- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Checkpoint firewall in SPAN mode in Google clo...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint firewall in SPAN mode in Google cloud
We were testing R80.40 CP Firewall in SPAN mode in Google cloud. But it is not working. It seems to be not working if we assign an IP address to the SPAN interface but that is what’s required in GCP for getting mirror traffic from the load balancer.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AFAIK there is a product that can do it : https://community.checkpoint.com/t5/SandBlast-Now/bd-p/sandblast-now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the update.
We actually trying to use the Mirroring feature of Google Cloud Platform (GCP) to get the data from load balancer to CP firewall. It requires the IP address needs to be assigned to SPAN interface for the load balancer to send the data. But when we assign the IP, CP firewall dropping all the packets which are coming to SPAN interface saying 'missing OS route'
Can you suggest which CP product we have to choose in GCP Marketing place for this to work?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A firewall is a layer 3 device and as such is not applicable to a traffic mirroring scenario. Traffic mirroring is typically used for IDS or NDR solutions. As Ofir indicated above, CloudGuard Now (the cloud variant of SandBlast Now) is such a product, and can indeed interoperate with GCP traffic mirroring. However, CloudGuard Now for GCP is not in General Availability yet, so if you're interested in trying it out, please contact me offline. See the SandBlast Now product brief for more details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the info. I will send you an email for further details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please provide me with your email id?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I’ll make sure @Nir_Naaman has your email and contacts you.