<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure Scale Set - CloudGuard - Is source NAT necessary? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157483#M776</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10255"&gt;@Dmitry_Gorn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you very much for the helpful information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if I have understood everything correctly:&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;You have shared information about two different deployments Plans.&lt;UL&gt;&lt;LI&gt;Public Preview CloudGuard Gateway Load Balancer&lt;UL&gt;&lt;LI&gt;This Plan only requires one subnet (FrontEnd subnet)&lt;/LI&gt;&lt;LI&gt;This Plan does not require SNAT for external traffic. We have to chain a Public LB or Standar IP of our applications to our GWLB deployed in this Plan.&lt;/LI&gt;&lt;LI&gt;This deployment only works for North/South traffic.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;CloudGuard Scale Set&amp;nbsp;&lt;UL&gt;&lt;LI&gt;This Plan requires two subnets (FrontEnd and BackEnd subnets)&lt;/LI&gt;&lt;LI&gt;This Plan DOES NOT require SNAT for East/West traffic, because the Azure Internal LB is aware of the replay traffic, and sends the replays to the right Gateway to avoid asymmetric routing issues.&lt;/LI&gt;&lt;LI&gt;This Plan DOES requiere SNAT for North/South traffic. It is not especifically pointed in the document, but jugding for the Traffic Flows section, it is likely that SNAT is required for sure.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, the thing is that we would like to find a solution able to inspect both, N/S and E/W traffic, without using SNAT for any of these traffic flows. Assuming that it is not possible for E/W Traffic to point to the GWLB and it just works if you link a Public LB or Standard IP to it, in order to be able to inspect N/S and E/W traffic flows, we would need to different deployments Plans, right? Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Sep 2022 10:41:26 GMT</pubDate>
    <dc:creator>Gusa2727</dc:creator>
    <dc:date>2022-09-18T10:41:26Z</dc:date>
    <item>
      <title>Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157295#M770</link>
      <description>&lt;P&gt;Hi, we are thinking on deploying a multiple Gateways in a Scale Set solution in Azure. How is assymetric routing avoided with this solution? I know that some time ago, we had to use source NAT, but we would not like to apply this solution for our network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the other hand, as far I know, in Azure we have not something similar to AWS Gateway Load Balancer which uses geneve to ensure that the replay goes using the same firewall instance.&lt;/P&gt;&lt;P&gt;Fortinet has the FGSP protocol which syncs sessions within all firewall instances in the cluster, so it is not a problem if the traffic goes through one intance, and the replay goes through a different one. Is there something similar for Check Point? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 11:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157295#M770</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2022-09-15T11:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157298#M771</link>
      <description>&lt;P&gt;Why do you think this is a General Topic ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 11:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157298#M771</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-15T11:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157309#M772</link>
      <description>&lt;P&gt;Azure GWLB via VXLAN:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_Azure_VMSS_GWLB/Content/Topics-Azure-VMSS-GWLB/Introduction-to-VMSS.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_Azure_VMSS_GWLB/Content/Topics-Azure-VMSS-GWLB/Introduction-to-VMSS.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 12:51:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157309#M772</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-15T12:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157323#M774</link>
      <description>&lt;P&gt;Thanks, I missed that Azure has released a GWLB similar to AWS GWLB.&lt;/P&gt;&lt;P&gt;After checking the below video, it looks like it is still a preview solution, and it does not work for inspecting the east-west traffic, right? In case we want to inspect east-west traffic through Gateways in a scale set, and without having to deploy an External LB, is there a way to achieve this keeping aside from using source nat?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=gN74syBIJio" target="_blank" rel="noopener"&gt;https://www.youtube.com/watch?v=gN74syBIJio&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 13:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157323#M774</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2022-09-15T13:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157470#M775</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Sure. You can deploy a VMSS solution without an External Load Balancer and only use it for East West traffic inspection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Load Balancer combination can be selected as part of the deployment template.&lt;/P&gt;
&lt;P&gt;For East-West traffic, as long as the request and reply go via the Internal Load Balancer (as documented) you will not have to S-NAT the traffic.&lt;/P&gt;
&lt;P&gt;Refer to the "East West" and "East West Reply" sections in the traffic flows page:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Content/Topics-Azure-VMSS/Traffic-Flows.htm?tocpath=Traffic%20Flows%7C_____0#Traffic_Flows" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Content/Topics-Azure-VMSS/Traffic-Flows.htm?tocpath=Traffic%20Flows%7C_____0#Traffic_Flows&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dmitry&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 06:11:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157470#M775</guid>
      <dc:creator>Dmitry_Gorn</dc:creator>
      <dc:date>2022-09-18T06:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157483#M776</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10255"&gt;@Dmitry_Gorn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you very much for the helpful information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if I have understood everything correctly:&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;You have shared information about two different deployments Plans.&lt;UL&gt;&lt;LI&gt;Public Preview CloudGuard Gateway Load Balancer&lt;UL&gt;&lt;LI&gt;This Plan only requires one subnet (FrontEnd subnet)&lt;/LI&gt;&lt;LI&gt;This Plan does not require SNAT for external traffic. We have to chain a Public LB or Standar IP of our applications to our GWLB deployed in this Plan.&lt;/LI&gt;&lt;LI&gt;This deployment only works for North/South traffic.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;CloudGuard Scale Set&amp;nbsp;&lt;UL&gt;&lt;LI&gt;This Plan requires two subnets (FrontEnd and BackEnd subnets)&lt;/LI&gt;&lt;LI&gt;This Plan DOES NOT require SNAT for East/West traffic, because the Azure Internal LB is aware of the replay traffic, and sends the replays to the right Gateway to avoid asymmetric routing issues.&lt;/LI&gt;&lt;LI&gt;This Plan DOES requiere SNAT for North/South traffic. It is not especifically pointed in the document, but jugding for the Traffic Flows section, it is likely that SNAT is required for sure.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, the thing is that we would like to find a solution able to inspect both, N/S and E/W traffic, without using SNAT for any of these traffic flows. Assuming that it is not possible for E/W Traffic to point to the GWLB and it just works if you link a Public LB or Standard IP to it, in order to be able to inspect N/S and E/W traffic flows, we would need to different deployments Plans, right? Thanks!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 10:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157483#M776</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2022-09-18T10:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157499#M777</link>
      <description>&lt;P&gt;You are correct. The SNAT for N-S traffic is mentioned in the traffic flow "animated GIFs". Perhaps we can make it more clear in the admin guide - will put it on the list.&lt;/P&gt;
&lt;P&gt;You are also correct that you will need two separate deployments - one with GWLB and one regular VMSS. A regular VMSS cannot work with GWLB (GWLB required VXLAN tunnels and in general operates differently).&lt;/P&gt;
&lt;P&gt;One more option to consider is to use XFF header feature on the VMSS for N-S traffic. Traffic will still be NATed but you will have XFF headers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dmitry&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 06:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157499#M777</guid>
      <dc:creator>Dmitry_Gorn</dc:creator>
      <dc:date>2022-09-19T06:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Scale Set - CloudGuard - Is source NAT necessary?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157506#M778</link>
      <description>&lt;P&gt;Thank you very much!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 10:52:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Scale-Set-CloudGuard-Is-source-NAT-necessary/m-p/157506#M778</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2022-09-19T10:52:06Z</dc:date>
    </item>
  </channel>
</rss>

