- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- CME configurating same rule name for all policy pu...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CME configurating same rule name for all policy push
Hi,
Would appreciate any help possible here. I recently deployed the following 81.20 setup (1 Management server + ASG (2 security GW)) on AWS cloud. The setup is utilizing CME and auto creating the access rules using checkpoint tags. The access rule that is generated follows the format "auto-generated by CME - allow traffic to auto scaling group." and it does that for all the rules even with different application ports. So, if there is an existing autogenerated rule for port 9990, the CME does not create new rule for 8900, but instead overrides the existing rule with the same name. I don't understand how to overcome this and create a separate rule name for each application/port.
CME tags in use are the:
1) on ASG, Security Gateway: management, template, ip-address
2) on load balancers: x-chkp-forwarding, x-chkp-management, x-chkp-template
Is there a modification required in the templates and where? Thanks in advance.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you mean that instead of adding the port 8900 to the same rule (that contains the port 9990) it overrides the 9990 port?
Can you share your internal load balancer listeners details (protocol:port), your external target groups details (protocol:port) and the value of the tag "x-chkp-forwarding"?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I usually do this in Azure, only once in AWS, but never had such a problem. Lets see if @nimrodgab can help.
Andy