Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
avi3383
Participant

Need to enable Geo Fencing on CLoudguard IaaS with External ALB(Application Load Balancer)

Hi,

We have deployed Cloudguard IaaS security gateway on AWS cloud for inbound and Northbound traffic  with AWS External Application Load Balancer.

There are multiple application hosted in customer AWS account behind same Cloudguard IaaS gateway.

Now We have a requirement to apply Geo fencing restriction on all application and These should be only accessible from INDIA only.

I have created  a access policy with updateable object on firewall to achieve the same.

 

But in this case I am not seeing client real public IP in traffic  on firewall. ALB send the traffic to firewall with its own private IPs. So in this case traffic is not hitting that rule.

 

Kindly let me know how we can archive this.

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

This has been supported for a while using the XFF headers that the ALBs should be providing (or can be configured to provide).
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
However, this may only apply to the legacy Geo Filtering and not the mechanism with Updatable Objects.
@Micky_Michaeli do you happen to know for sure?

0 Kudos
avi3383
Participant

Thanks for your reply...you are correct we can achieve this by Geo Policy...but first achieve this I have to enable https inspection on same traffic to inspect by firewall/IPS.I need certificate to enable https inspection on firewall.

In my environment team is using Amazon public certificate on ALB and managing it through ACM(Amazon certificate Manager).Due to ACM limitation public certificate can't be export outside from ACM.

Due to this limitation I am not able to find the certificate and not able to import in checkpoint firewall and So https inspection not able to enable.

Kindly let me know how to enable https inspection on my checkpoint firewall in this scenario....and achieve Geo fencing restriction.

It will be very helpful your reply.

 

0 Kudos
_Val_
Admin
Admin

It looks like the most reasonable way would be to enable geo-fencing on the load balancer itself. 

0 Kudos
PhoneBoy
Admin
Admin

You'd actually need the private key in order to do inbound HTTPS Inspection.
Unless the ALB can provide a cleartext version of the traffic or the relevant private key, there's not much we can do on the Check Point side of things.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events