<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can i import an Internal ELB from aws and use it in the NAT and security policy in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/66450#M2834</link>
    <description>&lt;P&gt;sk104249 deals with scenario when CheckPoint vSEC runs in AWS VPC.&lt;/P&gt;&lt;P&gt;When CheckPoint gateway sits on-premises and has VPN tunnel to Amazon VPC this solution fails to match ELB traffic. One can try using domain objects, but it is still not the best solution.&lt;/P&gt;</description>
    <pubDate>Sun, 03 Nov 2019 12:52:45 GMT</pubDate>
    <dc:creator>Boris_Karnaukh</dc:creator>
    <dc:date>2019-11-03T12:52:45Z</dc:date>
    <item>
      <title>Can i import an Internal ELB from aws and use it in the NAT and security policy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/59952#M2832</link>
      <description>&lt;P&gt;we are trying to setup an internal ALB and nat to the Public IP of the On-prem firewall so any inbound connections go from the public ip get NAT'ed and go to the internal&amp;nbsp; ALB via VPN and VGW, i do not see any load balancers when i import objects using cloudguard controller&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 13:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/59952#M2832</guid>
      <dc:creator>rohan_savant</dc:creator>
      <dc:date>2019-08-09T13:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can i import an Internal ELB from aws and use it in the NAT and security policy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/59966#M2833</link>
      <description>While I can't speak to whether the CloudGuard Controller can import them or not, I do know in general we handle ELB objects using Logical Server objects.&lt;BR /&gt;This is required because ELBs are load balanced with DNS.&lt;BR /&gt;Using the Logical Server object as described in SK handles this and performs the necessary NAT.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104249" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104249&lt;/A&gt;</description>
      <pubDate>Fri, 09 Aug 2019 18:33:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/59966#M2833</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-09T18:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can i import an Internal ELB from aws and use it in the NAT and security policy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/66450#M2834</link>
      <description>&lt;P&gt;sk104249 deals with scenario when CheckPoint vSEC runs in AWS VPC.&lt;/P&gt;&lt;P&gt;When CheckPoint gateway sits on-premises and has VPN tunnel to Amazon VPC this solution fails to match ELB traffic. One can try using domain objects, but it is still not the best solution.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2019 12:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/66450#M2834</guid>
      <dc:creator>Boris_Karnaukh</dc:creator>
      <dc:date>2019-11-03T12:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can i import an Internal ELB from aws and use it in the NAT and security policy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/66484#M2835</link>
      <description>Domain objects don't work with NAT.&lt;BR /&gt;Even if the ELB could be imported with CloudGuard Connector, you wouldn't be able to use it in the NAT policy anyway.&lt;BR /&gt;But you could use a Dynamic Object and update it based on a DNS record.&lt;BR /&gt;See: &lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Pre-R80-10-dynamic-objects-from-DNS-A-record-lists-one-liner/m-p/11566" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Pre-R80-10-dynamic-objects-from-DNS-A-record-lists-one-liner/m-p/11566&lt;/A&gt;</description>
      <pubDate>Mon, 04 Nov 2019 09:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Can-i-import-an-Internal-ELB-from-aws-and-use-it-in-the-NAT-and/m-p/66484#M2835</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-04T09:31:30Z</dc:date>
    </item>
  </channel>
</rss>

