Solved: Cloudguard Implementation without a Public loadbal... - Check Point CheckMates

Cloudguard Implementation without a Public loadbalancer / public IP's

Hi all,

Where can i find information about a Cloud Guard Implementation without a public loadbalancer or without a loadbalancer without Public IP's.

Situation (See the screenshot)

-2x Check Point Applicance ClusterXL (On-Premise) with a connection to Azure by ExpressRoute

-1x Check Point Management (On-Premise)

-Microsoft Azure Environment with multiple VNET's.

The Azure environment is only accessible by the ExpressRoute connection.

I want to use the Check Point Cloud Guard between VNET's and the ExpressRoute within Azure without a Internet Connection or the use of Public IP's.

So traffic from On-Premise must go to the FrontEnd Loadbalancer -Check Point CloudGuard -> BackEnd Loadbalancers -> Different kind of azure virtual machines and vice versa.

When we create a CloudGuard Network Security environment within Azure, we choose not to use "Use Public IP Prefix", but it still does.

How can we achieve this, or is this even possible?

Labels

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

1 Solution

Accepted Solutions

Nir_Shamir

Employee

‎2022-03-0910:52 PM

Show option menu

Jump to solution

Hi,

I have done this several times. this is what you need to do:

  1. you can't use the Frontend LB because it only has Public IPs. you can even delete it if you don't need to use it.

  2. All your UDRs need to go to the Internal LB private IP and on the CloudGuard GWs make sure the default route in changed to the Azure Router on eth1 subnet.

This way all the traffic goes in and out from the same interface of the Check Point GWs (eth1) .

This way you have like a Firewall on a stick.

you can also detach the Public IPs from the CloudGuard GWs interface eth0 . the only thing you can't remove is the Public IP on the Cluster's VIP.

View solution in original post

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

2 Replies

Nir_Shamir

Employee

‎2022-03-0910:52 PM

Jump to solution

Hi,

I have done this several times. this is what you need to do:

  1. you can't use the Frontend LB because it only has Public IPs. you can even delete it if you don't need to use it.

  2. All your UDRs need to go to the Internal LB private IP and on the CloudGuard GWs make sure the default route in changed to the Azure Router on eth1 subnet.

This way all the traffic goes in and out from the same interface of the Check Point GWs (eth1) .

This way you have like a Firewall on a stick.

you can also detach the Public IPs from the CloudGuard GWs interface eth0 . the only thing you can't remove is the Public IP on the Cluster's VIP.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

RayP

Contributor

‎2022-03-1102:37 PM

In response to Nir_Shamir

Jump to solution

Thnx for the information Nir_Shamir, that helped us.👍

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

WiliRGasparetto
13

Jeff_Engel
1

jorgeluiznim
1

View All ≫

Trending Discussions

Part 1 How CloudGuard Controller R82.10 Builds Dynamic Security Context

Identity Distribution, TTL, Monitoring, and Operations in CloudGuard Controller R82.10

Known R82.10 Limitations That Affect Architecture The current R82.10 documentation lists limitati

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.