<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Center Object Enforcement in Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33571#M3480</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Carsten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont panic! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp; All thats happened it is you must have combined regular objects, and objects learned from Azure in the same source field in the rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easiest thing I expect is to duplicate the rule, and in one rule leave the normal objects, and in the other rule put the objects in that are learned from azure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Feb 2019 13:49:39 GMT</pubDate>
    <dc:creator>Nicholas_Sherid</dc:creator>
    <dc:date>2019-02-18T13:49:39Z</dc:date>
    <item>
      <title>Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33564#M3473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi forum!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My management server has been integrated with azure (I set up the data centre server).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can read all the objects in Azure.&amp;nbsp; (I'm running R80.10 gateway and mgt)&lt;/P&gt;&lt;P&gt;I have set up Identity Awareness too.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My gateways are not enforcing the rules I have created with datacentre objects!&lt;/STRONG&gt; &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;Everything looks perfect on the management server, I can even see the IP addresses dynamically associated with the tags!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need some help figuring out why the gateways are not enforcing the rules.&lt;/P&gt;&lt;P&gt;I have looked all over for this - and I have a case raised, but TAC have gone a bit quiet!&lt;/P&gt;&lt;P&gt;Anyone help me with locating the documentation for this?&amp;nbsp; I have looked everywhere.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a "pep show user all" (not sure if this shows output on azure integration) i get nothing on the gateway - whcih makes sense.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any logfiles?&amp;nbsp; I have checked /var/log/messages - nothing!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Oct 2018 20:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33564#M3473</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2018-10-06T20:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33565#M3474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think: TAC will know better &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116797&amp;amp;partition=Advanced&amp;amp;product=vSEC" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116797&amp;amp;partition=Advanced&amp;amp;product=vSEC"&gt;How to debug issues related to Security Groups / Data Center objects not being enforced by vSEC Gateway&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;GW side:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;"$FWDIR/log/azure_had.elg*" log files.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 12.8px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;"$FWDIR/conf/azure-ha.json" log file.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 12.8px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;"$FWDIR/log/cloud_proxy.elg" log file.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122636&amp;amp;partition=Advanced&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122636&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;How to troubleshoot Updatable Objects in R80.20 (and higher)&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;SPAN&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131932&amp;amp;partition=Advanced&amp;amp;product=CloudGuard" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131932&amp;amp;partition=Advanced&amp;amp;product=CloudGuard"&gt;Azure portal reports read and/or write limits, throttling API resources&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12.8px;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 18:17:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33565#M3474</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2018-10-07T18:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33566#M3475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Top response&amp;nbsp;ofirsea040d26-f1f2-3b12-9fc6-5c89debaf56c!&amp;nbsp; I&amp;nbsp;was thinking about getting R80.20 and just blowing away my cirrent install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again mate - much appreciated &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 21:17:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33566#M3475</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2018-10-07T21:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33567#M3476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll post up root cause and corrective action when I am done - share the wealth - I suspect it's something I have overlooked!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 21:20:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33567#M3476</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2018-10-07T21:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33568#M3477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;OL&gt;&lt;LI&gt;configured datacentre object (azure intergration)&lt;/LI&gt;&lt;LI&gt;entered dynamically learned objects into fw policy&lt;/LI&gt;&lt;LI&gt;console told me to configure identity awareness&lt;/LI&gt;&lt;LI&gt;configured as terminal based, do AD later&lt;/LI&gt;&lt;LI&gt;no enforcement occuring - but updates being learned by console&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Added a host_localhost (127.0.0.1) object&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Went to cluster config &amp;gt; identity awareness &amp;gt; ticket Identity web api&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Dropped&amp;nbsp;&lt;EM&gt;host_localhost object into authorized client&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;BOOOM!&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;EM&gt;Dynamic enforcement enabled!!!!&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;EM&gt;So I missed out the bold bits &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp; HTH anyone who has the same issue as me&amp;nbsp; &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 17:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33568#M3477</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2018-10-08T17:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33569#M3478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;validate with&amp;nbsp;&lt;SPAN&gt;pep show user all&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71302_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 17:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33569#M3478</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2018-10-08T17:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33570#M3479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have problems with that data center objetcs on an VMSS gateway in Azure.&lt;/P&gt;&lt;P&gt;I have enabled the Identity Awareness blade with the autoprov CLI feature. The VMSS gateway has an active Identity Awareness blade, the Remote Web API is checked, and one autogenerated host with IP 127.0.0.1 is added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the data center object for Azure, and everything is fine, I can seach all objects in my Azure inventory.&lt;/P&gt;&lt;P&gt;But when I would like to install the policy with one virtual machine from that Azure inventory, I receive an error.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="78932" alt="Policy install error" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78932_error.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any good advise, because I'm normally familar with that data center objects for on-prem vCenter environments. In my opinion, it should the nearly "the same" for Azure objects...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Management and VMSS gateway is running on R80.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2019 13:38:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33570#M3479</guid>
      <dc:creator>Carsten_R</dc:creator>
      <dc:date>2019-02-18T13:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33571#M3480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Carsten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dont panic! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp; All thats happened it is you must have combined regular objects, and objects learned from Azure in the same source field in the rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easiest thing I expect is to duplicate the rule, and in one rule leave the normal objects, and in the other rule put the objects in that are learned from azure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2019 13:49:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33571#M3480</guid>
      <dc:creator>Nicholas_Sherid</dc:creator>
      <dc:date>2019-02-18T13:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33572#M3481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upps, life can be so easy when you only read the error message &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You're right Nicholas, that was the problem, it is working now - thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 05:00:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/33572#M3481</guid>
      <dc:creator>Carsten_R</dc:creator>
      <dc:date>2019-02-19T05:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/66826#M3482</link>
      <description>I would like to know if Azure Data Center objects only work with vSec gateways or does it also work with 15400 (r80.30) on-prem security gateways?</description>
      <pubDate>Fri, 08 Nov 2019 02:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/66826#M3482</guid>
      <dc:creator>Senaka</dc:creator>
      <dc:date>2019-11-08T02:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Data Center Object Enforcement in Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/66848#M3483</link>
      <description>&lt;P&gt;Data Center objects works also with on-prem GW.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 07:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Data-Center-Object-Enforcement-in-Azure/m-p/66848#M3483</guid>
      <dc:creator>Gil_Sudai</dc:creator>
      <dc:date>2019-11-08T07:52:25Z</dc:date>
    </item>
  </channel>
</rss>

