<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515 in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217632#M4853</link>
    <description>&lt;P&gt;thanks a lot !!&lt;/P&gt;</description>
    <pubDate>Sat, 15 Jun 2024 18:30:33 GMT</pubDate>
    <dc:creator>Gongya_Yu</dc:creator>
    <dc:date>2024-06-15T18:30:33Z</dc:date>
    <item>
      <title>really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217603#M4842</link>
      <description>&lt;P&gt;Working on Cloudguard with Azure express route&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ER-Nexthop-1.PNG" style="width: 925px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26267i93FC41B7EB0896B7/image-size/large?v=v2&amp;amp;px=999" role="button" title="ER-Nexthop-1.PNG" alt="ER-Nexthop-1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What do the IPs in red point to ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Know it is Azure related ? But no one in Azure answers.&amp;nbsp; Here there are lots of experts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks !!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 03:56:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217603#M4842</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T03:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217609#M4843</link>
      <description>&lt;P&gt;Seems to be the BGP Peering Addresses of the Azure peer, like a Router or VPN Gateway.&lt;/P&gt;
&lt;P&gt;On Check Point, this would be the router-id.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 09:37:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217609#M4843</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-06-15T09:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217611#M4844</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;is 100% right. If you look at 3rd column, shows 65535, which in your case would be AS number.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 11:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217611#M4844</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T11:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217620#M4845</link>
      <description>&lt;P&gt;Here is the &lt;A href="https://blog.cloudtrooper.net/2023/02/06/virtual-network-gateways-routing-in-azure/" target="_self"&gt;link&lt;/A&gt; related to this question ?&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ER-Nexthop-2.PNG" style="width: 495px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26269i41215C9D445FDDD9/image-size/large?v=v2&amp;amp;px=999" role="button" title="ER-Nexthop-2.PNG" alt="ER-Nexthop-2.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ER-Nexthop-3.PNG" style="width: 951px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26270i3BA0B2B986526470/image-size/large?v=v2&amp;amp;px=999" role="button" title="ER-Nexthop-3.PNG" alt="ER-Nexthop-3.PNG" /&gt;&lt;/span&gt;&lt;BR /&gt;I do not know what peers these IPs in red point to ?&lt;BR /&gt;&lt;BR /&gt;These IPs should be within GatewaySubnet,&amp;nbsp; 65515 is MS&amp;nbsp; reserved internal ASN.&lt;BR /&gt;&lt;BR /&gt;Are they virtual network gateway IPs ? If yes, we have 3 IPs in our environment. why ?&lt;BR /&gt;When a virtual network gateway is deployed, MS deploys two by default, right ?&lt;BR /&gt;&lt;BR /&gt;thanks a lot !!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 15:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217620#M4845</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T15:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217621#M4846</link>
      <description>&lt;P&gt;What is BGP peer |P?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 15:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217621#M4846</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T15:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217623#M4847</link>
      <description>&lt;P&gt;That is my question.&amp;nbsp; This is more Azure related question. I posed this in Azure community and no one answer. I am trying some luck here as more helpers are here.&lt;BR /&gt;&lt;BR /&gt;We are deploying cloudguard in Azure. I am digging some details in order to understand the cloud environment.&lt;BR /&gt;&lt;BR /&gt;I searched the internet for 2 days without any luck. The link above is the only thing I found which displays the&amp;nbsp; routing table.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our express routing table, the next-hop even has 3 IPs. I do not know where they point .&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ER-Nexthop.PNG" style="width: 740px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26271iB400AC74A05CBF78/image-size/large?v=v2&amp;amp;px=999" role="button" title="ER-Nexthop.PNG" alt="ER-Nexthop.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hopefully,&amp;nbsp;Gustavo Coronel&amp;nbsp; and shay Levin can shed some light here. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; I watched their many nice videos.&lt;BR /&gt;thanks !!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 17:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217623#M4847</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T17:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217625#M4848</link>
      <description>&lt;P&gt;K, I see what you are saying now. Not sure what sort of support leven you have for Azure, but it might be worth opening case with their support to confirm.&lt;/P&gt;
&lt;P&gt;Just a thought...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;I will keep checking myself as well to see if I can find anything for you.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 17:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217625#M4848</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T17:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217628#M4849</link>
      <description>&lt;P&gt;K, just had more careful look at this. I mean, could it be as simple as below?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26272i2B683FB9297F2E38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 17:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217628#M4849</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T17:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217629#M4850</link>
      <description>&lt;P&gt;thanks so much !!!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 17:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217629#M4850</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T17:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217630#M4851</link>
      <description>&lt;P&gt;I guess those next-hop IPs are network virtual gateway. Like to get confirmation from some experts. Also how do we have three ?&lt;BR /&gt;&lt;BR /&gt;Some MS docs mention:&lt;BR /&gt;"The Azure gateway subnet is needed by Azure to host the two virtual machines of your Azure gateway"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"A virtual network gateway is composed of two or more Azure-managed VMs that are automatically configured and deployed to a specific subnet that you create called the&amp;nbsp;gateway subnet. &lt;/SPAN&gt;&lt;SPAN&gt;The gateway VMs contain routing tables and run specific gateway services&lt;/SPAN&gt;&lt;SPAN&gt;."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217630#M4851</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T18:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217631#M4852</link>
      <description>&lt;P&gt;&lt;A href="https://learn.microsoft.com/bs-latn-ba/azure/network-watcher/next-hop-overview" target="_blank"&gt;https://learn.microsoft.com/bs-latn-ba/azure/network-watcher/next-hop-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/network-watcher/next-hop-overview" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/network-watcher/next-hop-overview&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.tufin.com/blog/demystifying-azure-route-table" target="_blank"&gt;https://www.tufin.com/blog/demystifying-azure-route-table&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;.12 hops all seem to have * beside them, whatever that means, most likely its DIRECTLY CONNECTED, as per below in the lab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@CP-STANDALONE:0]# route&lt;BR /&gt;Kernel IP routing table&lt;BR /&gt;Destination Gateway Genmask Flags Metric Ref Use Iface&lt;BR /&gt;default 172.16.10.1 0.0.0.0 UG 0 0 0 eth0&lt;BR /&gt;172.16.10.0 * 255.255.255.0 U 0 0 0 eth0&lt;BR /&gt;192.168.10.0 * 255.255.255.0 U 0 0 0 eth1&lt;BR /&gt;\[Expert@CP-STANDALONE:0]# clish&lt;BR /&gt;CLINFR0771 Config lock is owned by admin. Use the command 'lock database override' to acquire the lock.&lt;BR /&gt;CP-STANDALONE&amp;gt; show route&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;
&lt;P&gt;S 0.0.0.0/0 via 172.16.10.1, eth0, cost 0, age 92910&lt;BR /&gt;C 127.0.0.0/8 is directly connected, lo&lt;BR /&gt;C 172.16.10.0/24 is directly connected, eth0&lt;BR /&gt;external&lt;BR /&gt;C 192.168.10.0/24 is directly connected, eth1&lt;BR /&gt;internal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:19:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217631#M4852</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T18:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217632#M4853</link>
      <description>&lt;P&gt;thanks a lot !!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:30:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217632#M4853</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T18:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217633#M4854</link>
      <description>&lt;P&gt;No worries mate. Does that sort of makes sense?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217633#M4854</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T18:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217634#M4855</link>
      <description>&lt;P&gt;I am reading them now.&lt;BR /&gt;I just sent a message to my previous co-worker. He is an Azure expert working for MS.&lt;/P&gt;&lt;P&gt;thanks so much !!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217634#M4855</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T18:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: really like to know what the next-hop IP points to in Azure express route table for ASN 65515</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217635#M4856</link>
      <description>&lt;P&gt;Sounds good!&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 18:44:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/really-like-to-know-what-the-next-hop-IP-points-to-in-Azure/m-p/217635#M4856</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-15T18:44:15Z</dc:date>
    </item>
  </channel>
</rss>

