<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CloudGuard VMSS instance and logging question? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143879#M1128</link>
    <description>&lt;P&gt;Of course, the suboptimal thing is that I have to change the masters for each VMSS instance. &lt;BR /&gt;Furthermore, I have to change the GuiDBEdit entries for each VMSS instance.&lt;/P&gt;
&lt;P&gt;This is a problem with autoscaling!&lt;/P&gt;
&lt;P&gt;Is there a better approach here for a on premise management server connection?&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2022 10:49:30 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2022-03-16T10:49:30Z</dc:date>
    <item>
      <title>CloudGuard VMSS instance and logging (on premise SMS)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143807#M1121</link>
      <description>&lt;P&gt;I have a question about logging for CloudGuard VMSS instances and logging. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My management server is on a on premise network and all check point ports are forwarded via static NAT from the internet gateway to the SMS. Unfortunately, I do not receive any log information from the Cloudguard VMSS instance on port 257. There is no traffic on the VMSS gateway or on the on premise internet gateway visible.&lt;/P&gt;
&lt;P&gt;tcpdump -i eth0 -nn port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; does not display any packet&lt;/P&gt;
&lt;P&gt;I had also tried to implement the following sk102712:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102712&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_self"&gt;$FWDIR/conf/masters file on Security Gateway is overwritten during each policy installation - procedure to preserve manual changes &lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Therefore my question:&lt;/P&gt;
&lt;P&gt;Does CloudGuard VMSS instances also use port 257?&lt;BR /&gt;Or Azure CME mechanissmen are used here to upload loggging informations?&lt;/P&gt;
&lt;P&gt;Design:&lt;BR /&gt;&lt;BR /&gt;[Azure VMSS instance] &amp;nbsp;&amp;nbsp; --&amp;gt; &amp;nbsp;&amp;nbsp; [Internet]&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; &amp;nbsp;&amp;nbsp; [on premise FW gateway with static NAT rule]&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt;&amp;nbsp;&amp;nbsp; [SMS]&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143807#M1121</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-22T14:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143841#M1122</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;All Check Point Gateways use port 257 for logging , this of course includes CloudGuard Gateways.&lt;/P&gt;
&lt;P&gt;which Log Server is configured in the GWs ? is it configured with its public IP or its private IP ?&lt;/P&gt;
&lt;P&gt;You should see traffic with port 257 on the GWs , no matter what is configured.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 05:55:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143841#M1122</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-03-16T05:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143845#M1123</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Is it configured with a public IP. &lt;BR /&gt;Here I do not have the option of specifying a management IP if I roll this out via marketplace. &lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip.jpg" style="width: 608px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15722iA05799891631DADD/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMS_publicip.jpg" alt="SMS_publicip.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I am missing the IP address of the management server here:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip_2.jpg" style="width: 641px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15723i50F226808C75274E/image-dimensions/641x49?v=v2" width="641" height="49" role="button" title="SMS_publicip_2.jpg" alt="SMS_publicip_2.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;So I had tried&amp;nbsp; implement sk102712 and configure the "$FWDIR/conf/masters" file. That didn't work either.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 06:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143845#M1123</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-16T06:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143846#M1124</link>
      <description>&lt;P&gt;the IP Address of the management server in the template is isn't part of the GWs configuration. its just for NSG configuration.&lt;/P&gt;
&lt;P&gt;I am guessing you followed&amp;nbsp;&lt;SPAN&gt;sk100583 Scenario 2 to configure the Public IP address of the Management server as the log server ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 06:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143846#M1124</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-03-16T06:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143851#M1125</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;That's exactly what I did and it doesn't work either.&lt;BR /&gt;&lt;BR /&gt;On the VMSS gateway:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip_m1.jpg" style="width: 822px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15725i4E44E815180FC57A/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMS_publicip_m1.jpg" alt="SMS_publicip_m1.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Gguidbedit on SMS :&lt;BR /&gt;&lt;BR /&gt;use_loggers_and_masters = true:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip_m2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15726iD560B82D9A6DEAFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMS_publicip_m2.jpg" alt="SMS_publicip_m2.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;and&lt;BR /&gt;&lt;BR /&gt;define_logging_servers = false:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip_m3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15727i5DC19ACEF5F38585/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMS_publicip_m3.jpg" alt="SMS_publicip_m3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 07:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143851#M1125</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-16T07:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143853#M1126</link>
      <description>&lt;P&gt;and you don't see any tcp port 257 traffic on the GWs ?&lt;/P&gt;
&lt;P&gt;have you tried installing DB , rebooting GWs .&lt;/P&gt;
&lt;P&gt;of there is no logging traffic then something is off&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 07:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143853#M1126</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-03-16T07:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143877#M1127</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I had done all that and thanks for the tips.&lt;BR /&gt;&lt;BR /&gt;But I have found the issue!&lt;BR /&gt;&lt;BR /&gt;If I create a static NAT rule for the management object, everything works fine.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SMS_publicip_m99.jpg" style="width: 701px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15728i6B9FC5BA18438712/image-size/large?v=v2&amp;amp;px=999" role="button" title="SMS_publicip_m99.jpg" alt="SMS_publicip_m99.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 09:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143877#M1127</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-16T09:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143879#M1128</link>
      <description>&lt;P&gt;Of course, the suboptimal thing is that I have to change the masters for each VMSS instance. &lt;BR /&gt;Furthermore, I have to change the GuiDBEdit entries for each VMSS instance.&lt;/P&gt;
&lt;P&gt;This is a problem with autoscaling!&lt;/P&gt;
&lt;P&gt;Is there a better approach here for a on premise management server connection?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143879#M1128</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-16T10:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143886#M1129</link>
      <description>&lt;P&gt;well , basically the NAT configuration on the management server should be enough.&lt;/P&gt;
&lt;P&gt;I would change everything back as it was (GUIDBEDIT etc.) and only leave the NAT on the management server.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:43:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/143886#M1129</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-03-16T10:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/144430#M1130</link>
      <description>&lt;P&gt;Both solutions do not work!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/144430#M1130</guid>
      <dc:creator>ori1</dc:creator>
      <dc:date>2022-03-22T14:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard VMSS instance and logging question?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/144432#M1131</link>
      <description>&lt;P&gt;You may have to implement the following &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk171055" target="_blank"&gt;sk171055.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Then you can roll out the parameter via the routing script when activating the VMSS instance.&lt;BR /&gt;&lt;SPAN&gt;&lt;BR /&gt;# vi &lt;/SPAN&gt;$MDS_FWDIR/conf/&lt;SPAN&gt;static&lt;/SPAN&gt;_route_config_&amp;lt;CONFIGURATION-TEMPLATE-NAME&amp;gt;.sh&lt;BR /&gt;# chmod u+x $MDS_FWDIR/conf/&lt;SPAN&gt;static&lt;/SPAN&gt;_route_config_&amp;lt;CONFIGURATION-TEMPLATE-NAME&amp;gt;.sh&lt;BR /&gt;# autoprov_cfg set template –tn &amp;lt;CONFIGURATION-TEMPLATE-NAME&amp;gt; –cg $MDS_FWDIR/conf/&lt;SPAN&gt;static&lt;/SPAN&gt;_route_config_&amp;lt;CONFIGURATION-TEMPLATE-NAME&amp;gt;.sh&lt;BR /&gt;&lt;BR /&gt;Here is the content of the script. The area marked with the dots is the original routing script. &lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;$MDS_FWDIR/conf/static&lt;/SPAN&gt;_route_config_&amp;lt;CONFIGURATION-TEMPLATE-NAME&amp;gt;.sh &lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;#! /bin/bash&lt;BR /&gt;ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 FORCE_NATTED_IP -n 1&lt;/P&gt;
&lt;P&gt;.......&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CloudGuard-VMSS-instance-and-logging-on-premise-SMS/m-p/144432#M1131</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-03-22T14:54:22Z</dc:date>
    </item>
  </channel>
</rss>

