<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99198#M1966</link>
    <description>&lt;P&gt;Hi Matthias,&lt;/P&gt;&lt;P&gt;Thanks for the reply. But Cluster failover won't happen in that case. And yes it is too expensive, Customer will not agree for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Amarpreet Singh&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2020 11:26:13 GMT</pubDate>
    <dc:creator>Amarpreet_Singh</dc:creator>
    <dc:date>2020-10-15T11:26:13Z</dc:date>
    <item>
      <title>Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for field</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98763#M1948</link>
      <description>&lt;P&gt;Please help me with this. How to achieve seeing &lt;STRONG&gt;Clients Real Public IP&lt;/STRONG&gt; at my &lt;STRONG&gt;backend servers&lt;/STRONG&gt; allowing gateways to &lt;STRONG&gt;pass&lt;/STRONG&gt; Public IPs through.&lt;/P&gt;&lt;P&gt;~My Network Flow when client tries to open a URL over the internet (Accessing a web page): -&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Client&lt;/STRONG&gt; --&amp;gt; &lt;STRONG&gt;Internet&lt;/STRONG&gt; --&amp;gt; &lt;STRONG&gt;Azure Load balancer (Layer4)&lt;/STRONG&gt; --&amp;gt; &lt;STRONG&gt;Cloud Guard IaaS Cluster HA(A-P) R80.30&lt;/STRONG&gt; --&amp;gt; &lt;STRONG&gt;Azure Application Gateway(Layer 7)&lt;/STRONG&gt; --&amp;gt; &lt;STRONG&gt;Web Apps (Azure App Services)/Servers&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this architecture I am able to see Clients real Public-IP till the Firewall logs only.&lt;/P&gt;&lt;P&gt;~What I want to achieve: -&lt;/P&gt;&lt;P&gt;&lt;U&gt;I need the &lt;STRONG&gt;same public IP&lt;/STRONG&gt; to be seen at the Azure Application Gateway(Layer 7). Which at the moment I am seeing firewalls internal &lt;STRONG&gt;Translated Source&lt;/STRONG&gt; IP (Private IP) for each and every request.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="AppGW-log.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8378iABF98791B6179F1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="AppGW-log.jpg" alt="AppGW-log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the Application&amp;nbsp;Gateway(Layer 7) logs where I am seeing IP as "&lt;STRONG&gt;clientIP:10.0.11.10&lt;/STRONG&gt;" which is my Check Point gateways eth1/port2/internal port. Instead of this I should get real clients public-IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~As a knowledge: -&lt;/P&gt;&lt;P&gt;I am using NAT here where &lt;U&gt;&lt;STRONG&gt;All internet&lt;/STRONG&gt;&lt;/U&gt; as a &lt;U&gt;&lt;STRONG&gt;Original Source&lt;/STRONG&gt;&lt;/U&gt; gets converted to Gateways &lt;STRONG&gt;&lt;U&gt;port2/eth1&lt;/U&gt;&lt;/STRONG&gt; (&lt;U&gt;&lt;STRONG&gt;Hide behind NAT&lt;/STRONG&gt;&lt;/U&gt;) as &lt;U&gt;&lt;STRONG&gt;Translated Source&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="AppGW-log.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8379i63C391713E6AF131/image-size/large?v=v2&amp;amp;px=999" role="button" title="AppGW-log.jpg" alt="AppGW-log.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;~&lt;FONT color="#993300"&gt;&lt;U&gt;&lt;STRONG&gt;Once I am able to see the public IP at Azure Application Gateway(Layer 7), the work is done here&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Amarpreet Singh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 06:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98763#M1948</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-11T06:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98777#M1949</link>
      <description>&lt;P&gt;My understanding is this is added by the upstream load balancer, not us.&lt;BR /&gt;In which case, we should pass it along.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 16:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98777#M1949</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-11T16:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98827#M1950</link>
      <description>&lt;P&gt;..&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 08:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98827#M1950</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-12T08:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98831#M1951</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8402i25FA13ADD0A366B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8400i710F5B954526754A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8401iA22B69210DEB410B/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.jpg" alt="3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 08:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98831#M1951</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-12T08:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98855#M1952</link>
      <description>&lt;P&gt;Hi Amarpreet,&lt;/P&gt;&lt;P&gt;do you need Source IP NAT on the Cloud Guard at all ?&lt;/P&gt;&lt;P&gt;Not sure if it´s possible, but if the default route on the Application Gateway / (or the subnet in which the Application Gateway is deployed) is pointing to the internal IP of the cloudguard/internal LB if a Cluster is used,&amp;nbsp; you may dont need the Source NAT.&lt;/P&gt;&lt;P&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 12:07:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98855#M1952</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-12T12:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98869#M1953</link>
      <description>&lt;P&gt;Hi Matthias,&lt;/P&gt;&lt;P&gt;Without snat our scenario does not work &amp;nbsp;&lt;/P&gt;&lt;P&gt;Also on app gateway there are no methods to apply default gateway. &amp;nbsp;It is all based on sessions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 13:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98869#M1953</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-12T13:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98899#M1954</link>
      <description>&lt;P&gt;I have tested this with a custom fix provider by R&amp;amp;D .That time it was not ready for production . Fix is to add the&amp;nbsp; client IP in header . You can please check with SE .&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 15:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98899#M1954</guid>
      <dc:creator>Harshpal_Bhati</dc:creator>
      <dc:date>2020-10-12T15:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98901#M1955</link>
      <description>&lt;P&gt;I have also noticed that you are using cluster then there is no need of&amp;nbsp; SNAT typically SNAT is needed when u have auto scale architecture .&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 15:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98901#M1955</guid>
      <dc:creator>Harshpal_Bhati</dc:creator>
      <dc:date>2020-10-12T15:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98902#M1956</link>
      <description>&lt;P&gt;Hi Harshpal,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I will try without using SNAT, I had tried it earlier but did not worked.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In my case I have application gateway after firewalls which then sends traffic back to azure app services (PaaS Service) and not IaaS servers. That is why we used SNAT here.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;but still i will try other way if SNAT could be removed. And if not then I have to find a soln beside it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 15:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98902#M1956</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-12T15:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98905#M1957</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Tried doing it without SNAT. Scenario not working. We need SNAT here.&amp;nbsp; (Translated Source - Hide behind is reqd.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8413iAE9CACFB41C9002F/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Web Apps we are accessing here does not require internet access as these are not servers, these are PaaS offerings. Only inbound is concerned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;~Any other options to go through?&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 09:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98905#M1957</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-13T09:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98974#M1958</link>
      <description>&lt;P&gt;When you deploy an Azure Cluster it deploys also an internal Network Load Balancer.&lt;/P&gt;
&lt;P&gt;1. Remove the Translated source from the NAT rule&lt;/P&gt;
&lt;P&gt;2. Create a UDR for the Subnet where the AppGW is located , and create a static route with destination 0.0.0.0/0 to the Internal Network LoadBlancer.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 13:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98974#M1958</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2020-10-13T13:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98987#M1959</link>
      <description>&lt;P&gt;Hi Shay,&lt;/P&gt;&lt;P&gt;On your second point. I will perform these changes. And test it removing snat. I think this might work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/98987#M1959</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-13T14:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99009#M1960</link>
      <description>&lt;P&gt;Hi Shay,&lt;/P&gt;&lt;P&gt;Did not worked: - It is not letting me add next hop as ILB. AppGWs can only route to internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CP.jpg" style="width: 513px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8431i522CC5037825FB51/image-dimensions/513x367?v=v2" width="513" height="367" role="button" title="CP.jpg" alt="CP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 17:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99009#M1960</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-13T17:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99073#M1961</link>
      <description>&lt;P&gt;Does the application gateway have a public or private IP address?&lt;/P&gt;
&lt;P&gt;As it would need to have only private internal IP address&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 10:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99073#M1961</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2020-10-14T10:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99074#M1962</link>
      <description>&lt;P&gt;Please read&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure#supported-user-defined-routes" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/azure/application-gateway/configuration-infrastructure#supported-user-defined-routes&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will need to use AppGW-&lt;SPAN&gt;v1 SKU&amp;nbsp;&lt;/SPAN&gt;to route 0.0.0.0/0 to virtual appliance (ILB)&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 10:32:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99074#M1962</guid>
      <dc:creator>Shay_Levin</dc:creator>
      <dc:date>2020-10-14T10:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99075#M1963</link>
      <description>&lt;P&gt;Both, but we are using private IP Add because it is internal and not external.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 10:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99075#M1963</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-14T10:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99077#M1964</link>
      <description>&lt;P&gt;UDR not supported : -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="CP.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8445i398DD3D8B45FB4D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="CP.jpg" alt="CP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I believe that SNAT is required here because App GW can only listen if traffic originates from same V-Net(10.0.0.0/16).&lt;/P&gt;&lt;P&gt;And to make it happen we have to do SNAT to change source public IP to either of the firewalls Internal IP and then DNAT to APPGW private IP.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 10:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99077#M1964</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-14T10:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99197#M1965</link>
      <description>&lt;P&gt;further options you may have (not tested):&lt;/P&gt;&lt;P&gt;1. Replace the external LB by a Application Gateway (not sure if this is supported by Checkpoint)&lt;/P&gt;&lt;P&gt;see&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security-IaaS/Whilst-doing-a-SNAT-on-HTTP-can-I-insert-an-X-Forwarded-For/td-p/28888" target="_self"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security-IaaS/Whilst-doing-a-SNAT-on-HTTP-can-I-insert-an-X-Forwarded-For/td-p/28888&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Setup a additional Application Gateway which has the Public IP of the external LB as the Backend Pool&lt;/P&gt;&lt;P&gt;see&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/azure/application-gateway/how-application-gateway-works" target="_self"&gt;https://docs.microsoft.com/en-us/azure/application-gateway/how-application-gateway-works&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In either case you could use SSL interception and add the X-Forward Header on the App Gateway&lt;/P&gt;&lt;P&gt;may be too complicated and expensive of course&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 11:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99197#M1965</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-15T11:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99198#M1966</link>
      <description>&lt;P&gt;Hi Matthias,&lt;/P&gt;&lt;P&gt;Thanks for the reply. But Cluster failover won't happen in that case. And yes it is too expensive, Customer will not agree for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Amarpreet Singh&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 11:26:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/99198#M1966</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-10-15T11:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Want to see real client Public IP at my backend servers. Allow gateways to add X-forwarded-for f</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/102233#M1968</link>
      <description>&lt;P&gt;This can be achieved by switching to R81 new version of Check Point and use App &amp;amp; URL filtering with https inspection.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 06:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Want-to-see-real-client-Public-IP-at-my-backend-servers-Allow/m-p/102233#M1968</guid>
      <dc:creator>Amarpreet_Singh</dc:creator>
      <dc:date>2020-11-17T06:21:55Z</dc:date>
    </item>
  </channel>
</rss>

