<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with Azure platform communication (168.63.129.16) in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154124#M941</link>
    <description>&lt;P&gt;Having an issue communicating to the Azure platform IP 168.63.129.16. When I do a&amp;nbsp;&lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; the errors on the console stop and the VM in Azure Portal stops reporting that the Azure agent is not working. However, I tried the following in my firewall policy and none solved the issue:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Allow HTTP, DNS and TCP\32526 from cluster object to&amp;nbsp;168.63.129.16.&lt;/LI&gt;&lt;LI&gt;Bypass HTTPS inspection (shouldn't have an effect since communication to Azure platform is HTTP)&lt;/LI&gt;&lt;LI&gt;Applied new policy package with no Threat Prevention.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Edit: The default routes on the gateway VMs have not been changed.&lt;/P&gt;&lt;P&gt;Some errors seen on the command line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022/07/28 12:50:45.964617 WARNING ExtHandler [PERIODIC] [IMDS_CONNECTION_ERROR] Unable to connect to IMDS endpoint 169.254.169.254
2022/07/28 12:52:17.057629 WARNING ExtHandler [PERIODIC] [IMDS_CONNECTION_ERROR] Unable to connect to IMDS endpoint 168.63.129.16
2022/07/28 12:53:48.151508 WARNING ExtHandler HealthService: could not report observations: [HttpError] [HTTP Failed] POST http://168.63.129.16:80/HealthService -- IOError timed out -- 6 attempts made
2022/07/28 12:54:19.489577 ERROR ExtHandler ProtocolError processing goal state, giving up [[ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] GET http://168.63.129.16/machine/?comp=goalstate -- IOError timed out -- 6 attempts made]
2022/07/28 12:54:19.491258 WARNING ExtHandler Exception retrieving extension handlers: [ProtocolError] Exceeded max retry updating goal state
2022/07/28 12:54:19.492048 ERROR ExtHandler Event: name=WALinuxAgent, op=ExtensionProcessing, message=Exception retrieving extension handlers: [ProtocolError] Exceeded max retry updating goal state [&amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/ga/exthandlers.py, line 230 in run&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 153 in get_ext_handlers&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 112 in update_goal_state&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 837 in update_goal_state&amp;gt;], duration=0
2022/07/28 12:56:19.317619 ERROR ExtHandler [ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] POST http://168.63.129.16/machine?comp=telemetrydata -- IOError timed out -- 6 attempts made
2022/07/28 13:01:02.607474 WARNING ExtHandler HealthService: could not report observations: [HttpError] [HTTP Failed] POST http://168.63.129.16:80/HealthService -- IOError timed out -- 6 attempts made
2022/07/28 13:03:33.775584 ERROR ExtHandler [ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] POST http://168.63.129.16/machine?comp=telemetrydata -- IOError timed out -- 6 attempts made
2022/07/28 13:03:52.867623 ERROR ExtHandler ProtocolError processing goal state, giving up [[ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] GET http://168.63.129.16/machine/?comp=goalstate -- IOError timed out -- 6 attempts made]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jul 2022 18:53:50 GMT</pubDate>
    <dc:creator>RickyDan</dc:creator>
    <dc:date>2022-07-28T18:53:50Z</dc:date>
    <item>
      <title>Issue with Azure platform communication (168.63.129.16)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154124#M941</link>
      <description>&lt;P&gt;Having an issue communicating to the Azure platform IP 168.63.129.16. When I do a&amp;nbsp;&lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; the errors on the console stop and the VM in Azure Portal stops reporting that the Azure agent is not working. However, I tried the following in my firewall policy and none solved the issue:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Allow HTTP, DNS and TCP\32526 from cluster object to&amp;nbsp;168.63.129.16.&lt;/LI&gt;&lt;LI&gt;Bypass HTTPS inspection (shouldn't have an effect since communication to Azure platform is HTTP)&lt;/LI&gt;&lt;LI&gt;Applied new policy package with no Threat Prevention.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Edit: The default routes on the gateway VMs have not been changed.&lt;/P&gt;&lt;P&gt;Some errors seen on the command line:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2022/07/28 12:50:45.964617 WARNING ExtHandler [PERIODIC] [IMDS_CONNECTION_ERROR] Unable to connect to IMDS endpoint 169.254.169.254
2022/07/28 12:52:17.057629 WARNING ExtHandler [PERIODIC] [IMDS_CONNECTION_ERROR] Unable to connect to IMDS endpoint 168.63.129.16
2022/07/28 12:53:48.151508 WARNING ExtHandler HealthService: could not report observations: [HttpError] [HTTP Failed] POST http://168.63.129.16:80/HealthService -- IOError timed out -- 6 attempts made
2022/07/28 12:54:19.489577 ERROR ExtHandler ProtocolError processing goal state, giving up [[ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] GET http://168.63.129.16/machine/?comp=goalstate -- IOError timed out -- 6 attempts made]
2022/07/28 12:54:19.491258 WARNING ExtHandler Exception retrieving extension handlers: [ProtocolError] Exceeded max retry updating goal state
2022/07/28 12:54:19.492048 ERROR ExtHandler Event: name=WALinuxAgent, op=ExtensionProcessing, message=Exception retrieving extension handlers: [ProtocolError] Exceeded max retry updating goal state [&amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/ga/exthandlers.py, line 230 in run&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 153 in get_ext_handlers&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 112 in update_goal_state&amp;gt;, &amp;lt;FrameSummary file /usr/lib/waagent/azurelinuxagent/common/protocol/wire.py, line 837 in update_goal_state&amp;gt;], duration=0
2022/07/28 12:56:19.317619 ERROR ExtHandler [ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] POST http://168.63.129.16/machine?comp=telemetrydata -- IOError timed out -- 6 attempts made
2022/07/28 13:01:02.607474 WARNING ExtHandler HealthService: could not report observations: [HttpError] [HTTP Failed] POST http://168.63.129.16:80/HealthService -- IOError timed out -- 6 attempts made
2022/07/28 13:03:33.775584 ERROR ExtHandler [ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] POST http://168.63.129.16/machine?comp=telemetrydata -- IOError timed out -- 6 attempts made
2022/07/28 13:03:52.867623 ERROR ExtHandler ProtocolError processing goal state, giving up [[ProtocolError] [Wireserver Exception] [HttpError] [HTTP Failed] GET http://168.63.129.16/machine/?comp=goalstate -- IOError timed out -- 6 attempts made]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 18:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154124#M941</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-07-28T18:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure platform communication (168.63.129.16)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154127#M942</link>
      <description>&lt;P&gt;What do the drop logs look like, have you tried ANY as the source?&lt;/P&gt;
&lt;P&gt;Do you have the fwkern.conf entries per&amp;nbsp;&lt;SPAN&gt;sk171584?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 21:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154127#M942</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-28T21:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure platform communication (168.63.129.16)</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154129#M943</link>
      <description>&lt;P&gt;I confirmed the file is configured correctly. It works when I unload the firewall policy so I believe something broke it when turning on blades and configuring security policy.&lt;/P&gt;&lt;P&gt;Output of&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;fw ctl zdebug -m cluster cloud&lt;/SPAN&gt;&lt;/STRONG&gt; shows that only the active member is replying to health probes but the active member is only replying on eth1. It is not replying on eth0.&lt;/P&gt;&lt;P&gt;Also, how do I check the active/passive state on Cloudguard since &lt;STRONG&gt;cphaprob stat&lt;/STRONG&gt; is not relevant?&lt;/P&gt;&lt;P&gt;The built-in static route to 168.63.129.16 is via eth0 tho.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 21:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Issue-with-Azure-platform-communication-168-63-129-16/m-p/154129#M943</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-07-28T21:56:18Z</dc:date>
    </item>
  </channel>
</rss>

