<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Request from AWS NLB didn't enter vpn tunnel in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Request-from-AWS-NLB-didn-t-enter-vpn-tunnel/m-p/59327#M2827</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are deploying a Transit VPC architecture right now.&lt;/P&gt;&lt;P&gt;we tried to publish a service via AWS NLB.&lt;/P&gt;&lt;P&gt;NLB would transfer the request to our Gateway ,and we setup a NAT rule to translate the destination to our internal server.&lt;/P&gt;&lt;P&gt;But we found the gateway did translate the packet but didn't transfer to the internal gw(in transit&amp;nbsp; VPC).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we tried to capture packets via tcpdump and fw monitor.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01.png" style="width: 628px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2034i96B4F6616B9960C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="01.png" alt="01.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="02.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2035iAF2EE1F53C7B0FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="02.png" alt="02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;10.64.6.4 is NLB's addreess.&lt;/P&gt;&lt;P&gt;in tcpdump records,it seems the traffic sent out via physical interface?&lt;/P&gt;&lt;P&gt;in gw logs ,it didn't enter vpn tunnel but did NAT translation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03.png" style="width: 428px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2036i02925270283914F0/image-dimensions/428x321?v=v2" width="428" height="321" role="button" title="03.png" alt="03.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2019 09:42:33 GMT</pubDate>
    <dc:creator>Dawei_Ye</dc:creator>
    <dc:date>2019-07-31T09:42:33Z</dc:date>
    <item>
      <title>Request from AWS NLB didn't enter vpn tunnel</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Request-from-AWS-NLB-didn-t-enter-vpn-tunnel/m-p/59327#M2827</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are deploying a Transit VPC architecture right now.&lt;/P&gt;&lt;P&gt;we tried to publish a service via AWS NLB.&lt;/P&gt;&lt;P&gt;NLB would transfer the request to our Gateway ,and we setup a NAT rule to translate the destination to our internal server.&lt;/P&gt;&lt;P&gt;But we found the gateway did translate the packet but didn't transfer to the internal gw(in transit&amp;nbsp; VPC).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we tried to capture packets via tcpdump and fw monitor.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01.png" style="width: 628px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2034i96B4F6616B9960C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="01.png" alt="01.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="02.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2035iAF2EE1F53C7B0FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="02.png" alt="02.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;10.64.6.4 is NLB's addreess.&lt;/P&gt;&lt;P&gt;in tcpdump records,it seems the traffic sent out via physical interface?&lt;/P&gt;&lt;P&gt;in gw logs ,it didn't enter vpn tunnel but did NAT translation.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03.png" style="width: 428px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2036i02925270283914F0/image-dimensions/428x321?v=v2" width="428" height="321" role="button" title="03.png" alt="03.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 09:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Request-from-AWS-NLB-didn-t-enter-vpn-tunnel/m-p/59327#M2827</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-07-31T09:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Request from AWS NLB didn't enter vpn tunnel</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Request-from-AWS-NLB-didn-t-enter-vpn-tunnel/m-p/59348#M2828</link>
      <description>Additional:&lt;BR /&gt;Running R80.20GA in AWS.</description>
      <pubDate>Wed, 31 Jul 2019 12:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Request-from-AWS-NLB-didn-t-enter-vpn-tunnel/m-p/59348#M2828</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-07-31T12:24:13Z</dc:date>
    </item>
  </channel>
</rss>

