<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I add an AWS AutoScaling Firewall from a new AWS account to an SMS in a existing AWS Account in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241610#M5241</link>
    <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;I hope you are all well.&lt;/P&gt;&lt;P&gt;I am developing a lab on an AWS account where there is an SMS and AWS AutoScaling Group Security Gateways. Both in a CIDR VPC with 172.168.0.0/16 network.&lt;BR /&gt;Let's call it &lt;STRONG&gt;“SMS + AutoScaling A”.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Create another AWS AutoScaling Group Security Gateways on the same AWS account with another VPC CIDR 10.0.0.0.0/16&lt;BR /&gt;Let's call it &lt;STRONG&gt;“AutoScaling B”.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm a bit at a loss as to,&amp;nbsp; how I can add this new&amp;nbsp;&lt;STRONG&gt;“AutoScaling B”&lt;/STRONG&gt; to the current CME template for&amp;nbsp;&lt;STRONG&gt;“SMS + AutoScaling A”.&lt;/STRONG&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;=========================================================================================================&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;=========================================================================================================&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;According to the CME syntax, it shows the following options to add a new driver on top of the current template:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,us-east-1,eu-central-1 -fi &amp;lt;FILE-PATH&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,eu-central-1 -ak &amp;lt;ACCESS-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt; autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,eu-central-1 -ak &amp;lt;ACCESS-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1 -iam -sn &amp;lt;SUB-ACCOUNT-NAME&amp;gt; -sak &amp;lt;SUB-ACCOUNT-ACCESS-KEY&amp;gt; -ssk &amp;lt;SUB-ACCOUNT-SECRET-KEY&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Do I need to create an IAM user in the same AWS account and use these credentials in the controller configuration?&lt;BR /&gt;&lt;/STRONG&gt;First I want to know how to solve this: Add AutoScaling B to SMS from AutoScaling A&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I see something on this sk but I'm still a bit lost.&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk130372" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk130372&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;=========================================================================================================&lt;BR /&gt;=========================================================================================================&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As a second question on this topic:&lt;BR /&gt;-I am developing this lab now on a single AWS account.&lt;BR /&gt;-The purpose of this lab is to carry it out in a project with a customer, where customer has “SMS + AutoScaling A” in an existing AWS Account and is going to deploy “AutoScaling B” in another VPC of another new AWS Account different from the AWS Account of “SMS + AutoScaling A”.&lt;/P&gt;&lt;P&gt;In this scenario, how do I integrate “AutoScaling B” to the CME template controller of “SMS + AutoScaling A”?&lt;BR /&gt;Is this possible?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is a high level topology to explain our environment:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29682iB5B0C0B5E74C2CCF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2025 21:19:34 GMT</pubDate>
    <dc:creator>israelsc</dc:creator>
    <dc:date>2025-02-20T21:19:34Z</dc:date>
    <item>
      <title>How can I add an AWS AutoScaling Firewall from a new AWS account to an SMS in a existing AWS Account</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241610#M5241</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;I hope you are all well.&lt;/P&gt;&lt;P&gt;I am developing a lab on an AWS account where there is an SMS and AWS AutoScaling Group Security Gateways. Both in a CIDR VPC with 172.168.0.0/16 network.&lt;BR /&gt;Let's call it &lt;STRONG&gt;“SMS + AutoScaling A”.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Create another AWS AutoScaling Group Security Gateways on the same AWS account with another VPC CIDR 10.0.0.0.0/16&lt;BR /&gt;Let's call it &lt;STRONG&gt;“AutoScaling B”.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm a bit at a loss as to,&amp;nbsp; how I can add this new&amp;nbsp;&lt;STRONG&gt;“AutoScaling B”&lt;/STRONG&gt; to the current CME template for&amp;nbsp;&lt;STRONG&gt;“SMS + AutoScaling A”.&lt;/STRONG&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;=========================================================================================================&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;=========================================================================================================&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;According to the CME syntax, it shows the following options to add a new driver on top of the current template:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,us-east-1,eu-central-1 -fi &amp;lt;FILE-PATH&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,eu-central-1 -ak &amp;lt;ACCESS-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt; autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,eu-central-1 -ak &amp;lt;ACCESS-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1 -iam -sn &amp;lt;SUB-ACCOUNT-NAME&amp;gt; -sak &amp;lt;SUB-ACCOUNT-ACCESS-KEY&amp;gt; -ssk &amp;lt;SUB-ACCOUNT-SECRET-KEY&amp;gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Do I need to create an IAM user in the same AWS account and use these credentials in the controller configuration?&lt;BR /&gt;&lt;/STRONG&gt;First I want to know how to solve this: Add AutoScaling B to SMS from AutoScaling A&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I see something on this sk but I'm still a bit lost.&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk130372" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk130372&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;=========================================================================================================&lt;BR /&gt;=========================================================================================================&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As a second question on this topic:&lt;BR /&gt;-I am developing this lab now on a single AWS account.&lt;BR /&gt;-The purpose of this lab is to carry it out in a project with a customer, where customer has “SMS + AutoScaling A” in an existing AWS Account and is going to deploy “AutoScaling B” in another VPC of another new AWS Account different from the AWS Account of “SMS + AutoScaling A”.&lt;/P&gt;&lt;P&gt;In this scenario, how do I integrate “AutoScaling B” to the CME template controller of “SMS + AutoScaling A”?&lt;BR /&gt;Is this possible?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is a high level topology to explain our environment:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29682iB5B0C0B5E74C2CCF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 21:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241610#M5241</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2025-02-20T21:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I add an AWS AutoScaling Firewall from a new AWS account to an SMS in a existing AWS Acc</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241613#M5242</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;for the first question.&lt;/P&gt;
&lt;P&gt;You already created a Controller that has access to the account so you only need to add a new template:&lt;/P&gt;
&lt;P&gt;autoprov_cfg add template -tn &amp;lt;template_name&amp;gt; ......and the rest of the template variables.&lt;/P&gt;
&lt;P&gt;for the 2nd question.&lt;/P&gt;
&lt;P&gt;You need to create roles that has trust between the accounts so they can scan these accounts and create the GW's.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk122074" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk122074&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 05:40:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241613#M5242</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2025-02-19T05:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: How can I add an AWS AutoScaling Firewall from a new AWS account to an SMS in a existing AWS Acc</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241831#M5243</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;Following the sk &lt;A href="https://support.checkpoint.com/results/sk/sk122074" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk122074&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have a couple of doubts in the step “Configuration of AWS STS to Delegate Access across two AWS accounts”:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;-In step 2 it mentions “Provide the 12 digits number that represents the ID of the trusted account, in the Trusted Account ID field”.&lt;BR /&gt;*&lt;STRONG&gt;Is this account the AWS target account where the SMS is located?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;I mean, I have to create the STS role in the account where the new autoscaling is located and the Trusted Account ID is where the SMS is located?&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;-In step 3 it mentions “Select what type of permissions to grant the management server, in the IAM role field.”&lt;BR /&gt;*On the sk &lt;A href="https://support.checkpoint.com/results/sk/sk130372" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk130372&lt;/A&gt;, I see that in section “(3) Creating an AWS IAM User and IAM Role” in the step “Creating AWS IAM policies”, there is a JSON to certify permissions for “CloudGuard Network Auto Scaling and CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway”.&lt;BR /&gt;JSON contains the following permissions:&lt;/P&gt;&lt;P&gt;{&lt;BR /&gt;"Version": "2012-10-17",&lt;BR /&gt;"Statement": [&lt;BR /&gt;{&lt;BR /&gt;"Action": [&lt;BR /&gt;"autoscaling:DescribeAutoScalingGroups",&lt;BR /&gt;"ec2:DescribeInstances",&lt;BR /&gt;"ec2:DescribeNetworkInterfaces",&lt;BR /&gt;"ec2:DescribeSubnets",&lt;BR /&gt;"ec2:DescribeRegions",&lt;BR /&gt;"elasticloadbalancing:DescribeLoadBalancers",&lt;BR /&gt;"elasticloadbalancing:DescribeTags",&lt;BR /&gt;"elasticloadbalancing:DescribeListeners",&lt;BR /&gt;"elasticloadbalancing:DescribeTargetGroups",&lt;BR /&gt;"elasticloadbalancing:DescribeRules",&lt;BR /&gt;"elasticloadbalancing:DescribeTargetHealth"&lt;BR /&gt;],&lt;BR /&gt;"Resource": "*",&lt;BR /&gt;"Effect": "Allow"&lt;BR /&gt;}&lt;BR /&gt;]&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;These are the permissions I need to define in the STS role?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;======================================================================================================&lt;BR /&gt;======================================================================================================&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For the template &lt;A href="https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml" target="_blank" rel="noopener"&gt;https://cgi-cfts.s3.amazonaws.com/gwlb/cme-iam-role-gwlb.yaml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk122074" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk122074&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-We will run the CFT on the AWS account “B” where the new autoscaling is located, correct?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;-We will select the option “Create with read-write permissions” because our SMS will manage a CloudGuard Network for AWS Gateway Load Balancer Security VPC for Transit Gateway.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-I understand that in the “STS Roles” field we will paste the ARN Role value that we generated when we created the STS role, correct?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-In the “Trusted Account ID” field, this will be the AWS account “A” where the correct SMS is located?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;======================================================================================================&lt;BR /&gt;======================================================================================================&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Once we deploy the CFT Template with IAM Role, STS role and Trusted Account values defined, I see that in Check Point CME it is necessary to add a new driver to add the new autoscaling “B” to the SMS where autoscaling “A” is located.&lt;BR /&gt;The command mentions the following examples:&lt;/P&gt;&lt;P&gt;*autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,us-east-1,eu-central-1 -fi &amp;lt;FILE-PATH&amp;gt;&lt;BR /&gt;*autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1,eu-central-1 -ak &amp;lt;ACCESS-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt; -sk &amp;lt;SECRET-KEY&amp;gt;&lt;BR /&gt;*autoprov_cfg add controller AWS -cn &amp;lt;NAME&amp;gt; -r eu-west-1 -iam -sn &amp;lt;SUB-ACCOUNT-NAME&amp;gt; -sak &amp;lt;SUB-ACCOUNT-ACCESS-KEY&amp;gt; -ssk &amp;lt;SUB-ACCOUNT-SECRET-KEY&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;With this CFT Template, which option would we select?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Where we could obtain these values for complete CME configuration?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Below is a high level topology to explain our environment:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29681i1FF4188E60ED5AB3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" alt="Duda AWS AutoScaling ''B'' integration with SMS ''A''.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 21:18:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/241831#M5243</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2025-02-20T21:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I add an AWS AutoScaling Firewall from a new AWS account to an SMS in a existing AWS Acc</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/242093#M5244</link>
      <description>&lt;P&gt;Ok,&lt;/P&gt;
&lt;P&gt;1) create on your GW's account a new role that will trust the Management account. you can use this cloudformation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/iam/cme-iam-role.yaml&amp;amp;stackName=Check-Point-IAM-Role" target="_blank" rel="noopener"&gt;https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://cgi-cfts.s3.amazonaws.com/iam/cme-iam-role.yaml&amp;amp;stackName=Check-Point-IAM-Role&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Give this role permissions to scan for the GWLB GW's, like you have in your other account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) add the new sts role to your CME configuration. Example:&lt;/P&gt;
&lt;P&gt;ontrollers:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; tgw:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; class: AWS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; communities:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - "Transit_VPC"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cred-file: IAM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; regions:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - us-east-1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sub-creds:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;SpokeVPC1:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sts-role: "arn:aws:iam::581109049297:role/Check_Point_Transit_VPC"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) add the same role the your SMS role. example:&lt;/P&gt;
&lt;P&gt;{&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Action": [&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "sts:AssumeRole"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Resource": [&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "arn:aws:iam::581109049297:role/Check-Point-IAM-Role-IAMRole-1L8H5XDKP5VQS"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ],&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "Effect": "Allow"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; },&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 07:47:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/How-can-I-add-an-AWS-AutoScaling-Firewall-from-a-new-AWS-account/m-p/242093#M5244</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2025-02-24T07:47:55Z</dc:date>
    </item>
  </channel>
</rss>

