<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint gateway failover with service principal in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110425#M1675</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We don't want to use VMSS, we have already deployed cloud guard high availability R 8.40 in azure. We want to utilize the same.&lt;/P&gt;&lt;P&gt;Can you please confirm what will be the next hop in route table. Is it backend ILB and Cluster VIP or is it gateway eth0 and eth1 interface IP?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Feb 2021 10:50:13 GMT</pubDate>
    <dc:creator>snehams</dc:creator>
    <dc:date>2021-02-10T10:50:13Z</dc:date>
    <item>
      <title>Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110171#M1673</link>
      <description>&lt;P&gt;Currently we have 2 checkpoint gateways R80.40 deployed on Azure. UDR changes during failover is happening automatically using Azure service principal.&lt;/P&gt;&lt;P&gt;UDR changes to current active firewall is taking least 15 mins and causing a huge downtime/outage.&lt;/P&gt;&lt;P&gt;Can we set the Front end LB ip and cluster VIP as the next hop is route table instead of using active firewall ip’s. We think the outage will be minimal with this.&lt;/P&gt;&lt;P&gt;Also need to understand what api's will be executed during failover?&lt;/P&gt;&lt;P&gt;Can you please confirm if this setup is possible. Also need some highlight on this approach.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 11:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110171#M1673</guid>
      <dc:creator>snehams</dc:creator>
      <dc:date>2021-02-08T11:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110381#M1674</link>
      <description>&lt;P&gt;You can set up the firewall using a VMSS.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Default.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 08:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110381#M1674</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-19T08:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110425#M1675</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We don't want to use VMSS, we have already deployed cloud guard high availability R 8.40 in azure. We want to utilize the same.&lt;/P&gt;&lt;P&gt;Can you please confirm what will be the next hop in route table. Is it backend ILB and Cluster VIP or is it gateway eth0 and eth1 interface IP?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 10:50:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110425#M1675</guid>
      <dc:creator>snehams</dc:creator>
      <dc:date>2021-02-10T10:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110472#M1676</link>
      <description>&lt;P&gt;The HA works as you describe: by changing UDR routes.&lt;BR /&gt;The fact it can take some time for Azure to process the relevant API calls is one of the limitations of this approach.&lt;BR /&gt;The canonical (supported) approach to resolve this is to deploy with VMSS.&lt;/P&gt;
&lt;P&gt;You might be able to change how the HA works by modifying the&amp;nbsp;azure_ha_test.py script, but I assume this won't survive an upgrade...or be supported.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 16:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110472#M1676</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-10T16:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110475#M1677</link>
      <description>&lt;P&gt;Thank you for the explanation, One last question.&lt;/P&gt;&lt;P&gt;If I use backend ILB and Cluster VIP as a next hop in the azure route table, during failover will&amp;nbsp;&lt;SPAN&gt;checkpoint API calls modify the next hop in the azure route table?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Feb 2021 16:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110475#M1677</guid>
      <dc:creator>snehams</dc:creator>
      <dc:date>2021-02-10T16:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110477#M1678</link>
      <description>&lt;P&gt;Pretty sure it's supposed to go to the ILB.&lt;BR /&gt;Refer to the documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Default.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Default.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 09:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110477#M1678</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-19T09:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110551#M1679</link>
      <description>&lt;P&gt;with the latest HA template, I would expect no UDR modification at all. There should be a internal LB with a VIP. This VIP is the next hop for your UDRs and will not change. Only the Master/Active FW will answer the LB health checks, so the traffic is forwarded to the Master only. After failover, the Backup FW will answer the LB Health Checks and will get the traffic. This failover should happen within seconds.&lt;/P&gt;
&lt;P&gt;On the external side, the Public/Private Cluster IP will move via Azure API calls from the Master to the Backup which could take a while&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110551#M1679</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2021-02-11T14:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110555#M1680</link>
      <description>&lt;P&gt;Thanks for the solution. This was the exact answer I was looking for.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 14:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/110555#M1680</guid>
      <dc:creator>snehams</dc:creator>
      <dc:date>2021-02-11T14:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/111727#M1681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for your answer. How many SPN we need in case we had two members ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 15:13:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/111727#M1681</guid>
      <dc:creator>Equipe_reseau</dc:creator>
      <dc:date>2021-02-24T15:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint gateway failover with service principal</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/111734#M1682</link>
      <description>&lt;P&gt;You only need one SPN with contributor rights for the resource group, the cluster is deployed in. If, during deployment, you decide checkpoint to create the SPN, they will create two, one for each GW. See for example&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/general-topics/19978/1/CP_CloudGuard_IaaS_High_Availability_for_Azure_R80.10_and_Higher_Deployment_Guide.pdf#page17" target="_self"&gt;CP_CloudGuard_IaaS_High_Availability_for_Azure_R80.10_and_Higher_Deployment_Guide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 16:42:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-gateway-failover-with-service-principal/m-p/111734#M1682</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2021-02-24T16:42:37Z</dc:date>
    </item>
  </channel>
</rss>

