<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Vsec Cluster in Azure ?? anyone know how to? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7973#M4024</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same question as &lt;A href="https://community.checkpoint.com/migrated-users/45863"&gt;Vladislav Nedosekin&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;I have a ClouldGuard Cluster but had lots of problems when fail-over takes place, and it happens occasionally. Every few days/weeks randomly, fail-over takes place with no good reason out of the blue, and most of the time the whole API call process does not complete smooth, until manually using cluster_XL down/up command.&lt;/P&gt;&lt;P&gt;We&amp;nbsp;decided to shutdown manually the secondary node for a while (we are few months in this state), and since then we have a stable environment, except one known in advance Microsoft maintenance activity.&lt;/P&gt;&lt;P&gt;I agree about&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;availability-group, but I think we saved lots of money every month since then.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2018 14:54:04 GMT</pubDate>
    <dc:creator>Gilad_Pomerantz</dc:creator>
    <dc:date>2018-05-21T14:54:04Z</dc:date>
    <item>
      <title>Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M4013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi CheckMates!,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to know is someone can help me or lead me in order to setup a HA cluster of checkpoint Vsec on Azure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk110194 doesn't mention nothing about the proper way to configure the cluster HA, just we need to work with Active directory and API. but , to be honest, i never worked before with active directory on azure and no API knowledge.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;So , if someone can lead me some tip about how to deploy it? we already have all running but, to failover, have to be done manually changing the route tables to point the new active memeber.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Thanks for any help&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 12:48:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7962#M4013</guid>
      <dc:creator>Edson_Adrian_Di</dc:creator>
      <dc:date>2017-10-24T12:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7963#M4014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For HA to work correctly in Azure, we must make calls to the Azure API.&lt;/P&gt;&lt;P&gt;The API calls allow us to monitor state and fail over the relevant routes when needed.&lt;/P&gt;&lt;P&gt;In order to call the API, you need credentials.&lt;/P&gt;&lt;P&gt;Those credentials need to be created and configured on the instances, as described in the SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2017 14:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7963#M4014</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-24T14:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7964#M4015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My name is Dmitry and I'm from Check Point R&amp;amp;D.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to deploy a check point vSEC high availability cluster in MS Azure. The deployment and configuration process is described in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194"&gt;sk110194&lt;/A&gt;&amp;nbsp;that you're referring to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;After deploying the vSEC Cluster from the Azure marketplace you should follow the steps in the article to create&amp;nbsp;a service account&amp;nbsp;and assign it to the cluster's resource group. No API knowledge is required in order to do that - this can be done via the &lt;SPAN style="text-decoration: underline;"&gt;azure portal&lt;/SPAN&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;It is then required to configure the high availability daemon on each cluster member (see the section "&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194#Deployment using a Solution Template"&gt;Deployment using a Solution Template&lt;/A&gt;" that covers the creation of a service account and the configuration of the HA daemon).&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;On failover, the HA daemon will &lt;SPAN style="text-decoration: underline;"&gt;make all the API calls automatically&lt;/SPAN&gt; and reassign all routing tables accordingly.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;Note that the cluster must be properly configured in SmartDashboard / SmartConsole and policy must be installed (see section "&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194#SmartDashboard"&gt;SmartDashboard Configuration&lt;/A&gt;" for instructions).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have specific comments on the SK please feel free share them with me. If you are having trouble configuring the cluster you may open a support ticket or contact your local SE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dmitry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 11:09:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7964#M4015</guid>
      <dc:creator>Dmitry_Gorn</dc:creator>
      <dc:date>2017-10-25T11:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7965#M4016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your detailed answer Dmitry,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, we already have working the cluster in Azure following the sk110194 and this video which is really helpful:&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A class="link-titled" href="https://www.youtube.com/watch?v=f6hbbFal0JE" title="https://www.youtube.com/watch?v=f6hbbFal0JE"&gt;Checkpoint vSEC cluster Deployment in azure - YouTube&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now, we are stock because everything is ok for the incoming traffic, but outgoing, traffic generated from the lan of the checkpoint in azure doesn't work.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 19:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7965#M4016</guid>
      <dc:creator>Edson_Adrian_Di</dc:creator>
      <dc:date>2017-10-25T19:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7966#M4017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Off the top of my head, I would troubleshoot each hop.&lt;/P&gt;&lt;P&gt;From host behind the vSEC Gateway, try to ping the vSEC Gateway.&lt;/P&gt;&lt;P&gt;Use tcpdump on the vSEC gateway to confirm traffic is being received on the expected interface.&lt;/P&gt;&lt;P&gt;If not you will need to review the User Defined Routes to ensure they are configured correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Oct 2017 21:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7966#M4017</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-25T21:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7967#M4018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have followed&amp;nbsp;s&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;k110194&lt;SPAN&gt;&amp;nbsp;and applied the routing tables as explained in the article.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;When i NAT behind the clustermember-frontend IP, outgoing internet access is fine. When I NAT behind the cluster virtual front-end IP, we have no internet access.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;From fwmonitor we see that traffic is correctly being NAT-ted behind the cluster IP but we see no return traffic. Is there any further configuration we need to do in Azure routing tables for this to work?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Kurt&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2017 10:48:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7967#M4018</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2017-10-26T10:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7968#M4019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we had the same issue. To get outgoing azure traffic hide NATed by the cluster IP address, it should leave the gateway as hide NATed to its _private_ interface address, and Azure will translate the src address to the cluster IP.&lt;BR /&gt;This works fine until a failover, when the secondary still translates to the private address of the _primary_ gateway, as they have identical policies/config but interface addresses are different.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am still trying to find an answer to a failover scenario and outgoing internet traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gyula&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 03:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7968#M4019</guid>
      <dc:creator>gyula_jona</dc:creator>
      <dc:date>2017-12-19T03:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7969#M4020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gyula,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to set the external interface as Sync only not Cluster or Cluster + Sync. There is no need for a VIP to be defined. Gateways will then automatically NAT behind their respective Front End IPs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do not need to define a manual NAT rule to hide behind a specific IP, just auto hide NAT all subnet behind Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kurt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 07:33:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7969#M4020</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2017-12-19T07:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7970#M4021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Can I ask what is the point to have a cluster in Azure?&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no physical device that you would need to replace.&amp;nbsp;&lt;/P&gt;&lt;P&gt;HA - takes a bit of time, within average environment almost the same time as to redeploy appliance.&lt;/P&gt;&lt;P&gt;Keep a live packages&amp;nbsp; some time cause split brain, so you have an outage.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my personal point of view it is quite a bad practice to try to replicated on-premise datacentre in the cloud, instead of using benefits that cloud introduce.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 15:30:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7970#M4021</guid>
      <dc:creator>Vladislav_Nedos</dc:creator>
      <dc:date>2018-01-02T15:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7971#M4022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The gateways in the cluster are put into an availability-group. Although they are in the same Datacenter, they should be on different racks and hardware. This ensures that in case of any failures or maintenance the cluster will switch over onto the secondary gateway. This process takes around&amp;nbsp;4 minutes due to changes done automatically using APIs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 15:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7971#M4022</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2018-01-02T15:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7972#M4023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your share. Inherited the system as-is... no auto hide-nat enabled on Azure subnet objects, just a single NAT to&amp;nbsp;the Cluster PIP, which was not working &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;BR /&gt;On the other hand, due to Azur's fabric nature (heavily policy routing like UDRs) there is a heavy traffic arriving and leaving the same inside interface. This is the reason why I tried to do&amp;nbsp;hide NAT explicitly/manually applied only traffic heading out to the Internet. I do not want to get the traffic (from subnets in Azure with auto hide-nat configured)&amp;nbsp; NAT-ed when not going out to the internet, and the ingress/egress&amp;nbsp;are inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gyula&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 22:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7972#M4023</guid>
      <dc:creator>gyula_jona</dc:creator>
      <dc:date>2018-01-08T22:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7973#M4024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same question as &lt;A href="https://community.checkpoint.com/migrated-users/45863"&gt;Vladislav Nedosekin&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;I have a ClouldGuard Cluster but had lots of problems when fail-over takes place, and it happens occasionally. Every few days/weeks randomly, fail-over takes place with no good reason out of the blue, and most of the time the whole API call process does not complete smooth, until manually using cluster_XL down/up command.&lt;/P&gt;&lt;P&gt;We&amp;nbsp;decided to shutdown manually the secondary node for a while (we are few months in this state), and since then we have a stable environment, except one known in advance Microsoft maintenance activity.&lt;/P&gt;&lt;P&gt;I agree about&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;availability-group, but I think we saved lots of money every month since then.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 14:54:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7973#M4024</guid>
      <dc:creator>Gilad_Pomerantz</dc:creator>
      <dc:date>2018-05-21T14:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7974#M4025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/43062"&gt;Edson Adrian Diaz Cuevas&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If u are still facing LAN outgoing traffic issue, please check on Network Interface of any LAN VM, the &lt;STRONG&gt;&lt;EM&gt;Effective Routes&lt;/EM&gt;&lt;/STRONG&gt; that are active to understand what routes are active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Validate your HA related configuration is correct. (including API&amp;nbsp;Credentials and Role being provided to respective Resource&amp;nbsp; Group)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[Expert]# python -m json.tool $FWDIR/conf/azure-ha.json&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reconf the same&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Expert]#&amp;nbsp;&lt;/SPAN&gt;$FWDIR/scripts/azure_ha_cli.py reconf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Test the same&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Expert]#&amp;nbsp;&lt;/SPAN&gt;$FWDIR/scripts/azure_ha_test.py&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Work on the errors found with test.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FACT:&lt;/STRONG&gt; Highest Priority for User defined routes, the Express Route / On Premise Routes and Lastly System Defined Routes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 06:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7974#M4025</guid>
      <dc:creator>Nikhil_Deshmukh</dc:creator>
      <dc:date>2018-05-22T06:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7975#M4026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information, I have already used the script long time ago:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# python -m json.tool $FWDIR/conf/azure-ha.json&lt;/P&gt;&lt;P&gt;And while the results were OK, we found later that the API user credentials where incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll go over the configuration again and see if it is mature enough to be stable as it should be.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 13:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7975#M4026</guid>
      <dc:creator>Gilad_Pomerantz</dc:creator>
      <dc:date>2018-05-22T13:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7976#M4027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nikhil&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue was already solved. As kurt explained "&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;You need to set the external interface as Sync only not Cluster or Cluster + Sync. There is no need for a VIP to be defined. Gateways will then automatically NAT behind their respective Front End IPs.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;You do not need to define a manual NAT rule to hide behind a specific IP, just auto hide NAT all subnet behind Gateway.&lt;/P&gt;&lt;P&gt;"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not "clear" in the checkpoint Azure documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 20:27:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7976#M4027</guid>
      <dc:creator>Edson_Adrian_Di</dc:creator>
      <dc:date>2018-05-22T20:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7977#M4028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've had vSec cluster deployed for around 6 months now and I agree with you, there are a lot of issues when it comes to cluster and failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever a change related to interfaces, static routes, dynamic routing or route redistribution is made on the gateways, the routing daemon crashes, causing a failover. Unlike on premise, a failover in Azure takes 5-6 minutes due to API calls so this effectively results in 6 minutes of downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround, we always do a clusterXL_admin down on the standby member to avoid failover. We then perform the necessary changes and re enable cluster on the standby member.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 21:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7977#M4028</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2018-05-22T21:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7978#M4029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Due to the nature of public cloud environments, we are reliant on things like the public cloud APIs to perform cluster failovers.&lt;/P&gt;&lt;P&gt;Obviously we can't control how long it takes for these API calls to complete.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said, the experience is not currently optimal and we are looking for ways to improve it.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 04:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7978#M4029</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-23T04:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7979#M4030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;@Kurt Abela&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the internal interfaces need to be set to? sync or cluster + sync.&lt;/P&gt;&lt;P&gt;Both interfaces set to sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;You do not need to define a manual NAT rule to hide behind a specific IP, just auto hide NAT all subnet behind Gateway.&lt;/SPAN&gt;"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have 2 NAT rules in the below manner and failover works(UDR's change) but outgoing traffic still NAT's to GW1-IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Internal LAN subnet | Any | Any | GW1-external private IP(hide) | Original | Original&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&lt;SPAN&gt;Internal LAN subnet | Any | Any | GW2-external private IP(hide) | Original | Original&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know what am i missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 06:34:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7979#M4030</guid>
      <dc:creator>Sarath_M</dc:creator>
      <dc:date>2018-08-30T06:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7980#M4031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/52648"&gt;Sarath M&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External = Sync&lt;/P&gt;&lt;P&gt;Internal = cluster + Sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not use manual Hide-NAT rules. Use automatic NAT (object NAT) and choose hide behind gateway. This will ensure that during a fail over, traffic is NAT-ted behind the correct active gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 06:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7980#M4031</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2018-08-30T06:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vsec Cluster in Azure ?? anyone know how to?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7981#M4032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2018 06:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Vsec-Cluster-in-Azure-anyone-know-how-to/m-p/7981#M4032</guid>
      <dc:creator>Sarath_M</dc:creator>
      <dc:date>2018-08-30T06:50:43Z</dc:date>
    </item>
  </channel>
</rss>

