<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76859#M2375</link>
    <description>&lt;P&gt;So. The IP for cluster was assigned but to the standby member. We've been able to fix that with &lt;A href="https://community.checkpoint.com/t5/CloudGuard-IaaS/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M328" target="_blank"&gt;https://community.checkpoint.com/t5/CloudGuard-IaaS/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M328&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So now we can ping the vip and see it's being directed to the proper active member. We still can't establish a VPN tunnel but that might need another post...&lt;/P&gt;</description>
    <pubDate>Mon, 02 Mar 2020 14:17:25 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2020-03-02T14:17:25Z</dc:date>
    <item>
      <title>do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76611#M2370</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;we're setting up CloudGuard Iaas High Availability in Azure (R80.30)&lt;BR /&gt;I can access the two firewall members when using their respective external IPs. But connectivity using the cluster-vip external IP doesn't seem to work. Trying to establish a VPN tunnel or just pinging doesn't work. I'm not seeing anything on the Active firewall with fw monitor&lt;BR /&gt;do you need to add the cluster-vip external IP&amp;nbsp;to the LoadBalancerFrontend IP configuration?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 16:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76611#M2370</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-02-27T16:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76688#M2371</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you should have a NSG attached to the external subnet ?&lt;/P&gt;&lt;P&gt;If so, please check if the access to the&amp;nbsp; VIP is allowed&lt;/P&gt;&lt;P&gt;Matthias&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 12:55:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76688#M2371</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-02-28T12:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76702#M2372</link>
      <description>&lt;P&gt;Mathias,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the NSG attached to the frontend subnet&lt;/P&gt;&lt;P&gt;Inbound&lt;/P&gt;&lt;P&gt;AllowAllInbound Any Any Any Any Allow&lt;/P&gt;&lt;P&gt;AllowVnetInbound Any Any VirtualNetwork VirtualNetwork Allow&lt;/P&gt;&lt;P&gt;AllowAzureLBInbound Any Any AzureLoadBalancer Any Allow&lt;/P&gt;&lt;P&gt;DenyAllInbound Any Any Any Any Deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outbound&lt;/P&gt;&lt;P&gt;AllowVnetOutbound Any any VirtualNetwork VirtualNetwork Allow&lt;/P&gt;&lt;P&gt;AllowInternetOutbound Any Any Any Internet Allow&lt;/P&gt;&lt;P&gt;DenyAllOutbound Any Any Any Any Deny&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 14:21:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76702#M2372</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-02-28T14:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76704#M2373</link>
      <description>&lt;P&gt;ok, and your VIP is attached to the external interface of the master&amp;nbsp; I guess ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Unbenannt.png" style="width: 670px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4624iD069B49658404D0D/image-dimensions/670x231?v=v2" width="670" height="231" role="button" title="Unbenannt.png" alt="Unbenannt.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 14:37:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76704#M2373</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-02-28T14:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76740#M2374</link>
      <description>&lt;P&gt;to your specific question, no, you don't need it, the VIP for VPN purposes on the CG IaaS HA Template is a "floating IP" attached as secondary to the NIC of the active member, this job is done by a service principal deployed by the template if selected (this is by default); attached image.&lt;/P&gt;
&lt;P&gt;If you selected "NO" that can cause the no modification of this IP to the active member also.&lt;/P&gt;
&lt;DIV id="tinyMceEditorChristianCastil_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 17:11:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76740#M2374</guid>
      <dc:creator>ChristianCastil</dc:creator>
      <dc:date>2020-02-28T17:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: do you need to add the external IP of the cluster to the LoadBalancerFrontend IP configuration?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76859#M2375</link>
      <description>&lt;P&gt;So. The IP for cluster was assigned but to the standby member. We've been able to fix that with &lt;A href="https://community.checkpoint.com/t5/CloudGuard-IaaS/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M328" target="_blank"&gt;https://community.checkpoint.com/t5/CloudGuard-IaaS/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M328&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So now we can ping the vip and see it's being directed to the proper active member. We still can't establish a VPN tunnel but that might need another post...&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 14:17:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/do-you-need-to-add-the-external-IP-of-the-cluster-to-the/m-p/76859#M2375</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-03-02T14:17:25Z</dc:date>
    </item>
  </channel>
</rss>

