<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP through Azure Load Balancer as part of CloudGuard VMSS in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177984#M325</link>
    <description>&lt;P&gt;On the "frontend-lb" created by the Check Point CloudGuard deployment scripts, adding an "Outbound rule"&amp;nbsp; of protocol UDP got outbound UDP working correctly.&lt;/P&gt;&lt;P&gt;I think the logic here is that outbound SNAT for TCP is automagically created because the deployment script creates an example inbound NAT rule, however as there is no example UDP inbound rule, there is no corresponding automagic UDP outbound SNAT rule created. Creating an outbound rule for UDP corrects this. I also tried creating an inbound UDP rule (similar to the example TCP one) instead of an outbound UDP rule, however this did not work in my case.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp rule.JPG" style="width: 956px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20496iC7EB5078B0071126/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp rule.JPG" alt="udp rule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2023 21:34:54 GMT</pubDate>
    <dc:creator>AK2</dc:creator>
    <dc:date>2023-04-12T21:34:54Z</dc:date>
    <item>
      <title>UDP through Azure Load Balancer as part of CloudGuard VMSS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177816#M323</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have deployed a standard Scale Set, CloudGuard R81.20&lt;/P&gt;&lt;P&gt;TCP traffic works fine, for example outbound https to internet is NAT-ed correctly and connects ok.&lt;/P&gt;&lt;P&gt;However, I can't send UDP traffic to the internet. For example, ntpdate 0.pool.ntp.org&lt;/P&gt;&lt;P&gt;I logged a case with TAC. They confirmed UDP traffic is leaving the Check Point gateway correctly and suggested I open a case with Microsoft. I'm not in a position to do this.&lt;/P&gt;&lt;P&gt;The load balancer is the standard backend-lb deployed by the Azure Marketplace solution. The loadbalancer rule is the standard "HA" one (all ports, all protocols) deployed in the same way.&lt;/P&gt;&lt;P&gt;I tried separating into a TCP LB rule and a UDP lb rule. This did not help.&lt;/P&gt;&lt;P&gt;I have reproduced the issue in a freshly built test environment.&lt;/P&gt;&lt;P&gt;Any help/suggestions appreciated.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 05:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177816#M323</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-04-11T05:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: UDP through Azure Load Balancer as part of CloudGuard VMSS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177968#M324</link>
      <description>&lt;P&gt;This is likely caused by a networking issue in Azure if the traffic is leaving the gateway correctly.&lt;BR /&gt;In which case, you will have to troubleshoot the issue there (possibly with Microsoft's help).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 16:30:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177968#M324</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-12T16:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: UDP through Azure Load Balancer as part of CloudGuard VMSS</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177984#M325</link>
      <description>&lt;P&gt;On the "frontend-lb" created by the Check Point CloudGuard deployment scripts, adding an "Outbound rule"&amp;nbsp; of protocol UDP got outbound UDP working correctly.&lt;/P&gt;&lt;P&gt;I think the logic here is that outbound SNAT for TCP is automagically created because the deployment script creates an example inbound NAT rule, however as there is no example UDP inbound rule, there is no corresponding automagic UDP outbound SNAT rule created. Creating an outbound rule for UDP corrects this. I also tried creating an inbound UDP rule (similar to the example TCP one) instead of an outbound UDP rule, however this did not work in my case.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udp rule.JPG" style="width: 956px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20496iC7EB5078B0071126/image-size/large?v=v2&amp;amp;px=999" role="button" title="udp rule.JPG" alt="udp rule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 21:34:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/UDP-through-Azure-Load-Balancer-as-part-of-CloudGuard-VMSS/m-p/177984#M325</guid>
      <dc:creator>AK2</dc:creator>
      <dc:date>2023-04-12T21:34:54Z</dc:date>
    </item>
  </channel>
</rss>

