<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS LB sandwich does not come up healthy in some cases in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89434#M2582</link>
    <description>&lt;P&gt;So this was a bug we faced in r80.20. the only way to solve was turn off fwaccel on r80.20 IAAS.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jun 2020 13:45:59 GMT</pubDate>
    <dc:creator>rohan_savant</dc:creator>
    <dc:date>2020-06-22T13:45:59Z</dc:date>
    <item>
      <title>AWS LB sandwich does not come up healthy in some cases</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838#M2579</link>
      <description>&lt;P&gt;we have an AWS ingress gateway auto scale group deployed. We have all routing setup between accounts using tgw.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, and this is random, some of our External load balancers with targets as gateways do not come up healthy. this is completely random but once comes up as unhealthy it never turns healthy for that particular lb.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am able to curl from the gateway to the internal LB and the internal LB is healthy and can be hit directly and shows the webpage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;External lb:&lt;/P&gt;&lt;P&gt;Listen port 443&lt;/P&gt;&lt;P&gt;Target port: 9500 (doesnt come up healthy but autoprov and provisioned the rules)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal LB:&lt;/P&gt;&lt;P&gt;Listen port 443&lt;/P&gt;&lt;P&gt;Target port 443&lt;/P&gt;&lt;P&gt;TAG-: x-chkp-forwarding-&amp;nbsp; https-9500-443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any idea what could be happening here? we are not doing https inspection, just passing from https traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rohan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2019 17:59:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838#M2579</guid>
      <dc:creator>rohan_savant</dc:creator>
      <dc:date>2019-10-24T17:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LB sandwich does not come up healthy in some cases</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65863#M2580</link>
      <description>Can you see traffic coming from the external load balanced at all?&lt;BR /&gt;Maybe they need to be killed and restarted?</description>
      <pubDate>Fri, 25 Oct 2019 04:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65863#M2580</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-25T04:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LB sandwich does not come up healthy in some cases</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89432#M2581</link>
      <description>&lt;P&gt;Hi Rohan,&lt;/P&gt;&lt;P&gt;Try the below setting on the Target groups of Firewall- Health Checks:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Protocol: HTTPS&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Path: /&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Port: traffic port&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Healthy Threshold:2&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;UnHealthy Threshold:2&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Timeout: 4&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Internal:10&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Success Codes: 200-499&lt;/P&gt;&lt;P class="lia-align-left"&gt;This should give Firewall health check fine.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 13:43:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89432#M2581</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-06-22T13:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LB sandwich does not come up healthy in some cases</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89434#M2582</link>
      <description>&lt;P&gt;So this was a bug we faced in r80.20. the only way to solve was turn off fwaccel on r80.20 IAAS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 13:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89434#M2582</guid>
      <dc:creator>rohan_savant</dc:creator>
      <dc:date>2020-06-22T13:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: AWS LB sandwich does not come up healthy in some cases</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89435#M2583</link>
      <description>&lt;P&gt;Not tested in R80.20.&lt;/P&gt;&lt;P&gt;But for my customer in R80.30 have "fwaccel on" and that setting on Health Check did work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards, Prabu&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 13:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/89435#M2583</guid>
      <dc:creator>Prabulingam_N1</dc:creator>
      <dc:date>2020-06-22T13:49:09Z</dc:date>
    </item>
  </channel>
</rss>

