- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: R80.30 AWS - AutoScaleGW for Outbound traffic ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.30 AWS - AutoScaleGW for Outbound traffic from Internal Webservers
Dear CheckMates,
I have deployed R80.30 Mgmt server Cloudguard controller and R80.30 AutoScale Gateways in AWS.
Deployed External Network LB and Internal Application LB.
Placed internal Webserver behind Internal ALB - works fine.
(Inbound traffic from Internet to the Webserver thru LBs)
Now we need to make the outbound traffic from Internal webservers thru AutoScale GW to the internet so that we can inspect the outbound webserver traffic.
Is this feasible?. Per sk112575 - Point 5th:
"Web clients in private subnets are configured to use an ELB as their HTTP/HTTPS proxy.
This Proxy ELB is configured to forward TCP connections to the CloudGuard Auto Scaling group"
Per AWS team they could not make Internal ALB as proxy. Only Classic LB we can docreate ProxyProtocolPolicy.
Any comments to do will be helpful.
Regards, Prabulingam.N
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That does appear to be the case. The AWS docs only refer to Classic LB for enabling the Proxy Protocol.
Guessing Check Point just setup with Classic in there testing as not looking to use the extra features.
Now is it possible to create a second Internal LB that is Classic (presuming you are using some of the ALB features) and then use that as the Proxy per that SK.
As the clients configured with Proxy and the Check Point see's the traffic from the LB not the Client then wouldn't have thought to be an issue doing this, however don't work with AWS so there will be more experienced people with AWS that can confirm/deny that this is possible
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for input mdjmcnally...
Dear Cloud experts - Any suggestion for this requirement to achieve...
Regards, Prabu