<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104497#M1721</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes had looked into SNAT behavior.&lt;/P&gt;&lt;P&gt;But in my setup - For FrontendLB - The backend Pools weer only VMSS and no other Internal VMs.&lt;/P&gt;&lt;P&gt;So I made HIDE NAT with All gateway(VMSS) for Internal machine so that Internal machine will Hide behind VMSS and go outside.&lt;/P&gt;&lt;P&gt;Had Outbound Rules for VMSS to use FrontendLB Public IP. So my both VMSS &amp;amp; Internal VMs use FrontendLB IP for outgoing Traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2020 12:15:05 GMT</pubDate>
    <dc:creator>Prabulingam_N1</dc:creator>
    <dc:date>2020-12-07T12:15:05Z</dc:date>
    <item>
      <title>CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103602#M1715</link>
      <description>&lt;P&gt;Dear CheckMates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have CheckPoint VMSS working in Azure.&lt;/P&gt;&lt;P&gt;I have given Hide NAT behind Gateway for Internal Server, so it gets Hide behind one of VMSS and reaches Internet - works fine&lt;/P&gt;&lt;P&gt;Requirement is - I want to Hide NAT my Internal Server to a New Public IP (Not to use any of VMSS Public IP)&lt;/P&gt;&lt;P&gt;I tried creating New External Interface in VMSS and able to Hide NAT my Internal Server to that New IP.&lt;/P&gt;&lt;P&gt;Outbound packet gets Hide NAT with New IP, but UNABLE to see REPLY traffic from Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to achieve the Outbound Hide NAT for Internal Server using New IP apart from VMSS IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 13:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103602#M1715</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-11-29T13:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103909#M1716</link>
      <description>&lt;P&gt;Not sure exactly what you can do on the Azure side to make this work, but that is where the issue lies.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 16:57:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103909#M1716</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-01T16:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103949#M1717</link>
      <description>&lt;P&gt;Hello PhoneBoy,&lt;/P&gt;&lt;P&gt;Yeah looks like that will not work as I had made many trials and reason could be in "ifconfig" of VMSS where the Primary External Interface is tagged and no other External can be added onto its NIC settings (&lt;STRONG&gt;ens192P2g3&lt;/STRONG&gt;..... adapter is bound for eth0 ONLY)&lt;/P&gt;&lt;P&gt;Now as per document I'm doing the below and still unable to get it done.&lt;/P&gt;&lt;P&gt;1) Created CheckPoint VMSS without ILPIP.&lt;/P&gt;&lt;P&gt;2) Integrated with Mgmt Server with Frontend NIC Private IP of VMSS&lt;/P&gt;&lt;P&gt;3) Created Inbound LB rule in FrontendLB to reach Internal Server - works fine&lt;/P&gt;&lt;P&gt;4) Now my VMSS &amp;amp; Internal Server both don't have Internet Outbound Connectivity.&lt;/P&gt;&lt;P&gt;5) As per CheckPoint document and Azure, I had given Outbound Rule in FrontendLB so that Backend VMSS instances will get Outbound Internet using FrontendLB Public IP.&lt;/P&gt;&lt;P&gt;But no luck. I tried some NAT in SmartConsole on VMSS Objects and subnets for Internal Server - -No Luck&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how should I achieve the Outbound Internet Connection for my VMSS instances which has ONLY Private IP (No ILPIP) and for Internal Servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 04:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/103949#M1717</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-02T04:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104451#M1718</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;according to the information on this page&amp;nbsp; &lt;A href="https://docs.microsoft.com/en-us/azure/load-balancer/outbound-rules#:~:text=Outbound%20rules%20allow%20you%20to,IP%20masquerading" target="_self"&gt;Azure LB&lt;/A&gt;&amp;nbsp;I guess it´s too complicated for a VMSS as outbound Load Balancing Rules have the following limitation:&lt;/P&gt;
&lt;P&gt;&amp;lt;&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;Outbound rules can only be applied to primary IP configuration of a NIC. You can't create an outbound rule for the secondary IP of a VM or NVA. Multiple NICs are supported.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;So you would have to add NICs to each ScaleSet Member , not sure if this is supported by Checkpoint at all.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;In addition, the LB has to be of type "Standard", with a Basic LB you can not configure outbound Rules.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;May be a Single GW or Checkpoint Cluster for outbound traffic could be a alternative ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;At least for a Single GW I have tested it that way:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security-IaaS/STATIC-NAT-in-Azure-Checkpoint/td-p/75730" target="_self"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security-IaaS/STATIC-NAT-in-Azure-Checkpoint/td-p/75730&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;Matthias&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 07:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104451#M1718</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-07T07:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104486#M1719</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes I could create additional NIC but it cannot be used for Outbound traffic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes in Single GW it is working but not in Cluster &amp;amp; VMSS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyways I could able to get Internet Outbound for VMSS &amp;amp; Internal servers with FrontendLB's IP as my VMSS don't have ILPIP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards, Prabu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 11:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104486#M1719</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-07T11:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104490#M1720</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;lt;Yes I could create additional NIC but it cannot be used for Outbound traffic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Have you studied the provided microsoft link:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;With outbound rules, you can explicitly define outbound&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SNAT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;behavior.&lt;/P&gt;
&lt;P&gt;Outbound rules allow you to control:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Which virtual machines are translated to which public IP addresses.&lt;/STRONG&gt;
&lt;UL&gt;
&lt;LI&gt;Two rules were backend pool A uses IP address A and B, backend pool B uses IP address C and D.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 11:26:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104490#M1720</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-07T11:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104497#M1721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes had looked into SNAT behavior.&lt;/P&gt;&lt;P&gt;But in my setup - For FrontendLB - The backend Pools weer only VMSS and no other Internal VMs.&lt;/P&gt;&lt;P&gt;So I made HIDE NAT with All gateway(VMSS) for Internal machine so that Internal machine will Hide behind VMSS and go outside.&lt;/P&gt;&lt;P&gt;Had Outbound Rules for VMSS to use FrontendLB Public IP. So my both VMSS &amp;amp; Internal VMs use FrontendLB IP for outgoing Traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 12:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104497#M1721</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-07T12:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104509#M1722</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;the backend Pool&amp;nbsp;consists of NICs,&amp;nbsp; not VMs. As you would have a VM/scaleset with multiple NICs you could define two backendPools on the external LB, each containing a different NIC of the same VM/scaleset&lt;/P&gt;
&lt;P&gt;Same is true for your external and internal LB which is deployed with your VMSS.&amp;nbsp; &amp;nbsp;Check the backend Pool of these LBs, same scaleset but different NICs &lt;BR /&gt;(eth1 with the backend-lb, eth0 with the frontend-lb)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 14:24:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104509#M1722</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-07T14:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104543#M1723</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Created New NIC on VMSS instance and tried to add or create New backendpool for this new NIC - no luck.&lt;/P&gt;&lt;P&gt;Its not getting added fo new NIC VMSS instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 17:07:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104543#M1723</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-07T17:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104618#M1724</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;I guess you still have only two NICs at the instance level ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NIC-1.png" style="width: 556px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9577i55AA97C7EBD96EE2/image-dimensions/556x215?v=v2" width="556" height="215" role="button" title="NIC-1.png" alt="NIC-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 07:03:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104618#M1724</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-08T07:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104619#M1725</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I created 3rd NIC as External apart from etho(External) &amp;amp; eth1(Internal).&lt;/P&gt;&lt;P&gt;So already 1st backendpool for FrontendLB has been tagged with eth0 of VMSS.&lt;/P&gt;&lt;P&gt;Now if I try to create 2nd backendpool with 3rd NIC of VMSS - unable to do so.&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 07:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104619#M1725</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-08T07:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104621#M1726</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;when&amp;nbsp; I added a 3rd NIC , I had to redeploy the already running instances. Only then the 3 NICs where available&amp;nbsp; at the instance level and I could add a further backend pool with the third NIC.&lt;/P&gt;
&lt;P&gt;Have you done this ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 07:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104621#M1726</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-08T07:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104622#M1727</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yup after new VMSS spinned, I can see 3rd New NIC as well. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Created 2nd Backendpool to tag New NIC, but unable to do so.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thats where I was stuck.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards, Prabu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 07:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104622#M1727</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-08T07:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104643#M1728</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;look´s like the NIC has to have network acceleration enabled (which is not the case if added via the Azure Portal).&lt;/P&gt;
&lt;P&gt;If doing so via azure CLI&amp;nbsp; like:&lt;/P&gt;
&lt;P&gt;az vmss update -g cpss --name cpss --set virtualMachineProfile.networkProfile.networkInterfaceConfigurations[2].enableAcceleratedNetworking=true&lt;/P&gt;
&lt;P&gt;i was able to add a 2nd Backenpool. (after redeploying the instance again)&lt;/P&gt;
&lt;P&gt;After configuring a outbound rule, the second public IP of the external LB was used.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 11:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104643#M1728</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-08T11:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104644#M1729</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me try your action.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Azure CLI - Should i need to replace any text in below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;az vmss update -g cpss --name cpss --set virtualMachineProfile.networkProfile.networkInterfaceConfigurations[2].enableAcceleratedNetworking=true&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards, Prabu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 11:07:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104644#M1729</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-08T11:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104646#M1730</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;yes, the name is the resource group the scalest ist deployed in and after the "-g" switch you&amp;nbsp; have to add the name of your scaleset.&lt;/P&gt;
&lt;P&gt;If it is succesfull, the added NIC (I called it eth2) should have acceleration enabled:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scaleset.png" style="width: 358px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9579iC144932C88910682/image-dimensions/358x158?v=v2" width="358" height="158" role="button" title="scaleset.png" alt="scaleset.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, you have to redeploy the instance again.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 11:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104646#M1730</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-08T11:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104670#M1731</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Matthias,&lt;BR /&gt;Thanks for your input, I could able to create 2nd BackendPool &amp;amp; tagged New NIC as well.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture1.PNG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9584iA0FF435044539F01/image-size/small?v=v2&amp;amp;px=200" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture2.PNG" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9585iE91F597DA402D8A0/image-size/small?v=v2&amp;amp;px=200" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Now my requirement is that my VMSS should go Outbound to Internet thru this New NIC.&lt;BR /&gt;It doesn't work if I do as above?&lt;BR /&gt;It works only thru backendpool which has eth0..Not with&amp;nbsp;backendpool which has newnic&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 15:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104670#M1731</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-08T15:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104744#M1732</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;your VMSS is using eth0 as your default route is through eth0, I guess ?&lt;/P&gt;
&lt;P&gt;If you change the default route to the first IP of the newnic network it will use that interface&lt;/P&gt;
&lt;P&gt;But if I get it right, only&amp;nbsp; your internal Server should use that new Public IP ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 10:11:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104744#M1732</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-09T10:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104745#M1733</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Matthias,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I also changed the Default route in VMSS from eth0 to newnic &amp;amp; checked.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;VMSS lost Internet connection. (Then changed back from newnic to eth0 in Default Route - started woking)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Internal server, I made HIDE NAT of NewNIC IP of VMSS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No luck.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Seems to me a limitation????&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards, Prabu&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 10:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104745#M1733</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-12-09T10:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint IaaS VMSS -Azure - Doubt in Outbound NAT for Internal server</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104747#M1734</link>
      <description>&lt;P&gt;Hi Prabu,&lt;/P&gt;
&lt;P&gt;did you put the newnic (10.10.10.5) in the same subnet as eth0 (10.10.10.4) ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Matthias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 10:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/CheckPoint-IaaS-VMSS-Azure-Doubt-in-Outbound-NAT-for-Internal/m-p/104747#M1734</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-12-09T10:22:46Z</dc:date>
    </item>
  </channel>
</rss>

