- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Cloudguard Network FW - egress NAT
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cloudguard Network FW - egress NAT
Hello,
Before I reach out to TAC for an official answer, maybe someone already knows the answer
Is this supported? Cloudguard Network Firewall used via Gateway Load Balancer in transit GW setup
Two-arm mode: As shown in figure 5b below, the firewall is deployed in two-arm mode and performs both inspection as well as NAT. Some AWS partners provide firewall with NAT functionality. GWLB integrates seamlessly in such deployment mode. You don’t need to do any additional configuration changes in the GWLB. However, the firewall networking differs – one network interface is on the private subnet and the other is on public subnet. This mode requires software support from the firewall partner. Some of the GWLB partners (Palo Alto Networks, Valtix) support this feature, however consult with an AWS partner of your choice before using this mode.
source:
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @abihsot__
Unfortunately NAT is not supported on Check Point Gateways behind Gateway Load balancer
You have to use NAT Gateway
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did not have a chance to try this myself, (use of public IPs on firewall interfaces in AWS), but it should work just fine, as this is basic functionality of CheckPoint gateways.
Last time I was working with CloudGuard in AWS, I was using NAT between private and public segments, but I had to associate AWS public EIP to the external interface, so there was one more NAT step being performed by AWS Internet Gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
From what I know this should work , although the GWLB in TGW template we usually use have NAT Gateways for outbound NAT do deal with all the routing .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I know, template deploys AWS NAT gateways automatically, however I was thinking if I already have checkpoint gateways, why not use them to NAT outgoing traffic. This might be interesting to try. Thank you for replies!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @abihsot__
Unfortunately NAT is not supported on Check Point Gateways behind Gateway Load balancer
You have to use NAT Gateway
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for confirmation. Any idea if this limitation could be changed in the future?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi abihsot__
In addition to Nir's reply
Architectures references can be found in the GWLB admin guide and sk: