Create a Post
ChristianCastil
Employee
Employee

MUH with VMSS to protect AVD (VDI in Azure)

this post will show a use case for my past post about ID-Sharing.

Customer with VDI solution uses our MUH agent to identify users behind the same machine and apply rules based on their identity, this is great and uses the agent to communicate with a GW that stores the identity and ports used by a specific user, the issue is when we are in the Cloud and a VMSS, the agent can communicate only to one GW so VMSS environments are an issue, so we can use the ID Sharing mechanism to connect the MUH agent to one GW that only will serve as Collector and Share the learned Identities from this one to the VMSS members, this can be automated with a simple script that I shared in the past (past post).

Here a simple diagram from my demo.

id-sharing-demo.PNG

 

and a video showing all the stuffs

 

(1)
7 Replies
Shay_Levin
Admin
Admin

@ChristianCastil You bring great architecture and ideas here!
Wonderful

jmaresky
Employee
Employee

Awesome!

Martin_Valenta
Advisor

wouldn't it be better to have simple gateway deployed in same backend subnet as VMSS and use it ? instead of going back to on-prem via vpn/express route.

0 Kudos
ChristianCastil
Employee
Employee

meanwhile there is connectivity the place of the collector/sharing GW is not relevant, in this scenario I place on-prem to avoid the use of rented compute in the cloud, since will be static and no benefit from any cloud feature, also because normally the customer will have some on-prem devices, in case this is not true or they are allowed to pay for a collector machine in the cloud, they can place it.

Chris_Atkinson
Employee
Employee

Nice work, on a related note I know many have been waiting for the Identity Awareness APIs coming in R81.20.

https://community.checkpoint.com/t5/Product-Announcements/R81-20-EA-Program-Production/bc-p/135943#M... 

For MUH on Windows 10 please see sk177024

0 Kudos
Diego_Cambroner
Employee
Employee

Nice Document!!

0 Kudos
Norbert_Bohusch
Advisor

Nice!

Unfortunately the Word document is protected by Capsule Docs!

0 Kudos