<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard Network FW - egress NAT in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152612#M1071</link>
    <description>&lt;P&gt;I did not have a chance to try this myself, (use of public IPs on firewall interfaces in AWS), but it should work just fine, as this is basic functionality of CheckPoint gateways.&lt;/P&gt;
&lt;P&gt;Last time I was working with CloudGuard in AWS, I was using NAT between private and public segments, but I had to associate AWS public EIP to the external interface, so there was one more NAT step being performed by AWS Internet Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jul 2022 21:48:02 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2022-07-08T21:48:02Z</dc:date>
    <item>
      <title>Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152594#M1070</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Before I reach out to TAC for an official answer, maybe someone already knows the answer&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this supported? Cloudguard Network Firewall used via Gateway Load Balancer in transit GW setup&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Two-arm mode: As shown in figure 5b below, the firewall is deployed in two-arm mode and performs both inspection as well as NAT. Some AWS partners provide firewall with NAT functionality. GWLB integrates seamlessly in such deployment mode. You don’t need to do any additional configuration changes in the GWLB. However, the firewall networking differs – one network interface is on the private subnet and the other is on public subnet. This mode requires software support from the firewall partner. Some of the GWLB partners (Palo Alto Networks, Valtix) support this feature, however consult with an AWS partner of your choice before using this mode.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;source:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://aws.amazon.com/blogs/networking-and-content-delivery/best-practices-for-deploying-gateway-load-balancer/" target="_blank"&gt;https://aws.amazon.com/blogs/networking-and-content-delivery/best-practices-for-deploying-gateway-load-balancer/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 15:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152594#M1070</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-07-08T15:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152612#M1071</link>
      <description>&lt;P&gt;I did not have a chance to try this myself, (use of public IPs on firewall interfaces in AWS), but it should work just fine, as this is basic functionality of CheckPoint gateways.&lt;/P&gt;
&lt;P&gt;Last time I was working with CloudGuard in AWS, I was using NAT between private and public segments, but I had to associate AWS public EIP to the external interface, so there was one more NAT step being performed by AWS Internet Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 21:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152612#M1071</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-07-08T21:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152623#M1072</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;From what I know this should work , although the GWLB in TGW template we usually use have NAT Gateways for outbound NAT do deal with all the routing .&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 05:15:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152623#M1072</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-07-10T05:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152630#M1073</link>
      <description>&lt;P&gt;Hi abihsot__&lt;BR /&gt;In addition to Nir's reply&lt;BR /&gt;Architectures references can be found in the GWLB admin guide and sk:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Default.htm" target="_blank"&gt;CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway R80.40 Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk174447" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk174447&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jul 2022 09:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152630#M1073</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2022-07-10T09:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152652#M1074</link>
      <description>&lt;P&gt;Yes, I know, template deploys AWS NAT gateways automatically, however I was thinking if I already have checkpoint gateways, why not use them to NAT outgoing traffic. This might be interesting to try. Thank you for replies!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 06:52:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152652#M1074</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-07-11T06:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152659#M1075</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23615"&gt;@abihsot__&lt;/a&gt;&lt;BR /&gt;Unfortunately NAT is not supported on Check Point Gateways behind Gateway Load balancer&amp;nbsp;&lt;BR /&gt;You have to use NAT Gateway&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 07:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152659#M1075</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2022-07-11T07:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Network FW - egress NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152780#M1076</link>
      <description>&lt;P&gt;Thank you for confirmation. Any idea if this limitation could be changed in the future?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 11:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Network-FW-egress-NAT/m-p/152780#M1076</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2022-07-12T11:21:24Z</dc:date>
    </item>
  </channel>
</rss>

