<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic info about exposing services using AWS multi AZ and Checkpoint in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177107#M312</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;this is our situation:&lt;BR /&gt;&lt;BR /&gt;we AWS account with two AZ ; in these zone there is a Geo Cluster L3 Active Active that is facing internet.&lt;BR /&gt;&lt;BR /&gt;With the actual configuration each firewall has its own public ip ,and for testing purpose I used dynamic object ( configuring them using CLI on each FW ) to public a service over Internet and this is working fine.&lt;BR /&gt;But i don't know how to manage the dns registration...&lt;/P&gt;&lt;P&gt;for example when AZ1 is managing the traffic for&amp;nbsp;&amp;nbsp;&lt;A href="http://www.pippo.it" target="_blank"&gt;www.pippo.it&lt;/A&gt;&amp;nbsp;has the public ip of the checkpoint in AZ1&lt;BR /&gt;when I force the traffic to switch in AZ2 the traffic is managed by the checkpoint in AZ2 ,but &lt;A href="http://www.pippo.it" target="_blank"&gt;www.pippo.it&lt;/A&gt;&amp;nbsp;obviously point to ip of AZ1&lt;/P&gt;&lt;P&gt;Is there any other solution ?&lt;BR /&gt;&lt;BR /&gt;In normal situations usually I use a routed network for managing nat ,but on aws it seems impossible&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2023 08:31:36 GMT</pubDate>
    <dc:creator>AleLovaz82</dc:creator>
    <dc:date>2023-04-03T08:31:36Z</dc:date>
    <item>
      <title>info about exposing services using AWS multi AZ and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177107#M312</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;this is our situation:&lt;BR /&gt;&lt;BR /&gt;we AWS account with two AZ ; in these zone there is a Geo Cluster L3 Active Active that is facing internet.&lt;BR /&gt;&lt;BR /&gt;With the actual configuration each firewall has its own public ip ,and for testing purpose I used dynamic object ( configuring them using CLI on each FW ) to public a service over Internet and this is working fine.&lt;BR /&gt;But i don't know how to manage the dns registration...&lt;/P&gt;&lt;P&gt;for example when AZ1 is managing the traffic for&amp;nbsp;&amp;nbsp;&lt;A href="http://www.pippo.it" target="_blank"&gt;www.pippo.it&lt;/A&gt;&amp;nbsp;has the public ip of the checkpoint in AZ1&lt;BR /&gt;when I force the traffic to switch in AZ2 the traffic is managed by the checkpoint in AZ2 ,but &lt;A href="http://www.pippo.it" target="_blank"&gt;www.pippo.it&lt;/A&gt;&amp;nbsp;obviously point to ip of AZ1&lt;/P&gt;&lt;P&gt;Is there any other solution ?&lt;BR /&gt;&lt;BR /&gt;In normal situations usually I use a routed network for managing nat ,but on aws it seems impossible&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 08:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177107#M312</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2023-04-03T08:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: info about exposing services using AWS multi AZ and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177182#M313</link>
      <description>&lt;P&gt;If this is truly Active-Active, wouldn't you configure the DNS to use both IPs?&lt;BR /&gt;Also, I believe Amazon can assist with maintaining the DNS in the situation using Route53.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 22:54:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177182#M313</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-03T22:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: info about exposing services using AWS multi AZ and Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177220#M314</link>
      <description>&lt;P&gt;is a fake active active, all the routing table in aws are attached only at a single AZ at once,basically only one AZ manage the traffic,both external and internal.&lt;BR /&gt;When we configured everything the only allowed CP configuration was the L3 Geo Cluster because the two AZ are like two different datacenter with two different provider,to make an example with "not cloud" technology.&lt;BR /&gt;&lt;BR /&gt;We are thinking about converting our cluster into a GWLB that *should* works across different zones&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 07:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/info-about-exposing-services-using-AWS-multi-AZ-and-Checkpoint/m-p/177220#M314</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2023-04-04T07:26:25Z</dc:date>
    </item>
  </channel>
</rss>

