<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB) in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178597#M354</link>
    <description>&lt;P&gt;first, they need to be added automatically to the Management SmartConsole using CME. this is how it is done.&lt;/P&gt;
&lt;P&gt;check the GWLB admin guide.&lt;/P&gt;
&lt;P&gt;they will be added and both will have the same policy installed on them.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 09:05:21 GMT</pubDate>
    <dc:creator>Nir_Shamir</dc:creator>
    <dc:date>2023-04-20T09:05:21Z</dc:date>
    <item>
      <title>AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178450#M349</link>
      <description>&lt;P&gt;Scenario: We have Production deployments in several AWS regions and want to deploy CloudGuard to protect egress internet traffic. Requirement is for north/south traffic&lt;/P&gt;&lt;P&gt;We have an on prem Checkpoint deployment for all branch and DC. As such our security management servers are on prem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AWS Solution we are trying to deploy:&lt;/P&gt;&lt;P&gt;Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB) -&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk111013" target="_blank"&gt;AWS CloudFormation Templates (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(Deploys a Gateway Load Balancer, Check Point CloudGuard IaaS Security Gateway Auto Scaling Group, and optionally a Security Management Server into an existing VPC.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have on prem Security Management servers so will be using them, otherwise all other elements have deployed successfully.&lt;BR /&gt;We have created the TGW attachments and have confirmed routing is good.&lt;/P&gt;&lt;P&gt;I am getting stuck on which CGNS to establish SIC with ? For example at the moment I see Security gateways created and I do&lt;BR /&gt;have reachability but as these are created as a scale set which do I use to establish SIC with management servers?&lt;/P&gt;&lt;P&gt;Attached image shows the flows. I dont have problem with reachability just understanding what I establish SIC with for SMS servers. As the IP's of the provisioned CGNS are likely to change as they are part of a scale set.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 08:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178450#M349</guid>
      <dc:creator>Finner1976</dc:creator>
      <dc:date>2023-04-19T08:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178452#M350</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84692"&gt;@Finner1976&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Are you seeing errors in the /var/log/CPcme/cme.log on the Management machine?&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 09:00:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178452#M350</guid>
      <dc:creator>Roman_Kats</dc:creator>
      <dc:date>2023-04-19T09:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178479#M351</link>
      <description>&lt;P&gt;the GWs have only one IP address which is the one connected to the PUBLIC SUBNET of the deployment.&lt;/P&gt;
&lt;P&gt;You will be using those IPs to establish SIC. of course they will change when new GWs will be deployed and old will be deleted according to the ASG sizing but we are using the CME component to automatically scan / deploy / delete the ASG GWs from the Management Server.&lt;/P&gt;
&lt;P&gt;Check the GWLB admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Default.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 12:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178479#M351</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-04-19T12:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178589#M352</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thank you Nir.&lt;/P&gt;&lt;P&gt;I will try that, however its a bit confusing. For example&amp;nbsp; I see two CP gateways provisioned at the moment in public subnet. Do I add both to the SMS and push the same policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:40:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178589#M352</guid>
      <dc:creator>Finner1976</dc:creator>
      <dc:date>2023-04-20T08:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178590#M353</link>
      <description>&lt;P&gt;Hi Roman&lt;/P&gt;&lt;P&gt;I have reachability and I can establish SIC, The question i have is do I need to establish SIC with every GW in the scaleset&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 08:42:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178590#M353</guid>
      <dc:creator>Finner1976</dc:creator>
      <dc:date>2023-04-20T08:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: AWS CloudGuard - Security Gateways Auto Scaling Group for Gateway Load Balancer (GWLB)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178597#M354</link>
      <description>&lt;P&gt;first, they need to be added automatically to the Management SmartConsole using CME. this is how it is done.&lt;/P&gt;
&lt;P&gt;check the GWLB admin guide.&lt;/P&gt;
&lt;P&gt;they will be added and both will have the same policy installed on them.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:05:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-CloudGuard-Security-Gateways-Auto-Scaling-Group-for-Gateway/m-p/178597#M354</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-04-20T09:05:21Z</dc:date>
    </item>
  </channel>
</rss>

