<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I am curious about the fail-over logic in the Azure environment. in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206634#M4611</link>
    <description>&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are parts of your advice that I would like to respond to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I deployed the checkpoint cluster from the marketplace.&lt;/P&gt;&lt;P&gt;2. Configured a separate subnet for the vm server.&lt;/P&gt;&lt;P&gt;3. Configured Hide NAT for the subnet of the VM server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And as per your advice, I added both firewall IP and VIP to Frontend-LB and configured it, but the symptom is the same.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-21_16-24-53.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24574iDFB3FFE4840703AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-21_16-24-53.png" alt="2024-02-21_16-24-53.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-21_16-30-39.png" style="width: 791px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24575iA598C0F2EA5A5A68/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-21_16-30-39.png" alt="2024-02-21_16-30-39.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 07:31:11 GMT</pubDate>
    <dc:creator>ChoiYunSoo</dc:creator>
    <dc:date>2024-02-21T07:31:11Z</dc:date>
    <item>
      <title>I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206468#M4609</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am curious about the fail-over logic in the Azure environment.&lt;/P&gt;&lt;P&gt;To test the customer configuration, I deployed cloudguard clusterXL.&lt;/P&gt;&lt;P&gt;And most things worked as intended, but during fail-over, things didn't work as I intended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a VM server under the firewall backend and I executed the ping command with destination 8.8.8.8&lt;/P&gt;&lt;P&gt;FW_A confirmed that communication was normal, but a problem occurred when fail-over.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you look at the tcpdump results, you can see that request packets come in to FW_B and request packets are sent out again to the firewall's VIP.&lt;/P&gt;&lt;P&gt;But I can't see the response packet at all.&lt;/P&gt;&lt;P&gt;I waited about 10 minutes considering the nature of the Azure environment, but the result was the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have not configured LB on the frontend based on the firewall. Could this be a problem?&lt;/P&gt;&lt;P&gt;If there is any other configuration you need, please let us know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The test environment I have configured is below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP - Frontend VIP: 10.4.0.7&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP - Frontend FW_A: 10.4.0.5&lt;/P&gt;&lt;P&gt;CP - Frontend FW_B: 10.4.0.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP - Backend FW_A: 10.4.1.6&lt;/P&gt;&lt;P&gt;CP - Backend FW_B: 10.4.1.7&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-20_16-42-39.png" style="width: 873px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24548i9D29D89D09F1EA68/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-20_16-42-39.png" alt="2024-02-20_16-42-39.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 07:43:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206468#M4609</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-20T07:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206470#M4610</link>
      <description>&lt;P&gt;Hi ChoiYunSoo,&lt;BR /&gt;The topology you are describing is not correct. Did you deploy the cluster using the market place template for high availability? you should have a frontend loaf balancer and subnet by default.&lt;BR /&gt;A few things to note:&lt;BR /&gt;1. The backend subnet should only have the Check Point VM interfaces. you need to deploy a separate subnet for the VM server.&lt;BR /&gt;2. You need to implement hide NAT scenario for the outgoing traffic. per the admin guide&lt;/P&gt;
&lt;P&gt;Please refer to the topology and instructions of the admin guide for this:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Network.htm?tocpath=Network%7C_____1#Network_Diagram" target="_blank" rel="noopener"&gt;Network (checkpoint.com)&lt;/A&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HA topology.png" style="width: 589px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24549iE637960A00AB7954/image-size/large?v=v2&amp;amp;px=999" role="button" title="HA topology.png" alt="HA topology.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 08:06:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206470#M4610</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2024-02-20T08:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206634#M4611</link>
      <description>&lt;P&gt;Thanks for your reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are parts of your advice that I would like to respond to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I deployed the checkpoint cluster from the marketplace.&lt;/P&gt;&lt;P&gt;2. Configured a separate subnet for the vm server.&lt;/P&gt;&lt;P&gt;3. Configured Hide NAT for the subnet of the VM server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And as per your advice, I added both firewall IP and VIP to Frontend-LB and configured it, but the symptom is the same.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-21_16-24-53.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24574iDFB3FFE4840703AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-21_16-24-53.png" alt="2024-02-21_16-24-53.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-21_16-30-39.png" style="width: 791px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24575iA598C0F2EA5A5A68/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-21_16-30-39.png" alt="2024-02-21_16-30-39.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 07:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206634#M4611</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-21T07:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206636#M4612</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi ChoiYunSoo,&lt;BR /&gt;The outbound response should be directed to the public IP of the member&amp;nbsp;originating the request.&lt;BR /&gt;Can you confirm whether the HA was set up with public IPs? &lt;BR /&gt;Did you also run&amp;nbsp;tcpdump on the second member? If you received a response on the standby member, I suggest verifying whether the outbound response unexpectedly passes through the external LB.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 08:09:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206636#M4612</guid>
      <dc:creator>Rivka-Strilitz</dc:creator>
      <dc:date>2024-02-21T08:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206768#M4620</link>
      <description>&lt;P&gt;&amp;nbsp;Hi&amp;nbsp;Rivka-Strilitz&lt;/P&gt;&lt;P&gt;Thanks you for reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to add the firewall's public VIP to the frontend LB IP as you said, but it seems I can't add it.&lt;/P&gt;&lt;P&gt;Are the settings below correct what you were trying to tell me?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_10-23-47.png" style="width: 810px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24597iB712CA2A99321DE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_10-23-47.png" alt="2024-02-22_10-23-47.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 01:28:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206768#M4620</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-22T01:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206770#M4622</link>
      <description>&lt;P&gt;Everything CP folks said is correct. Ping me if you need help, I have perfectly working cluster in Azure lab, we can do any tests you like.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 01:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206770#M4622</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T01:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206780#M4623</link>
      <description>&lt;P&gt;Hi Legend&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you for reply&lt;/P&gt;&lt;P&gt;Below is the current configuration of my test lab.&lt;/P&gt;&lt;P&gt;The only thing I think is unique is that FW_A shows the Frontend, Backend, and VIP interfaces, but FW_B does not show the VIP interface.&lt;/P&gt;&lt;P&gt;Is there anything I did wrong in the configuration below?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24598iA2D524A4B4959A6C/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 994px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24599iABD7FB07E29B49FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 989px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24600iC57F7A89C311F92A/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24601iB3E099790FE9A8FF/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24602iB21209815B38E21A/image-size/large?v=v2&amp;amp;px=999" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 04:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206780#M4623</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-22T04:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206781#M4624</link>
      <description>&lt;P&gt;Thanks for the details. I will review in the morning and update.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 04:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206781#M4624</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T04:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206789#M4625</link>
      <description>&lt;P&gt;Thanks you for help&lt;BR /&gt;To help you understand, we will update the configuration and also update the checkpoint settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_13-45-18.png" style="width: 940px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24603i62F4F637C81DBBE7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_13-45-18.png" alt="2024-02-22_13-45-18.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_13-37-47.png" style="width: 850px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24604i5DD7A196A631AECF/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_13-37-47.png" alt="2024-02-22_13-37-47.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_13-36-43.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24606i0C291EEC7470D650/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_13-36-43.png" alt="2024-02-22_13-36-43.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_13-36-49.png" style="width: 510px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24607i15C25DD1F12FB73A/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_13-36-49.png" alt="2024-02-22_13-36-49.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-22_13-44-13.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24608i67FACB2EE1E8FA05/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-22_13-44-13.png" alt="2024-02-22_13-44-13.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 04:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206789#M4625</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-22T04:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206840#M4626</link>
      <description>&lt;P&gt;Since it may take some time to review all this, in the meantime, can you run below from both members and post the output. Below is my lab. Also, SUPER IMPORTANT...MAKE SURE anti-spoofing is DISABLED, as its not supported to have it on on any interface, and it would also cause policy failure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;master:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@cpazurecluster1:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 (local) 10.5.1.5 100% ACTIVE CPAZUREcluster1&lt;BR /&gt;2 10.5.1.6 0% STANDBY CPAZUREcluster2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114904&lt;BR /&gt;State change: ACTIVE(!) -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: Reason for ACTIVE! alert has been resolved&lt;BR /&gt;Event time: Sat Feb 10 16:01:44 2024&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 0&lt;BR /&gt;Time of counter reset: Sat Feb 10 15:59:48 2024 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@cpazurecluster1:0]# cd /opt/CPsuite-R81.20/fw1/scripts/azure_&lt;BR /&gt;azure_conf.py azure_ha_globals.py azure_had.py&lt;BR /&gt;azure_ha_cli.py azure_ha_test.py&lt;BR /&gt;[Expert@cpazurecluster1:0]# cd /opt/CPsuite-R81.20/fw1/scripts/azure_ha_test.py&lt;BR /&gt;-bash: cd: /opt/CPsuite-R81.20/fw1/scripts/azure_ha_test.py: Not a directory&lt;BR /&gt;[Expert@cpazurecluster1:0]# cd /opt/CPsuite-R81.20/fw1/scripts/&lt;BR /&gt;[Expert@cpazurecluster1:0]# ./azure_ha_&lt;BR /&gt;azure_ha_cli.py azure_ha_test.py&lt;BR /&gt;[Expert@cpazurecluster1:0]# ./azure_ha_test.py&lt;BR /&gt;Setting api versions for "ha" solution&lt;BR /&gt;ARM versions are: {&lt;BR /&gt;"resources": "?api-version=2019-07-01"&lt;BR /&gt;}&lt;BR /&gt;Testing if DNS is configured...&lt;BR /&gt;- Primary DNS server is: 168.63.129.16&lt;BR /&gt;Testing if DNS is working...&lt;BR /&gt;- DNS resolving test was successful&lt;BR /&gt;Testing connectivity to login.windows.net:443...&lt;BR /&gt;Testing ClusterXL parameters...&lt;BR /&gt;Testing cluster interface configuration...&lt;BR /&gt;Testing credentials...&lt;BR /&gt;Getting information about the environment...&lt;BR /&gt;Getting information about the VM cpazurecluster1...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourceGroups/CP-cluster/providers/Microsoft.Network/networkInterfaces/CPAZUREcluster1-eth0&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : CPAZUREcluster1-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [OK]&lt;BR /&gt;Getting information about the VM cpazurecluster2...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourceGroups/CP-cluster/providers/Microsoft.Network/networkInterfaces/CPAZUREcluster2-eth0&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : CPAZUREcluster2-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [OK]&lt;BR /&gt;Testing cluster public IP address...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourcegroups/CP-cluster/providers/Microsoft.Network/publicIPAddresses/CPAZUREcluster&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/publicIPAddresses&lt;BR /&gt;Name : CPAZUREcluster&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Verifying Azure interface configuration...&lt;BR /&gt;- Interface eth0: local IP address = 10.5.0.4, peer IP address = 10.5.0.5&lt;BR /&gt;- Interface eth1: local IP address = 10.5.1.5, peer IP address = 10.5.1.6&lt;BR /&gt;- Interface vpnt7: local IP address = 10.5.0.4, peer IP address = 10.5.0.5&lt;/P&gt;
&lt;P&gt;All tests were successful!&lt;BR /&gt;[Expert@cpazurecluster1:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;**************************************************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;backup:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@cpazurecluster2:0]# cphaprob state&lt;/P&gt;
&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;
&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;
&lt;P&gt;1 10.5.1.5 100% ACTIVE CPAZUREcluster1&lt;BR /&gt;2 (local) 10.5.1.6 0% STANDBY CPAZUREcluster2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;
&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114802&lt;BR /&gt;State change: INIT -&amp;gt; STANDBY&lt;BR /&gt;Reason for state change: There is already an ACTIVE member in the cluster (member 1)&lt;BR /&gt;Event time: Sat Feb 10 16:11:31 2024&lt;/P&gt;
&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 0&lt;BR /&gt;Time of counter reset: Sat Feb 10 15:59:48 2024 (reboot)&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@cpazurecluster2:0]# cd /opt/CPsuite-R81.20/fw1/scripts/&lt;BR /&gt;[Expert@cpazurecluster2:0]# ./azure_ha_test.py&lt;BR /&gt;Setting api versions for "ha" solution&lt;BR /&gt;ARM versions are: {&lt;BR /&gt;"resources": "?api-version=2019-07-01"&lt;BR /&gt;}&lt;BR /&gt;Testing if DNS is configured...&lt;BR /&gt;- Primary DNS server is: 168.63.129.16&lt;BR /&gt;Testing if DNS is working...&lt;BR /&gt;- DNS resolving test was successful&lt;BR /&gt;Testing connectivity to login.windows.net:443...&lt;BR /&gt;Testing ClusterXL parameters...&lt;BR /&gt;Testing cluster interface configuration...&lt;BR /&gt;Testing credentials...&lt;BR /&gt;Getting information about the environment...&lt;BR /&gt;Getting information about the VM cpazurecluster2...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourceGroups/CP-cluster/providers/Microsoft.Network/networkInterfaces/CPAZUREcluster2-eth0&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : CPAZUREcluster2-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [OK]&lt;BR /&gt;Getting information about the VM cpazurecluster1...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourceGroups/CP-cluster/providers/Microsoft.Network/networkInterfaces/CPAZUREcluster1-eth0&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : CPAZUREcluster1-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [OK]&lt;BR /&gt;Testing cluster public IP address...&lt;BR /&gt;Id : /subscriptions/40c8d051-e4b3-45ea-b165-451d47e33fec/resourcegroups/CP-cluster/providers/Microsoft.Network/publicIPAddresses/CPAZUREcluster&lt;BR /&gt;Subscription : 40c8d051-e4b3-45ea-b165-451d47e33fec&lt;BR /&gt;Resource group: CP-cluster&lt;BR /&gt;Type : Microsoft.Network/publicIPAddresses&lt;BR /&gt;Name : CPAZUREcluster&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Verifying Azure interface configuration...&lt;BR /&gt;- Interface eth0: local IP address = 10.5.0.5, peer IP address = 10.5.0.4&lt;BR /&gt;- Interface eth1: local IP address = 10.5.1.6, peer IP address = 10.5.1.5&lt;BR /&gt;- Interface vpnt7: local IP address = 10.5.0.5, peer IP address = 10.5.0.4&lt;/P&gt;
&lt;P&gt;All tests were successful!&lt;BR /&gt;[Expert@cpazurecluster2:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206840#M4626</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T14:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206841#M4627</link>
      <description>&lt;P&gt;Also&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41270"&gt;@ChoiYunSoo&lt;/a&gt;&amp;nbsp;, can you run below when other member thats having issues is active.&lt;/P&gt;
&lt;P&gt;from expert:&lt;/P&gt;
&lt;P&gt;curl_cli -k google.com&lt;/P&gt;
&lt;P&gt;ping 8.8.8.8&lt;/P&gt;
&lt;P&gt;ip r g 8.8.8.8&lt;/P&gt;
&lt;P&gt;clish -c "show route"&lt;/P&gt;
&lt;P&gt;Please compare with one that works to ensure 100% it is the same.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:08:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206841#M4627</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T14:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206984#M4628</link>
      <description>&lt;P&gt;Thank you for your active help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the answers to your inquiries&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* FW_A (Standby)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@northclu11:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 10.4.1.6 0% STANDBY FW_A&lt;BR /&gt;2 10.4.1.7 100% ACTIVE FW_B&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114802&lt;BR /&gt;State change: DOWN -&amp;gt; STANDBY&lt;BR /&gt;Reason for state change: There is already an ACTIVE member in the cluster (member 2)&lt;BR /&gt;Event time: Fri Feb 23 03:59:40 2024&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Fri Feb 23 03:59:36 2024&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 1&lt;BR /&gt;Time of counter reset: Fri Feb 23 03:53:33 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]# ./azure_ha_test.py&lt;BR /&gt;Setting api versions for "ha" solution&lt;BR /&gt;ARM versions are: {&lt;BR /&gt;"resources": "?api-version=2019-07-01"&lt;BR /&gt;}&lt;BR /&gt;Testing if DNS is configured...&lt;BR /&gt;- Primary DNS server is: 168.63.129.16&lt;BR /&gt;Testing if DNS is working...&lt;BR /&gt;- DNS resolving test was successful&lt;BR /&gt;Testing connectivity to login.windows.net:443...&lt;BR /&gt;Testing ClusterXL parameters...&lt;BR /&gt;Testing cluster interface configuration...&lt;BR /&gt;Testing credentials...&lt;BR /&gt;Getting information about the environment...&lt;BR /&gt;Getting information about the VM northclu11...&lt;BR /&gt;Id : /subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/North_CLU_1/providers/Microsoft.Network/networkInterfaces/NorthClu11-eth0&lt;BR /&gt;Subscription : 1efe27ac-5c1b-497b-bc60-6510b07d1c92&lt;BR /&gt;Resource group: North_CLU_1&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : NorthClu11-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [Forbidden]&lt;BR /&gt;Error:&lt;BR /&gt;HTTP/1.1 403 Forbidden&lt;BR /&gt;b'{"error":{"code":"LinkedAuthorizationFailed","message":"The client \'b7a8cf26-f859-41aa-b8af-f103f9a14aa9\' with object id \'b7a8cf26-f859-41aa-b8af-f103f9a14aa9\' has permission to perform action \'Microsoft.Network/networkInterfaces/write\' on scope \'/subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/North_CLU_1/providers/Microsoft.Network/networkInterfaces/NorthClu11-eth0\'; however, it does not have permission to perform action(s) \'Microsoft.Network/virtualNetworks/subnets/join/action\' on the linked scope(s) \'/subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/ODL-checkpoint_v1-72163-01/providers/Microsoft.Network/virtualNetworks/North-Hub/subnets/VMSS-FrontEnd\' (respectively) or the linked scope(s) are invalid."}}'&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]# curl_cli -k google.com&lt;BR /&gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&amp;lt;meta http-equiv="content-type" content="text/html;charset=utf-8"&amp;gt;&lt;BR /&gt;&amp;lt;TITLE&amp;gt;301 Moved&amp;lt;/TITLE&amp;gt;&amp;lt;/HEAD&amp;gt;&amp;lt;BODY&amp;gt;&lt;BR /&gt;&amp;lt;H1&amp;gt;301 Moved&amp;lt;/H1&amp;gt;&lt;BR /&gt;The document has moved&lt;BR /&gt;&amp;lt;A HREF="&lt;A href="http://www.google.com/" target="_blank"&gt;http://www.google.com/&lt;/A&gt;"&amp;gt;here&amp;lt;/A&amp;gt;.&lt;BR /&gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]#&lt;BR /&gt;[Expert@northclu11:0]# clish -c "show route"&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;S 0.0.0.0/0 via 10.4.0.1, eth0, cost 0, age 659&lt;BR /&gt;S 10.0.0.0/8 via 10.4.1.1, eth1, cost 0, age 659&lt;BR /&gt;S 10.4.0.0/16 via 10.4.1.1, eth1, cost 0, age 659&lt;BR /&gt;C 10.4.0.0/24 is directly connected, eth0&lt;BR /&gt;C 10.4.1.0/24 is directly connected, eth1&lt;BR /&gt;C 127.0.0.0/8 is directly connected, lo&lt;BR /&gt;S 168.63.129.16/32 via 10.4.0.1, eth0, cost 0, age 659&lt;BR /&gt;S 169.254.169.254/32 via 10.4.0.1, eth0, cost 0, age 659&lt;BR /&gt;S 172.16.0.0/12 via 10.4.1.1, eth1, cost 0, age 659&lt;BR /&gt;S 192.168.0.0/16 via 10.4.1.1, eth1, cost 0, age 659&lt;BR /&gt;[Expert@northclu11:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW_B (Active)&lt;/P&gt;&lt;P&gt;[Expert@northclu12:0]# cphaprob stat&lt;/P&gt;&lt;P&gt;Cluster Mode: High Availability (Active Up) with IGMP Membership&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 10.4.1.6 0% STANDBY FW_A&lt;BR /&gt;2 (local) 10.4.1.7 100% ACTIVE FW_B&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-114704&lt;BR /&gt;State change: STANDBY -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: No other ACTIVE members have been found in the cluster&lt;BR /&gt;Event time: Fri Feb 23 03:59:36 2024&lt;/P&gt;&lt;P&gt;Last cluster failover event:&lt;BR /&gt;Transition to new ACTIVE: Member 1 -&amp;gt; Member 2&lt;BR /&gt;Reason: ADMIN_DOWN PNOTE&lt;BR /&gt;Event time: Fri Feb 23 03:59:36 2024&lt;/P&gt;&lt;P&gt;Cluster failover count:&lt;BR /&gt;Failover counter: 1&lt;BR /&gt;Time of counter reset: Fri Feb 23 03:53:33 2024 (reboot)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@northclu12:0]# cd /opt/CPsuite-R81.10/fw1/scripts/&lt;BR /&gt;[Expert@northclu12:0]# ./azure_ha_test.py&lt;BR /&gt;Setting api versions for "ha" solution&lt;BR /&gt;ARM versions are: {&lt;BR /&gt;"resources": "?api-version=2019-07-01"&lt;BR /&gt;}&lt;BR /&gt;Testing if DNS is configured...&lt;BR /&gt;- Primary DNS server is: 168.63.129.16&lt;BR /&gt;Testing if DNS is working...&lt;BR /&gt;- DNS resolving test was successful&lt;BR /&gt;Testing connectivity to login.windows.net:443...&lt;BR /&gt;Testing ClusterXL parameters...&lt;BR /&gt;Testing cluster interface configuration...&lt;BR /&gt;Testing credentials...&lt;BR /&gt;Getting information about the environment...&lt;BR /&gt;Getting information about the VM northclu12...&lt;BR /&gt;Id : /subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/North_CLU_1/providers/Microsoft.Network/networkInterfaces/NorthClu12-eth0&lt;BR /&gt;Subscription : 1efe27ac-5c1b-497b-bc60-6510b07d1c92&lt;BR /&gt;Resource group: North_CLU_1&lt;BR /&gt;Type : Microsoft.Network/networkInterfaces&lt;BR /&gt;Name : NorthClu12-eth0&lt;BR /&gt;Attempting to read - [OK]&lt;BR /&gt;Attempting to write - [Forbidden]&lt;BR /&gt;Error:&lt;BR /&gt;HTTP/1.1 403 Forbidden&lt;BR /&gt;b'{"error":{"code":"LinkedAuthorizationFailed","message":"The client \'08b7ff4e-a0e2-462e-a85c-d5dea401b99c\' with object id \'08b7ff4e-a0e2-462e-a85c-d5dea401b99c\' has permission to perform action \'Microsoft.Network/networkInterfaces/write\' on scope \'/subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/North_CLU_1/providers/Microsoft.Network/networkInterfaces/NorthClu12-eth0\'; however, it does not have permission to perform action(s) \'Microsoft.Network/virtualNetworks/subnets/join/action\' on the linked scope(s) \'/subscriptions/1efe27ac-5c1b-497b-bc60-6510b07d1c92/resourceGroups/ODL-checkpoint_v1-72163-01/providers/Microsoft.Network/virtualNetworks/North-Hub/subnets/VMSS-FrontEnd\' (respectively) or the linked scope(s) are invalid."}}'&lt;BR /&gt;[Expert@northclu12:0]#&lt;BR /&gt;[Expert@northclu12:0]#&lt;BR /&gt;[Expert@northclu12:0]# curl_cli -k google.com&lt;BR /&gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&amp;lt;meta http-equiv="content-type" content="text/html;charset=utf-8"&amp;gt;&lt;BR /&gt;&amp;lt;TITLE&amp;gt;301 Moved&amp;lt;/TITLE&amp;gt;&amp;lt;/HEAD&amp;gt;&amp;lt;BODY&amp;gt;&lt;BR /&gt;&amp;lt;H1&amp;gt;301 Moved&amp;lt;/H1&amp;gt;&lt;BR /&gt;The document has moved&lt;BR /&gt;&amp;lt;A HREF="&lt;A href="http://www.google.com/" target="_blank"&gt;http://www.google.com/&lt;/A&gt;"&amp;gt;here&amp;lt;/A&amp;gt;.&lt;BR /&gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;BR /&gt;[Expert@northclu12:0]# clish -c "show route"&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt;O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),&lt;BR /&gt;A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt;NP - NAT Pool, U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;S 0.0.0.0/0 via 10.4.0.1, eth0, cost 0, age 667&lt;BR /&gt;S 10.0.0.0/8 via 10.4.1.1, eth1, cost 0, age 667&lt;BR /&gt;S 10.4.0.0/16 via 10.4.1.1, eth1, cost 0, age 667&lt;BR /&gt;C 10.4.0.0/24 is directly connected, eth0&lt;BR /&gt;C 10.4.1.0/24 is directly connected, eth1&lt;BR /&gt;C 127.0.0.0/8 is directly connected, lo&lt;BR /&gt;S 168.63.129.16/32 via 10.4.0.1, eth0, cost 0, age 667&lt;BR /&gt;S 169.254.169.254/32 via 10.4.0.1, eth0, cost 0, age 667&lt;BR /&gt;S 172.16.0.0/12 via 10.4.1.1, eth1, cost 0, age 667&lt;BR /&gt;S 192.168.0.0/16 via 10.4.1.1, eth1, cost 0, age 667&lt;BR /&gt;[Expert@northclu12:0]#&lt;BR /&gt;[Expert@northclu12:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-23_18-00-25.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24625i2DEEC34397847267/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-23_18-00-25.png" alt="2024-02-23_18-00-25.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 09:07:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206984#M4628</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-23T09:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206995#M4629</link>
      <description>&lt;P&gt;Let me examine this later carefully and will update.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 10:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/206995#M4629</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T10:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207013#M4630</link>
      <description>&lt;P&gt;Sorry, just drove to the office today, had a quick look...to me, this apepars 100% right. Here is my question...when the problematic fw is active, are you having issues connecting outbound, period, OR only certain apps dont work?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 13:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207013#M4630</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T13:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207073#M4634</link>
      <description>&lt;P&gt;Thanks you for reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To summarize the problem situation, if you fail-over from FW_A to FW_B, all communication will not work.&lt;/P&gt;&lt;P&gt;Backend LB recognizes the fail-over situation and sends traffic to FW_B.&lt;/P&gt;&lt;P&gt;However, the problem situation is that FW_A continues to recognize VIP in the frontend interface.&lt;/P&gt;&lt;P&gt;When the server pings the firewall Real IP and VIP, VIP traffic is delivered to FW_A even though FW_B is Active.&lt;/P&gt;&lt;P&gt;I believe this is the core issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW_B receives traffic from the server and forwards the traffic by NATing the source IP to the VIP, but since FW_A owns the VIP, FW_B cannot receive traffic.&lt;/P&gt;&lt;P&gt;However, when tcpdump is performed on FW_A, there is no traffic received from FW_A either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect that there may be a problem with the API call to Azure to transfer the VIP when fa/ilover is done.&lt;/P&gt;&lt;P&gt;However, I cannot accurately determine whether there is a problem with my settings or a checkpoint bug.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2024 02:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207073#M4634</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-24T02:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207074#M4635</link>
      <description>&lt;P&gt;I dont think its cp bug, sounds like something with config in Azure.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2024 02:26:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207074#M4635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-24T02:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207335#M4638</link>
      <description>&lt;P&gt;I think so too. The probability of it being a checkpoint bug is very small.&lt;/P&gt;&lt;P&gt;I suspect that I may have configured something incorrectly in the Azure environment.&lt;/P&gt;&lt;P&gt;but i don't know what it is&lt;/P&gt;&lt;P&gt;Please let me know if there are any mistakes or additional parts I have set up.&lt;/P&gt;&lt;P&gt;I welcome your response at any time.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 06:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207335#M4638</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-02-28T06:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207476#M4639</link>
      <description>&lt;P&gt;I agree 100%. The only way for me to tell would be if we did remote session...hard to say for sure based on screenshots you sent : - (&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 14:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/207476#M4639</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-29T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/208193#M4663</link>
      <description>&lt;P&gt;Hi Legend&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Found the cause&lt;/P&gt;&lt;P&gt;There was a problem with the application in the environment.&lt;/P&gt;&lt;P&gt;API communication did not occur between Check Point and Azure due to a client secret issue.&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 08:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/208193#M4663</guid>
      <dc:creator>ChoiYunSoo</dc:creator>
      <dc:date>2024-03-08T08:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: I am curious about the fail-over logic in the Azure environment.</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/208200#M4664</link>
      <description>&lt;P&gt;Excellent!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 11:31:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/I-am-curious-about-the-fail-over-logic-in-the-Azure-environment/m-p/208200#M4664</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-08T11:31:12Z</dc:date>
    </item>
  </channel>
</rss>

