Configuring a VPN between a Nokia CC500 (AlchemyOS, Version V3.1(72)) and Checkpoint Firewall 1.

Nokia CC500:

Attach Nokia CC500 to the network, the protected internal network attach to "Ethernet0" and the external network to "Ethernet1".
Plug in serial cable into "Console" on CC500 and into serial port on PC.
Start Hyper Terminal using standard options. Hit Enter. You will see:

Welcome to Nokia AlchemyOS, Version V3.1(72)

Nokia CryptoCluster(tm) Configuration Wizard

Press "Enter" or "Return" to begin initial configuration.

        Nokia Configuration Wizard

    Security Token:
% Invalid input.
% Format is "xxxx-xxxx-xxxx-xxxx" where 'x' is a hexidecimal digit.

Install and run the Nokia Policy Manager v3.1 software onto your PC.
Enter an Administrator password.
Choose standalone.
Enter a description, for example "NOKIA-ELC".
Click "Next".
Enter the IP and Subnet of the "internal" protected network (Ethernet0).
Enter the IP and Subnet of the "external" network (Ethernet1).
No FQDN.
Enter IP of next hop.
Click "Next".
Click "New..."
Click "New..."
Enter the IP and Subnet of the internal Subnet ID and Subnet Mask.
Click "OK".
Click "OK".
Click "Next".
Click "Next".
Click "Copy to Clipboard".
Click "Next".
Select the top "No" radio button.
Select "Use Drop mode".
Click "Next".

Now go back to Hyper Terminal and right click in the window and select "Paste to Host".

Enter "y" and press Enter.
It should have looked something like this:

% Format is "xxxx-xxxx-xxxx-xxxx" where 'x' is a hexidecimal digit.
Security Token: 4e78-eb5c-4be2-24ac
Inside IP Address: 192.168.0.65
Inside Subnet Mask: 255.255.255.192
Outside IP Address: 10.250.97.173
Outside Subnet Mask: 255.255.255.0
Policy Manager Route: 10.250.97.254
    Hostname: NOKIA-ELC

Are these correct [y/n]?: y
Wizard: Erasing configurations on flash
Wizard: PIN cleared from NVRAM
Wizard: Saving configuration to flash
Nokia AlchemyOS, Version V3.1(72) ready

Now go back to the Nokia Policy Manager v3.1 software window.
Select "edit, VPN Global Properties".

Select "POLICY CONFIGURATION, Non Managed Gateways", right click then "New".

in the Identity tab add a description of the Checkpoint Firewall-1 gateway and add its external IP address", Ignore FQDN.
Click the "VPN" tab.
Enter a description of the internal protected network.
Click "New...".
Add the Subnet ID and Subnet mask of the Checkpoint Firewall-1 internal protected network.
Click "OK".
Click "OK".
Click "OK".

Select "POLICY CONFIGURATION, IKE Policies", right click then "New".
Enter a description, for example "Preshared Key".
Select "IKE: Pre-Shared Key for the. keying method".
Enter a pre-shared key and confirm it. (A pre-shared Secret).
Click "Advanced...".
Select "SHA-1" for integrity algorithm.
Select "TRIPLE DES" for encryption algorithm.
Select "Group #2 (MODP 1024-bit) for Diffie-Hellman group.
Tick "Include ISAKMP VENFOR-ID".
Tick "ENABLE INITIAL-CONTACT".
Tick "Generate new security associations", choose 0 days 8 hours.
Click "OK".
Click "OK".

Select "POLICY CONFIGURATION, IPSEC Policies", right click then "New".
Enter a description, for example "Encryption and Integrity".
Tick "Enable Privacy", select "TRIPLE DES".
Tick "Enable Integrity", select "HMAC-SHA1".
Click "Advanced..."
Tick "Enable PFS".
Select "Group #1 (MODP 768-bit) for Diffie-Hellman group.
Tick "Enable ISAKMP COMMIT".
Tick "Include REPLAY-STATUS".
Tick "Include RESPODER-LIFETIME".
Tick "Generate new keys", choose 1 hour 0 minutes.
Click "OK".
Click "OK".

Select "VPN SETTINGS, Policy", right click then "New".

Select "Preshared Key" in the IKE policy drop down menu.
Select "Encryption and Integrity" from the IPSEC policy drop down menu.
Click "OK".
Close the "VPN Global Properties" window.
Right click on the "NOKIA-VPN" policy and select "Complete Pending Installation".
Another window opens, it should have looked something like this:

Report Title: Progress Log
Database: C:\Program Files\Nokia\VPN Policy Manager 3.1\Default_Database\
CryptoConsole: v3.1(188)
Requested by: administrator
Date generated: Jan 8, 2002 17:20:22 GMT+00:00

Owner                Status     Message
________________________________________________________________________________

NOKIA-ELC         Info         Trying to connect to 192.168.0.65
NOKIA-ELC         Info         Trying to connect to 10.250.97.173
NOKIA-ELC         Success     Connection established to 10.250.97.173
NOKIA-ELC         Info         Verifying connection
NOKIA-ELC         Info         Securing connection
NOKIA-ELC         Info         Setting device time
NOKIA-ELC         Info         Generating PIN
NOKIA-ELC         Info         Generating gateway SSL certificate
NOKIA-ELC         Info         Generating management SSL certificate
NOKIA-ELC         Info         Generating IKE public key pair
NOKIA-ELC         Info         Downloading configuration
NOKIA-ELC         Info         Downloading certificate policies
NOKIA-ELC         Info         Downloading IPSec policies
NOKIA-ELC         Info         Committing configuration
NOKIA-ELC         Info         Rebooting gateway
NOKIA-ELC         Success        Gateway installation complete
NOKIA-ELC         Info         Preparing data for download
NOKIA-ELC         Info         Waiting to reconnect
NOKIA-ELC         Info         Trying to connect to 10.250.97.173
NOKIA-ELC         Info         Trying to connect to 192.168.0.65
NOKIA-ELC         Success         Connection established to 10.250.97.173
NOKIA-ELC         Info         Verifying connection
NOKIA-ELC         Info         Querying device
NOKIA-ELC         Info         Downloading configuration
NOKIA-ELC         Info         Downloading certificate policies
NOKIA-ELC         Info         Downloading IPSec policies
NOKIA-ELC         Info         Committing configuration
NOKIA-ELC         Complete         All tasks completed

Close the window.
Another window opens, this contains important pin information. Select "Copy to Clipboard", then copy and
paste the information into notepad and store in a safe place.
Close the window.
Test.

NOTE: If the Nokia CC500 is power-cycled it is necessary to re-apply the Checkpoint Firewall-1 Policy.
8th Jan 2002 - Jim Parker.