Configuring a VPN between a Nokia CC500 (AlchemyOS, Version V3.1(72)) and Checkpoint Firewall 1.
Nokia CC500:
Attach Nokia CC500 to the network, the protected internal network attach to
"Ethernet0" and the external network to "Ethernet1".
Plug in serial cable into "Console" on CC500 and into serial port on
PC.
Start Hyper Terminal using standard options. Hit Enter. You will see:
Welcome to Nokia AlchemyOS, Version V3.1(72)
Nokia CryptoCluster(tm) Configuration Wizard
Press "Enter" or "Return" to begin initial configuration.
Nokia Configuration Wizard
Security Token:
% Invalid input.
% Format is "xxxx-xxxx-xxxx-xxxx" where 'x' is a hexidecimal digit.
Install and run the Nokia Policy Manager v3.1 software onto your PC.
Enter an Administrator password.
Choose standalone.
Enter a description, for example "NOKIA-ELC".
Click "Next".
Enter the IP and Subnet of the "internal" protected network
(Ethernet0).
Enter the IP and Subnet of the "external" network (Ethernet1).
No FQDN.
Enter IP of next hop.
Click "Next".
Click "New..."
Click "New..."
Enter the IP and Subnet of the internal Subnet ID and Subnet Mask.
Click "OK".
Click "OK".
Click "Next".
Click "Next".
Click "Copy to Clipboard".
Click "Next".
Select the top "No" radio button.
Select "Use Drop mode".
Click "Next".
Now go back to Hyper Terminal and right click in the window and select "Paste to Host".
Enter "y" and press Enter.
It should have looked something like this:
Are these correct [y/n]?: y
Wizard: Erasing configurations on flash
Wizard: PIN cleared from NVRAM
Wizard: Saving configuration to flash
Nokia AlchemyOS, Version V3.1(72) ready
Now go back to the
Nokia Policy Manager v3.1 software window.Select "POLICY CONFIGURATION, Non Managed Gateways", right click then "New".
in the Identity tab add a description of the Checkpoint Firewall-1 gateway
and add its external IP address", Ignore FQDN.
Click the "VPN" tab.
Enter a description of the internal protected network.
Click "New...".
Add the Subnet ID and Subnet mask of the Checkpoint Firewall-1 internal
protected network.
Click "OK".
Click "OK".
Click "OK".
Select "POLICY CONFIGURATION, IKE Policies", right click then
"New".
Enter a description, for example "Preshared Key".
Select "IKE: Pre-Shared Key for the. keying method".
Enter a pre-shared key and confirm it. (A pre-shared Secret).
Click "Advanced...".
Select "SHA-1" for integrity algorithm.
Select "TRIPLE DES" for encryption algorithm.
Select "Group #2 (MODP 1024-bit) for Diffie-Hellman group.
Tick "Include ISAKMP VENFOR-ID".
Tick "ENABLE INITIAL-CONTACT".
Tick "Generate new security associations", choose 0 days 8 hours.
Click "OK".
Click "OK".
Select "POLICY CONFIGURATION, IPSEC Policies", right click then
"New".
Enter a description, for example "Encryption and Integrity".
Tick "Enable Privacy", select "TRIPLE DES".
Tick "Enable Integrity", select "HMAC-SHA1".
Click "Advanced..."
Tick "Enable PFS".
Select "Group #1 (MODP 768-bit) for Diffie-Hellman group.
Tick "Enable ISAKMP COMMIT".
Tick "Include REPLAY-STATUS".
Tick "Include RESPODER-LIFETIME".
Tick "Generate new keys", choose 1 hour 0 minutes.
Click "OK".
Click "OK".
Select "VPN SETTINGS, Policy", right click then "New".
Select "Preshared Key" in the IKE policy drop down menu.
Select "Encryption and Integrity" from the IPSEC policy drop down
menu.
Click "OK".
Close the "VPN Global Properties" window.
Right click on the "NOKIA-VPN" policy and select "Complete
Pending Installation".
Another window opens, it should have looked something like this:
NOKIA-ELC
Info Trying to connect to
192.168.0.65
NOKIA-ELC
Info Trying to connect to
10.250.97.173
NOKIA-ELC
Success Connection established to 10.250.97.173
NOKIA-ELC
Info Verifying connection
NOKIA-ELC
Info Securing connection
NOKIA-ELC
Info Setting device time
NOKIA-ELC
Info Generating PIN
NOKIA-ELC
Info Generating gateway SSL
certificate
NOKIA-ELC
Info Generating management SSL
certificate
NOKIA-ELC
Info Generating IKE public key
pair
NOKIA-ELC
Info Downloading configuration
NOKIA-ELC
Info Downloading certificate
policies
NOKIA-ELC
Info Downloading IPSec policies
NOKIA-ELC
Info Committing configuration
NOKIA-ELC
Info Rebooting gateway
NOKIA-ELC
Success Gateway installation complete
NOKIA-ELC
Info Preparing data for download
NOKIA-ELC
Info Waiting to reconnect
NOKIA-ELC
Info Trying to connect to
10.250.97.173
NOKIA-ELC
Info Trying to connect to
192.168.0.65
NOKIA-ELC
Success Connection established
to 10.250.97.173
NOKIA-ELC
Info Verifying connection
NOKIA-ELC
Info Querying device
NOKIA-ELC
Info Downloading configuration
NOKIA-ELC
Info Downloading certificate
policies
NOKIA-ELC
Info Downloading IPSec policies
NOKIA-ELC
Info Committing configuration
NOKIA-ELC
Complete All tasks completed
NOTE: If the Nokia CC500 is power-cycled it is
necessary to re-apply the Checkpoint Firewall-1 Policy.
8th Jan 2002 - Jim Parker.