<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloud Space IP Rules in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129129#M23552</link>
    <description>&lt;P&gt;I'm newer to this. Our rule base has a source IP address and a desination IP address/DNS Name. We aren't given any groups of subnets really to use to create a AWS DC object. Don't recognize what GCP is referencing. Is that global Checkpoint Policy?&lt;/P&gt;&lt;P&gt;Sorry, still tryin to pick this up.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Sep 2021 17:52:00 GMT</pubDate>
    <dc:creator>seanmc12</dc:creator>
    <dc:date>2021-09-10T17:52:00Z</dc:date>
    <item>
      <title>Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129127#M23550</link>
      <description>&lt;P&gt;We are moving some of our resources to AWS cloud space. We've setup rules to allow traffic to/from and from/to internal resources/external resources. The issue we are now seeing is that in the cloud space, their source IP addresses constantly change. We have to go in, look at the logs, see what IPs have changed and update the rules. How are folks setting up rules for cloud sources so that they aren't constantly going in and updating their rule set.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 17:25:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129127#M23550</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2021-09-10T17:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129128#M23551</link>
      <description>&lt;P&gt;It really depends on how detailed your rules have to be. One option is to just use small subnets vor every usecase and build the rules based on that. Another option would be to use the AWS Datacenter Object so you could easily use tags etc. on the machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use both options currently (but GCP and not AWS) and for basic internet access we use the zone Objects so we don't even have to add new subnets to the rulebase.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 17:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129128#M23551</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-09-10T17:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129129#M23552</link>
      <description>&lt;P&gt;I'm newer to this. Our rule base has a source IP address and a desination IP address/DNS Name. We aren't given any groups of subnets really to use to create a AWS DC object. Don't recognize what GCP is referencing. Is that global Checkpoint Policy?&lt;/P&gt;&lt;P&gt;Sorry, still tryin to pick this up.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 17:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129129#M23552</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2021-09-10T17:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129133#M23555</link>
      <description>&lt;P&gt;This is what Cloud Management Extension (formerly CloudGuard Controller) is designed to solve.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157492&amp;amp;partition=Advanced&amp;amp;product=CloudGuard" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157492&amp;amp;partition=Advanced&amp;amp;product=CloudGuard&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can create objects based on their definition in AWS.&lt;BR /&gt;Your gateways (on premise and/or in the cloud) will be continually up-to-date with the relevant IP addresses.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 18:26:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129133#M23555</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T18:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129147#M23562</link>
      <description>&lt;P&gt;I was talking about the CloudGuard Controller:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CloudGuard_Controller_AdminGuide/Topics-CGRDG/Supported-Data-Centers.htm?tocpath=%20Supported%20Data%20Centers%7C_____0#CloudGuard_Controller_for_Amazon_Web_Services" target="_blank"&gt;Supported Data Centers (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can add your AWS credentials (permissions needed are in this document) to a Data Center Object and import resources based on vpc, subnets, tags etc. It looks like this for GCP (Google Cloud Platform):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="controller.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13665iF491B165D43EDB22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="controller.png" alt="controller.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You create this Data Center Objects and afterwards you can right-click on it and select "import". Select the resources you want. They are updated automatically.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 20:06:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129147#M23562</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-09-10T20:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129148#M23563</link>
      <description>&lt;P&gt;Was the CME also a part of CloudGuard Controller naming before? Because that is a different feature:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_CloudGuard_Controller_AdminGuide/Topics-CGRDG/Introduction-to-CloudGuard-Controller.htm?tocpath=Introduction%20to%20CloudGuard%20Controller%7C_____0#Introduction_to_CloudGuard_Controller" target="_blank"&gt;Introduction to CloudGuard Controller (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CME is for managing the Gateways etc. itself (from what I understand) and CloudGuard Controller is for using actual resources from the Cloud in the rulebase.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 20:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129148#M23563</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2021-09-10T20:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cloud Space IP Rules</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129155#M23566</link>
      <description>&lt;P&gt;I believe at one point they were the same, but you're right, they're different.&lt;BR /&gt;CloudGuard Controller is definitely what I was thinking of.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 21:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cloud-Space-IP-Rules/m-p/129155#M23566</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T21:12:01Z</dc:date>
    </item>
  </channel>
</rss>

