<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IaaS BluePrint on Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/83140#M2308</link>
    <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;one question to the recommended blueprint designed by CP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 748px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5790iFA4CC73EA941ABD3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you have to implement it in an azure cloud, do you use for each spoke and each hub a dedicated VNET?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It means you have to pay a lot of money for incoming and outgoing vnet traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you take a look to an older deployment guide the recommendation is to use one vnet and seperate it with subnets.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5791i84268CBA314F63E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is best practise with all advantages and disadvantages?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance &amp;amp; best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Apr 2020 10:33:46 GMT</pubDate>
    <dc:creator>IdentityUnknown</dc:creator>
    <dc:date>2020-04-25T10:33:46Z</dc:date>
    <item>
      <title>IaaS BluePrint on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/83140#M2308</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;one question to the recommended blueprint designed by CP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 748px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5790iFA4CC73EA941ABD3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you have to implement it in an azure cloud, do you use for each spoke and each hub a dedicated VNET?&amp;nbsp;&lt;/P&gt;&lt;P&gt;It means you have to pay a lot of money for incoming and outgoing vnet traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you take a look to an older deployment guide the recommendation is to use one vnet and seperate it with subnets.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5791i84268CBA314F63E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is best practise with all advantages and disadvantages?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance &amp;amp; best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 10:33:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/83140#M2308</guid>
      <dc:creator>IdentityUnknown</dc:creator>
      <dc:date>2020-04-25T10:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: IaaS BluePrint on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/84793#M2309</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check Point's Cloud Security BluePrint is a conceptual "best practice" approach&lt;/P&gt;
&lt;P&gt;with that in mind, when it comes to Azure, it can be deployed inside the same vNET or across multiple vNETs. From an architecture approach, it is preserving the same principles and thus a viable solution.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The decision whether to implement it that way or the other is up to the customer decision and depends on some factors such as organization structure, environment size &amp;amp; scale, locations and cost as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In other words, for an organization with limited cloud presence (Subscriptions, Regions, vNET's), it would probably make sense to follow the BluePrint and deploy the solution within a single vNET (I have added a diagram as an example)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope that helps&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 06:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/84793#M2309</guid>
      <dc:creator>Amit_Schnitzer</dc:creator>
      <dc:date>2020-05-11T06:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: IaaS BluePrint on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/116165#M2310</link>
      <description>&lt;P&gt;In Microsoft documentation (&lt;A href="https://docs.microsoft.com/en-us/azure/virtual-network/concepts-and-best-practices" target="_blank" rel="noopener"&gt;Azure Virtual Network concepts and best practices&lt;/A&gt;) you can find this:&lt;/P&gt;&lt;P&gt;It is recommended you have fewer large VNets rather than multiple small VNets.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 07:09:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IaaS-BluePrint-on-Azure/m-p/116165#M2310</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2021-04-16T07:09:41Z</dc:date>
    </item>
  </channel>
</rss>

