<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cloudguard HA with Loadbalancer in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200630#M4471</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having issues with my test lab, same config was working previously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloudguard deployed in HA with Frontend and backend Loadbalancer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version R81.20 for both Mgmt and Cluster&lt;/P&gt;&lt;P&gt;Frontend subnet: 10.0.0.0/24&lt;/P&gt;&lt;P&gt;FW-1 10.0.0.4&amp;nbsp;&amp;nbsp;FW-2 10.0.0.5&amp;nbsp;&amp;nbsp;Frontend VIP: 10.0.0.6&lt;/P&gt;&lt;P&gt;Backend subnet: 10.0.1.0/24&lt;/P&gt;&lt;P&gt;FW-1 10.0.1.5&amp;nbsp; &amp;nbsp; &amp;nbsp;FW-2 10.0.1.6&amp;nbsp; &amp;nbsp;Backend LB: 10.0.1.4&lt;/P&gt;&lt;P&gt;Prod Subnet: 10.1.0.0/24&lt;/P&gt;&lt;P&gt;Webserver IP 10.1.0.4&lt;/P&gt;&lt;P&gt;NO Public IP attached.&lt;/P&gt;&lt;P&gt;Prod Route : Picture attached&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT rules attached&lt;/P&gt;&lt;P&gt;Access Rules attached&lt;/P&gt;&lt;P&gt;AntiSpoofing off on both internal and external interface&lt;/P&gt;&lt;P&gt;FLB Load balancing rules configured and enable with Floating IP&amp;nbsp; (attached)&lt;/P&gt;&lt;P&gt;VNET peering setup and firewall can ping backend host and also able to ssh from firewall to backend host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue:&amp;nbsp;&lt;/P&gt;&lt;P&gt;same deployment previously worked traffic coming on FrontLB public IP natted to internal (backend server 10.1.0.4).&amp;nbsp;&lt;/P&gt;&lt;P&gt;something has recently changed on Azure Level and its to do with routing dont know what. but traffic from outside to internal/backend host is not reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP:&lt;/P&gt;&lt;P&gt;Traffic coming from home Public IP going to FLB public IP can be seen on Eth0 and on Eth1, no traffic arrive on Backend host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP on Backend host:&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic going out from Host to internet can be seen on firewall logs and Firewall Eth1&lt;/P&gt;&lt;P&gt;backend can access Internet and tracroute shows going via active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have tried everything can be possible and here to ask help, best would be someone to do the lab and can see the behaviour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Dec 2023 15:59:51 GMT</pubDate>
    <dc:creator>kamaladmire1</dc:creator>
    <dc:date>2023-12-14T15:59:51Z</dc:date>
    <item>
      <title>Cloudguard HA with Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200630#M4471</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having issues with my test lab, same config was working previously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloudguard deployed in HA with Frontend and backend Loadbalancer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version R81.20 for both Mgmt and Cluster&lt;/P&gt;&lt;P&gt;Frontend subnet: 10.0.0.0/24&lt;/P&gt;&lt;P&gt;FW-1 10.0.0.4&amp;nbsp;&amp;nbsp;FW-2 10.0.0.5&amp;nbsp;&amp;nbsp;Frontend VIP: 10.0.0.6&lt;/P&gt;&lt;P&gt;Backend subnet: 10.0.1.0/24&lt;/P&gt;&lt;P&gt;FW-1 10.0.1.5&amp;nbsp; &amp;nbsp; &amp;nbsp;FW-2 10.0.1.6&amp;nbsp; &amp;nbsp;Backend LB: 10.0.1.4&lt;/P&gt;&lt;P&gt;Prod Subnet: 10.1.0.0/24&lt;/P&gt;&lt;P&gt;Webserver IP 10.1.0.4&lt;/P&gt;&lt;P&gt;NO Public IP attached.&lt;/P&gt;&lt;P&gt;Prod Route : Picture attached&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT rules attached&lt;/P&gt;&lt;P&gt;Access Rules attached&lt;/P&gt;&lt;P&gt;AntiSpoofing off on both internal and external interface&lt;/P&gt;&lt;P&gt;FLB Load balancing rules configured and enable with Floating IP&amp;nbsp; (attached)&lt;/P&gt;&lt;P&gt;VNET peering setup and firewall can ping backend host and also able to ssh from firewall to backend host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue:&amp;nbsp;&lt;/P&gt;&lt;P&gt;same deployment previously worked traffic coming on FrontLB public IP natted to internal (backend server 10.1.0.4).&amp;nbsp;&lt;/P&gt;&lt;P&gt;something has recently changed on Azure Level and its to do with routing dont know what. but traffic from outside to internal/backend host is not reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP:&lt;/P&gt;&lt;P&gt;Traffic coming from home Public IP going to FLB public IP can be seen on Eth0 and on Eth1, no traffic arrive on Backend host.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP on Backend host:&amp;nbsp;&lt;/P&gt;&lt;P&gt;traffic going out from Host to internet can be seen on firewall logs and Firewall Eth1&lt;/P&gt;&lt;P&gt;backend can access Internet and tracroute shows going via active firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have tried everything can be possible and here to ask help, best would be someone to do the lab and can see the behaviour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 15:59:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200630#M4471</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-12-14T15:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard HA with Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200707#M4472</link>
      <description>&lt;P&gt;any thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 10:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200707#M4472</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-12-15T10:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard HA with Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200713#M4473</link>
      <description>&lt;P&gt;Have you checked if any applicable Azure NSG has changed and verified that it allows the traffic flow?&lt;/P&gt;
&lt;P&gt;Might otherwise be faster to consult TAC via a remote session if you suspect the actual firewall...&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 11:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200713#M4473</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-15T11:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard HA with Loadbalancer</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200715#M4474</link>
      <description>&lt;P&gt;Hi Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;NSG allow traffic, I have also created an Any Any rule for both direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 11:14:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-HA-with-Loadbalancer/m-p/200715#M4474</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-12-15T11:14:38Z</dc:date>
    </item>
  </channel>
</rss>

