<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Azure setup- Difference over VSRX in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103184#M1878</link>
    <description>&lt;P&gt;The cluster synchronization process happens between the two gateways continuously.&lt;BR /&gt;There are some limitations to what is synced, but nothing specific to operating in public cloud here.&lt;/P&gt;
&lt;P&gt;In a regular, physical environment, gateways can affect failover themselves by changing who responds to a given MAC address.&lt;BR /&gt;Public Cloud does not operate on this premise and requires API calls to the relevant cloud provider to effectively move the traffic flow from one gateway to the other.&lt;BR /&gt;The timing of responding/reacting to these API calls can vary and is not in our control.&lt;BR /&gt;However, when the failover is affected, the gateways will be in sync.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 19:32:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-24T19:32:37Z</dc:date>
    <item>
      <title>Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103060#M1872</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;We have a customer who is looking for a VPN Solution - both Site to Site IPSEC&amp;nbsp; and for Remote Users( Client vpn)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They are evaluating Vsrx&amp;nbsp; and cloudguard .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone provide the Differences . I know VSRX does not provide High Availability . But Checkpoint solution does.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But What is the real benefit of HA over Autoscaling ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know Juniper has no Remote VPN Solution which is a strong point for Checkpoint in this case .&lt;/P&gt;&lt;P&gt;If someone has Battlecard , please provide&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 22:25:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103060#M1872</guid>
      <dc:creator>a_security</dc:creator>
      <dc:date>2020-11-23T22:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103068#M1873</link>
      <description>&lt;P&gt;Autoscaling is about creating more resources as needed to handle the demand/load.&lt;BR /&gt;High Availability has active/standby nodes and is meant for availability only (not necessarily to handle more load).&lt;BR /&gt;We do have an autoscaling Remote Access solution also (at least in Azure):&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=108408" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=108408&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 00:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103068#M1873</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T00:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103083#M1874</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i am trying to say here is - how much time it takes to failover if we go for HA ? I have read in various forums that it takes 3-4 minutes . So this mean it is not a stateful failover ?&lt;/P&gt;&lt;P&gt;And Autoscaling also takes approx same time ; so is there a benefit of using HA ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also does the HA Solution support both Site to Site VPN and Client to Site VPN ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or Autoscaling is the only option for Client to site ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 08:10:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103083#M1874</guid>
      <dc:creator>a_security</dc:creator>
      <dc:date>2020-11-24T08:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103171#M1875</link>
      <description>&lt;P&gt;For HA, the issue isn't with the lack of state, it's an issue with the amount of time it takes for the various APIs to respond and affect traffic flow.&lt;BR /&gt;For Autoscaling, there is no synchronization taking place, but it might take that long to recognize a particular node in the VMSS "failed" and route around/restart it.&lt;/P&gt;
&lt;P&gt;HA works with Client-to-Site VPN and Site-to-Site VPN.&lt;BR /&gt;Autoscaling doesn't support Site-to-Site VPN.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 18:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103171#M1875</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T18:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103178#M1876</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; : Glad to have you here to answer and clearing all the doubts . I have seen all other posts and you have been awsome .&lt;/P&gt;&lt;P&gt;Last thing , this means if API take time to respond , it will&amp;nbsp; be an issue and we will never have stateful failover ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;and if it recognize quickly like 15-20 seconds , state synchronisation takes place ?&lt;/P&gt;&lt;P&gt;Kindly clarify these 2 points please&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 18:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103178#M1876</guid>
      <dc:creator>a_security</dc:creator>
      <dc:date>2020-11-24T18:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103181#M1877</link>
      <description>&lt;P&gt;This means if API takes time - it will be a stateless failover or no failover at all&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 19:16:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103181#M1877</guid>
      <dc:creator>a_security</dc:creator>
      <dc:date>2020-11-24T19:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Azure setup- Difference over VSRX</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103184#M1878</link>
      <description>&lt;P&gt;The cluster synchronization process happens between the two gateways continuously.&lt;BR /&gt;There are some limitations to what is synced, but nothing specific to operating in public cloud here.&lt;/P&gt;
&lt;P&gt;In a regular, physical environment, gateways can affect failover themselves by changing who responds to a given MAC address.&lt;BR /&gt;Public Cloud does not operate on this premise and requires API calls to the relevant cloud provider to effectively move the traffic flow from one gateway to the other.&lt;BR /&gt;The timing of responding/reacting to these API calls can vary and is not in our control.&lt;BR /&gt;However, when the failover is affected, the gateways will be in sync.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 19:32:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-Azure-setup-Difference-over-VSRX/m-p/103184#M1878</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T19:32:37Z</dc:date>
    </item>
  </channel>
</rss>

