cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Meraki Z3 and Checkpoint FW

SOLVED
Highlighted
Conversationalist

Meraki Z3 and Checkpoint FW

Hello,

 

We would like to use Z3 box as teleworker gateway from remote location (like home) for softphone and POE phone. We are running Checkpoint FW at the HQ.

 

How can we setup a VPN with a public ip which is not fix for the Z3 (xDSL)?

I suppose we can only use site-to-site VPN configuration (between Z3 and Checkpoint FW)

Do I miss something?

 

Thank you for your help and guidance

Regards,

K

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
Kind of a big deal

Re: Meraki Z3 and Checkpoint FW

Don't do this.  It is not worth the pain.

 

Get yourself another MX for your HQ and use AutoVPN.  You can keep your CheckPoint and put the MX "side by side".

View solution in original post

5 REPLIES 5
Highlighted
Kind of a big deal

Re: Meraki Z3 and Checkpoint FW

This explains how it is done.

DDNS is used

Robin St.Clair | Principal, Caithness Analytics | @uberseehandel
Highlighted
Kind of a big deal

Re: Meraki Z3 and Checkpoint FW

Wouldn't the Z3 connect using Site-to-site VPN Non-Meraki VPN peers with your Checkpoint using its static IP?  The IP of the Z3 wouldn't really matter since it'll be reaching out to the Checkpoint to establish the tunnel.  Unless you need something on the Checkpoint side. 

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
Highlighted
Kind of a big deal

Re: Meraki Z3 and Checkpoint FW

Don't do this.  It is not worth the pain.

 

Get yourself another MX for your HQ and use AutoVPN.  You can keep your CheckPoint and put the MX "side by side".

View solution in original post

Highlighted
Kind of a big deal

Re: Meraki Z3 and Checkpoint FW

I thought the same thing as @PhilipDAth, another MX would make this maintenance free. 

Adam R MS | CISSP, CISM, VCP, MCITP, CCNP, ITILv3, CMNO
If this was helpful click the Kudo button below
If my reply solved your issue, please mark it as a solution.
Highlighted
Conversationalist

Re: Meraki Z3 and Checkpoint FW

Hello,

 

Yes, with Checkpoint FW (R77) we cannot use site to site VPN with dynamic ip, at least with using certificate - which is not feasible with Meraki Z. We will investigate to purchase additional MX as suggested.

 

In resume, if I am not wrong

 

-Goal is deploy Z3 on remote site (home running xDSL and dynamic ip), so we can connect softphone or physical poe phone (as teleworker gateway)

-Purchase new MX on HQ and use MX as VPN concentrator

-Traffic arriving from MX will be inspected by our Checkpoint FW before accessing the LAN

 

Thank you all for your support

Have a great day

Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.