<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Service exposed in multiple AWS region in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101270#M1826</link>
    <description>&lt;P&gt;You can use the LocalGateway object in NAT rules, yes, and it resolves on the local gateway itself.&lt;BR /&gt;One comment on the source, you can't really use "Internet" or "Any" for a source, but you can use the "All_Internet" object, which is basically the same thing.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 04:54:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-06T04:54:41Z</dc:date>
    <item>
      <title>Service exposed in multiple AWS region</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101269#M1825</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I've deployed Cloudguard IaaS instances in front of the Internet and published an RDP service through an NLB in AWS US region.&lt;BR /&gt;I'll plan to publish the service also in AWS APAC region and protected with the same way as the first NLB+CloudGuard.&lt;/P&gt;&lt;P&gt;I'd like to use the same firewall policy and NAT rules for both regions.&amp;nbsp;I create the policy and NAT rule manually:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;src: Internet&amp;nbsp; &amp;nbsp;---&amp;nbsp; &amp;nbsp;dst: LocalGateway&amp;nbsp; --- Xlate Src:&amp;nbsp;LocalGateway (Hide)&amp;nbsp; --- Xlate Dst: RDP_Service_US (s)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'd like to know how I can add the NAT rule by using the 'LocalGateway' dynamic object. I don't if I can create the rule below when my 2nd AWS region will ready.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#333399"&gt;&lt;STRONG&gt;src: Internet&amp;nbsp; &amp;nbsp;---&amp;nbsp; &amp;nbsp;dst: LocalGateway&amp;nbsp; --- Xlate Src:&amp;nbsp;LocalGateway (Hide)&amp;nbsp; --- Xlate Dst: RDP_Service_APAC (s)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Ay&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 02:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101269#M1825</guid>
      <dc:creator>AyGit</dc:creator>
      <dc:date>2020-11-06T02:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Service exposed in multiple AWS region</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101270#M1826</link>
      <description>&lt;P&gt;You can use the LocalGateway object in NAT rules, yes, and it resolves on the local gateway itself.&lt;BR /&gt;One comment on the source, you can't really use "Internet" or "Any" for a source, but you can use the "All_Internet" object, which is basically the same thing.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 04:54:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101270#M1826</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-06T04:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Service exposed in multiple AWS region</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101290#M1827</link>
      <description>&lt;P&gt;Thanks for your feedback.&lt;/P&gt;&lt;P&gt;But I don't understand how both rules will match the correct gateway (US and APAC one) with the same LogalGateway object with a unique NAT rule? agree&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 21:59:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101290#M1827</guid>
      <dc:creator>AyGit</dc:creator>
      <dc:date>2020-11-09T21:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Service exposed in multiple AWS region</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101567#M1828</link>
      <description>&lt;P&gt;LocalGateway is a dynamic object, which is effectively a "placeholder" object.&lt;BR /&gt;It has no definition in Security Management and resolves on the security gateway itself.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A handful of dynamic objects (LocalGateway being one) are managed by the gateway itself.&lt;BR /&gt;You can create other dynamic objects as well, and their definition is defined using the dynamic_objects CLI command on the gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 22:17:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Service-exposed-in-multiple-AWS-region/m-p/101567#M1828</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-09T22:17:45Z</dc:date>
    </item>
  </channel>
</rss>

