<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CloudGuard Blueprint Architecture Diagrams in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/100463#M1816</link>
    <description>&lt;P&gt;UPDATED JUNE 16, 2021 - AWS Gateway Load Balancer Diagrams and GCP Architecture Diagrams have been added!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document is designed to help with deciding how to architect cloud environments. It includes reference architectures for multi-cloud and specific cloud providers. It provides a succinct, technical overview of deployment options, highlighting the values and architecture differences of each one. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 19:55:58 GMT</pubDate>
    <dc:creator>Maya_Levine</dc:creator>
    <dc:date>2021-06-16T19:55:58Z</dc:date>
    <item>
      <title>CloudGuard Blueprint Architecture Diagrams</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/100463#M1816</link>
      <description>&lt;P&gt;UPDATED JUNE 16, 2021 - AWS Gateway Load Balancer Diagrams and GCP Architecture Diagrams have been added!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document is designed to help with deciding how to architect cloud environments. It includes reference architectures for multi-cloud and specific cloud providers. It provides a succinct, technical overview of deployment options, highlighting the values and architecture differences of each one. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 19:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/100463#M1816</guid>
      <dc:creator>Maya_Levine</dc:creator>
      <dc:date>2021-06-16T19:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard Blueprint Architecture Diagrams</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/100509#M1817</link>
      <description>&lt;P&gt;Very useful document! Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 08:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/100509#M1817</guid>
      <dc:creator>mk1</dc:creator>
      <dc:date>2020-10-29T08:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard Blueprint Architecture Diagrams</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112058#M1818</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19458"&gt;@Maya_Levine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is there any videos somewhere in the community or in YouTube showing more details about the designs (AWS) in the document? I'd like to know why VPN is used between TGW and Egress VPCs, instead of standard VPC attachment to the TGW. The part with VPC peering between Ingress VPC and the rest of spokes is also interesting.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 08:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112058#M1818</guid>
      <dc:creator>mk1</dc:creator>
      <dc:date>2021-03-01T08:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard Blueprint Architecture Diagrams</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112311#M1819</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With a standard VPC attachment you are bound to the VPC's public routing. The attachments point to a subnet so you can only point to one ENI at a time. This limits you to an HA solution, you cannot use auto-scaling.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We use VPN because in AWS peering is not transitive. The better way to pass traffic across multiple CP instances is VTI (Virtual Tunnel Interfaces). TGW comes with some sort of VPN GW and has ECMP, which will load balance traffic from any source VPC to CP GW. We also use VPNs because we have automation that allows us to build tunnels with the CME (see the &lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm" target="_blank" rel="noopener"&gt;Cloud Management Extension R80.10 and Higher Administration Guide&lt;/A&gt;). It will automatically take care of everything when a new auto-scaling instance is in the auto-scaling group. It will trigger a script to build site to site VPNs, advertise routes, and more.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In terms of resources, I attached a PDF made by Cloud Security Architect Eugene Tcheby that goes over the differences between TGW-ASG and TGW-HA. You can also check out this webinar which goes over what is required to deploy an auto-scaling group of CG GWs:&lt;/P&gt;
&lt;DIV&gt;&lt;A tabindex="-1" title="https://www.brighttalk.com/webcast/16731/400673?utm_campaign=viewing-history&amp;amp;utm_source=brighttalk-portal&amp;amp;utm_medium=web" href="https://www.brighttalk.com/webcast/16731/400673?utm_campaign=viewing-history&amp;amp;utm_source=brighttalk-portal&amp;amp;utm_medium=web" target="_blank" rel="noreferrer noopener"&gt;https://www.brighttalk.com/webcast/16731/400673?utm_campaign=viewing-history&amp;amp;utm_source=brighttalk-portal&amp;amp;utm_medium=web&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Best Regards,&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Maya&lt;/DIV&gt;</description>
      <pubDate>Sun, 19 Dec 2021 13:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112311#M1819</guid>
      <dc:creator>Maya_Levine</dc:creator>
      <dc:date>2021-12-19T13:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard Blueprint Architecture Diagrams</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112442#M1820</link>
      <description>&lt;P&gt;Thank you for your reply and for the useful links and file!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 07:27:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-Blueprint-Architecture-Diagrams/m-p/112442#M1820</guid>
      <dc:creator>mk1</dc:creator>
      <dc:date>2021-03-04T07:27:13Z</dc:date>
    </item>
  </channel>
</rss>

