gt; Add &gt;&gt; Configure Static Route &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728375996552/9b3c9996-9615-4ccf-b4b3-2c029e8b8ae1.png align="center")

**Configure Route for Checkpoint Internal Network**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376011394/d3187ed9-2e88-4231-b96f-07802ab69a62.png align="center")

**IKE Crypto Profile Configuration**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376039004/0fda0a9d-d54c-45da-885e-88b96adfd69d.png align="center")

**IPSec Crypto Profile Configuration**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376056934/ebf08311-ac35-42e7-bac5-6fe638aeda6c.png align="center")

**IKE Gateway Configuration**

**Click Network &gt;&gt; IKE Gateways &gt;&gt; Add &gt;&gt; Name &gt;&gt; Version &gt;&gt; Interface &gt;&gt; Local IP Address &gt;&gt; Peer Address &gt;&gt; Authentication &gt;&gt;**

 **Pre-shared Key &gt;&gt; Click OK**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376080800/9402f069-f502-430b-b071-a4d97f5c95bb.png align="center")

**IKE Parameter**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376095220/375367d2-d730-46b4-91f2-f341f6a61661.png align="center")

**IPSec Tunnel Configuration**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376111465/92983aed-03cc-4222-ba87-c335091df121.png align="center")

**After All Parameter Configure Sucessfully Your IPSec Tunnel Will be up !!!**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376297710/8394db10-a8a3-4ea6-964f-254ed6b338e0.png align="center")

**Monitor Traffic From PA Side**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376316936/56af88e8-7c92-4dcc-9d64-82cd3969b978.png align="center")

**Monitor Traffic From CheckPoint Side**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376332534/7c47c085-1279-4130-bebb-9586fef40dc3.png align="center")

**Monitor From CheckPoint Side(Details)**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1728376348158/5615f2bc-f664-469c-8539-e273891ddeb7.png align="center")

**THANK FOR YOUR ATTENTION !!!!!**
