<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloud Guard Azure Appliances &amp;amp; Express Route Guidance in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156031#M958</link>
    <description>&lt;P&gt;Hi all.&amp;nbsp; I am helping a customer on their journey migrating to Microsoft Azure.&amp;nbsp; They currently are using (2) Cloud Guard Network Security appliances in Azure in a HA pair with a S2S VPN configuration connecting to on-premise Checkpoint NGFW 6400s.&amp;nbsp; &amp;nbsp;We're starting the process to identifying a ExpressRoute service provider, and will eventually be looking to go through the process of configuring the Azure ExpressRoute from their on-premise data center to Azure using the Check Point devices.&amp;nbsp; I'm reaching out to see if there was any guidance or knowledge base to properly set this up with these devices.&amp;nbsp; I did some searching and wasn't able to find anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance, input, or help would be greatly appreciated.&amp;nbsp; Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 31 Aug 2022 00:55:29 GMT</pubDate>
    <dc:creator>mr87</dc:creator>
    <dc:date>2022-08-31T00:55:29Z</dc:date>
    <item>
      <title>Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156031#M958</link>
      <description>&lt;P&gt;Hi all.&amp;nbsp; I am helping a customer on their journey migrating to Microsoft Azure.&amp;nbsp; They currently are using (2) Cloud Guard Network Security appliances in Azure in a HA pair with a S2S VPN configuration connecting to on-premise Checkpoint NGFW 6400s.&amp;nbsp; &amp;nbsp;We're starting the process to identifying a ExpressRoute service provider, and will eventually be looking to go through the process of configuring the Azure ExpressRoute from their on-premise data center to Azure using the Check Point devices.&amp;nbsp; I'm reaching out to see if there was any guidance or knowledge base to properly set this up with these devices.&amp;nbsp; I did some searching and wasn't able to find anything.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance, input, or help would be greatly appreciated.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 00:55:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156031#M958</guid>
      <dc:creator>mr87</dc:creator>
      <dc:date>2022-08-31T00:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156133#M959</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;There is no official guide for this but with ExpressRoute you will connect the customer's Azure environment via ExpressRoute directly do his On-Premise Gateways on a new interface and then you can use Static-routes or BGP , which is the preferred way, to route the networks between them . the Azure Cluster is not needed in this configuration and you will just need to route the traffic coming from On-Premise to the Cluster using Azure UDRs.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 05:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156133#M959</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-09-01T05:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156179#M960</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;.&amp;nbsp; Thanks for your reply.&amp;nbsp; This makes sense.&amp;nbsp; They currently have a S2S VPN tunnel between on-premise and Azure.&amp;nbsp; They are terminating their VPN directly on the Check Point appliances in Azure and are not using the Azure VPN Gateway to connect.&amp;nbsp; As you stated, they will need to send all traffic from the on-premise Check Point firewalls to an ExpressRoute Virtual Network Gateway, and then route that traffic from the GatewaySubnet to the Check Point virtual appliances in Azure using UDRs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see any issues with the S2S VPN and ExpressRoute co-existing in this configuration?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156179#M960</guid>
      <dc:creator>mr87</dc:creator>
      <dc:date>2022-09-01T11:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156190#M961</link>
      <description>&lt;P&gt;If the VPN is Domain-Based then it will take precedence over the Routing. you will need to remove the VPN configuration on both sides before moving to the ExpressRoute.&lt;/P&gt;
&lt;P&gt;If it's route-based (VTI)&amp;nbsp; then we can play with the routing.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156190#M961</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-09-01T11:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156191#M962</link>
      <description>&lt;P&gt;Thanks Nir!&amp;nbsp; I'm not familiar with the Check Points.&amp;nbsp; Is there a straight forward way to see if the VPN is Domain or VTI based?&amp;nbsp; I was looking at this article -&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Domain-Based-VPN.htm?tocpath=Domain%20Based%20VPN%7C_____0#Domain_Based_VPN" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Domain-Based-VPN.htm?tocpath=Domain%20Based%20VPN%7C_____0#Domain_Based_VPN&lt;/A&gt;&amp;nbsp;but wasn't sure if there is a sure fire way to know or not.&amp;nbsp; I'll have to ask the customer to check.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 11:51:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156191#M962</guid>
      <dc:creator>mr87</dc:creator>
      <dc:date>2022-09-01T11:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156196#M963</link>
      <description>&lt;P&gt;if it's route-based you will have under the networking topology of the GW/Cluster object in SmartConsole interfaces with names like vpntX.&lt;/P&gt;
&lt;P&gt;also , if you have access to the GAIA WEBUI you will see under the interfaces , interfaces names like vpntX.&lt;/P&gt;
&lt;P&gt;If you don't see them them it's Domain-Based.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 12:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156196#M963</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-09-01T12:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Guard Azure Appliances &amp; Express Route Guidance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156197#M964</link>
      <description>&lt;P&gt;Thanks Nir!&amp;nbsp; &amp;nbsp;Appreciate the quick responses.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2022 12:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloud-Guard-Azure-Appliances-amp-Express-Route-Guidance/m-p/156197#M964</guid>
      <dc:creator>mr87</dc:creator>
      <dc:date>2022-09-01T12:20:07Z</dc:date>
    </item>
  </channel>
</rss>

