Multi-Domain Management Server (MDS) NAT Configuration For Public Clouds
Multi-Domain Management Server (MDS) NAT Configuration For Public Clouds
Last Modified2023-11-30
Solution
This article explains how to configure Primary MDS, Secondary MDS, and MLM behind
Public/Elastic IP addresses in public cloud platforms (AWS, Azure, and GCP).
Background:
Public cloud providers do NAT when a Virtual Machine communicates with its Public/Elastic IP
address.
When MDS in a public cloud communicates with a Security Gateway with its Public/Elastic IP
address, it is required to configure static NAT configuration for each CMA/CLM object that is
behind a Public/Elastic IP address.
Example environment:
a. In the Gateway’s general properties, set a dummy IPv4 address (for example
1.2.3.4).
d. Click Action and create an interface in the subnet range for each relevant object
requiring NAT configuration.
1. Override.
Example:
Configure Active, Standby CMAs and CLMs in SmartConsole
Example:
1. Connect to the Security Gateway with SSH and enter Expert mode.
3. From the active CMA, install the policy on the Security Gateway.
Follow these instructions for each Security Gateway that must communicate with the
CMA/CLM with its public/elastic IP address.
Note: The configuration can be done automatically for Auto Scale Instances (Gateways)
managed by Cloud Management Extension (CME). You can do this by configuring a custom
gateway script that runs the command above on each provisioned Gateway. To Configure a
custom gateway script, refer to Cloud Management Extension Administration Guide > CME
Structure and Configurations > Configuration Templates (gateway-configurations) > Supported
Configuration Template parameters > General Parameters > CUSTOM_GATEWAY_SCRIPT.
4. Update the tables with the relevant Check Point Host objects.
6. Update the tables with the relevant Check Point Host objects.
7. Click OK.
Example:
Note: Logs configuration can be done automatically for Auto Scale Instances (Gateways)
managed by Cloud Management Extension (CME). To configure Log Server settings, refer
to Cloud Management Extension Administration Guide > CME Structure and Configurations >
Configuration Templates (gateway-configurations) > Log Server parameters