<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 CloudGuard IaaS High Availability for Microsoft Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46949#M3468</link>
    <description>&lt;P&gt;It was not a routing issue and the cause has finally been sorted.&lt;/P&gt;&lt;P&gt;After validating everything in the document and the setup in Azure the issue was discovered to be Anti-Spoofing.&lt;/P&gt;&lt;P&gt;The &lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm" target="_blank"&gt;documentation&lt;/A&gt; states that Anti-Spoofing should be disabled on the frontend cluster interfaces (eth0).&amp;nbsp; &amp;nbsp;&amp;nbsp;It does not however mention anything about disabling Anti-Spoofing on the backend cluster interfaces (eth1).&lt;/P&gt;&lt;P&gt;After going through the document again this morning I set a log filter for a source of the backend-lb,&amp;nbsp;&lt;SPAN&gt;168.63.129.16.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2019-03-14 at 10.35.33 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/63i0BD81129D0A4B6CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-03-14 at 10.35.33 AM.png" alt="Screen Shot 2019-03-14 at 10.35.33 AM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After a couple of iterations while working with support we finally came to the conclusion that Anti-Spoofing needed to be disabled on cluster internal interfaces also.&lt;/P&gt;&lt;P&gt;Policy was pushed after disabling Anti-Spoofing and everything started working as expected.&lt;/P&gt;&lt;P&gt;The documentation needs to be updated to also include disabling Anti-Spoofing on eth1.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 16:12:31 GMT</pubDate>
    <dc:creator>Ave_Joe</dc:creator>
    <dc:date>2019-03-14T16:12:31Z</dc:date>
    <item>
      <title>R80.10 CloudGuard IaaS High Availability for Microsoft Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/40519#M3465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most current version of this document will be here:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm"&gt;Check Point CloudGuard IaaS High Availability for Microsoft Azure R80.10 Deployment Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 Sep 2018 18:10:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/40519#M3465</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-29T18:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 CloudGuard IaaS High Availability for Microsoft Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46842#M3466</link>
      <description>&lt;P&gt;Anyone know if there is an updated CloudGuard IaaS High Availability for Microsoft Azure guide for R80.20 release? &amp;nbsp;I deployed a R80.20 IAAS Cluster and traffic to VM hosts behind the Azure gateway is not working &amp;nbsp;Using a test VM host I started a tcpdump looking for traffic. &amp;nbsp;The VM host responds to packets but the CP security gateway never sees the return packet.&lt;/P&gt;&lt;P&gt;I have been through this document several times trying to see what I may have missed but everything seems to &amp;nbsp;be configured per the document.&lt;/P&gt;&lt;P&gt;I think the issue is somewhere between the load balancer and the CP security gateway but have figured that maybe an updated version may help me figure it out.&lt;/P&gt;&lt;P&gt;Any one else having this issue?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 00:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46842#M3466</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2019-03-14T00:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 CloudGuard IaaS High Availability for Microsoft Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46859#M3467</link>
      <description>&lt;P&gt;That sounds like more a routing issue only..&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 06:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46859#M3467</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2019-03-14T06:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 CloudGuard IaaS High Availability for Microsoft Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46949#M3468</link>
      <description>&lt;P&gt;It was not a routing issue and the cause has finally been sorted.&lt;/P&gt;&lt;P&gt;After validating everything in the document and the setup in Azure the issue was discovered to be Anti-Spoofing.&lt;/P&gt;&lt;P&gt;The &lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/html_frameset.htm" target="_blank"&gt;documentation&lt;/A&gt; states that Anti-Spoofing should be disabled on the frontend cluster interfaces (eth0).&amp;nbsp; &amp;nbsp;&amp;nbsp;It does not however mention anything about disabling Anti-Spoofing on the backend cluster interfaces (eth1).&lt;/P&gt;&lt;P&gt;After going through the document again this morning I set a log filter for a source of the backend-lb,&amp;nbsp;&lt;SPAN&gt;168.63.129.16.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screen Shot 2019-03-14 at 10.35.33 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/63i0BD81129D0A4B6CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-03-14 at 10.35.33 AM.png" alt="Screen Shot 2019-03-14 at 10.35.33 AM.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;After a couple of iterations while working with support we finally came to the conclusion that Anti-Spoofing needed to be disabled on cluster internal interfaces also.&lt;/P&gt;&lt;P&gt;Policy was pushed after disabling Anti-Spoofing and everything started working as expected.&lt;/P&gt;&lt;P&gt;The documentation needs to be updated to also include disabling Anti-Spoofing on eth1.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 16:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/46949#M3468</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2019-03-14T16:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 CloudGuard IaaS High Availability for Microsoft Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/66731#M3469</link>
      <description>Hi Dameon,&lt;BR /&gt;&lt;BR /&gt;The above link looks like broken</description>
      <pubDate>Thu, 07 Nov 2019 01:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R80-10-CloudGuard-IaaS-High-Availability-for-Microsoft-Azure/m-p/66731#M3469</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2019-11-07T01:29:13Z</dc:date>
    </item>
  </channel>
</rss>

