I have a Checkpoint Geo-Cluster in Active-Active Mode in AWS.. i need to setup outbound NAT for a webserver..WAN IP/Elastic IP of that server will be whitelisted at the remote site.
The issue here is i dont want to use NAT (hide behind Gateway) for outbound communication as in that case i have to share external ip of my GW.. i created a secondary IP in AWS for this Gateway and mapped an elastic ip with it..is there any way i can make Checkpoint take the secondary elastic IP while using hide behind Gateway NAT ? hide behind IP wont work here as its an Active-Active Cluster where one member handles traffic at a time..if i use hide behind ip ..outbound communication will fail if traffic switches to secondary device.
Pls advice..