<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure S2S vpn in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/178000#M329</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we don't use the LB for VPN at all , the LBs don't pass ESP traffic so it will never work.&lt;/P&gt;
&lt;P&gt;you need to configure it with the Cluster's VIP which attached to the ACTIVE member , like we do with any other regular deployments.&lt;/P&gt;
&lt;P&gt;check the Azure HA admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm#Step_10__Configure_VPN" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm#Step_10__Configure_VPN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2023 05:51:45 GMT</pubDate>
    <dc:creator>Nir_Shamir</dc:creator>
    <dc:date>2023-04-13T05:51:45Z</dc:date>
    <item>
      <title>Azure S2S vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177966#M326</link>
      <description>&lt;P&gt;Hello Team,&lt;BR /&gt;&lt;BR /&gt;Have a question and apologies in advance if its not very precise.&lt;/P&gt;&lt;P&gt;Have deployed a cluster in Azure, classic cloudguard Iaas HA topology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;everything seems to work fine when i dont nat anything behind the external VIP (private).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the question is regarding VPN, do you usually need extra config on the load balancers or anywhere in azure to permit 500/4500/ESP towards the gateway from the load-balnacers public IP?&lt;BR /&gt;&lt;BR /&gt;As i dont seem to get anything except if there is a rule in the lB in azure for it.&lt;BR /&gt;&lt;BR /&gt;Hope its more or less clear.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;Juan&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 16:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177966#M326</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-04-12T16:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Azure S2S vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177975#M327</link>
      <description>&lt;P&gt;I dont recall one of our customers having to do any extra config on load balancer end for this couple of years ago. We have pay as you go Azure subscription, so I can fire up a lab in it this week and verify for you. I know Azure is super limited when it comes to doing any sort of troubleshooting (certainly nothing like any major vendor's firewall).&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 17:19:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177975#M327</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-12T17:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Azure S2S vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177977#M328</link>
      <description>&lt;P&gt;I don't believe you can use Load Balancers with VPN (either Site-to-Site or Remote Access).&lt;BR /&gt;That's suggested by:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk109360" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk109360&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You would need to set up an active/passive cluster pair for VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 17:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/177977#M328</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-12T17:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Azure S2S vpn</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/178000#M329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we don't use the LB for VPN at all , the LBs don't pass ESP traffic so it will never work.&lt;/P&gt;
&lt;P&gt;you need to configure it with the Cluster's VIP which attached to the ACTIVE member , like we do with any other regular deployments.&lt;/P&gt;
&lt;P&gt;check the Azure HA admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm#Step_10__Configure_VPN" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm#Step_10__Configure_VPN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 05:51:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-S2S-vpn/m-p/178000#M329</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-04-13T05:51:45Z</dc:date>
    </item>
  </channel>
</rss>

