<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inbound Inspection in Cloud NGFW for AWS Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/inbound-inspection/m-p/560047#M422</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question regarding inbound inspection in centralised model using Palo Alto Cloud NGFW, which was described here.&lt;/P&gt;
&lt;P&gt;I'm focusing on the&amp;nbsp;&lt;I&gt;&lt;SPAN&gt;Figure 11: Cloud NGFW is deployed to protect inbound traffic to a VPC (Single AZ).&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this architecture, the&amp;nbsp;&lt;STRONG&gt;Application Load Balancer&lt;/STRONG&gt; was deployed in central Security Account. My assumption is that you can bind multiple domains to the same ALB and route traffic to different internal web-server (i.e. example.com, example2.com), based on the host-header feature provided by the ALB. So far so good.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what if I want to provide inspection to services that are not working on HTTP/HTTPs protocols, i.e SFTP, FTP, SSH (and many others)? My first thought was to deploy another subnet in the central Security Account with Network Load Balancer. NLB works on layer 3/4, so it's not understanding host headers. Solution for that would be to create listeners on different ports and bind them to appropriate target groups, i.e:&lt;/P&gt;
&lt;P&gt;- 222 NLB -&amp;gt; 22 (internal sftp-server-1)&lt;/P&gt;
&lt;P&gt;- 223 NLB -&amp;gt; 22 (internal sftp-server-2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this viable solution or is there any other way to handle multiple services via the same central NLB?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Sep 2023 14:32:34 GMT</pubDate>
    <dc:creator>wilm25</dc:creator>
    <dc:date>2023-09-29T14:32:34Z</dc:date>
    <item>
      <title>Inbound Inspection</title>
      <link>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/inbound-inspection/m-p/560047#M422</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question regarding inbound inspection in centralised model using Palo Alto Cloud NGFW, which was described here.&lt;/P&gt;
&lt;P&gt;I'm focusing on the&amp;nbsp;&lt;I&gt;&lt;SPAN&gt;Figure 11: Cloud NGFW is deployed to protect inbound traffic to a VPC (Single AZ).&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this architecture, the&amp;nbsp;&lt;STRONG&gt;Application Load Balancer&lt;/STRONG&gt; was deployed in central Security Account. My assumption is that you can bind multiple domains to the same ALB and route traffic to different internal web-server (i.e. example.com, example2.com), based on the host-header feature provided by the ALB. So far so good.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But what if I want to provide inspection to services that are not working on HTTP/HTTPs protocols, i.e SFTP, FTP, SSH (and many others)? My first thought was to deploy another subnet in the central Security Account with Network Load Balancer. NLB works on layer 3/4, so it's not understanding host headers. Solution for that would be to create listeners on different ports and bind them to appropriate target groups, i.e:&lt;/P&gt;
&lt;P&gt;- 222 NLB -&amp;gt; 22 (internal sftp-server-1)&lt;/P&gt;
&lt;P&gt;- 223 NLB -&amp;gt; 22 (internal sftp-server-2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this viable solution or is there any other way to handle multiple services via the same central NLB?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 14:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cloud-ngfw-for-aws-discussions/inbound-inspection/m-p/560047#M422</guid>
      <dc:creator>wilm25</dc:creator>
      <dc:date>2023-09-29T14:32:34Z</dc:date>
    </item>
  </channel>
</rss>

