> Source: [sk182260](https://support.checkpoint.com/results/sk/sk182260)

# sk182260 - How to add a Harmony SASE Gateway to an allow-list

| Property | Value |
|----------|-------|
| Solution ID | sk182260 |
| Date Created | 2024-05-02 |
| Last Modified | 2024-06-05 |
| Technical Level | General |
| Products | SASE |
| Versions | Cloud |

## Solution

You can add Harmony SASE Gateway IP address to an allow-list in applications, such as Microsoft Azure, Salesforce, and so on to allow access to corporate resources from these applications in devices configured with this Harmony SASE Gateway's IP address.  

This article describes the procedure to add a Harmony SASE Gateway to an allow-list in:  

* **Microsoft Azure**
* **Salesforce**
* **Amazon Web Service**
* **Google Cloud Platform**

### Microsoft Azure {#Microsoft Azure}

1. Log in to the Azure Management portal.
2. Select the resource that you want to restrict access to.
3. Go to **Settings** \> **Networking**.
4. In the **Inbound Port Rules** section, click **Add inbound port** .  
   The **Add inbound security rule** window appears.
5. From the **Source** list, select **Any**.
6. In the **Source IP address/CIDR ranges** field, enter the Harmony SASE gateway IP address.
7. In the **Source port ranges** field, enter the port number or range on which you want to deny the access to your server.
8. From the **Destination** list, select **Any**
9. In the **Destination** **port** **ranges** field, enter the port range. For example, 8988-8999
10. From the **Protocol** list, select **Any**.
11. From the **Action** list, select **Allow**.
12. In the **Priority** field, leave the default value.
13. In the **Name** field, enter a name for the inbound security rule.
14. In the **Description** filed, enter a description.
15. Click **Add Rule**.

### Salesforce {#Salesforce}

1. Log in to Salesforce.
2. Click **Setup**.
3. In the quick search box, search and select **Network Access**
4. Click **New** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/salesforce202405080933391.png)
5. In the **Start IP Address** field, enter the Harmony SASE Private Server start IP address.
6. In the **End IP Address** field, enter the Harmony SASE Private Server end IP address.
7. In the **Description** field, enter a description.
8. Click **Save**.

### Amazon Web Service {#Amazon Web Service}

### Creating a Security Group

1. Log in to the AWS Management portal.
2. Navigate to **EC2 dashboard**.
3. Go to **Network \& Security** \> **Security Groups** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/SecurityGroups202405080934142.png)
4. Click **Create** .  
   The **Create Security Group** page appears.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/Createsecuritygrouppage202405080934473.png)
5. In the **Security group name** field, enter a security group name.
6. In the **Description** field, enter the use case of the group.
7. From the **VPC** list, select the appropriate VPC.   
   If you use VPC peering, you can update the rules for your VPC security groups to reference security groups in the peered VPC.   
   If you use a Transit Gateway, spoke Amazon VPCs cannot reference security groups in other spokes connected to the same AWS Transit Gateway.
8. In the **Inbound rules** section, click **Add rule** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/InboundrulesSection202405080935224.png)
9. Configure these:
   1. From the **Type** list, select **All traffic**.
   2. In the **Protocol** field, enter **All**.
   3. In the **Port** **range** field, enter **All**.
   4. In the **Source** list, select **Custom**.
   5. Search for the Harmony SASE Gateway IP address and select it.
   6. In the **Description** field, enter a description.
10. Click **Create security group**.

### Attaching AWS Resources to Security Group

1. Log in to the AWS Management portal.
2. Navigate to **EC2 dashboard**.
3. Go to **Instances** \> **Instances** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/Instances202405080936025.png)
4. Select the instance to which you want to apply the security group.
5. Click **Actions** and go to **Networking** \> **Change Security Groups** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/ChangeSecurityGroups202405080936276.png)
6. Select the newly created security group.
7. Click **Assign security group** .  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/AssignsecurityGroup202405080936527.png)

### Google Cloud Platform {#Google Could Platform}

### Finding your gateway IP address {#Finding your gateway IP address}

1. Access the Harmony SASE Administrator portal.
2. Click **Networks**.
3. Click the network that contains the gateway which you want to add to an allow-list.
4. From the **Gateways** tile, copy the gateway IP address.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/SaveGatewayIP2024050809374710.png)

### Configuring a rule in Google Cloud Platform firewall

1. Log in to Google Cloud Platform.
2. Go to **VPC network** \> **Firewall** **rules**.
3. Click **Create Firewall Rule** .  
   The **Create a firewall rule** page appears.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/CreateaFirewallRulePage2024050809382311.png)
4. In the **Name** field, enter a name for the rule.
5. In the **Description** field, enter a description.
6. From the **Logs** list, select the applicable option:
   * **On** - Generates firewall logs.
   * **Off** - Do not generate firewall logs.
7. From the **Networks** list, select a network that contains resources that you want to add to an allow-list.
8. In the **Priority** field, leave the default value.  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182260/CreateaFirewallRulePage22024050809390612.png)
9. From the **Direction of traffic** list, select the applicable option:
   * **Ingress -**Incoming network traffic.
   * **Egress -** Outgoing network traffic.
10. From the Action on match list, select the applicable option:
    * **Allow**
    * **Deny**
11. From the **Targets** list, select your target.  
    For example, you can either select all instances in the network or specific target tags.
12. From the**Source filter** list, select**IP ranges**.
13. In the **Source IP ranges** field, paste the gateway IP address you copied in Step 3 in***Finding your gateway IP address*** and add the **/32** subnet mask.  
    For example: `37.142.11.100/32`
14. From the **Second source filter** list, select **None**.
15. From the **Protocols and ports** list, select **Allow all**.
16. Click **Create**.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
