How to create AWS site to site VPN with dynamic IP of Customer Gateway?

0

Hi Sir,

I have a Checkpoint Firewall for site to site VPN Customer Gateway which has dynamic public IP, how to create site to site VPN without static IP Customer Gateway?

Below is the Checkpoint Firewall information: Brand: Checkpoint 1530 Firmware: R81+

Thanks.

質問済み 2年前534ビュー
2回答
0
承認された回答

Hi,

This is possible to use Certificate-based Authentication to deal with the dynamic IP issue. You can configure a CGW (Customer Gateway) without a static IP address.

Resolution:

1/ Create and install a root CA and a subordinate CA

2/ Create a private certificate to use as the identity certificate for your customer gateway

3/ Create a customer gateway for your VPN connection

4/ Configure the AWS Site-to-Site VPN connection with a virtual private gateway

5/ Copy the end entity certificate (the private certificate that you created in above task 2), root CA certificate, and subordinate CA certificate to the customer gateway device

For details, please see: https://aws.amazon.com/premiumsupport/knowledge-center/vpn-certificate-based-site-to-site/

profile pictureAWS
jcvip
回答済み 2年前
profile picture
エキスパート
レビュー済み 1年前
profile pictureAWS
エキスパート
レビュー済み 2年前
  • Would this work in situations where the customer gateway is behind CGNat and doesn't have a publicly routable IP address at all?

  • Yes, as long as the VPN session is configured for NAT Traversal (NAT-T).

0

You can use certificates to authenticate the Customer Gateway, therefore removing the requirement for a static IP: https://aws.amazon.com/premiumsupport/knowledge-center/vpn-certificate-based-site-to-site/

profile pictureAWS
エキスパート
回答済み 2年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ