Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
NetAdminFTW
Contributor

Something just don’t click for me regarding CloudGuard and AWS gateway load balancer

Hey guys,

I am in the process of deploying CloudGuard for the first time (and Check Point in general), and even after going through the various admin guides, there is something that I just don’t understand. 

I am required to use transit gateway and gateway load balancer for the solution. The transit gateway and gateway load balancer are already made.
I have spoke VPCs and security VPC, every VPC has 2 AZs, and they are all attached to the transit gateway.
I have deployed a gateway load balancer with 2 GLBEs, each in AZ.

All north south traffic is going through a Site to Site VPN that is attached to the transit gateway for an an on prem network, and I’m not allowed to use NAT / Internet Gateway at all.

I manually deployed 2 CloudGuard ec2 instances each in its own AZ, and I’m supposed to add them to on prem security management server.

my question is this (sorry if this is a newb question)- are they supposed to be joined as a cluster? Or 2 standalone machines? 
And if I add them as a cluster, I don’t use elastic IP, so what I type in as the “Cluster IP”? 

Thanks!

 

(1)
Who rated this post