<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cloudguard Azure HA Failover in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239897#M5221</link>
    <description>&lt;P&gt;The problem has been fixed. FYI, I did the following&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;STRONG&gt;$FWDIR/scripts/azure_ha_cli.py reconf&lt;/STRONG&gt;&lt;SPAN&gt;" - no change&lt;BR /&gt;2. Moved the PIP from the old resource group to the new one - no change&lt;BR /&gt;3. Changed to the "new" way in&amp;nbsp;$FWDIR/conf/azure-ha.json - no change&lt;BR /&gt;4. Ran $FWDIR/scripts/azure_ha_cli.py restart - fixed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It might have been a combination of the above but 'reconf' didn't appear to do anything, 'restart' had a pause as if it was doing something before giving me the cursor back..&lt;/P&gt;&lt;P&gt;In the upgrade guide it talks about "image build number". I'm not sure which build number it is referring to. There seem to be at least a couple. Can anyone clarify?&lt;/P&gt;&lt;P&gt;Thanks for all your help.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2025 21:27:42 GMT</pubDate>
    <dc:creator>wanartisan</dc:creator>
    <dc:date>2025-01-28T21:27:42Z</dc:date>
    <item>
      <title>Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239777#M5213</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I inherited an old cluster running R80.40. At some point it developed a problem with HA. Long story, but I needed to rebuild it anyway, so did so. A new build side-by-side on R81.20 but found it too had a problem with HA (the secondary device doesn't pass traffic so you need to failback).&amp;nbsp;&lt;/P&gt;&lt;P&gt;I &lt;SPAN&gt;ran the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;azure_ha_test.py and&amp;nbsp;&lt;/SPAN&gt;found our error message in the&amp;nbsp;&lt;SPAN&gt;sk175023 ATRG: [Forbidden] Error: HTTP/1.1 403 Forbidden" error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We got the permissions update using the gateway managed identities and the test script now runs clean. Yay!&amp;nbsp;Now the actual problem.&lt;/P&gt;&lt;P&gt;The HA template in Azure Marketplace creates 3 public IPs (PIPs), one of which is the "cluster-vip" which gets attached to the active gateway in Azure. As part of the rebuild and migration, I changed this is Azure to our established egress PIP in Azure, which is whitelisted by many external services.&lt;/P&gt;&lt;P&gt;Now when failover occurs, the cluster-vip is changing back to the PIP that was created by the template, and removing the one I selected in Azure and I don't know why.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found a reference to the old PIP in&amp;nbsp;$FWDIR/conf/azure-ha.json (caps below replace actual IPs)&lt;/P&gt;&lt;P&gt;"name": "cluster-vip"&amp;nbsp;&lt;BR /&gt;"addr": "PRIVATE IP"&lt;BR /&gt;"pub": "TEMPLATE_PIP"&lt;/P&gt;&lt;P&gt;So I changed this to&lt;/P&gt;&lt;P&gt;&amp;nbsp;"name": "cluster-vip"&amp;nbsp;&lt;BR /&gt;"addr": "PRIVATE IP"&lt;BR /&gt;"pub": "ESTABLISHED_EGRESS_PIP"&lt;/P&gt;&lt;P&gt;I tested the failover again but the same thing is happening. Does anyone know where the command to use the template cluster-vip is coming from?&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 06:20:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239777#M5213</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2025-01-28T06:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239789#M5214</link>
      <description>&lt;P&gt;Follow the steps in the UPGRADE section of the Azure HA admin guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Upgrade.htm?TocPath=Upgrade%7C_____0#Upgrading_a_Check_Point_CloudGuard_Network_Security_High_Availability_Solution" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Cluster/Content/Topics-Azure-HA/Upgrade.htm?TocPath=Upgrade%7C_____0#Upgrading_a_Check_Point_CloudGuard_Network_Security_High_Availability_Solution&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239789#M5214</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2025-01-28T09:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239790#M5215</link>
      <description>&lt;P&gt;This makes me think of the HCP tool and if enhancements in that, specifically for CloudGuard, could help resolve issues like this in the complex web that is the public cloud.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229324#M38304" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229324#M38304&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239790#M5215</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-01-28T09:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239792#M5216</link>
      <description>&lt;P&gt;That looks perfect. I hadn't seen that. I'll try again the "new" way and report back.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239792#M5216</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2025-01-28T09:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239798#M5217</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110029"&gt;@wanartisan&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;The admin guide's upgrade section explains how to use the old cluster-vip, and you are trying to use a different public IP as VIP,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In this case, here’s what you need to do:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to the active member’s ETH-0 NIC resource in the Azure portal.&lt;/LI&gt;
&lt;LI&gt;Navigate to &lt;STRONG&gt;Settings &amp;gt; IP configurations&lt;/STRONG&gt; and replace the Public IP address of the cluster-vip with the new address (see attached screenshot).&lt;/LI&gt;
&lt;LI&gt;Edit the azure_ha.json file on &lt;STRONG&gt;both&lt;/STRONG&gt; members (as you’ve done with &lt;SPAN&gt;"pub": "ESTABLISHED_EGRESS_PIP"&lt;/SPAN&gt;).&lt;/LI&gt;
&lt;LI&gt;Run the following command on &lt;STRONG&gt;both&lt;/STRONG&gt; members to apply the updated configuration from azure_ha.json: "$FWDIR/scripts/azure_ha_cli.py restart"&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's it, failover should work with the new Public IP&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 09:55:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239798#M5217</guid>
      <dc:creator>yairra</dc:creator>
      <dc:date>2025-01-28T09:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239824#M5219</link>
      <description>&lt;P&gt;sk175023 ATRG suggests&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;$FWDIR/scripts/azure_ha_cli.py reconf&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;Is this correct? I will be testing later.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239824#M5219</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2025-01-28T14:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239828#M5220</link>
      <description>&lt;P&gt;yes, do that.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:04:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239828#M5220</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2025-01-28T14:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239897#M5221</link>
      <description>&lt;P&gt;The problem has been fixed. FYI, I did the following&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;STRONG&gt;$FWDIR/scripts/azure_ha_cli.py reconf&lt;/STRONG&gt;&lt;SPAN&gt;" - no change&lt;BR /&gt;2. Moved the PIP from the old resource group to the new one - no change&lt;BR /&gt;3. Changed to the "new" way in&amp;nbsp;$FWDIR/conf/azure-ha.json - no change&lt;BR /&gt;4. Ran $FWDIR/scripts/azure_ha_cli.py restart - fixed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It might have been a combination of the above but 'reconf' didn't appear to do anything, 'restart' had a pause as if it was doing something before giving me the cursor back..&lt;/P&gt;&lt;P&gt;In the upgrade guide it talks about "image build number". I'm not sure which build number it is referring to. There seem to be at least a couple. Can anyone clarify?&lt;/P&gt;&lt;P&gt;Thanks for all your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 21:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239897#M5221</guid>
      <dc:creator>wanartisan</dc:creator>
      <dc:date>2025-01-28T21:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudguard Azure HA Failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239959#M5222</link>
      <description>&lt;P&gt;CC&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37178"&gt;@Amir_Senn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 12:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Cloudguard-Azure-HA-Failover/m-p/239959#M5222</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-01-29T12:41:49Z</dc:date>
    </item>
  </channel>
</rss>

