Hello,
We would like to use Z3 box as teleworker gateway from remote location (like home) for softphone and POE phone. We are running Checkpoint FW at the HQ.
How can we setup a VPN with a public ip which is not fix for the Z3 (xDSL)?
I suppose we can only use site-to-site VPN configuration (between Z3 and Checkpoint FW)
Do I miss something?
Thank you for your help and guidance
Regards,
K
Solved! Go to solution.
Don't do this. It is not worth the pain.
Get yourself another MX for your HQ and use AutoVPN. You can keep your CheckPoint and put the MX "side by side".
This explains how it is done.
DDNS is used
Wouldn't the Z3 connect using Site-to-site VPN Non-Meraki VPN peers with your Checkpoint using its static IP? The IP of the Z3 wouldn't really matter since it'll be reaching out to the Checkpoint to establish the tunnel. Unless you need something on the Checkpoint side.
Don't do this. It is not worth the pain.
Get yourself another MX for your HQ and use AutoVPN. You can keep your CheckPoint and put the MX "side by side".
I thought the same thing as @PhilipDAth, another MX would make this maintenance free.
Hello,
Yes, with Checkpoint FW (R77) we cannot use site to site VPN with dynamic ip, at least with using certificate - which is not feasible with Meraki Z. We will investigate to purchase additional MX as suggested.
In resume, if I am not wrong
-Goal is deploy Z3 on remote site (home running xDSL and dynamic ip), so we can connect softphone or physical poe phone (as teleworker gateway)
-Purchase new MX on HQ and use MX as VPN concentrator
-Traffic arriving from MX will be inspected by our Checkpoint FW before accessing the LAN
Thank you all for your support
Have a great day