Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the easy-accordion-free domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the zoho-flow domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wordpress-seo domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php on line 6114

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893

Warning: Cannot modify header information - headers already sent by (output started at /home/mother99/jacksonholdingcompany.com/wp-includes/functions.php:6114) in /home/mother99/jacksonholdingcompany.com/wp-includes/rest-api/class-wp-rest-server.php on line 1893
{"id":1463,"date":"2023-10-24T17:51:27","date_gmt":"2023-10-24T17:51:27","guid":{"rendered":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/"},"modified":"2023-10-24T17:51:27","modified_gmt":"2023-10-24T17:51:27","slug":"using-cloud-connectors-without-nat-gateway-joost-hage","status":"publish","type":"post","link":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/","title":{"rendered":"Using Cloud Connectors without NAT Gateway Joost Hage"},"content":{"rendered":"

Post Content\u00a0\u00a0<\/p>\n

\u200b<\/p>\n

Zscaler Cloud Connector is a VM-based solution built to forward traffic from cloud-based workloads to public and\/or private destinations using the Zscaler cloud. As such, it needs to be able to initiate traffic to Zscaler Service Edges, which requires public IP addresses (more detailed information on Cloud Connector communication can be found at https:\/\/help.zscaler.com\/cloud-branch-connector\/networking-flows-cloud-connector<\/a>).\u00a0<\/p>\n

In general, Zscaler recommends setting up Cloud Connector with a NAT Gateway as it solves a number of required functions:<\/p>\n

It assigns public IP addresses to all interfaces for outbound traffic
\n\tIt prevents unsolicited inbound connections (from the internet)
\n\tIt allows for the use of private IP space within the cloud, making for an easier local routing setup<\/p>\n

\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0Diagram: recommended Cloud Connector setup with NAT-GW<\/em><\/p>\n

However, NAT Gateways can introduce significant additional costs, especially when combined with high data throughput. At the same time, Cloud Connectors are designed to be exposed to the internet and only require outbound internet access, which makes them less of a target and, in turn, non-reliant on the NAT Gateway for security. Moreover, since Cloud Connectors act as the default forwarding function, this means that internal workloads don\u2019t need a NAT Gateway either.\u00a0<\/p>\n

This document describes a Cloud Connector setup that replaces the NAT Gateway functionality where it makes sense, while still maintaining the same security considerations.<\/p>\n

\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Diagram: alternative Cloud Connector setup without NAT-GW<\/em><\/p>\n

Note that the main article describes setup and considerations; a few configuration examples have been added at the bottom of this document.<\/p>\n

Setting up public IP addresses to the CC interfaces<\/strong><\/p>\n

The first thing to do is to assign public IP addresses to these interfaces. Note that (as the NAT Gateway already implied) this doesn\u2019t have to be a fixed address, as long as it\u2019s consistent during the Cloud Connector\u2019s uptime.\u00a0<\/p>\n

In Azure,<\/strong> you link public IP addresses to the Cloud Connector interfaces. First, ensure there is no NAT Gateway associated with the subnet (or remove it when there is). Then go into the Cloud Connector VM, select the Network Interface, select IP Configuration, and toggle the Public IP address settings to \u201cAssociate\u201d. Do this for all interfaces.<\/p>\n

In AWS,<\/strong> you need to place the Cloud Connector in a public subnet which will assign one public IP address to it, and assign Elastic IP addresses to all other interfaces.\u00a0<\/p>\n

When using Terraform, this can be achieved by first creating an aws_eip resource<\/em>, then associating it to the Cloud Connector interface-ids through aws_eip_association<\/em><\/p>\n

When using CloudFormation, you must assign a public subnet when creating the stack. This will automatically assign one Public IP address to the instance and, as such, to one of the Interfaces. Allocate an Elastic IP address and, once the Cloud Connector EC2 instance is created, associate it with another interface. Repeat until all Cloud Connector interfaces have a public IP association.\u00a0<\/p>\n

Note: By default, AWS only allows a limited number of E-IPs per Region. For additional addresses, the customer has to create a support ticket with AWS. <\/strong>See <\/em>https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/amazon-vpc-limits.html<\/em><\/a> for more details.<\/em><\/p>\n

Since requesting additional E-IPs can be a cumbersome process, and<\/em> since most of the cost for NAT-GW comes with the throughput used, it can be interesting to not have E-IPs assigned to all interfaces, but to the service interfaces only and still use NAT Gateway for the management interface:<\/p>\n

\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0<\/p>\n

\u00a0\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u00a0Diagram: alternative Cloud Connector setup with partial NAT-GW<\/em><\/p>\n

Protecting against Internet-sourced attacks<\/strong><\/p>\n

Setting up Cloud Connectors without a NAT Gateway requires that they\u2019re placed in a public subnet, which makes them addressable from the internet. The attack surface of a Cloud Connector is limited; it is hardened and only allows limited direct access. Still, the management interface allows inbound SSH access, which can<\/em> be a target for both compromise and denial-of-service and should be protected.<\/p>\n

More fundamentally, the CC service<\/em> interface must accept traffic coming from the internal Cloud workloads but should never accept unsolicited traffic from the internet. However, if an attacker can mimic\/spoof Workload traffic, CC will pick it up and process it as normal. This opens up attack vectors towards ZIA and ZPA resources, which need to be mitigated.\u00a0<\/p>\n

Fortunately, some attacks are unfeasible due to regular routing, and Azure and AWS have a few useful options that allow for a ruleset that doesn\u2019t need continuous updating after adding new workloads:<\/p>\n

Transparent access from the internet through Cloud Connectors to ZIA or ZPA resources will be prevented by regular Internet routing (the traffic will never end up at the CC in the first place)
\n\tAWS and Azure have anti-spoofing measures to block inbound traffic using cloud-local IP space
\n\tAzure has default labeling for local Cloud resources. This means you don\u2019t have to change the Security Groups each time you add a new subnet<\/p>\n

Unfortunately, although AWS and Azure do provide protection against spoofing (Cloud-) local addresses, it can\u2019t protect against spoofed internet address space. And, since the CC service interface must respond to DNS requests, it could be used as a target by itself and<\/em> as facilitator to (D)DoS public and private services. Incidentally, it could also lead to Zscaler counting these spoofed addresses towards the ZIA and ZPA Workload licenses. Combined, this leads to the following attacks and mitigation measures: <\/p>\n

\n

Attack (Internet Sourced)<\/strong><\/p>\n


\n\t\t\t <\/p>\n

Mitiga<\/strong>tion<\/strong><\/p>\n


\n\t\t\t <\/p>\n

Cust Risk<\/strong><\/p>\n


\n\t\t\t <\/p>\n

Mitigate<\/strong><\/p>\n


\n\t\t\t <\/p>\n

Attacking (to compromise or DoS) the Cloud Connector management interface using open listening services (SSH)<\/p>\n


\n\t\t\t <\/p>\n

Inbound Security Group on management interface<\/p>\n


\n\t\t\t <\/p>\n

Med<\/p>\n


\n\t\t\t <\/p>\n

Should<\/p>\n


\n\t\t\t <\/p>\n

DDoS ZPA resources through CC<\/p>\n


\n\t\t\t <\/p>\n

Inbound Security Group on service interface<\/p>\n


\n\t\t\t <\/p>\n

Med<\/p>\n


\n\t\t\t <\/p>\n

Must<\/p>\n


\n\t\t\t <\/p>\n

DDoS internet resources using CC DNS
\n\t\t\t(also incurring BW cost)<\/p>\n


\n\t\t\t <\/p>\n

Inbound Security Group on service interface<\/p>\n


\n\t\t\t <\/p>\n

High<\/p>\n


\n\t\t\t <\/p>\n

Must<\/p>\n

\n\t\t\t<\/p><\/div>\n

So, we need a number of Security Group rules to mitigate these risks by making sure that only local resources can use the CCs.\u00a0<\/p>\n

In Azure,<\/strong> this is straightforward. In fact: the Zscaler ARM and Terraform provisioning scripts create the correct Security Group rules by using Azure defined network TAGs. For the management interface only sources on \u201cVirtualNetwork\u201d should be allowed access to listening services, like SSH. Of course, if you have a specific subnet to manage workloads from (containing management systems and\/or jump hosts), then you should further limit SSH access to only those systems. Additionally, the management interface needs public outbound access towards DNS (UDP\/TCP 53), (D)TLS (UDP\/TCP 443) and NTP (UDP 123).\u00a0<\/p>\n

For the service interface, this means only sources on \u201cVirtualNetwork\u201d are allowed full TCP\/UDP access to ANY destination behind the Cloud Connector. Note that if<\/em> you have additional networks connected (through Direct Access, virtual WAN or VPN) that also want to use Cloud Connector to protect their traffic going out, you\u2019ll need to manually add policy rules for them as well.<\/p>\n

In AWS,<\/strong> this configuration is slightly less convenient; you\u2019ll have to define these ACLs using your local IP subnets manually. Again, the management interface should only allow inbound SSH from a management subnet or from specific bastion\/jump-hosts. The management also needs public outbound access towards DNS (UDP\/TCP 53),\u00a0 (D)TLS (UDP\/TCP 443) and NTP (UDP 123).<\/p>\n

For the service interface this means only your locally defined subnets (or IP ranges from other connected networks, if they want to use Cloud Connector to protect their traffic going out) should be allowed full TCP\/UDP access to ANY destination behind the Cloud Connector (including the Cloud Connector itself). Note that since AWS will protect against traffic with (spoofed) private (RFC1918) IP addresses, allowing inbound connections only from RFC1918 sources protects against all external connection attempts.<\/p>\n


\n\u00a0<\/p>\n

\u00a0\u00a0<\/p>","protected":false},"excerpt":{"rendered":"

Post Content\u00a0\u00a0 \u200b Zscaler Cloud Connector is a VM-based solution […]<\/p>\n","protected":false},"author":0,"featured_media":1464,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-1463","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zenith-zscaler"],"yoast_head":"\nUsing Cloud Connectors without NAT Gateway Joost Hage - JHC<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Using Cloud Connectors without NAT Gateway Joost Hage\" \/>\n<meta property=\"og:description\" content=\"Post Content\u00a0\u00a0 \u200b Zscaler Cloud Connector is a VM-based solution […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\" \/>\n<meta property=\"og:site_name\" content=\"JHC\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-24T17:51:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\"},\"author\":{\"name\":\"\",\"@id\":\"\"},\"headline\":\"Using Cloud Connectors without NAT Gateway Joost Hage\",\"datePublished\":\"2023-10-24T17:51:27+00:00\",\"dateModified\":\"2023-10-24T17:51:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\"},\"wordCount\":1274,\"publisher\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg\",\"articleSection\":[\"Zenith: Zscaler\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\",\"url\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\",\"name\":\"Using Cloud Connectors without NAT Gateway Joost Hage - JHC\",\"isPartOf\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg\",\"datePublished\":\"2023-10-24T17:51:27+00:00\",\"dateModified\":\"2023-10-24T17:51:27+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage\",\"url\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg\",\"contentUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg\",\"width\":1200,\"height\":628},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/jacksonholdingcompany.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Using Cloud Connectors without NAT Gateway Joost Hage\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#website\",\"url\":\"https:\/\/jacksonholdingcompany.com\/\",\"name\":\"JHC\",\"description\":\"Your Business Is Our Business\",\"publisher\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/jacksonholdingcompany.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#organization\",\"name\":\"JHC\",\"url\":\"https:\/\/jacksonholdingcompany.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png\",\"contentUrl\":\"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png\",\"width\":452,\"height\":149,\"caption\":\"JHC\"},\"image\":{\"@id\":\"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Using Cloud Connectors without NAT Gateway Joost Hage - JHC","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/","og_locale":"en_US","og_type":"article","og_title":"Using Cloud Connectors without NAT Gateway Joost Hage","og_description":"Post Content\u00a0\u00a0 \u200b Zscaler Cloud Connector is a VM-based solution […]","og_url":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/","og_site_name":"JHC","article_published_time":"2023-10-24T17:51:27+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#article","isPartOf":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/"},"author":{"name":"","@id":""},"headline":"Using Cloud Connectors without NAT Gateway Joost Hage","datePublished":"2023-10-24T17:51:27+00:00","dateModified":"2023-10-24T17:51:27+00:00","mainEntityOfPage":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/"},"wordCount":1274,"publisher":{"@id":"https:\/\/jacksonholdingcompany.com\/#organization"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage"},"thumbnailUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg","articleSection":["Zenith: Zscaler"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/","url":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/","name":"Using Cloud Connectors without NAT Gateway Joost Hage - JHC","isPartOf":{"@id":"https:\/\/jacksonholdingcompany.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage"},"thumbnailUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg","datePublished":"2023-10-24T17:51:27+00:00","dateModified":"2023-10-24T17:51:27+00:00","breadcrumb":{"@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#primaryimage","url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg","contentUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/10\/zscaler-logo-og-3NvvRz.jpeg","width":1200,"height":628},{"@type":"BreadcrumbList","@id":"https:\/\/jacksonholdingcompany.com\/using-cloud-connectors-without-nat-gateway-joost-hage\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/jacksonholdingcompany.com\/"},{"@type":"ListItem","position":2,"name":"Using Cloud Connectors without NAT Gateway Joost Hage"}]},{"@type":"WebSite","@id":"https:\/\/jacksonholdingcompany.com\/#website","url":"https:\/\/jacksonholdingcompany.com\/","name":"JHC","description":"Your Business Is Our Business","publisher":{"@id":"https:\/\/jacksonholdingcompany.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/jacksonholdingcompany.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/jacksonholdingcompany.com\/#organization","name":"JHC","url":"https:\/\/jacksonholdingcompany.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/","url":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png","contentUrl":"https:\/\/jacksonholdingcompany.com\/wp-content\/uploads\/2023\/07\/cropped-cropped-jHC-white-500-\u00d7-200-px-1-1.png","width":452,"height":149,"caption":"JHC"},"image":{"@id":"https:\/\/jacksonholdingcompany.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts\/1463","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/comments?post=1463"}],"version-history":[{"count":0,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/posts\/1463\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/media\/1464"}],"wp:attachment":[{"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/media?parent=1463"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/categories?post=1463"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jacksonholdingcompany.com\/wp-json\/wp\/v2\/tags?post=1463"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}