<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GCP Cloudguard GW manual-failover in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233654#M5807</link>
    <description>&lt;P&gt;It sounds like you might be using the nic0 external IP for SSH. Could that be the case? &lt;BR /&gt;This is the&amp;nbsp; IP that gets switched between members during failover which is why the SSH connection gets lost. &lt;BR /&gt;Try connecting via SSH using NIC1 instead.&lt;/P&gt;
&lt;P&gt;If that's not the case, then I think Nir's suggestion is a great place to start the investigation.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2024 12:06:55 GMT</pubDate>
    <dc:creator>Rivka-Strilitz</dc:creator>
    <dc:date>2024-11-25T12:06:55Z</dc:date>
    <item>
      <title>GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233640#M5803</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;
&lt;P&gt;I have some questions about HA failover in cloud.&lt;/P&gt;
&lt;P&gt;Is there anybody here who is expert in GCP?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 09:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233640#M5803</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T09:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233642#M5804</link>
      <description>&lt;P&gt;Ask away &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; .&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 10:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233642#M5804</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-11-25T10:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233646#M5805</link>
      <description>&lt;P&gt;Thanks, Great!&lt;/P&gt;
&lt;P&gt;So I have a basic setup:&lt;/P&gt;
&lt;P&gt;Interlnet -&amp;gt; HA cloudguard custer -&amp;gt; client inside.&lt;/P&gt;
&lt;P&gt;I initiate a traffic eg. SSH sesion to the internet. If I do a clusterXL_admin down on the active member, the SSH disconnects.&lt;/P&gt;
&lt;P&gt;It seems the connection does not sync to the standby member.&lt;/P&gt;
&lt;P&gt;Are there any issues around this?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 10:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233646#M5805</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T10:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233648#M5806</link>
      <description>&lt;P&gt;Cluster HA in Google Works like a regular Cluster but there are external Google things you need to check before and after the failover.&lt;/P&gt;
&lt;P&gt;first, on the Internal VPC the default route should point to the ACTIVE member. I guess that works otherwise you wouldn't have any connection.&lt;/P&gt;
&lt;P&gt;When you failover, our GW sends an API call to Google Cloud which tells it to change the default route to the new ACTIVE member.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So first check if this happens. Also check if on the External VPC subnet the "Private Google API access" is enabled.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 11:22:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233648#M5806</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-11-25T11:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233654#M5807</link>
      <description>&lt;P&gt;It sounds like you might be using the nic0 external IP for SSH. Could that be the case? &lt;BR /&gt;This is the&amp;nbsp; IP that gets switched between members during failover which is why the SSH connection gets lost. &lt;BR /&gt;Try connecting via SSH using NIC1 instead.&lt;/P&gt;
&lt;P&gt;If that's not the case, then I think Nir's suggestion is a great place to start the investigation.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:06:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233654#M5807</guid>
      <dc:creator>Rivka-Strilitz</dc:creator>
      <dc:date>2024-11-25T12:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233659#M5808</link>
      <description>&lt;P&gt;Yes, it is set.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233659#M5808</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T12:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233660#M5809</link>
      <description>&lt;P&gt;&lt;SPAN&gt;It sounds like you might be using the nic0 external IP for SSH. Could that be the case?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No, because I NAT to the external IP of the loadbalancer in VPC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akos&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:29:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233660#M5809</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T12:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233662#M5810</link>
      <description>&lt;P&gt;I attach a basic topology&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpc.png" style="width: 173px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28548i0FD5D2288F2A5E8C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vpc.png" alt="vpc.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233662#M5810</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T12:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233663#M5811</link>
      <description>&lt;P&gt;A small clarification:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"It seems the connection does not sync to the standby member."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In case of manual failver (clusterXL_adn down),&amp;nbsp; the packet flow is changed. The outgoing packet flow through the Active member, but the reply packets in this session flow through on the stanby member.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It cause assymentric route.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Akos&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 12:50:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233663#M5811</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-25T12:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: GCP Cloudguard GW manual-failover</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233665#M5812</link>
      <description>&lt;P&gt;when you failover , check the health check on the LB screen.&lt;/P&gt;
&lt;P&gt;does it see the correct member as healthy (should be the ACTIVE member).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also have you configured the right things in order to use an LB ?&lt;/P&gt;
&lt;P&gt;you need to monitor port TCP 8117 and make sure you have this kernel parameter activated on the GWs:&lt;/P&gt;
&lt;P&gt;fw ctl get int cloud_balancer&lt;/P&gt;
&lt;P&gt;should return 8117&lt;/P&gt;
&lt;P&gt;if not add it&lt;/P&gt;
&lt;P&gt;fw ctl set -f int cloud_balancer 8117&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;" lang="en-US"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 13:10:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/GCP-Cloudguard-GW-manual-failover/m-p/233665#M5812</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2024-11-25T13:10:45Z</dc:date>
    </item>
  </channel>
</rss>

