<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/123136#M17653</link>
    <description>&lt;P&gt;You'd actually need the private key in order to do inbound HTTPS Inspection.&lt;BR /&gt;Unless the ALB can provide a cleartext version of the traffic or the relevant private key, there's not much we can do on the Check Point side of things.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jul 2021 00:02:01 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-07-07T00:02:01Z</dc:date>
    <item>
      <title>Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122245#M17487</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have deployed Cloudguard IaaS security gateway on AWS cloud for inbound and Northbound traffic&amp;nbsp; with AWS External Application Load Balancer.&lt;/P&gt;&lt;P&gt;There are multiple application hosted in customer AWS account behind same Cloudguard IaaS gateway.&lt;/P&gt;&lt;P&gt;Now We have a requirement to apply Geo fencing restriction on all application and These should be only accessible from INDIA only.&lt;/P&gt;&lt;P&gt;I have created&amp;nbsp; a access policy with updateable object on firewall to achieve the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in this case I am not seeing client real public IP in traffic&amp;nbsp; on firewall. ALB send the traffic to firewall with its own private IPs. So in this case traffic is not hitting that rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly let me know how we can archive this.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 05:06:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122245#M17487</guid>
      <dc:creator>avi3383</dc:creator>
      <dc:date>2021-06-26T05:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122265#M17499</link>
      <description>&lt;P&gt;This has been supported for a while using the XFF headers that the ALBs should be providing (or can be configured to provide).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115532&amp;amp;partition=Advanced&amp;amp;product=CloudGuard" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115532&amp;amp;partition=Advanced&amp;amp;product=CloudGuard&lt;/A&gt;&lt;BR /&gt;However, this may only apply to the legacy Geo Filtering and not the mechanism with Updatable Objects.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/22913"&gt;@Micky_Michaeli&lt;/a&gt;&amp;nbsp;do you happen to know for sure?&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 16:14:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122265#M17499</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-26T16:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122980#M17609</link>
      <description>&lt;P&gt;Thanks for your reply...you are correct we can achieve this by Geo Policy...but first achieve this I have to enable https inspection on same traffic to inspect by firewall/IPS.I need certificate to enable https inspection on firewall.&lt;/P&gt;&lt;P&gt;In my environment team is using Amazon public certificate on ALB and managing it through ACM(Amazon certificate Manager).Due to ACM limitation public certificate can't be export outside from ACM.&lt;/P&gt;&lt;P&gt;Due to this limitation I am not able to find the certificate and not able to import in checkpoint firewall and So https inspection not able to enable.&lt;/P&gt;&lt;P&gt;Kindly let me know how to enable https inspection on my checkpoint firewall in this scenario....and achieve Geo fencing restriction.&lt;/P&gt;&lt;P&gt;It will be very helpful your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122980#M17609</guid>
      <dc:creator>avi3383</dc:creator>
      <dc:date>2021-07-05T13:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122991#M17610</link>
      <description>&lt;P&gt;It looks like the most reasonable way would be to enable geo-fencing on the load balancer itself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 14:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/122991#M17610</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-05T14:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/123136#M17653</link>
      <description>&lt;P&gt;You'd actually need the private key in order to do inbound HTTPS Inspection.&lt;BR /&gt;Unless the ALB can provide a cleartext version of the traffic or the relevant private key, there's not much we can do on the Check Point side of things.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 00:02:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Need-to-enable-Geo-Fencing-on-CLoudguard-IaaS-with-External-ALB/m-p/123136#M17653</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-07T00:02:01Z</dc:date>
    </item>
  </channel>
</rss>

