<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS IAM User Account Permissions in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187374#M182</link>
    <description>&lt;P&gt;Hello Simon,&lt;BR /&gt;While we are working to prepare the detailed minimum required permissions for IAM user&amp;nbsp; in general there should be&lt;/P&gt;
&lt;P&gt;For Gateway:&lt;BR /&gt;1. Read + Write permissions for EC2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Read + Write permissions for VPC&lt;/P&gt;
&lt;P&gt;3. Read permissions for S3&lt;/P&gt;
&lt;P&gt;For Cluster:&lt;BR /&gt;1. Read + Write permissions for EC2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Read + Write permissions for VPC&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;Read + Write permissions for IAM&lt;/P&gt;
&lt;P&gt;4. Read permissions for S3&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2023 15:33:13 GMT</pubDate>
    <dc:creator>Roman_Kats</dc:creator>
    <dc:date>2023-07-24T15:33:13Z</dc:date>
    <item>
      <title>AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187279#M181</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What are the minimum AWS IAM user account permissions required for deploying a single gateway and cluster via Terraform?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 05:20:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187279#M181</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-07-24T05:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187374#M182</link>
      <description>&lt;P&gt;Hello Simon,&lt;BR /&gt;While we are working to prepare the detailed minimum required permissions for IAM user&amp;nbsp; in general there should be&lt;/P&gt;
&lt;P&gt;For Gateway:&lt;BR /&gt;1. Read + Write permissions for EC2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Read + Write permissions for VPC&lt;/P&gt;
&lt;P&gt;3. Read permissions for S3&lt;/P&gt;
&lt;P&gt;For Cluster:&lt;BR /&gt;1. Read + Write permissions for EC2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Read + Write permissions for VPC&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;Read + Write permissions for IAM&lt;/P&gt;
&lt;P&gt;4. Read permissions for S3&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 15:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187374#M182</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2023-07-24T15:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187404#M183</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6318"&gt;@Roman_Kats&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Once created, can you please post the location to the reference document where the &lt;SPAN&gt;minimum required permissions&amp;nbsp;for an IAM user&amp;nbsp;&lt;/SPAN&gt;will been outlined.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Simon&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 23:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187404#M183</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-07-24T23:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187460#M184</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16342"&gt;@Simon_Macpherso&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Yes, I will&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 09:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/187460#M184</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2023-07-25T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/192710#M185</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6318"&gt;@Roman_Kats&lt;/a&gt;&amp;nbsp;Any update?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 05:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/192710#M185</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-09-15T05:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/197761#M4395</link>
      <description>&lt;P&gt;Hello Simon,&lt;/P&gt;
&lt;P&gt;Apologies for the delayed response.&lt;/P&gt;
&lt;P&gt;The minimum AWS IAM user account permissions required for deploying a single gateway and cluster using Terraform are (attached are the &lt;SPAN&gt;Permissions policies&amp;nbsp;&lt;/SPAN&gt;JSON files for each deployment):&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="312"&gt;
&lt;P&gt;Template&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="325"&gt;
&lt;P&gt;Premmision&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="312"&gt;
&lt;P&gt;cluster-master&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="325"&gt;
&lt;P&gt;ec2:DescribeTags&lt;/P&gt;
&lt;P&gt;ec2:ReleaseAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceAttribute&lt;/P&gt;
&lt;P&gt;ec2:DeleteSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcs&lt;/P&gt;
&lt;P&gt;ec2:DescribeRouteTables&lt;/P&gt;
&lt;P&gt;ec2:CreateLocalGatewayRouteTable&lt;/P&gt;
&lt;P&gt;ec2:TerminateInstances&lt;/P&gt;
&lt;P&gt;ec2:CreateTags&lt;/P&gt;
&lt;P&gt;ec2:DescribeVolumes&lt;/P&gt;
&lt;P&gt;ec2:ModifyNetworkInterfaceAttribute&lt;/P&gt;
&lt;P&gt;ec2:DetachInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DisassociateAddress&lt;/P&gt;
&lt;P&gt;ec2:CreateInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DeleteVpc&lt;/P&gt;
&lt;P&gt;ec2:DeleteInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:AttachInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DescribeInternetGateways&lt;/P&gt;
&lt;P&gt;ec2:ModifySubnetAttribute&lt;/P&gt;
&lt;P&gt;ec2:RevokeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:DeleteNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceTypes&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcClassicLinkDnsSupport&lt;/P&gt;
&lt;P&gt;ec2:RunInstances&lt;/P&gt;
&lt;P&gt;ec2:DeleteRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DeleteSubnet&lt;/P&gt;
&lt;P&gt;ec2:ModifyVpcAttribute&lt;/P&gt;
&lt;P&gt;ec2:AssociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DescribeAvailabilityZones&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupIngress&lt;/P&gt;
&lt;P&gt;ec2:CreateRoute&lt;/P&gt;
&lt;P&gt;ec2:AssociateAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeSubnets&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcClassicLink&lt;/P&gt;
&lt;P&gt;ec2:CreateSubnet&lt;/P&gt;
&lt;P&gt;ec2:DetachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:CreateSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:DescribeAddresses&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcAttribute&lt;/P&gt;
&lt;P&gt;ec2:DisassociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DescribeSecurityGroups&lt;/P&gt;
&lt;P&gt;ec2:DescribeRegions&lt;/P&gt;
&lt;P&gt;ec2:DeleteRoute&lt;/P&gt;
&lt;P&gt;ec2:DescribeKeyPairs&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkAcls&lt;/P&gt;
&lt;P&gt;ec2:AttachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:CreateNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:CreateVpc&lt;/P&gt;
&lt;P&gt;ec2:AllocateAddress&lt;/P&gt;
&lt;P&gt;ec2:CreateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DescribeAccountAttributes&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkInterfaces&lt;/P&gt;
&lt;P&gt;cloudformation:DescribeStacks&lt;/P&gt;
&lt;P&gt;cloudformation:DeleteStack&lt;/P&gt;
&lt;P&gt;cloudformation:ValidateTemplate&lt;/P&gt;
&lt;P&gt;cloudformation:CreateStack&lt;/P&gt;
&lt;P&gt;cloudformation:ListStackResources&lt;/P&gt;
&lt;P&gt;iam:ListInstanceProfilesForRole&lt;/P&gt;
&lt;P&gt;iam:AttachRolePolicy&lt;/P&gt;
&lt;P&gt;iam:DeletePolicy&lt;/P&gt;
&lt;P&gt;iam:DetachRolePolicy&lt;/P&gt;
&lt;P&gt;iam:GetPolicy&lt;/P&gt;
&lt;P&gt;iam:DeleteRole&lt;/P&gt;
&lt;P&gt;iam:GetInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:ListRolePolicies&lt;/P&gt;
&lt;P&gt;iam:CreatePolicy&lt;/P&gt;
&lt;P&gt;iam:PutRolePolicy&lt;/P&gt;
&lt;P&gt;iam:CreateRole&lt;/P&gt;
&lt;P&gt;iam:CreateInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:GetPolicyVersion&lt;/P&gt;
&lt;P&gt;iam:DeleteInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:GetRole&lt;/P&gt;
&lt;P&gt;iam:DeleteRolePolicy&lt;/P&gt;
&lt;P&gt;iam:PassRole&lt;/P&gt;
&lt;P&gt;iam:AddRoleToInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:ListAttachedRolePolicies&lt;/P&gt;
&lt;P&gt;iam:ListPolicyVersions&lt;/P&gt;
&lt;P&gt;iam:RemoveRoleFromInstanceProfile&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="312"&gt;
&lt;P&gt;cluster&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="325"&gt;
&lt;P&gt;ec2:DisassociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:CreateTags&lt;/P&gt;
&lt;P&gt;ec2:DeleteSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ModifyNetworkInterfaceAttribute&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcs&lt;/P&gt;
&lt;P&gt;ec2:AssociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DeleteNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DeleteRoute&lt;/P&gt;
&lt;P&gt;ec2:RevokeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:AssociateAddress&lt;/P&gt;
&lt;P&gt;ec2:AllocateAddress&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupIngress&lt;/P&gt;
&lt;P&gt;ec2:DisassociateAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeVolumes&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeAddresses&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceAttribute&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:CreateRoute&lt;/P&gt;
&lt;P&gt;ec2:DescribeTags&lt;/P&gt;
&lt;P&gt;ec2:DescribeKeyPairs&lt;/P&gt;
&lt;P&gt;ec2:DetachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceTypes&lt;/P&gt;
&lt;P&gt;ec2:CreateSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ReleaseAddress&lt;/P&gt;
&lt;P&gt;ec2:RunInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeRouteTables&lt;/P&gt;
&lt;P&gt;ec2:DescribeSecurityGroups&lt;/P&gt;
&lt;P&gt;ec2:CreateNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkInterfaces&lt;/P&gt;
&lt;P&gt;ec2:TerminateInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeSubnets&lt;/P&gt;
&lt;P&gt;iam:ListAttachedRolePolicies&lt;/P&gt;
&lt;P&gt;iam:AddRoleToInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:DeleteInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:CreateRole&lt;/P&gt;
&lt;P&gt;iam:CreatePolicy&lt;/P&gt;
&lt;P&gt;iam:GetRole&lt;/P&gt;
&lt;P&gt;iam:GetInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:DeletePolicy&lt;/P&gt;
&lt;P&gt;iam:ListRolePolicies&lt;/P&gt;
&lt;P&gt;iam:DeleteRole&lt;/P&gt;
&lt;P&gt;iam:ListPolicyVersions&lt;/P&gt;
&lt;P&gt;iam:PutRolePolicy&lt;/P&gt;
&lt;P&gt;iam:DetachRolePolicy&lt;/P&gt;
&lt;P&gt;iam:DeleteRolePolicy&lt;/P&gt;
&lt;P&gt;iam:CreateInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:GetPolicyVersion&lt;/P&gt;
&lt;P&gt;iam:AttachRolePolicy&lt;/P&gt;
&lt;P&gt;iam:RemoveRoleFromInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:ListInstanceProfilesForRole&lt;/P&gt;
&lt;P&gt;iam:GetPolicy&lt;/P&gt;
&lt;P&gt;iam:PassRole&lt;/P&gt;
&lt;P&gt;cloudformation:ListStackResources&lt;/P&gt;
&lt;P&gt;cloudformation:CreateStack&lt;/P&gt;
&lt;P&gt;cloudformation:DescribeStacks&lt;/P&gt;
&lt;P&gt;cloudformation:DeleteStack&lt;/P&gt;
&lt;P&gt;cloudformation:ValidateTemplate&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="312"&gt;
&lt;P&gt;gateway-master&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="325"&gt;
&lt;P&gt;ec2:DisassociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:CreateTags&lt;/P&gt;
&lt;P&gt;ec2:CreateSubnet&lt;/P&gt;
&lt;P&gt;ec2:DeleteSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ModifyNetworkInterfaceAttribute&lt;/P&gt;
&lt;P&gt;ec2:AssociateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:AttachInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcs&lt;/P&gt;
&lt;P&gt;ec2:CreateInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DeleteNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DeleteRoute&lt;/P&gt;
&lt;P&gt;ec2:CreateLocalGatewayRouteTable&lt;/P&gt;
&lt;P&gt;ec2:RevokeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:AssociateAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkAcls&lt;/P&gt;
&lt;P&gt;ec2:AllocateAddress&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupIngress&lt;/P&gt;
&lt;P&gt;ec2:DeleteVpc&lt;/P&gt;
&lt;P&gt;ec2:DisassociateAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeAvailabilityZones&lt;/P&gt;
&lt;P&gt;ec2:DescribeVolumes&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeAddresses&lt;/P&gt;
&lt;P&gt;ec2:DescribeInternetGateways&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceAttribute&lt;/P&gt;
&lt;P&gt;ec2:CreateVpc&lt;/P&gt;
&lt;P&gt;ec2:DeleteVolume&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:ModifyVpcAttribute&lt;/P&gt;
&lt;P&gt;ec2:CreateRoute&lt;/P&gt;
&lt;P&gt;ec2:DescribeTags&lt;/P&gt;
&lt;P&gt;ec2:AttachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeRegions&lt;/P&gt;
&lt;P&gt;ec2:DescribeKeyPairs&lt;/P&gt;
&lt;P&gt;ec2:DeleteSubnet&lt;/P&gt;
&lt;P&gt;ec2:DetachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceTypes&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcClassicLinkDnsSupport&lt;/P&gt;
&lt;P&gt;ec2:DescribeAccountAttributes&lt;/P&gt;
&lt;P&gt;ec2:DeleteRouteTable&lt;/P&gt;
&lt;P&gt;ec2:CreateSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ReleaseAddress&lt;/P&gt;
&lt;P&gt;ec2:RunInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcClassicLink&lt;/P&gt;
&lt;P&gt;ec2:CreateRouteTable&lt;/P&gt;
&lt;P&gt;ec2:DescribeRouteTables&lt;/P&gt;
&lt;P&gt;ec2:DescribeSecurityGroups&lt;/P&gt;
&lt;P&gt;ec2:DetachInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:CreateNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DeleteInternetGateway&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkInterfaces&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcAttribute&lt;/P&gt;
&lt;P&gt;ec2:TerminateInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeSubnets&lt;/P&gt;
&lt;P&gt;ec2:ModifySubnetAttribute&lt;/P&gt;
&lt;P&gt;iam:AddRoleToInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:DeleteInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:CreateRole&lt;/P&gt;
&lt;P&gt;iam:GetRole&lt;/P&gt;
&lt;P&gt;iam:DeleteRole&lt;/P&gt;
&lt;P&gt;iam:PutRolePolicy&lt;/P&gt;
&lt;P&gt;iam:DeleteRolePolicy&lt;/P&gt;
&lt;P&gt;iam:CreateInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:RemoveRoleFromInstanceProfile&lt;/P&gt;
&lt;P&gt;cloudformation:ListStackResources&lt;/P&gt;
&lt;P&gt;cloudformation:CreateStack&lt;/P&gt;
&lt;P&gt;cloudformation:DescribeStacks&lt;/P&gt;
&lt;P&gt;cloudformation:DeleteStack&lt;/P&gt;
&lt;P&gt;cloudformation:ValidateTemplate&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="312"&gt;
&lt;P&gt;gateway&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="325"&gt;
&lt;P&gt;ec2:CreateTags&lt;/P&gt;
&lt;P&gt;ec2:DeleteSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ModifyNetworkInterfaceAttribute&lt;/P&gt;
&lt;P&gt;ec2:DescribeVpcs&lt;/P&gt;
&lt;P&gt;ec2:DeleteNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DeleteRoute&lt;/P&gt;
&lt;P&gt;ec2:RevokeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:AssociateAddress&lt;/P&gt;
&lt;P&gt;ec2:AllocateAddress&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupIngress&lt;/P&gt;
&lt;P&gt;ec2:DisassociateAddress&lt;/P&gt;
&lt;P&gt;ec2:DescribeVolumes&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeAddresses&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceAttribute&lt;/P&gt;
&lt;P&gt;ec2:AuthorizeSecurityGroupEgress&lt;/P&gt;
&lt;P&gt;ec2:CreateRoute&lt;/P&gt;
&lt;P&gt;ec2:DescribeTags&lt;/P&gt;
&lt;P&gt;ec2:DescribeKeyPairs&lt;/P&gt;
&lt;P&gt;ec2:DetachNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeInstanceTypes&lt;/P&gt;
&lt;P&gt;ec2:CreateSecurityGroup&lt;/P&gt;
&lt;P&gt;ec2:ReleaseAddress&lt;/P&gt;
&lt;P&gt;ec2:RunInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeRouteTables&lt;/P&gt;
&lt;P&gt;ec2:DescribeSecurityGroups&lt;/P&gt;
&lt;P&gt;ec2:CreateNetworkInterface&lt;/P&gt;
&lt;P&gt;ec2:DescribeNetworkInterfaces&lt;/P&gt;
&lt;P&gt;ec2:TerminateInstances&lt;/P&gt;
&lt;P&gt;ec2:DescribeSubnets&lt;/P&gt;
&lt;P&gt;iam:AddRoleToInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:DeleteInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:CreateRole&lt;/P&gt;
&lt;P&gt;iam:DeleteRole&lt;/P&gt;
&lt;P&gt;iam:PutRolePolicy&lt;/P&gt;
&lt;P&gt;iam:DeleteRolePolicy&lt;/P&gt;
&lt;P&gt;iam:CreateInstanceProfile&lt;/P&gt;
&lt;P&gt;iam:RemoveRoleFromInstanceProfile&lt;/P&gt;
&lt;P&gt;cloudformation:ListStackResources&lt;/P&gt;
&lt;P&gt;cloudformation:CreateStack&lt;/P&gt;
&lt;P&gt;cloudformation:DescribeStacks&lt;/P&gt;
&lt;P&gt;cloudformation:DeleteStack&lt;/P&gt;
&lt;P&gt;cloudformation:ValidateTemplate&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Yizhak O.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 15:05:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/197761#M4395</guid>
      <dc:creator>yizhako</dc:creator>
      <dc:date>2023-11-12T15:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: AWS IAM User Account Permissions</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/197885#M4396</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;SPAN&gt;Yizhak O.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 06:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-IAM-User-Account-Permissions/m-p/197885#M4396</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2023-11-14T06:26:25Z</dc:date>
    </item>
  </channel>
</rss>

