<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help with AWS routing tables for CloudGuard with AWS GWLB, Transit Gateway in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Help-with-AWS-routing-tables-for-CloudGuard-with-AWS-GWLB/m-p/167356#M583</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to configure an environment per&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Content/Topics-AWS-GWLB-VPC-TGW-DG/Deploying-a-GWLB-Security-VPC-for-Transit-Gateway.htm?tocpath=Deploying%20a%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Step_3__Deploy_the_Check_Point_Security_Management_Server_(SMS)" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Content/Topics-AWS-GWLB-VPC-TGW-DG/Deploying-a-GWLB-Security-VPC-for-Transit-Gateway.htm?tocpath=Deploying%20a%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Step_3__Deploy_the_Check_Point_Security_Management_Server_(SMS)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Transit&amp;nbsp; Gateway&lt;/P&gt;&lt;P&gt;2. Scale set and GWLB&lt;/P&gt;&lt;P&gt;3. 1 spoke VPC&lt;/P&gt;&lt;P&gt;4. Trying to set up an internet-facing load balancer in the spoke VPC pointing to a workload in the spoke VPC, such that the traffic is inspected by Cloud Guard, ie the optional step in the guide "Configure Inbound traffic to spoke VPCs"&lt;/P&gt;&lt;P&gt;The guide referred to above has a diagram for all the required routes in all routing tables to achieve this. I believe I have followed this (double-checked all). I have set up separate route tables for&amp;nbsp; all spoke VPC subnets.&lt;/P&gt;&lt;P&gt;The external load balancer/workload setup works correctly when I set the default route of the spoke load balancer subnet to the IGW, however obviously the traffic bypasses CheckPoint.&lt;/P&gt;&lt;P&gt;When I set the default route of the spoke load balancer subnet to the GWLBe which is how the guide says it should be, I can see the traffic enter the workload instance, but the traffic does not seem to be being passed to the security VPC.&lt;/P&gt;&lt;P&gt;My question:&lt;/P&gt;&lt;P&gt;Can you point me to any resources (videos, documents) that cover this use case and the routing in a bit more detail for this CloudGuard set up? It may be that I am interpreting the document incorrectly or missing a vital piece of information.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2023 21:48:13 GMT</pubDate>
    <dc:creator>AK2</dc:creator>
    <dc:date>2023-01-10T21:48:13Z</dc:date>
    <item>
      <title>Help with AWS routing tables for CloudGuard with AWS GWLB, Transit Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Help-with-AWS-routing-tables-for-CloudGuard-with-AWS-GWLB/m-p/167356#M583</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to configure an environment per&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Content/Topics-AWS-GWLB-VPC-TGW-DG/Deploying-a-GWLB-Security-VPC-for-Transit-Gateway.htm?tocpath=Deploying%20a%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Step_3__Deploy_the_Check_Point_Security_Management_Server_(SMS)" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_Security_VPC_for_Transit_Gateway/Content/Topics-AWS-GWLB-VPC-TGW-DG/Deploying-a-GWLB-Security-VPC-for-Transit-Gateway.htm?tocpath=Deploying%20a%20GWLB%20Security%20VPC%20for%20Transit%20Gateway%7C_____0#Step_3__Deploy_the_Check_Point_Security_Management_Server_(SMS)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Transit&amp;nbsp; Gateway&lt;/P&gt;&lt;P&gt;2. Scale set and GWLB&lt;/P&gt;&lt;P&gt;3. 1 spoke VPC&lt;/P&gt;&lt;P&gt;4. Trying to set up an internet-facing load balancer in the spoke VPC pointing to a workload in the spoke VPC, such that the traffic is inspected by Cloud Guard, ie the optional step in the guide "Configure Inbound traffic to spoke VPCs"&lt;/P&gt;&lt;P&gt;The guide referred to above has a diagram for all the required routes in all routing tables to achieve this. I believe I have followed this (double-checked all). I have set up separate route tables for&amp;nbsp; all spoke VPC subnets.&lt;/P&gt;&lt;P&gt;The external load balancer/workload setup works correctly when I set the default route of the spoke load balancer subnet to the IGW, however obviously the traffic bypasses CheckPoint.&lt;/P&gt;&lt;P&gt;When I set the default route of the spoke load balancer subnet to the GWLBe which is how the guide says it should be, I can see the traffic enter the workload instance, but the traffic does not seem to be being passed to the security VPC.&lt;/P&gt;&lt;P&gt;My question:&lt;/P&gt;&lt;P&gt;Can you point me to any resources (videos, documents) that cover this use case and the routing in a bit more detail for this CloudGuard set up? It may be that I am interpreting the document incorrectly or missing a vital piece of information.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 21:48:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Help-with-AWS-routing-tables-for-CloudGuard-with-AWS-GWLB/m-p/167356#M583</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-01-10T21:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Help with AWS routing tables for CloudGuard with AWS GWLB, Transit Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Help-with-AWS-routing-tables-for-CloudGuard-with-AWS-GWLB/m-p/167358#M584</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry to reply to my own post however it seems I have made some progress following the AWS documentation here&amp;nbsp;&lt;A href="https://protect-eu.mimecast.com/s/tgowC1j0PTOjwWEnhLUNkL?domain=docs.aws.amazon.com" target="_blank"&gt;https://docs.aws.amazon.com/elasticloadbalancing/latest/gateway/getting-started.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 22:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Help-with-AWS-routing-tables-for-CloudGuard-with-AWS-GWLB/m-p/167358#M584</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-01-10T22:59:46Z</dc:date>
    </item>
  </channel>
</rss>

