<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What does the Azure Contributor role allow a CloudGuard HA cluster to do on a NSG? in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/What-does-the-Azure-Contributor-role-allow-a-CloudGuard-HA/m-p/211746#M4720</link>
    <description>&lt;P&gt;Hi Arned,&lt;/P&gt;
&lt;P&gt;The contributor role is required for a cluster in order to move the VIP of the cluster between members during a failover.&lt;/P&gt;
&lt;P&gt;As for the risks involved, at the end of the day you are giving the cluster members the following permissions:&lt;BR /&gt;&lt;SPAN&gt;"Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries"&lt;BR /&gt;&lt;/SPAN&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles" target="_blank"&gt;Azure built-in roles - Azure RBAC | Microsoft Learn&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Hope this is the information you needed.&lt;/P&gt;
&lt;P&gt;Edan&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2024 13:54:46 GMT</pubDate>
    <dc:creator>Edan_Leventhal</dc:creator>
    <dc:date>2024-04-18T13:54:46Z</dc:date>
    <item>
      <title>What does the Azure Contributor role allow a CloudGuard HA cluster to do on a NSG?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/What-does-the-Azure-Contributor-role-allow-a-CloudGuard-HA/m-p/211745#M4719</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In the manual at step 1. you are being notified that the new HA cluster you deploy needs a contributor role on the existing NSG.&lt;/P&gt;&lt;P&gt;Our customer is wondering what risks are involved in allowing this contributor role onto the existing NSG.&lt;/P&gt;&lt;P&gt;Otherwise said, what functions (risks) are involved?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CloudGuard Network for Azure High Availability Cluster Deployment Guide&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Workflow for Setting Up a High Availability Cluster in Azure:&lt;/P&gt;&lt;P&gt;Step 1: Deploy with a Template in Azure&lt;/P&gt;&lt;P&gt;If you select an existing NSG from a different Resource Group, create&amp;nbsp;&lt;STRONG&gt;roleAssignment&amp;nbsp;on the NSG with contributor permissions&lt;/STRONG&gt; for the Cluster’s managed identity.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 13:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/What-does-the-Azure-Contributor-role-allow-a-CloudGuard-HA/m-p/211745#M4719</guid>
      <dc:creator>Arend</dc:creator>
      <dc:date>2024-04-18T13:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: What does the Azure Contributor role allow a CloudGuard HA cluster to do on a NSG?</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/What-does-the-Azure-Contributor-role-allow-a-CloudGuard-HA/m-p/211746#M4720</link>
      <description>&lt;P&gt;Hi Arned,&lt;/P&gt;
&lt;P&gt;The contributor role is required for a cluster in order to move the VIP of the cluster between members during a failover.&lt;/P&gt;
&lt;P&gt;As for the risks involved, at the end of the day you are giving the cluster members the following permissions:&lt;BR /&gt;&lt;SPAN&gt;"Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries"&lt;BR /&gt;&lt;/SPAN&gt;(&lt;A href="https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles" target="_blank"&gt;Azure built-in roles - Azure RBAC | Microsoft Learn&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;Hope this is the information you needed.&lt;/P&gt;
&lt;P&gt;Edan&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 13:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/What-does-the-Azure-Contributor-role-allow-a-CloudGuard-HA/m-p/211746#M4720</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2024-04-18T13:54:46Z</dc:date>
    </item>
  </channel>
</rss>

