---
title: "Configure a Check Point cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1512810/Configure%20a%20Check%20Point%20cloud%20connector"
format: markdown
---
Check Point CloudGuard is a family of cloud security products that is designed to prevent various threats including the latest fifth generation (Gen V) multi-vector and polymorphic cyberattacks targeting enterprise cloud services. It includes CloudGuard SaaS and CloudGuard IaaS, which provide protections for software as a service (SaaS) applications, and cloud infrastructure as a service (IaaS) workloads. This topic describes Check Point-specific configuration settings for connecting your Aryaka ANAP device to the Check Point CloudGuard Connect platform using GRE or  IPSec VTI-IKEv2 tunnels. This topic is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors . It assumes the configuration is completed through the Basic Information pane on the Cloud Security Connector (Add) tab page at Sites >  siteName  > Cloud Security Vendors > Cloud Connector (Add). This integration is supported for the following Aryaka ANAP topologies: Inline routed  mode Edge routed mode Prerequisites Aryaka SmartServices service subscription Check Point CloudGuard subscription Check Point CloudGuard Configuration While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Log in to the CloudGuard Connect portal at  https://portal.checkpoint.com/signin . Click  My Services  >  CloudGuard Connect  >  Assets . The Sites page appears: Click  + Add  to add a new site. The Create New Site wizard appears. By default, the General page is selected: Configure the General fields as follows: Name—Enter a descriptive name for the connection. Site Address—Enter the street address or detailed description of the site where the ANAP is located. For example, 2400 Fulton St. San Francisco CA. Location of the cloud service—Enter the more general location of the site.  For example, South America or Asia Pacific. Number of Users (Estimation)—Enter an approximate number of the users at this site. Comments—Enter any additional information to identify or clarify the purpose of this site and tunnel. Click  Next . The Connection Details page appears in the Create New Site wizard: Configure the Connection Details fields as follows: Device Type—Select Generic Router / SD-WAN from the drop-down list. Tunnel Type—Select IPSec – Pre-Shared Key or GRE as appropriate from the drop-down list. External IP Address—Click one of the following options and enter the associated address: Dynamic IP Address (enter the ANAP's fully qualified domain name (FQDN)) Static IP Address (enter the ANAP's IP address) Click  Next . The Authentication page appears in the Create New Site wizard: Configure the Authentication fields as follows: Enter a fully qualified domain name in the Username (FQDN) field. Do one of the following in the Shared Secret field: Enter a manually generated shared key. Click  Auto-Generate  to have Check Point generate the key. Click  Next . The Internal Sub-Networks page appears in the Create New Site wizard: Configure the Internal Sub-Networks field as follows: Click the add  +  icon, then enter a network to be routed using the tunnels from this site. This is the LAN-side subnet that goes through Check Point. Click the add  +  icon again to add any additional subnets that you want to route through Check Point. Click  Next . The Confirm Site Creation page appears in the Create New Site wizard. It displays a summary of the entries that you provided: Review your entries, then do one of the following: Click  Back  to make an edit on a previous page. Click  Finish and Create Site . The site is created using the settings on the page. MyAryaka Configuration Aryaka enables you to connect to a supported third-party cloud security service using a cloud security connector. To configure the Check Point connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right), then click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations (Add) tab page appears. Configure the tunnel in the Tunnel Details pane as follows:  Click the   Tunnel Source Interface   drop-down list and select one of the following interface types: M1 or M2—Both options appear if the site's ANAP has  two  ISPs and uses a copper connector.   M1—This option appears selected by default if the site's ANAP has  one  ISP and uses a copper connector.  F1 or F2—Both options appear if the site's ANAP has  two  ISPs and uses a fiber connector.   F1—This option appears selected by default if the site's ANAP has  one  ISP and uses a fiber connector.  Click the  Tunnel Source Type  drop-down list and select one of the following tunnel types (this list is dynamically populated based on the tunnel type—VTI or GRP—selected in the  Basic Information pane ): Use Interface IP—Uses the IP address of the tunnel source interface (that is, F1 or M2). Use Interface Aux IP—When selected, you must specify the source IP address in the Tunnel Source IP Address field that appears.  Use FQDN—When selected, you must specify the fully qualified domain name in the Tunnel Source FQDN field that appears. Do one of the following depending on the tunnel type selected in the  Basic Information pane : If you selected GRE, enter the destination IP address in  the Tunnel Destination IP field. If you selected VTI, click the  Tunnel Destination Type  drop-down list and select either IP or FQDN, and then enter either the destination IP address or fully qualified domain name in the field that appears. (Conditional) If you are using a VTI tunnel type, enter the shared key that is configured for the IKE Gateway in the Check Point administrator portal.  Configure a keepalive message for the tunnel in the ICMP Keepalive pane to ensure that the tunnel can be monitored to ensure its availability:  Enter the IP address from which the keepalive messages are sent in the Ping Source Address field. (Optional) Enter the source mask from which the keepalive messages are sent in the Ping Source Mask field. Enter the destination IP address to which the keepalive messages are sent in the Ping Destination Address field. Click  OK . The following events occur: The tunnel configuration is saved. You are returned to the Tunnel Configurations (Add) tab page. The new tunnel is listed in the table in the Tunnel Configurations pane. (Optional) Click  Add New  and repeat this procedure to create one additional tunnels (Check Point currently supports a maximum of two tunnels). After they are added to the table, click the  Move  icon to reposition any of the tunnels. Tunnels are prioritized from the first (top) row downward to the last (bottom) row. Click the  Forward Traffic  toggle to select match rules for forwarding traffic to the selected cloud security vendor: Click  Choose  in the Traffic Details table. The Match Rules and If Forward Fails fields appear. Click the  Match Rules  drop-down list and select one of the user-defined match rules from the list.  Click the  If Forward Fails  drop-down list and select one of the following options to define what action is performed if the forward operation is not successful: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Aryaka Default—Cycle through all the rules until the last rule is reached. If no match has been found, the security rules are consulted. See  Create internet policies  for detailed information. Continue Through Local Policies—Override the routing table lookup and send the traffic flow to the desired destination. Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Click the  Save  icon in the match rule's row in the Traffic Details table. Click  Advanced  (top right). The following panes appear: Tunnel Properties ICMP Keepalive Settings Phase 1 Properties Phase 2 Properties Phase 2 Optional Properties (Optional) Configure the Tunnel Properties fields as follows: Tunnel MTU—Enter the maximum transmission unit (MTU) size in bytes for the tunnel. Restrictive Mode—Select one of the following options to determine whether to prevent traffic destined to private destinations from going through the connector's tunnel: Aryaka Default Yes No Unicast RPF—Select one of the following unicast reverse path forwarding options to determine whether the source IP address of the traffic is known to the ANAP before forwarding traffic out through the connector's tunnel:  Aryaka Default Yes No (Optional) Configure the  ICMP Keepalive Settings fields as follows: Keepalive Interval—Enter the number of seconds between consecutive keepalive messages. Default is three (3). Keepalive Retries—Enter the number of times a keepalive message is sent before it is determined that the tunnel is closed. Default is five (5). (Optional) Configure the IKE Phase 1 Properties fields as follows: Enc Type—Select one of the following encryption types: Default—AES 3DES—Triple Data Encryption Standard implements 56 bit keys similar to the original DES encryption except 3DES is applied three times, using a different key each time to perform the encryption. Generally regarded as slower, but the associated hardware and software used can make the difference small. AES—Advanced Encryption Standard implements 128, 192, and 256 bit keys. Generally regarded as secure and efficient. Hash Type—Select one of the following secure hash algorithms: Default - SHA SHA1 SHA2_256 SHA2_384 SHA2_512 Auth Type—Select one of the following authentication types: PSKEY—Authenticates using a  preshared key  (PSKEY) that is configured on each tunnel endpoint. RSASIG—Authenticates using an IPSec certificate that is configured on each tunnel endpoint. Life Time—Enter the phase 1 lifetime—the amount of time after which the tunnel must be reestablished—in seconds. Default is 3600 seconds (one hour). DH Group—Select one of the following Diffie-Hellman (DH) groups to determine the cryptography associated with the key exchange that establishes and secures the tunnel: MODP1024 (default) MODP1536 MODP2048 MODP3072 MODP4096 MODP6144 MODP8192 Tunnels that use a larger group number are more secure, but require additional resources and time to calculate the key. DPD Delay—Enter the number of seconds between consecutive dead peer detection (DPD) messages that attempt to reach the IKE peer. Default is thirty (30). DPD Retry—Enter the number of times a DPD message is sent before it is determined that the tunnel is closed. Default is five (5). DPD Maxfail—Enter the number of unsuccessful authentication attempts before a peer is denied a connection. Default is five (5). (Optional) Configure the IKE Phase 2 Properties fields as follows: Life Time—Enter the phase 2 lifetime for the tunnel in seconds. Default is 3600 seconds (one hour). PFS Group—Select one of the following perfect forward secrecy (PFS) groups: MODP1024 (default) MODP1536 MODP2048 MODP3072 MODP4096 MODP6144 MODP8192 Tunnels that use a larger group number are more secure, but require additional resources and time to calculate the key. PFS requires that the tunnel generates and uses a different key than the one used to establish the tunnel in phase 1. It also requires periodic key regeneration as defined by the setting in the (Phase 2) Life Time field. (Optional) Configure the IKE Phase 2 Optional Properties fields as follows: Click  Add New . The empty row in the Properties Details table enters edit mode. Click the  Enc Type  drop-down list then select one of the following encryption types: 3DES—Triple Data Encryption Standard implements 56 bit keys similar to the original DES encryption except 3DES is applied three times, using a different key each time to perform the encryption. It is generally regarded as slower, but the associated hardware and software used can make the difference small. AES—Advanced Encryption Standard implements 128, 192, and 256 bit keys. It is generally regarded as secure and efficient. Click the  Hash Type  drop-down list then select one of the following secure hash algorithms: NON_AUTH HMAC_SHA1 HMAC_SHA2_256 HMAC_SHA2_384 HMAC_SHA2_512 Enter the encryption length of the key in the Enc Length field. For example, for a 256 bit key, enter 256. Click the  Save  icon in the property's row in the Properties Details table. Click  OK  below the Phase 2 Optional Properties pane to validate your entries. This caches the entries, but does   not   save them. They are lost if you reload the page.  Do one of the following: Click the  Save  icon to save a draft of the entries made on this page. Click  Submit  to send a change request with the entries made on this page to Aryaka support. In this topic Related topics Configure cloud connectors Route controller Manage match rules