- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
We are currently deploying CGNS firewalls on AWS.
Architecture:
The Issue:
Should any exclusions be made in the "$FWDIR/lib/implied_rules.def file" to ensure CP management traffic is properly use the VPN tunnel instead of Implied rules.
Any guidance or suggestions to help resolve this would be greatly appreciated.
Thank you,
Chethan
I don't see why not, I've done this many times with many customers around the globe.
SIC traffic should not go via your VPN rules, ever. If your VPn tunnel is down, you would lose control. For that reason, it is covered by implied rules, and it is not recommended to change that.
Management traffic is encrypted, and there is no need to encrypt it again through your IPSec tunnels.
Thank you for the quick response, @_Val_
There is currently no alternative communication channel between the on-prem SMS and the cloud-deployed CGNS firewalls. AWS Direct Connect is also not yet in place.
Given that the management server traffic is already encrypted, would it be feasible to re-establish SIC using public IP addresses instead of private IP addresses?
Regards,
Chethan
I don't see why not, I've done this many times with many customers around the globe.
Thank you once again, I see — this is the solution.
Regards,
Chethan
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY