<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: use CIDR in firewall rules from Cloud datacenter objects in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163257#M721</link>
    <description>&lt;P&gt;Note Private Endpoint support for Azure was added with R81.20.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_cloudguard_controller_adminguide/content/topics-cgrdg/what-is-new.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_cloudguard_controller_adminguide/content/topics-cgrdg/what-is-new.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 26 Nov 2022 22:50:09 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-11-26T22:50:09Z</dc:date>
    <item>
      <title>use CIDR in firewall rules from Cloud datacenter objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163091#M720</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured a datacenter object for Azure (R81.10 HF66 on MDS&amp;nbsp; + GWs).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The datacenter object is retrieving correctly the subscription.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking at "Network by Subscriptions, Virtual Networks, subnets", the CIDR for networks are shown in the "Note" field.&lt;/P&gt;&lt;P&gt;However it seems that when one of these objects is used in a rule, only the discovered IPs ("IP" field) are actually used to populate the firewall rule.&amp;nbsp;&lt;SPAN&gt;This is a problem because the discovery finds VMs but not other type of objects (e.g. private endpoints).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to use these objects as plain subnets and not as a list of discovered IPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2022 16:27:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163091#M720</guid>
      <dc:creator>reloadin5</dc:creator>
      <dc:date>2022-11-24T16:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: use CIDR in firewall rules from Cloud datacenter objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163257#M721</link>
      <description>&lt;P&gt;Note Private Endpoint support for Azure was added with R81.20.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_cloudguard_controller_adminguide/content/topics-cgrdg/what-is-new.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/r81.20/webadminguides/en/cp_r81.20_cloudguard_controller_adminguide/content/topics-cgrdg/what-is-new.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2022 22:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163257#M721</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-26T22:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: use CIDR in firewall rules from Cloud datacenter objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163452#M722</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;thanks for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reading &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176726&amp;amp;partition=Basic&amp;amp;product=CloudGuard" target="_self"&gt;here&amp;nbsp;&amp;nbsp;&lt;/A&gt;it looks like this should work on R81.10 HF66 (&lt;SPAN&gt;Azure R81.10 – minimum requirements: Jumbo hotfix Take 14)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have added "&lt;SPAN&gt;azure.enableAsgAndPep=true" in&amp;nbsp;$MDSDIR/conf/vsec.conf (both mdsenv global and on the domain that is running cme)&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;as described &lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-Controller-Support-New-Object-Types/td-p/131743" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Restarted both vsec and cme, however we still do not see the private endpoint object types.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Do you have any advice on how to debug this (to check if this is a permissions issue, maybe)?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And other than including private endpoint in the discovery, is there any way to just get the CIDR and use it in the firewall rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 07:53:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163452#M722</guid>
      <dc:creator>reloadin5</dc:creator>
      <dc:date>2022-11-29T07:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: use CIDR in firewall rules from Cloud datacenter objects</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163708#M723</link>
      <description>&lt;P&gt;If it's not working as expected please take it to TAC for investigation.&lt;/P&gt;
&lt;P&gt;If you need the CIDR manual objects can be created as a workaround.&lt;/P&gt;
&lt;P&gt;My assumption being we don't interpret things this way for security reasons so things aren't blindly allowed unexpectedly but I could be mistaken. Having the choice for different behaviour is likely an RFE to be discussed with your local SE.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 13:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/use-CIDR-in-firewall-rules-from-Cloud-datacenter-objects/m-p/163708#M723</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-30T13:16:00Z</dc:date>
    </item>
  </channel>
</rss>

