<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Load balancer on port 8117 reports gw's unhealthy in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198911#M4433</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82175"&gt;@ajsingh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Let me see if I understood correctly: you are trying to create the cluster object in the smart console, but you cannot communicate with the gateway on ETH1 (SIC is failing). Is your management server trying to access the gateway through ETH1?&lt;/P&gt;
&lt;P&gt;For the health probes, CloudGuard Gateways will only respond to them after the policy installation, and only the active member will do so (the standby member does not respond by design).&lt;/P&gt;
&lt;P&gt;Please refer to step 5 in our guide to set up the GW objects in the SmartConsole:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Workflow.htm?TocPath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____5#Step_5__Configure_Cluster_Objects_in_SmartConsole" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Workflow.htm?TocPath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____5#Step_5__Configure_Cluster_Objects_in_SmartConsole&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this clarifies your question.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;Natanel&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2023 08:11:23 GMT</pubDate>
    <dc:creator>natanelm</dc:creator>
    <dc:date>2023-11-26T08:11:23Z</dc:date>
    <item>
      <title>Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198859#M4426</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I recently deployed R81.10 Template in Azure with HA cluster setup. After deploying first thing I checked is my NSG on ETH1 and then Load balancing status. I found Backend Load balancer is reporting Gateways Unhealthy and Gateway's are dropping traffic from ILB :&amp;nbsp;&lt;BR /&gt;@;2736753;[cpu_1];[fw4_2];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;&lt;BR /&gt;@;2736839;[cpu_3];[fw4_0];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;&lt;BR /&gt;@;2736912;[cpu_2];[fw4_1];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NSG on Backend ILB is fine and allowing all communication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;[Expert@naspdmzcpfwl1:0]# cat /etc/cloud-version&lt;BR /&gt;release: R81.10&lt;BR /&gt;take: 335&lt;BR /&gt;build: 991001383&lt;BR /&gt;platform: azure&lt;BR /&gt;license: byol&lt;BR /&gt;deployment_method: ftw&lt;BR /&gt;template_name: ha&lt;BR /&gt;template_version: 20231002&lt;BR /&gt;template_type: marketplace&lt;BR /&gt;maas_usage: 0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;[Expert@naspdmzcpfwl1:0]# cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;fwha_unicast_only=1&lt;BR /&gt;fwmultik_sync_processing_enabled=0&lt;BR /&gt;fw_aws_mode=1&lt;BR /&gt;fw_https_consider_nat=1&lt;BR /&gt;fw_xff_geo=1&lt;BR /&gt;cloud_balancer_ip1=0xa83f8110&lt;BR /&gt;fw_azure_mode=1&lt;BR /&gt;fwha_dead_timeout_multiplier=20&lt;BR /&gt;fwha_if_problem_tolerance=200&lt;BR /&gt;cloud_balancer_port=8117&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help? I have open TAC case too but thought to ask experts here too for faster resolution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:28:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198859#M4426</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2023-11-24T14:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198860#M4427</link>
      <description>&lt;P&gt;Maybe this would help?&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/Azure-cloudguard-VMSS-health-probes-on-8117-and-monitor/td-p/141582#" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/Azure-cloudguard-VMSS-health-probes-on-8117-and-monitor/td-p/141582#&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:36:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198860#M4427</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-24T14:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198861#M4428</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am using HA cluster Template. Right now I am unable to reach my gateway on ETH1 and hence no sic is established yet. I wanted to make SIC on ETH1 only so comms to firewall stays internal.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have default policy on firewalls yet since it is a brand new setup and i have tried to unload policy too but no success.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198861#M4428</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2023-11-24T14:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198862#M4429</link>
      <description>&lt;P&gt;Ah, now I got it. Well, in that case, we need to figure out why. Can you do traceroute to see why it fails? Did you do any captures to examine where it might be getting "stuck"?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:44:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198862#M4429</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-24T14:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198863#M4430</link>
      <description>&lt;P&gt;I do see traffic coming to my Eth1 on port 8117 but no reply from firewall. I just unloaded the policy too but same behavior . as soon as request reached ILB , its lost.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:47:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198863#M4430</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2023-11-24T14:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198864#M4431</link>
      <description>&lt;P&gt;IS ILB supposed to send traffic from below ip or from 10.x.x.5 IP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;168.63.129.16.60721 &amp;gt; 10.x.x.5.8117: Flags [SEW], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0&lt;BR /&gt;09:46:19.059523 IP 168.63.129.16.60721 &amp;gt; 10.x.x.5.8117: Flags [SEW], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0&lt;BR /&gt;09:46:21.074660 IP 168.63.129.16.60721 &amp;gt; 10.x.x.5.8117: Flags [S], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198864#M4431</guid>
      <dc:creator>ajsingh</dc:creator>
      <dc:date>2023-11-24T14:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198865#M4432</link>
      <description>&lt;P&gt;Wait, do you have ILB and ELB or just ILB?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 14:52:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198865#M4432</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-24T14:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: Load balancer on port 8117 reports gw's unhealthy</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198911#M4433</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82175"&gt;@ajsingh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Let me see if I understood correctly: you are trying to create the cluster object in the smart console, but you cannot communicate with the gateway on ETH1 (SIC is failing). Is your management server trying to access the gateway through ETH1?&lt;/P&gt;
&lt;P&gt;For the health probes, CloudGuard Gateways will only respond to them after the policy installation, and only the active member will do so (the standby member does not respond by design).&lt;/P&gt;
&lt;P&gt;Please refer to step 5 in our guide to set up the GW objects in the SmartConsole:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Workflow.htm?TocPath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____5#Step_5__Configure_Cluster_Objects_in_SmartConsole" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Workflow.htm?TocPath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____5#Step_5__Configure_Cluster_Objects_in_SmartConsole&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this clarifies your question.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;BR /&gt;Natanel&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 08:11:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Load-balancer-on-port-8117-reports-gw-s-unhealthy/m-p/198911#M4433</guid>
      <dc:creator>natanelm</dc:creator>
      <dc:date>2023-11-26T08:11:23Z</dc:date>
    </item>
  </channel>
</rss>

