<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS deployment with VSX on-prem gateway in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19576#M3573</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yonatan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This diagram is from&amp;nbsp;sk120534 and uses a Direct Connect.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="68900" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68900_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SK uses VTI. It is also mentioned in the articles and guides I listed above. In the articles similary pictures is used&amp;nbsp;both DC and VPN over internet is showed as exsamples for the same VTI configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that clarifies it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try to set up a test with BGP multihop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BGP is supported in a VS on VSX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Ole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2018 09:04:32 GMT</pubDate>
    <dc:creator>Ole_Jakobsen</dc:creator>
    <dc:date>2018-08-16T09:04:32Z</dc:date>
    <item>
      <title>AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19572#M3569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;I'm trying to do a deployment of CG in a AWS Transi VPC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;I have read the guides&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_Transit_VPC_for_AWS/html_frameset.htm"&gt;&lt;SPAN style="color: #2989c5;"&gt;Transit VPC for AWS R80.10 Deployment Guide&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120534"&gt;&lt;SPAN style="color: #2989c5;"&gt;CloudGuard for AWS - Transit VPC Architecture&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;, I have watched the video&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&lt;A _jive_internal="true" data-orig-content="Step by Step deployment of automated, multi hub Transit VPC" href="https://community.checkpoint.com/videos/6574-step-by-step-deployment-of-automated-multi-hub-transit-vpc"&gt;&lt;SPAN style="color: #2989c5;"&gt;Step by Step deployment of automated, multi hub Transit VPC&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;One thing that is described in every guide is to make a VTI between the on-prem gateway via the Direct Connect (DC) to the gateways in the Transit VPC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;My challange is that the on-prem gateway that is used to connect to the DC is a VS on VSX where VTI is not supported. (See:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700"&gt;VSX supported features on R75.40VS and above&lt;/A&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;As I understand the VTI is primarily used with the BGP peering so the peers is directly connected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;Then my solution to the unsupported VTI on VSX is to use BGP multihop os I don't need the VTI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;Can any of you see any issues with this solution?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;I'm looking forward to any reply to this question&lt;SPAN&gt;&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;Cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d;"&gt;Ole J&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19572#M3569</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-15T13:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19573#M3570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ole,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not using the VTI does this mean you plan to send traffic between your on-prem and the TransitVPC gateways in the clear over the internet or were you planning to use domain-based VPN instead?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Aug 2018 14:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19573#M3570</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-08-15T14:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19574#M3571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yoayan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Direct Connect line, which is a closed circuit from on-prem directly to a AWS region Data center. Therefore, no traffic from on-prem to AWS will transmitted over the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The guides say that either way, Direct Connect or internet, you have to use VTI to connect your on-prem gateway to the gateways int the AWS Transit VPC, because of the BGP peering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I run VSX on my on-prem gateway that terminates the Direct Connection, I can't use VTI because it is not supported on VSX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, I was think that I could skip the VTI interfaces and use BGP multihop for the peering between my on-prem gw and the Transsit gw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My only concern is, will it work with BGP multihop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Ole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 07:50:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19574#M3571</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T07:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19575#M3572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ole,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you point me to the exact place where it says you need VTI when using Direct Connect?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it might be a mistake (I could be wrong, but that doesn't sound right...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't had much experience with Direct Connect (or with VSX for that matter) but as far as I know, it supports BGP so I suspect it will just work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be easily tested - create a CP GW on a VPC and just test BGP and connectivity between your VSX and a single CP gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VTI is mainly used for the VPN tunnel. It's true that the BGP has a single hop, but since Direct Connect should support BGP I assume it's propagated along the route - again should be easily verified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 08:26:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19575#M3572</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-08-16T08:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19576#M3573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yonatan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This diagram is from&amp;nbsp;sk120534 and uses a Direct Connect.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="68900" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68900_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SK uses VTI. It is also mentioned in the articles and guides I listed above. In the articles similary pictures is used&amp;nbsp;both DC and VPN over internet is showed as exsamples for the same VTI configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that clarifies it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try to set up a test with BGP multihop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BGP is supported in a VS on VSX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Ole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:04:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19576#M3573</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T09:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19577#M3574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This diagram is the typical way to do it.&lt;/P&gt;&lt;P&gt;The VTI's are between the CloudGuard gateways and the AWS VGW&amp;nbsp;which is unattached and connected to DirectConnect.&lt;/P&gt;&lt;P&gt;So no need for VTI's in On-prem gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arnfinn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19577#M3574</guid>
      <dc:creator>Arnfinn_Strand</dc:creator>
      <dc:date>2018-08-16T09:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19578#M3575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was really hoping you weren't going to use that diagram &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I am 100% to blame for that.&lt;/P&gt;&lt;P&gt;I created this diagram. This was originally two diagrams - one with Direct Connect and one with VPN.&lt;/P&gt;&lt;P&gt;Since they were basically the same with such a minor difference between them we decided to combine them into one diagram to improve the readability&amp;nbsp;of the SK and explain in the text that you can use either one.&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;The connection is established via a secured VPN connection between your Check Point Security Appliance and a CloudGuard Gateway for AWS. You can also implement a secure connection with AWS&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://aws.amazon.com/directconnect/" style="color: #905690; background-color: #ffffff; text-decoration: none; font-size: 14px;" target="_blank"&gt;Direct Connect&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tunnels.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;At the time we spoke with a few customers and they said it was clear, but it was a very small sample size and there was always the worry that this will be misconstrued to mean you need both a VPN on top of the DC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So just to put this to bed - you can use either a VPN connection or a Direct Connect connection - no need for both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19578#M3575</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-08-16T09:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19579#M3576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arnfinn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand you correct, BGP multihop is the way to go if I use Direct Connect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Ole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19579#M3576</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T09:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19580#M3577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then that settles it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help and I'm sorry that I didn't understand the documentation first time I read it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/O&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:33:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19580#M3577</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T09:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19581#M3578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, if you create Route-Based VPN's between the CloudGuard gateways and the AWS VGW, you don't need BGP Multi-hop.&amp;nbsp;BGP will run over the VPN between&amp;nbsp;&lt;SPAN&gt;CloudGuard gateways and the AWS VGW. This is single hop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Arnfinn&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 09:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19581#M3578</guid>
      <dc:creator>Arnfinn_Strand</dc:creator>
      <dc:date>2018-08-16T09:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19582#M3579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Route-Based VPN it is based on VTI interfaces. VTI is not supported on VSX.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Ole&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 10:56:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19582#M3579</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T10:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19583#M3580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VTI is currently not supported on VSX.&lt;/P&gt;&lt;P&gt;As I understand you don't need encryption for the traffic over the DirectConnect, so there is no need to have VTI support on the On-prem gateway.&lt;/P&gt;&lt;P&gt;There are&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Route-Based VPN's (uisng VTI's) between the CloudGuard gateways and the AWS VGW. Between the&amp;nbsp;&lt;SPAN&gt;AWS VGW and On-prem there is the DirectConnect without VPN.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arnfinn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 11:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19583#M3580</guid>
      <dc:creator>Arnfinn_Strand</dc:creator>
      <dc:date>2018-08-16T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19584#M3581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So&amp;nbsp;with no direct link (eg VTI) between on-prem gw and CG gw BGP multihop is needed for the peering to work. Right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/O&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 11:45:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19584#M3581</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T11:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19585#M3582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't see why. There will be an other BGP peering b&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;etween the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; border: 0px;"&gt;AWS VGW and On-prem (or Service Providers BGP router).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/68904_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arnfinn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 11:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19585#M3582</guid>
      <dc:creator>Arnfinn_Strand</dc:creator>
      <dc:date>2018-08-16T11:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19586#M3583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok. I was just so hung up on the fact that I thought the Check Point gateways had to peer because that was how its described in the docs. Or at least that was how I read it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in short:&lt;/P&gt;&lt;P&gt;On-prem gw BGP peer to Service provider of Direct Connect router&lt;/P&gt;&lt;P&gt;GC gw BGP peer with VGW in Transit VPC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 13:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19586#M3583</guid>
      <dc:creator>Ole_Jakobsen</dc:creator>
      <dc:date>2018-08-16T13:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19587#M3584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The VGW is not "in" the Transit VPC or any other VPC, it is unattached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short:&lt;/P&gt;&lt;P style="border: 0px;"&gt;On-prem gateway BGP peer to Service provider BGP router of DirectConnect (optional)&lt;/P&gt;&lt;P style="border: 0px;"&gt;&lt;SPAN&gt;Service provider BGP router of DirectConnect BGP peer to unattached AWS VGW.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="border: 0px;"&gt;&lt;SPAN&gt;unattached AWS VGW BGP peer to both CloudGuard&lt;/SPAN&gt;&amp;nbsp;gateways&lt;/P&gt;&lt;P style="border: 0px;"&gt;&lt;/P&gt;&lt;P style="border: 0px;"&gt;Arnfinn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2018 14:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/19587#M3584</guid>
      <dc:creator>Arnfinn_Strand</dc:creator>
      <dc:date>2018-08-16T14:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/52919#M3585</link>
      <description>&lt;P&gt;I went through the whole comments.&amp;nbsp; Thank you for sharing.&amp;nbsp; I have a similar issue.&amp;nbsp; We are implementing Direct connect, but for now we have a VPN using a VSX virtual system to connect to a VGW.&amp;nbsp; We want to migrate that VPN connection to an actual pair of Cloud Guard Transit gateways.&amp;nbsp; When we do that VPN is established, but the request flows between a transit Cloud Guard FW in AZ1, which is routed through transit VPC, to its corresponding EC2 instance in a different VPC, in a a specific AZ.&amp;nbsp; The reply from that EC2 instance is routed through a transit Cloud Guard FW in AZ2 (Which is blocked because it is asymetric,&amp;nbsp; this CGFW didn't see the SYN coming).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got two different suggestions:&lt;/P&gt;&lt;P&gt;1. Checkpoint support mentioned that to fix this I was supposed to configure BGP between CG transit FW, and on-prem (VSX that doesn't support VTIs).&amp;nbsp; My question is:&amp;nbsp; is possible to setup BGP over two different VPNs using public IPs and private ASN between two CG transit FWs, and on-prem VSX?.&amp;nbsp; Will this fix my issues regarding asymmetric routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Somebody else was mentioning to configure MEP on actual CG transit FWs to select an active, and a standby CG FW.&amp;nbsp; At the same time configure BGP routemaps with different priorities to make always a CG FW Active, and other one Standby.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question I have is:&amp;nbsp; Will this BGP implementation on my actual VS VPN firewall cause any potential impact on my other actual VPNs with third parties?.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all suggestions I can get from you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 15:12:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/52919#M3585</guid>
      <dc:creator>Mauricio_Hurtad</dc:creator>
      <dc:date>2019-05-08T15:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: AWS deployment with VSX on-prem gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/74832#M3586</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already attempted this configuration trying BGP multi-hop.&amp;nbsp; It didn't work. The VPN tunnel came up because it was set to create a tunnel per gateway under tunnel management.&amp;nbsp; I our logs we observed that AWS was always attempting to do BGP peering with the VTIs we were supposed to be configured.&amp;nbsp; This is bad because the only way we were able to connect to AWS was using static routing VPN without possibility of using ECMP, and high availability across availability zones.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 17:32:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-deployment-with-VSX-on-prem-gateway/m-p/74832#M3586</guid>
      <dc:creator>Mauricio_Hurtad</dc:creator>
      <dc:date>2020-02-11T17:32:55Z</dc:date>
    </item>
  </channel>
</rss>

