<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint CloudGuard HA clustering VIP issue in OCI in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194255#M4326</link>
    <description>&lt;P&gt;Were you able to get this working?&amp;nbsp; Happy to help offline if need be.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2023 17:42:39 GMT</pubDate>
    <dc:creator>Jeff_Engel</dc:creator>
    <dc:date>2023-10-04T17:42:39Z</dc:date>
    <item>
      <title>Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/192907#M89</link>
      <description>&lt;P&gt;helo Peeps,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need some direction and troubleshooting guidance on Cloudguard HA clustering in OCI. we have deployed 2 cloudguard instances in same OCI region in HA cluster. the configs are fine which i got checked from TAC as well as they are are assisting me in this issue. the problem arises when we do the failover to secondary instance and the virtaul IPs dont move to secondary firewall. When primary is active , everything works fine both N-S and E-W traffic. in cloudguard we have to assign secondary IPs to both trust and untrust Vnics of the primary firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just wondering if anybody else has experienced this same issue in OCI , Azure or AWS ? we have followed the recommended architecture from official checkpoint documents to configure this solution. we have done dynamic grouping for IAM policies as well and went through some Sk articles as well which TAC shared to implment but no luck so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any leads would be highly appreciated. I also have TAC case opened for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 13:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/192907#M89</guid>
      <dc:creator>Akshayc</dc:creator>
      <dc:date>2023-09-18T13:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/192932#M90</link>
      <description>&lt;P&gt;What images are you using?&lt;BR /&gt;Seems like some sort of permissions issue on the credentials assigned to the instance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 14:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/192932#M90</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-18T14:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/193001#M4298</link>
      <description>&lt;P&gt;i am using R81.20 with latest hotfix take 26.&lt;/P&gt;&lt;P&gt;What sort of permissions do you think causing this issue? We created dynamic group and assigned highest level of IAM policy as per documentation for the cluster. Thats all they mentioned. is there something else which we are not aware of?&lt;/P&gt;&lt;P&gt;below is the link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Oracle_Cloud_Getting_Started/Content/Topics-Oracle-GS/Deploying-Cluster-in-Oracle-Cloud.htm?tocpath=_____4" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Oracle_Cloud_Getting_Started/Content/Topics-Oracle-GS/Deploying-Cluster-in-Oracle-Cloud.htm?tocpath=_____4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 00:22:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/193001#M4298</guid>
      <dc:creator>Akshayc</dc:creator>
      <dc:date>2023-09-19T00:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/193011#M4302</link>
      <description>&lt;P&gt;Are the VPC's and instances located in the same compartment ?&lt;/P&gt;
&lt;P&gt;also check logs under $FWDIR/log/oracle_had.elg to see the root cause.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 04:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/193011#M4302</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-09-19T04:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194255#M4326</link>
      <description>&lt;P&gt;Were you able to get this working?&amp;nbsp; Happy to help offline if need be.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2023 17:42:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194255#M4326</guid>
      <dc:creator>Jeff_Engel</dc:creator>
      <dc:date>2023-10-04T17:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194273#M4327</link>
      <description>&lt;P&gt;hey Jeff,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank for reaching out. not yet. we are stuck still at same issue. Happy to have a call or discussion if you are available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 00:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194273#M4327</guid>
      <dc:creator>Akshayc</dc:creator>
      <dc:date>2023-10-05T00:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194276#M4328</link>
      <description>&lt;P&gt;Hi Akshay,&lt;/P&gt;
&lt;P&gt;Feel free to send me an email at &lt;A href="mailto:jengel@checkpoint.com" target="_blank"&gt;jengel@checkpoint.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;In the meantime, one thing to check real quick is please ensure both cluster members NTP is configured and time is in sync.&amp;nbsp; API calls will not work if system time is not within 5 minutes of actual.&lt;/P&gt;
&lt;P&gt;Best Regards!&lt;/P&gt;
&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 01:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194276#M4328</guid>
      <dc:creator>Jeff_Engel</dc:creator>
      <dc:date>2023-10-05T01:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194278#M4329</link>
      <description>&lt;P&gt;Are the VPC's and instances located in the same compartment ?&lt;/P&gt;
&lt;P&gt;also check logs under $FWDIR/log/oracle_had.elg to see the root cause.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 05:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194278#M4329</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-10-05T05:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint CloudGuard HA clustering VIP issue in OCI</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194374#M4330</link>
      <description>&lt;P&gt;hi Nir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We ran this and found out below in the logs. We dont what the last error means&lt;/P&gt;&lt;P&gt;2023-09-21 14:48:46,814 OCI-CP-HA INFO Traceback (most recent call last):&lt;BR /&gt;File "/etc/fw/scripts/oracle_had.py", line 258, in main&lt;BR /&gt;reconf()&lt;BR /&gt;File "/etc/fw/scripts/oracle_had.py", line 72, in reconf&lt;BR /&gt;oci_client = oci.OCI()&lt;BR /&gt;File "/opt/CPsuite-R81.20/fw1/scripts/oci.py", line 292, in __init__&lt;BR /&gt;identity = metadata('identity/')&lt;BR /&gt;File "/opt/CPsuite-R81.20/fw1/scripts/oci.py", line 122, in metadata&lt;BR /&gt;resp.reason, data)&lt;BR /&gt;TypeError: __init__() missing 1 required positional argument: 'body'&lt;/P&gt;&lt;P&gt;does this ring any bell?&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2023 08:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-CloudGuard-HA-clustering-VIP-issue-in-OCI/m-p/194374#M4330</guid>
      <dc:creator>Akshayc</dc:creator>
      <dc:date>2023-10-06T08:10:11Z</dc:date>
    </item>
  </channel>
</rss>

