- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Question for VPN Limitations of CloudGuard Net...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Question for VPN Limitations of CloudGuard Network for Azure VMSS
I saw in the Limitations of CloudGuard Network for Azure VMSS
-
Site to Site VPN is not supported.
We want to use a site2site tunnel from on Premise gateway to a "CloudGuard Network for Azure VMSS" gateway. That's really not possible nor supported ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe that it is true and the documentation is accurate.
The problem is that the Azure External Load Balancer (service) takes in the traffic and distributes it to the SG/s behind the LB.
Problem #2: There is no synchronisation between the SGs since they are not a cluster and only enforce same policy for the traffic that is steered towards them (which is then sticky (as far as possible (scale in events change things..) - there's other threads on that)).
By design there is no S2S VPN support.
Still worth asking though because the cloud is so dynamic and you never know what they've got in the pipeline, or in another solution.
I think this one might need to go direct to the presales team if there is a customer demand/use case.
In the newer version of the CloudGuard Blueprints they always show the VMSS in the backend at the end of the Express Route.
They used to show a cluster there so that we could assume a IPSec VPN but that changed.
Can the solution use a CloudGuard Cluster?
https://www.checkpoint.com/downloads/products/cloudguard-architecture-blueprint-diagrams.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Wolfgang,
Its 100% true. RA and VPN were supported on vmss till 2022, but not after.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe that it is true and the documentation is accurate.
The problem is that the Azure External Load Balancer (service) takes in the traffic and distributes it to the SG/s behind the LB.
Problem #2: There is no synchronisation between the SGs since they are not a cluster and only enforce same policy for the traffic that is steered towards them (which is then sticky (as far as possible (scale in events change things..) - there's other threads on that)).
By design there is no S2S VPN support.
Still worth asking though because the cloud is so dynamic and you never know what they've got in the pipeline, or in another solution.
I think this one might need to go direct to the presales team if there is a customer demand/use case.
In the newer version of the CloudGuard Blueprints they always show the VMSS in the backend at the end of the Express Route.
They used to show a cluster there so that we could assume a IPSec VPN but that changed.
Can the solution use a CloudGuard Cluster?
https://www.checkpoint.com/downloads/products/cloudguard-architecture-blueprint-diagrams.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Wolfgang,
Its 100% true. RA and VPN were supported on vmss till 2022, but not after.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I guess vWAN is not in scope?
https://www.checkpoint.com/cloudguard/microsoft-azure-security/wan/#
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Seems like it.
Andy


