We are in the process of the deployment of cloudguard with Checkpoint assistance, also I am watching a few Checkpoint deployment videos. I noticed a few architecture options we moved from and to. As the change is hard after the deployment is done. I have the following questions:
1. cluster failover pros and cons:
For our cloudguard deployment in AWS, our cluster failover is achieved via API updating the route table. When we came to Azure deployment, we had LB,
Does AWS have LB option too ?
LB is a must for Azure ? (Note: We do not need Northbound, only need Southbound to on-prem)
2. Using Route Server or not
Based on some difference for routing approaches between AWS and Azure, Route servers should be used or not ?
3. VNET for Cloudguard
Cloudguard should be deployed in the same vnet with other network components or in its dedicated vnet.
Any suggested best practices for these options ?
thanks a lot !!