Hey guys,
I am in the process of deploying CloudGuard for the first time (and Check Point in general), and even after going through the various admin guides, there is something that I just don’t understand.
I am required to use transit gateway and gateway load balancer for the solution. The transit gateway and gateway load balancer are already made.
I have spoke VPCs and security VPC, every VPC has 2 AZs, and they are all attached to the transit gateway.
I have deployed a gateway load balancer with 2 GLBEs, each in AZ.
All north south traffic is going through a Site to Site VPN that is attached to the transit gateway for an an on prem network, and I’m not allowed to use NAT / Internet Gateway at all.
I manually deployed 2 CloudGuard ec2 instances each in its own AZ, and I’m supposed to add them to on prem security management server.
my question is this (sorry if this is a newb question)- are they supposed to be joined as a cluster? Or 2 standalone machines?
And if I add them as a cluster, I don’t use elastic IP, so what I type in as the “Cluster IP”?
Thanks!