Link to home
Create AccountLog in
Cisco

Cisco

--

Questions

--

Followers

Top Experts

Avatar of ibrahim A
ibrahim A🇰🇼

site to site VPN between Cisco ASA 5520 and checkpoint
Hi All,

  I need an urgent help in configuring vpn site to site between asa 5520 and checkpoint  FW in another  country

Remote county details:

Gateway:                                     10.10.20.1
Encryption Domain(s):                  192.230.230.200
                                                 
 
 
VPN traffic direction ( from my cisco asa 5520 to other country checkpoint )
Source                                       Destination                           Service
62.62.10.1                              192.230.230.200                   FTP
                                     
                                                 
  Below Configuration parameters sent by checkpoint administrator
 
Encryption Scheme defined:
 
 
Phase 1 Encryption Method:                            3DES
Phase 1 Hash Method:                                      MD5
Phase 2 Encryption Method:                            3DES
IKE & IPSEC Hash Method:                              SHA1
DH Group:                                                        Diffie Hellman Group 2
Security Association (SA) timers
Renegotiate IKE SA every                                 64800 seconds ( 18hrs)
Renegotiate IPSEC SA every                            3600 seconds
Aggressive Mode:                                            No
Support Perfect forward Secrecy:                     YES
Shared Secret:                                                 ************
Gateway:                                                          62.62.10.1

please advise whats the asa 5520 configuration to be done from my side to connect to their checkpoint, i have tried creating site to site using cisco ASDM but still unable to connect, is there any specific config for checkpoint to work.. please advise

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


ASKER CERTIFIED SOLUTION
Avatar of arnoldarnold🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Avatar of ibrahim Aibrahim A🇰🇼

ASKER

Hi Arnold

my local ip range is 192.168.14.x/24 and the remote I have only one IP 192.230.230.200 FTP

I'm using ASDM.

SOLUTION
Avatar of arnoldarnold🇺🇸

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.

Avatar of ibrahim Aibrahim A🇰🇼

ASKER

192.230.230.200  is the local IP in the other country, their WAN is 10.10.20.1.

192.168.14.x/24  is my local network and my WAN interface is 62.62.10.1

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.

Cisco

Cisco

--

Questions

--

Followers

Top Experts

Cisco PIX is a dedicated hardware firewall appliance; the Cisco Adaptive Security Appliance (ASA) is a firewall and anti-malware security appliance that provides unified threat management and protection the PIX does not. Other Cisco devices and systems include routers, switches, storage networking, wireless and the software and hardware for PIX Firewall Manager (PFM), PIX Device Manager (PDM) and Adaptive Security Device Manager (ASDM).