Checkpoint Secure VPN-1 using NAT ?

Posted on 2004-10-23
Last Modified: 2013-11-16
Is there a way to establish a vpn client tunnel using CheckpointSecure VPN-1 client with a invalid/Natted ip.

i.e. the Desktop is behind a nat on the Firewall. with a Checkpoint secure vpn-1 Client software.

Question by:kamalnv
    LVL 14

    Accepted Solution

    The current crop of CheckPoint client software supports UDP and TCP tunneling in order to work over NAT. It doesn't always work, but it might. Give it a try.
    LVL 3

    Expert Comment

    let me add my 2 cents (not for point):
    it's called UDP encapsulation, and the idea is to pack the whole IPsec packet (which originally misses TCP/UDP header), into another UDP+IP headers. (UDP is preferred over TCP as it's easier to implement and faster).

    [newIP [newUDP [IPSec's IP[ENCRYPTED DATA......]]]]

    there are some creepy flags in configuration files, which may have confusing meanings, but other then that, the feature rather works, then it doesn't .....

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Highfive + Dolby Voice = No More Audio Complaints!

    Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

    If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
    The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
    Want to pick and choose which updates you receive? Feel free to check out this quick video on how to manage your email notifications.
    Internet Business Fax to Email Made Easy - With eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

    913 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    16 Experts available now in Live!

    Get 1:1 Help Now