- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Gateway configuration on AWS instances
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gateway configuration on AWS instances
Hello, i created a simple lab with standalone Check Point r80.10 VM and a Linux (Ubuntu server) instance on AWS.
The internal interface and Linux server are in the same subnet (10.0.1.0/24). The IP address of gateway's internal interface is 10.0.1.202 and the Linux instance have IP 10.0.1.10. The AWS system configured 10.0.1.1 as Linux server gateway and for this reason NAT configuration performed by CP gateway doesnìt work (there isn't return traffic).
I configured a specific route for my current public IP address on Linux srv with 10.0.1.202 as gateway and in this case the maschine is reacheable from internet.
I need to change the default gateway of Linux server manually? This is the normal behaviour?
During the Check Point instance configuration i selected the option for distribuite the CP as gateway...
Thanks a lot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please see my article https://community.checkpoint.com/docs/DOC-2301-vsec-deployment-scenarios-in-aws .
I believe the first one addressing your requirements.
You have to have a route table associated with the internal subnet pointing to the gateway's internal IP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, thanks a lot, we will update you during the next days.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, we correcred the route table linked to internal subnet.
The internal server mantein the gw 10.0.1.1 but now the return traffic through CP is OK.
Thanks again