<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/235384#M5105</link>
    <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;After several revisions directly with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87765"&gt;@NoaD&lt;/a&gt;&amp;nbsp; and @almogar&amp;nbsp;we managed to deploy the environment with a SMS and AWS ASG Gateway LB Security Gateways with R80.40.&lt;BR /&gt;The solution, another CFT was shared with me and with that we were able to launch the stack successfully.&lt;/P&gt;&lt;P&gt;I share here the CFT I launched.&lt;BR /&gt;Please use for lab purposes only, R80.40 is already an unsupported version by Check Point.&lt;/P&gt;&lt;P&gt;Greetings to all!&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2024 18:35:35 GMT</pubDate>
    <dc:creator>israelsc</dc:creator>
    <dc:date>2024-12-11T18:35:35Z</dc:date>
    <item>
      <title>CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for ASG SG</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231700#M5019</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I am developing a lab to create Security Gateways with the AWS CFT for CloudGuard ASG Security Gateways AWS Gateway LB and Transit GW with a Mananagement Server.&lt;BR /&gt;I am choosing R80.40-BYOL for my ASG Security Gateways and R81.10-BYOL for the Management Server.&lt;/P&gt;&lt;P&gt;The goal is to create the environment with my Management Server and ASG Gateways to upgrade them both to R81.20.&lt;BR /&gt;This will then become a production activity with a customer.&lt;/P&gt;&lt;P&gt;I am using an AWS CFT yaml that I see from the workshop:&lt;BR /&gt;&amp;nbsp;&lt;A href="https://checkpoint.awsworkshop.io/" target="_blank"&gt;Check Point CloudGuard Network Security - Integration with AWS Gateway Load Balancer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;YAML template is:&lt;BR /&gt;&lt;A href="https://gwlb.s3.us-east-2.amazonaws.com/CGNS-GWLB-WS.yaml" target="_blank"&gt;https://gwlb.s3.us-east-2.amazonaws.com/CGNS-GWLB-WS.yaml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The problem is, when I launch the stack with those values I mentioned (80.40-BYOL for my ASG Security Gateways and R81.10-BYOL for the Management Server.)&amp;nbsp;the stack fails and the resources deletes due to a rollback action for CFT.&lt;BR /&gt;The error mentions something related to the stack failing due to a missing AMI resource:&lt;/P&gt;&lt;P&gt;In the AWS account subscriptions, I have Check Point products for Security Gateway and Management Server:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aws subscriptions.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28331i805D0DECF406D1F8/image-size/large?v=v2&amp;amp;px=999" role="button" title="aws subscriptions.png" alt="aws subscriptions.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is it possible that my deployment is failing because R80.40 is no longer available in the AMI repositories for these VMs for Security Gateways?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I know that R80.40 is out of support, I guess that is why it is failing but I would like to know if someone could give me some idea to investigate further.&lt;/P&gt;&lt;P&gt;Greetings to all!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 06:18:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231700#M5019</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2024-11-05T06:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231702#M5020</link>
      <description>&lt;P&gt;Hi Israelsc,&lt;/P&gt;
&lt;P&gt;To my knowledge all our modern templates won't let you deploy R80.40 as it was removed from our templates.&lt;/P&gt;
&lt;P&gt;I would also like to point out you are trying to deploy an ASG using a GWLB (Gateway load balancer) template, so that won't help you with the replication either.&lt;/P&gt;
&lt;P&gt;The only path I can think of trying to execute such an environment is by going to EC2 &amp;gt; AMI&amp;nbsp; in the AWS portal and searching for "R80.40" in the search bar under "public images" which will find you R80.40 images. However this will not deploy a ASG automatically and you will have to play around to make it work. (Unfortunately this is a bit outside of the scope to provide further steps)&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 07:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231702#M5020</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2024-11-05T07:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231705#M5021</link>
      <description>&lt;P&gt;Hi Israelsc,&lt;/P&gt;
&lt;P&gt;Your assumptions are correct, the deployment fails because R80.40 is no longer supported.&lt;/P&gt;
&lt;P&gt;You can search for R80.40 AMI under "public images", and then insert the AMI ID in the dedicated field in the CFT ("ImageId"). That way the CFT won't search for the AMI dynamically, but will have it hard-coded.&lt;/P&gt;
&lt;P&gt;Let me know if you need help with the CFT modification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Noam Cohen&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 07:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/231705#M5021</guid>
      <dc:creator>noamcoh</dc:creator>
      <dc:date>2024-11-05T07:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232669#M5048</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75740"&gt;@noamcoh&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your comments.&lt;BR /&gt;It makes a lot of sense to me what you comment, maybe “harcoding” the AMI ID of R80.40 in the CFT can solve the problem when trying to launch the template.&lt;/P&gt;&lt;P&gt;I review in the AWS Marketplace and I see this information for the AMI:&lt;/P&gt;&lt;P&gt;Ami Id: ami-03a6e51a7f4357779&lt;BR /&gt;Ami Alias: /aws/service/marketplace/prod-sip6fjeetm76y/r80.40-294.1564&lt;BR /&gt;Product Code: 263gtcd87e2xefwbacsdwvorx&lt;/P&gt;&lt;P&gt;I don't see the “ImageId” parameter in the CFT&lt;BR /&gt;Sorry for the inconvenience, could you help me with the modification of the CFT or guide me how to do it?&lt;/P&gt;&lt;P&gt;This is the base CFT: &lt;A href="https://gwlb.s3.us-east-2.amazonaws.com/CGNS-GWLB-WS.yaml" target="_blank"&gt;https://gwlb.s3.us-east-2.amazonaws.com/CGNS-GWLB-WS.yaml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This was extracted from the workshop:&amp;nbsp;&lt;A href="https://checkpoint.awsworkshop.io/" target="_blank" rel="nofollow noopener noreferrer"&gt;Check Point CloudGuard Network Security - Integration with AWS Gateway Load Balancer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you could share with me some email or some way to contact you, that would be great!&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 23:38:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232669#M5048</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2024-11-13T23:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232680#M5049</link>
      <description>&lt;P&gt;Hi Israelsc,&lt;/P&gt;
&lt;P&gt;I sent you a private message with email to contact us.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Noam&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 07:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232680#M5049</guid>
      <dc:creator>noamcoh</dc:creator>
      <dc:date>2024-11-14T07:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232791#M5051</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75740"&gt;@noamcoh&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you very much I replied to your private message and I have sent you an email.&lt;BR /&gt;I hope you could please help me, I would appreciate it very much.&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 20:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/232791#M5051</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2024-11-14T20:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard ASG AWS Gateway LB Transit GW - AWS CFT Error when launching stack with R80.40 for AS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/235384#M5105</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;After several revisions directly with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87765"&gt;@NoaD&lt;/a&gt;&amp;nbsp; and @almogar&amp;nbsp;we managed to deploy the environment with a SMS and AWS ASG Gateway LB Security Gateways with R80.40.&lt;BR /&gt;The solution, another CFT was shared with me and with that we were able to launch the stack successfully.&lt;/P&gt;&lt;P&gt;I share here the CFT I launched.&lt;BR /&gt;Please use for lab purposes only, R80.40 is already an unsupported version by Check Point.&lt;/P&gt;&lt;P&gt;Greetings to all!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2024 18:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-ASG-AWS-Gateway-LB-Transit-GW-AWS-CFT-Error-when/m-p/235384#M5105</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2024-12-11T18:35:35Z</dc:date>
    </item>
  </channel>
</rss>

