<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud pro in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70482#M11847</link>
    <description>&lt;P&gt;We have two VPN tunnels; one is a bidirectional between us and a Cloud Service and the other is a one way between us and a customer with the traffic originating on our side of the tunnel. We need to be able to, either create a bi-directional tunnel between us and our customer, or a second tunnel with the traffic originating on the customer's side which can communicate with the Cloud Service. The current one-way tunnel between us and our customer has our external IP address defined on the gateway, but our customer is requiring us to assign another public IP address for the Cloud Service's traffic before they will allow traffic from their side through our side, then out to cloud. I am at a loss as to how to make this happen. The Cloud Service does not provide public IPs to use. Does this make sense? If so, how would I accomplish this and be able to have the traffic route properly? I have included a simple diagram to help explain the flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VPN-Traffic-Public.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3752i95617D64D25DFA80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN-Traffic-Public.jpg" alt="VPN-Traffic-Public.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 14 Dec 2019 17:16:34 GMT</pubDate>
    <dc:creator>Karen_Foster</dc:creator>
    <dc:date>2019-12-14T17:16:34Z</dc:date>
    <item>
      <title>VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud pro</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70482#M11847</link>
      <description>&lt;P&gt;We have two VPN tunnels; one is a bidirectional between us and a Cloud Service and the other is a one way between us and a customer with the traffic originating on our side of the tunnel. We need to be able to, either create a bi-directional tunnel between us and our customer, or a second tunnel with the traffic originating on the customer's side which can communicate with the Cloud Service. The current one-way tunnel between us and our customer has our external IP address defined on the gateway, but our customer is requiring us to assign another public IP address for the Cloud Service's traffic before they will allow traffic from their side through our side, then out to cloud. I am at a loss as to how to make this happen. The Cloud Service does not provide public IPs to use. Does this make sense? If so, how would I accomplish this and be able to have the traffic route properly? I have included a simple diagram to help explain the flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="VPN-Traffic-Public.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3752i95617D64D25DFA80/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN-Traffic-Public.jpg" alt="VPN-Traffic-Public.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2019 17:16:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70482#M11847</guid>
      <dc:creator>Karen_Foster</dc:creator>
      <dc:date>2019-12-14T17:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70499#M11848</link>
      <description>Without knowing anything about the nature of this traffic that's supposed to go from your customer to this cloud service, it's hard to say if this will even work much less whether a truly public IP will be required.&lt;BR /&gt;&lt;BR /&gt;Assuming it's something simple like HTTPS, all that should be needed is an IP they're not using on their end.&lt;BR /&gt;They could even use the IP of the cloud service in question.&lt;BR /&gt;</description>
      <pubDate>Sun, 15 Dec 2019 04:43:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70499#M11848</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-15T04:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70567#M11849</link>
      <description>&lt;P&gt;PhoneBoy,&lt;/P&gt;&lt;P&gt;Assume https traffic.&lt;/P&gt;&lt;P&gt;1. The VPN connected to the cloud service is a Star topology with different encryption specifications than the tunnel with the client which is meshed, would I be able to add the client gateway and the cloud gateway to the same community? Because the tunnels are already established do I need to do anything further to route traffic from the client tunnel through our center gateway to the cloud tunnel assuming we can provide them with a public IP from the cloud provider? The VPN routing on the cloud tunnel is set to "To center or through the center to other .....".&lt;/P&gt;&lt;P&gt;2. If the cloud provider can not furnish a public IP (other than the one I have connected to the cloud tunnel), what are my other options?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for help&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 14:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70567#M11849</guid>
      <dc:creator>Karen_Foster</dc:creator>
      <dc:date>2019-12-16T14:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70592#M11850</link>
      <description>You could theoretically add the customer to your existing community, assuming they can set their encryption settings to match the existing community.&lt;BR /&gt;Whatever IP you're using to access the cloud service over the VPN from your end now could then be used by the customer.&lt;BR /&gt;That assumes no overlapping IPs being used and the appropriate rules are in place.&lt;BR /&gt;Otherwise, you'll need an IP that isn't being used on the customer side that can be NATted to the cloud service.</description>
      <pubDate>Mon, 16 Dec 2019 16:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70592#M11850</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-12-16T16:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with gateway as passthrough from cloud service to customer who requires public IP from cloud</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70611#M11851</link>
      <description>&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 21:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-with-gateway-as-passthrough-from-cloud-service-to-customer/m-p/70611#M11851</guid>
      <dc:creator>Karen_Foster</dc:creator>
      <dc:date>2019-12-16T21:30:24Z</dc:date>
    </item>
  </channel>
</rss>

