<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: publishing routes to On-Prem via Express Route in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/55271#M2920</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Nir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i am not sure if it is sufficient, but have you configured the peerings as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;•Configure the VNet peering connection in the hub to allow gateway transit.&lt;BR /&gt;•Configure the VNet peering connection in each spoke to use remote gateways.&lt;BR /&gt;•Configure all VNet peering connections to allow forwarded traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/hub-spoke" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/hub-spoke&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Matthias&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 09:22:52 GMT</pubDate>
    <dc:creator>Matthias_Haas</dc:creator>
    <dc:date>2019-06-07T09:22:52Z</dc:date>
    <item>
      <title>publishing routes to On-Prem via Express Route</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/54364#M2919</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a customer who is building a Hub-And-Spoke infrastructure in Azure.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We added a Cluster-HA in his HUB vNet in order to route all the traffic from spokes vNets via the Custer to On-Prem and vice versa.&lt;/P&gt;
&lt;P&gt;The customer has an Express Route in the HUB spoke to access the On-Prem networks. The Azure Virtual GW publish to On-Prem the networks of the HUB vNet.&lt;/P&gt;
&lt;P&gt;This is more an Azure questions , How can I make the Express Route Virtual GW to publish the spokes vNets to On-Prem ?&lt;/P&gt;
&lt;P&gt;I added a UDR on the GatewaySubnet to route traffic to the spokes via the CG Cluster but that route doesn't propagate to On-Prem.&lt;/P&gt;
&lt;P&gt;Someone told me that the Express Route Virtual GW should also see the Peered vNets subnets and publish them but we don't see it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If anyone did something similar in other customers , please advise,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nir&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 May 2019 09:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/54364#M2919</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2019-05-26T09:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: publishing routes to On-Prem via Express Route</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/55271#M2920</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Nir,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i am not sure if it is sufficient, but have you configured the peerings as follows:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;•Configure the VNet peering connection in the hub to allow gateway transit.&lt;BR /&gt;•Configure the VNet peering connection in each spoke to use remote gateways.&lt;BR /&gt;•Configure all VNet peering connections to allow forwarded traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/hub-spoke" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/hybrid-networking/hub-spoke&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Matthias&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 09:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/55271#M2920</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2019-06-07T09:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: publishing routes to On-Prem via Express Route</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/55278#M2921</link>
      <description>&lt;P&gt;Do you have BGP route propagation enabled? What do you see in effective routes?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 13:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/publishing-routes-to-On-Prem-via-Express-Route/m-p/55278#M2921</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2019-06-07T13:12:29Z</dc:date>
    </item>
  </channel>
</rss>

