<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GWLB Question in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119601#M1542</link>
    <description>&lt;P&gt;Hi Matt,&lt;BR /&gt;I suggest&amp;nbsp; to open a SR&lt;BR /&gt;In addition please send me cme.log privately so I can check the errors you are getting&lt;BR /&gt;Thanks,&lt;BR /&gt;Roman&lt;/P&gt;</description>
    <pubDate>Thu, 27 May 2021 15:30:45 GMT</pubDate>
    <dc:creator>Roman_Kats</dc:creator>
    <dc:date>2021-05-27T15:30:45Z</dc:date>
    <item>
      <title>GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119568#M1539</link>
      <description>&lt;P&gt;This is the very first dip in the water I've had with configuring CloudGuard, so I realise my question will sound novice and stupid to those who already know, but I'm really struggling to grasp setting up a GWLB CloudGuard in AWS.&amp;nbsp; I can't seem to find any admin guides or documentation that cover my questions below.&lt;/P&gt;&lt;P&gt;Firstly - I've watched Shay's "Deep Dive" webinar, but I'm still confused.&lt;/P&gt;&lt;P&gt;I've run through the GWLB TGW CloudFormation template (actually an AWS partner did this bit).&lt;/P&gt;&lt;P&gt;I've installed CME to the management server (on-prem).&lt;/P&gt;&lt;P&gt;I've run the "autoprov_cfg" command with the relevant parameters.&lt;/P&gt;&lt;P&gt;Two AWS gateways magically appeared in SmartConsole, so I'm guessing that bit worked OK.&amp;nbsp; SIC is communicating with both.&amp;nbsp; WEB API automatically installs the policy every 3-4 minutes, which after the first install, promptly blocked my SSH to the gateways.&lt;/P&gt;&lt;P&gt;On advice from my local SE, I've opened the &lt;STRONG&gt;__monitor__-restrictive-policy&lt;/STRONG&gt; and changed that Any Any rule from Drop, to Allow &amp;amp; log.&amp;nbsp; Now I can SSH to them again.&lt;/P&gt;&lt;P&gt;WEB API says it's installing the proper policy name, but when I SSH to the CloudGuards and run #fw stat, it shows they have&amp;nbsp;&lt;STRONG&gt;__monitor__-restrictive-policy&lt;/STRONG&gt; installed.&amp;nbsp; Not the proper policy name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I'm confused.&lt;/P&gt;&lt;P&gt;I've added the Data Center in SmartConsole, which connects fine.&amp;nbsp; When I click + on a rule I can open the Data Center object and browse it all...&amp;nbsp; So I think that's working fine too.&lt;/P&gt;&lt;P&gt;My novice questions are:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; Why is it still pushing the&amp;nbsp;&lt;STRONG&gt;__monitor__-restrictive-policy&lt;/STRONG&gt; policy?&amp;nbsp; Why isn't it installing the main/proper policy that it says it is, and that I specified in the autoprov_cfg command?&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; How do I configure my security rules for these gateways?&amp;nbsp; I get that I need to use the Data Center tagged objects in my rules, but how do the gateways get the policy?&amp;nbsp; Firstly as it's still pushing the&amp;nbsp;&lt;STRONG&gt;__monitor__-restrictive-policy&lt;/STRONG&gt; policy instead of the proper policy, and secondly as I can't add the gateways to the "Install On" column.&amp;nbsp; Or to be more accurate I can add the current two gateways, but when the ASG grows - the new gateways won't be automatically included in "Install On", so that can't be the way to do it?&lt;/P&gt;&lt;P&gt;3)&amp;nbsp; At the moment the policy installation targets for the main/proper rulebase specifies the existing physical gateways.&amp;nbsp; Do I need to change this to "All gateways" for it to work with AWS as the number of gateways in the ASG dynamically grows and shrinks?&lt;/P&gt;&lt;P&gt;4)&amp;nbsp; How do I put a Stealth rule on these to protect the public IP?&amp;nbsp; Or in the case of GLWB gateways is that done only via the AWS firewall/access list?&lt;/P&gt;&lt;P&gt;5)&amp;nbsp; When I manually install the policy, the Threat Prevent gives a verification error about the topology not being defined on the AWS instances, and that Threat blades won't apply until the topology is fixed.&amp;nbsp; Shouldn't this be done automatically by whatever process creates the gateway objects in SmartConsole?&amp;nbsp; (CME?)&lt;/P&gt;&lt;P&gt;If there is any documentation etc. that covers this I'd be grateful if someone could point me at it.&amp;nbsp; So far I can't find anything that tells me how to get past the&amp;nbsp;&lt;STRONG&gt;__monitor__-restrictive-policy&lt;/STRONG&gt; policy, or configure what security rules I want on these GWLB gateways, differently to my other physical gateways...&amp;nbsp; Or fix the topology verification warning...&amp;nbsp; I'm sure I'm missing something obvious and simple, but rightly or wrongly I'm extremely confused and documentation around this stuff seems to be lacking?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&amp;nbsp; Any help would be hugely appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 12:09:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119568#M1539</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-05-27T12:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119578#M1540</link>
      <description>&lt;P&gt;Hello Matt&lt;/P&gt;
&lt;P&gt;During new instance provisioning, CME install policy twice. It is done in order to avoid Threat Prevention policy installation before the Access one(first policy installation on newly provisioned GW has to be the Access one).&lt;BR /&gt;In case CME wasn't able to complete new instance provisioning and configuration, in the next cycle(by default CME cycle re-occurs every 30 seconds) CME will clean up all previous instance configurations and will try to configure the instance from scratch.&lt;BR /&gt;Usually uncompleted configuration points to CME configuration issues.&lt;BR /&gt;In order to troubleshoot the issue, I suggest first to check CME log that is located in the /var/log/CPcme/cme.log and see if there are any errors.&lt;/P&gt;
&lt;P&gt;In general we have CME and GWLB admin guides with detailed explanation on how to configure and troubleshoot CloudGuard Network solutions.&lt;/P&gt;
&lt;P&gt;CME Admin guide&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm" target="_blank" rel="noopener"&gt;Cloud Management Extension R80.10 and Higher Administration Guide&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;GWLB Admin guides:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Centralized_Gateway_Load_Balancer/Default.htm" target="_blank" rel="noopener"&gt;CloudGuard Network for AWS Centralized Gateway Load Balancer R80.40 Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Default.htm" target="_blank" rel="noopener"&gt;CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway R80.40 Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Referencing to your question How do I put a Stealth rule on these to protect the public IP? The public IP(Elastic IP) is AWS resource&lt;BR /&gt;So when the packet arrives to Internet Gateway(AWS VPC component) it performs NAT from/to Public IP &lt;BR /&gt;Therefore in the policy you should protect private IP&lt;BR /&gt;&lt;BR /&gt;In case you need additional assistance, just let me know&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Roman&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 11:34:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119578#M1540</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2021-12-19T11:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119598#M1541</link>
      <description>&lt;P&gt;Hi Roman,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp; I do see errors in the log file.&amp;nbsp; It seems to be trying over and over again...&amp;nbsp; creating it, hitting a problem, deleting it, then trying again....&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Troubleshooting sections in the guides aren't helping.&amp;nbsp; Am I best turning on debugging mode in CME then opening an SR with TAC?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 15:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119598#M1541</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-05-27T15:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119601#M1542</link>
      <description>&lt;P&gt;Hi Matt,&lt;BR /&gt;I suggest&amp;nbsp; to open a SR&lt;BR /&gt;In addition please send me cme.log privately so I can check the errors you are getting&lt;BR /&gt;Thanks,&lt;BR /&gt;Roman&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 15:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119601#M1542</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2021-05-27T15:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119863#M1543</link>
      <description>&lt;P&gt;It will help if you could share the CME configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;autoprov_cfg show all ( hide the key)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 May 2021 07:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/119863#M1543</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2021-05-31T07:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/120204#M1544</link>
      <description>&lt;P&gt;Or another alternative is you can use STRUCTURA.IO and do all of that in a drag and drop fashion with CheckPoint.&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A title="AWS TGW with GWLB Check Point, Zscaler using STRUCTURA.IO Demo" href="https://youtu.be/dP1XFSQjVxA" target="_self"&gt;https://youtu.be/dP1XFSQjVxA&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Jun 2021 14:38:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/120204#M1544</guid>
      <dc:creator>Miguel_Villarr1</dc:creator>
      <dc:date>2021-06-02T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: GWLB Question</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/141581#M1545</link>
      <description>&lt;P&gt;Hi Shay, same problem with R81.10 management and R81.10 VMSS on Azure. Applying "__Monitor__RestrictivePolicy" out of nowhere.&lt;/P&gt;&lt;P&gt;On top of that the image of the security gateways is missing "cloud_balancer_port=8117" and newly provisioned instances are not returning the health probes, respectively azure load balancer is not sending traffic because thinks they are unhealthy.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Autoprov_cfg show all seems correct and vSec controller is working fine. API status is ready, CME test is passing as also.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any idea how to proceed? I've opened SR with Checkpoint TAC, but it's been 10 days and no development.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 18:26:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GWLB-Question/m-p/141581#M1545</guid>
      <dc:creator>Razotevs</dc:creator>
      <dc:date>2022-02-15T18:26:23Z</dc:date>
    </item>
  </channel>
</rss>

