Traffic Flows in CloudGuard Network for Azure VMSS
Inbound Traffic
Inbound traffic flow:
-
The request traffic arrives from the Internet to the Web Public IP of the External Load Balancer, on port 80.
-
The External Load Balancer translates the port 80 to 8081 and forwards the request traffic to a VMSS Gateway instance.
-
The VMSS Gateway instance:
-
Inspects the request traffic.
-
Performs Static NAT on the request traffic.
-
Forwards the request traffic to the Web Internal Load Balancer.
-
-
The Web Internal Load Balancer forwards the request traffic to the Web Server Host.
Inbound Traffic Reply
Inbound traffic reply:
-
The reply traffic arrives from the Web Server Host to the original VMSS Gateway instance.
-
The VMSS Gateway instance:
-
Inspects the reply traffic.
-
Forwards the reply traffic to the destination on the Internet.
-
Outbound Traffic
Outbound traffic flow:
-
The request traffic arrives from the Web Server Host at the Internal Load Balancer in the Check Point deployed solution.
- The Internal Load Balancer forwards the request traffic to a VMSS Gateway instance.
-
The VMSS Gateway instance:
-
Inspects the request traffic.
-
Performs Hide NAT on the request traffic.
-
Sends the request traffic to the Azure route that forwards the connection to the Internet.
-
Outbound Traffic Reply
Outbound traffic reply:
-
The reply traffic arrives from the Internet at the original VMSS Gateway instance.
-
The Check Point Security Gateway
Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. instance:-
Inspects the reply traffic.
-
Forwards the reply traffic to the Internal Web Server Host.
-
East-West Outbound Traffic
East-West outbound traffic flow:
-
The request traffic arrives from the Web Server Host at the Internal Load Balancer in the Check Point deployed solution.
-
The Internal Load Balancer forwards the request traffic to a VMSS Gateway instance.
-
The VMSS Gateway instance:
-
Inspects the request traffic.
-
Forwards the request traffic to the Application's Internal Load Balancer of the App Server Host.
-
-
The Application's Internal Load Balancer forwards the request traffic to the destination App Server Host.
East-West Outbound Traffic Reply
East-West outbound traffic reply:
-
The reply traffic arrives from the App Server Host at the Internal Load Balancer in the Check Point deployed solution.
-
The Internal Load Balancer forwards the reply traffic to the same VMSS Gateway instance that processed the request traffic from the Web Server Host to the App Server Host.
-
The Check Point Security Gateway instance:
-
Inspects the reply traffic.
-
Forwards the reply traffic Web Internal Load Balancer of the Web Server Host.
-
-
The Web Internal Load Balancer forwards the request traffic to the destination Web Server Host.
Intra-Subnet Traffic
Traffic travels freely in the subnet without inspection.