<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint Cloudguard Iaas in Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133829#M1328</link>
    <description>&lt;P&gt;run 'fw monitor' on the Firewall to see the traffic.&lt;/P&gt;
&lt;P&gt;you need to see:&lt;/P&gt;
&lt;P&gt;i,I from incoming interface&lt;/P&gt;
&lt;P&gt;o,O from outgoing interface.&lt;/P&gt;
&lt;P&gt;if you have these four then traffic is going through the Firewall and exiting via the NIC.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Nov 2021 10:55:46 GMT</pubDate>
    <dc:creator>Nir_Shamir</dc:creator>
    <dc:date>2021-11-11T10:55:46Z</dc:date>
    <item>
      <title>CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133718#M1325</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Requesting anyone can help on the attached setup&lt;/P&gt;&lt;P&gt;Need to reach FROM internal VM 192.168.16.10&amp;nbsp; &amp;nbsp;TO&amp;nbsp; &amp;nbsp; On-Prem VM 192.168.94.3 via ExpressRouteCircuit&lt;/P&gt;&lt;P&gt;We have VNET Peering between CheckPoint Vnet &amp;amp; ExpressRouteCircuit,&amp;nbsp;ExpressRouteCircuit &amp;amp; On-Prem Vnet&lt;/P&gt;&lt;P&gt;1) CheckPoint Iaas Cluster in Azure Cloud&lt;BR /&gt;2) Internal VM (192.168.16.10, 17.10) has Route table pointing to BackendLB&lt;/P&gt;&lt;P&gt;Checked the packet capture in CheckPoint External interface: It leaves external interface, but not reaching On-Prem&lt;/P&gt;&lt;P&gt;How can i assure that this packet leaving CheckPoint External Interface passes via VNET Peering to ER Circuit and further&lt;/P&gt;&lt;P&gt;Any idea will be helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 10:52:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133718#M1325</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-11-10T10:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133724#M1326</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Does the Route table on the External Subnet of the Cluster points to the right default GW towards your On-Premise networks ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 11:39:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133724#M1326</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-11-10T11:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133823#M1327</link>
      <description>&lt;P&gt;Hi Nir,&lt;/P&gt;&lt;P&gt;I had created Route table for Frontend (External) subnet with next hop as ER only (since I did not get default GW IP of OnPrem)&lt;/P&gt;&lt;P&gt;If I get default GW of On-Prem I will apply.&lt;/P&gt;&lt;P&gt;Meanwhile how can we make sure that traffic destined to On-Prem actually passes via VNet Peer (my cloud&amp;lt;--&amp;gt;ER)&lt;/P&gt;&lt;P&gt;Is there any I have to point towards VNet peering?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 10:16:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133823#M1327</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-11-11T10:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133829#M1328</link>
      <description>&lt;P&gt;run 'fw monitor' on the Firewall to see the traffic.&lt;/P&gt;
&lt;P&gt;you need to see:&lt;/P&gt;
&lt;P&gt;i,I from incoming interface&lt;/P&gt;
&lt;P&gt;o,O from outgoing interface.&lt;/P&gt;
&lt;P&gt;if you have these four then traffic is going through the Firewall and exiting via the NIC.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 10:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133829#M1328</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-11-11T10:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133831#M1329</link>
      <description>&lt;P&gt;Hi Nir,&lt;/P&gt;&lt;P&gt;Yes I could see i,I,o,O the packet exits via External NIC of FW.&lt;/P&gt;&lt;P&gt;But how can we assure that this packet is passing inside VNET Peering and reaches other end On-Prem?&lt;/P&gt;&lt;P&gt;Or how can we force FW to send the packet inside the VNET Peering?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 12:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133831#M1329</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2021-11-11T12:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint Cloudguard Iaas in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133834#M1330</link>
      <description>&lt;P&gt;The only next hop the Firewall has is it's Azure Subnet Router on his Vnet. from there Azure takes charge.&lt;/P&gt;
&lt;P&gt;You can contact Azure Support and they can see those packets in the backend and see if they are directed to the right place.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 13:25:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-Cloudguard-Iaas-in-Azure/m-p/133834#M1330</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-11-11T13:25:50Z</dc:date>
    </item>
  </channel>
</rss>

