<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard cluster VPN termination fails after patching in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222777#M4918</link>
    <description>&lt;P&gt;Yes. It seems that after patching one of the gateways in the cluster ends up on a 'bad' host. If we fail over the cluster to the other gateway service is restored. If we fail back to the original gateway on the original host we lose service again. Redploying the bad gateway to a new host restores service again.&lt;/P&gt;
&lt;P&gt;We have seen this behaviour 3 times now, with 2 different clusters in 2 different subscriptions&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2024 20:47:38 GMT</pubDate>
    <dc:creator>Scott_Paisley</dc:creator>
    <dc:date>2024-08-05T20:47:38Z</dc:date>
    <item>
      <title>Cloudguard cluster VPN termination fails after patching</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222720#M4915</link>
      <description>&lt;P&gt;This is a follow on from a previous question about Linux agent versions&lt;/P&gt;
&lt;P&gt;We have several cloudguard clusters in Azure. We have VPN tunnels to each of them from various on-prem gateways, and also between them.&lt;/P&gt;
&lt;P&gt;When we patch the gateways, they obviously reboot.&lt;/P&gt;
&lt;P&gt;Several times now we have found that after patching, the VPN tunnels fail from one set of gateways (always a different set) to one of the gateways in the cluster. failing over the cluster restores service.&lt;/P&gt;
&lt;P&gt;The solution so far has been to redeploy the failing gateway onto a different Azure host.&lt;/P&gt;
&lt;P&gt;Has anyone else seen similar behaviour?&lt;/P&gt;
&lt;P&gt;We are using our IP space advertised by Microsoft fro each gateway. Could that we relevant?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 10:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222720#M4915</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-08-05T10:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard cluster VPN termination fails after patching</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222776#M4917</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15325"&gt;@Scott_Paisley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to clarify, you mention "failing over the cluster restores service" but then you also mention that you need to redeploy the failing gateway onto a different Azure host.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you saying that if you fail back to the other cluster member in Azure it still does not re-establish the VPN tunnel until completely redeployed?&lt;/P&gt;
&lt;P&gt;BR!&lt;/P&gt;
&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222776#M4917</guid>
      <dc:creator>Jeff_Engel</dc:creator>
      <dc:date>2024-08-05T20:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard cluster VPN termination fails after patching</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222777#M4918</link>
      <description>&lt;P&gt;Yes. It seems that after patching one of the gateways in the cluster ends up on a 'bad' host. If we fail over the cluster to the other gateway service is restored. If we fail back to the original gateway on the original host we lose service again. Redploying the bad gateway to a new host restores service again.&lt;/P&gt;
&lt;P&gt;We have seen this behaviour 3 times now, with 2 different clusters in 2 different subscriptions&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 20:47:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-cluster-VPN-termination-fails-after-patching/m-p/222777#M4918</guid>
      <dc:creator>Scott_Paisley</dc:creator>
      <dc:date>2024-08-05T20:47:38Z</dc:date>
    </item>
  </channel>
</rss>

