<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Solved: Servers behind Azure Cloudguard HA do not have internet access in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157880#M804</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cloudguard.png" style="width: 550px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17869i31192A1399859D60/image-size/large?v=v2&amp;amp;px=999" role="button" title="cloudguard.png" alt="cloudguard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basic network diagram as shown in image. Cluster configuration below:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In network management, eth1 (backend) leads to server subnet.&lt;/LI&gt;&lt;LI&gt;In firewall policy, server subnet has internet access.&lt;/LI&gt;&lt;LI&gt;In NAT policy, server subnet is SNAT'd to frontend private cluster IP address for internet traffic.&lt;/LI&gt;&lt;LI&gt;In Gaia OS, static route to server subnet via backend subnet (azure default gateway IP address).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The firewall cluster itself has internet access - I can ping and curl public IP addresses and websites. The logs also show that server traffic is hitting the firewall and being accepted and NAT'd.&lt;/P&gt;&lt;P&gt;Edit: This is version R81.10 template and tcpdump on eth0 shows SNAT'd traffic leaving the interface but no return traffic.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solved:&lt;/STRONG&gt; This was actually a HA issue. Firewall2 was the active when the internet was not working. I booted up only Firewall1 this morning (I shutdown all VMs overnight) and the internet was working for the servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I gave contributor permissions to the automatically created managed identities on the VNET where the firewalls are located and also on the resource group for my IP prefixes (&lt;SPAN&gt;$FWDIR/scripts/azure_ha_test.py complained about this).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Sep 2022 16:27:01 GMT</pubDate>
    <dc:creator>RickyDan</dc:creator>
    <dc:date>2022-09-23T16:27:01Z</dc:date>
    <item>
      <title>Solved: Servers behind Azure Cloudguard HA do not have internet access</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157880#M804</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cloudguard.png" style="width: 550px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17869i31192A1399859D60/image-size/large?v=v2&amp;amp;px=999" role="button" title="cloudguard.png" alt="cloudguard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basic network diagram as shown in image. Cluster configuration below:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;In network management, eth1 (backend) leads to server subnet.&lt;/LI&gt;&lt;LI&gt;In firewall policy, server subnet has internet access.&lt;/LI&gt;&lt;LI&gt;In NAT policy, server subnet is SNAT'd to frontend private cluster IP address for internet traffic.&lt;/LI&gt;&lt;LI&gt;In Gaia OS, static route to server subnet via backend subnet (azure default gateway IP address).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The firewall cluster itself has internet access - I can ping and curl public IP addresses and websites. The logs also show that server traffic is hitting the firewall and being accepted and NAT'd.&lt;/P&gt;&lt;P&gt;Edit: This is version R81.10 template and tcpdump on eth0 shows SNAT'd traffic leaving the interface but no return traffic.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solved:&lt;/STRONG&gt; This was actually a HA issue. Firewall2 was the active when the internet was not working. I booted up only Firewall1 this morning (I shutdown all VMs overnight) and the internet was working for the servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I gave contributor permissions to the automatically created managed identities on the VNET where the firewalls are located and also on the resource group for my IP prefixes (&lt;SPAN&gt;$FWDIR/scripts/azure_ha_test.py complained about this).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 16:27:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157880#M804</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-09-23T16:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Servers behind Azure Cloudguard HA do not have internet access</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157882#M805</link>
      <description>&lt;P&gt;Version/JHF?&lt;BR /&gt;What do you see in logs?&lt;BR /&gt;What do you see in tcpdump or fw monitor?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 22:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157882#M805</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-22T22:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Servers behind Azure Cloudguard HA do not have internet access</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157889#M806</link>
      <description>&lt;P&gt;This is the R81.10 template and&amp;nbsp;&lt;SPAN&gt;The logs also show that server traffic is hitting the firewall and being accepted and NAT'd. When I did a tcpdump on eth0, I saw SNAT'd traffic going towards the internet but no return traffic. I did not do a fw monitor.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 02:01:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Servers-behind-Azure-Cloudguard-HA-do-not-have-internet/m-p/157889#M806</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-09-23T02:01:40Z</dc:date>
    </item>
  </channel>
</rss>

