<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard deployment best practices in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217654#M4859</link>
    <description>&lt;P&gt;You got the answer.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sun, 16 Jun 2024 12:13:25 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-16T12:13:25Z</dc:date>
    <item>
      <title>Cloudguard deployment best practices</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217636#M4857</link>
      <description>&lt;P&gt;We are in the process of the deployment of cloudguard with Checkpoint assistance, also I am watching a few Checkpoint deployment videos. I noticed a few architecture options we moved from and to. As the change is hard after the deployment is done. I have the following questions:&lt;/P&gt;&lt;P&gt;1. cluster failover pros and cons:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; For our cloudguard deployment in AWS, our cluster failover is achieved via API updating the route table. When we came to Azure deployment, we had LB,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Does AWS have LB option too ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; LB is a must for Azure ? (Note: We do not need Northbound, only need Southbound to on-prem)&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Using Route Server or not&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Based on some difference for routing approaches between AWS and Azure, Route servers should be used or not ?&lt;/P&gt;&lt;P&gt;3. VNET for Cloudguard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cloudguard should be deployed in the same vnet with other network components or in its dedicated vnet.&lt;/P&gt;&lt;P&gt;Any suggested best practices for these options ?&lt;BR /&gt;&lt;BR /&gt;thanks a lot !!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 Jun 2024 22:11:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217636#M4857</guid>
      <dc:creator>Gongya_Yu</dc:creator>
      <dc:date>2024-06-15T22:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard deployment best practices</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217638#M4858</link>
      <description>&lt;P&gt;1. AWS doesn't have an LB option , everything works with API. we used to have the same in Azure until we moved to work with LBs. the API failover in AWS is pretty fast and usually you don't even notice it.&lt;/P&gt;
&lt;P&gt;2. Route-Servers are more dynamic the the regular UDRs . if you have a small static network then I would use UDRs. for large networks and VNETS + constant changes I would use Route Servers do ease the operation of changes.&lt;/P&gt;
&lt;P&gt;3. I always deploy the CloudGuard GWs in a separate compartment (VNET or VPC etc.) it's easier to manage it and it doesn't mixup with the rest of your networks.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2024 07:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217638#M4858</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-06-16T07:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard deployment best practices</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217654#M4859</link>
      <description>&lt;P&gt;You got the answer.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2024 12:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-deployment-best-practices/m-p/217654#M4859</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-16T12:13:25Z</dc:date>
    </item>
  </channel>
</rss>

