<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure Checkpoint VSEC Cluster Internal Load balancer in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29119#M3752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deployed CheckPoint VSEC cluster from Microsoft Azure Market place. I see the cluster is having a public load balancer, which has two cluster gateways outside IP's&amp;nbsp;as front end IPs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to spin up a second internal load balancer, which will have the cluster gateways inside IP's configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to deploy the load balancer and add the gateway IPs fine, however the challenge I am facing is, in order to achieve HA in Azure, we have to configure the second load balancer name is $FWDIR/conf/azure-ha.json file and reconf it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried adding the second (internal) load balancer name after the comma, the azure_ha_cli.py isn't recognizing the second load balancer name and isn't failing over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have tried this and can you let me know how you are achieving HA using this method&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chandru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Feb 2018 14:52:47 GMT</pubDate>
    <dc:creator>Chandhrasekar_S</dc:creator>
    <dc:date>2018-02-12T14:52:47Z</dc:date>
    <item>
      <title>Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29119#M3752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deployed CheckPoint VSEC cluster from Microsoft Azure Market place. I see the cluster is having a public load balancer, which has two cluster gateways outside IP's&amp;nbsp;as front end IPs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to spin up a second internal load balancer, which will have the cluster gateways inside IP's configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to deploy the load balancer and add the gateway IPs fine, however the challenge I am facing is, in order to achieve HA in Azure, we have to configure the second load balancer name is $FWDIR/conf/azure-ha.json file and reconf it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried adding the second (internal) load balancer name after the comma, the azure_ha_cli.py isn't recognizing the second load balancer name and isn't failing over.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have tried this and can you let me know how you are achieving HA using this method&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chandru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 14:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29119#M3752</guid>
      <dc:creator>Chandhrasekar_S</dc:creator>
      <dc:date>2018-02-12T14:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29120#M3753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In json file you can specify only public load balancer name, it doesn't count with internal load balancer. Azure template for vsec cluster is deployed per design specified here&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194"&gt;Deploying a Check Point Cluster in Microsoft Azure&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 07:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29120#M3753</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2018-02-16T07:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29121#M3754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree, in JSON file you specify the load balancer name.&amp;nbsp;I have internal load balancer working fine on eth0 interface&lt;/P&gt;&lt;P&gt;I do understand, Azure template for vSEC cluster only supports load balancer on eth0 interface&lt;/P&gt;&lt;P&gt;It would be better if Check Point comes up having a load balancer on eth1 interface as well&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 02:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29121#M3754</guid>
      <dc:creator>Chandhrasekar_S</dc:creator>
      <dc:date>2018-03-22T02:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29122#M3755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might want to look on Auto scale option, this will give you load balancer on eth0 and eth1 &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&amp;nbsp;Trust me having just one load balancer in front of cluster will give you a lot of fun.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 03:30:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29122#M3755</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2018-03-22T03:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29123#M3756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Check Point Scale sets offer load balancers on both eth0 and eth1 interfaces. however they can only do stateless protocols like http and https. It works for internet facing apps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant deploy them every where, since we have to inspect other stateful protocols like sql server, rdp etc.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Mar 2018 01:58:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29123#M3756</guid>
      <dc:creator>Chandhrasekar_S</dc:creator>
      <dc:date>2018-03-25T01:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29124#M3757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how do you get the cluster to answer health probes from load balancers? even on internal interfaces.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29124#M3757</guid>
      <dc:creator>Jerry_Thornhil1</dc:creator>
      <dc:date>2018-07-13T15:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Azure Checkpoint VSEC Cluster Internal Load balancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29125#M3758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;External &lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;&lt;SPAN&gt;Load Balancer's :- They are needed when you want to Publish Web Services (Web page / Application running on any Server) over the Internet.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;See as per my understanding Internal Load Balancer's are used for Balancing the Traffic loads for any server between different nodes or not to expose Server's directly to User's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wht is your specific requirement with Load Balancer's to be acknowledged by VSec on the Internal Azure plane.?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 12:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-Checkpoint-VSEC-Cluster-Internal-Load-balancer/m-p/29125#M3758</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-07-19T12:22:16Z</dc:date>
    </item>
  </channel>
</rss>

