<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Health Check Fails on AWS External Application Load Balancer for a Security Gateway in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184330#M98</link>
    <description>&lt;P&gt;I have attached an external application load balancer to my security gateway in AWS. The health check on port 80 is always failing even after changing the health settings according to&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838/highlight/true#M949" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838/highlight/true#M949&lt;/A&gt;. I am using R81.10 version of gateway. Is there any solution to this problem?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2023 09:15:15 GMT</pubDate>
    <dc:creator>mehtasiddha</dc:creator>
    <dc:date>2023-06-20T09:15:15Z</dc:date>
    <item>
      <title>Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184330#M98</link>
      <description>&lt;P&gt;I have attached an external application load balancer to my security gateway in AWS. The health check on port 80 is always failing even after changing the health settings according to&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838/highlight/true#M949" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/AWS-LB-sandwich-does-not-come-up-healthy-in-some-cases/m-p/65838/highlight/true#M949&lt;/A&gt;. I am using R81.10 version of gateway. Is there any solution to this problem?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 09:15:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184330#M98</guid>
      <dc:creator>mehtasiddha</dc:creator>
      <dc:date>2023-06-20T09:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184441#M99</link>
      <description>&lt;P&gt;make sure you have all the right Access and NAT rules to access the application from the Load Balancers.&lt;/P&gt;
&lt;P&gt;they need to health check the application.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 12:26:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184441#M99</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-06-21T12:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184460#M100</link>
      <description>&lt;P&gt;The application load balancer is in front of the gateway listening on port 80 and forwarding the traffic to the gateway. But the health checks at the gateway are failing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 17:21:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184460#M100</guid>
      <dc:creator>mehtasiddha</dc:creator>
      <dc:date>2023-06-21T17:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184489#M101</link>
      <description>&lt;P&gt;the GW needs to forward the port 80 health checks to the Application . the GW is not listening on port 80.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 04:35:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184489#M101</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-06-22T04:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184692#M103</link>
      <description>&lt;P&gt;But now I am facing a new issue, the http traffic is not being replied back, I am receiving connection timeout error while trying to the reach the internal servers running on port 80 via the external lb dns attached to the gateway. What could be causing the connection timeout error?&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 06:20:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184692#M103</guid>
      <dc:creator>mehtasiddha</dc:creator>
      <dc:date>2023-06-24T06:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184702#M104</link>
      <description>&lt;P&gt;first check access to the web server by login in one of the FW instances and curl or telnet the WEB server. if it works run fw monitor / cppcap on the GW and check if the traffic is coming in and out of the GW , doing NAT etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 04:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184702#M104</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2023-06-25T04:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Health Check Fails on AWS External Application Load Balancer for a Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184706#M106</link>
      <description>&lt;P&gt;If you have an ALB as a frontend to one firewall in each AZ...then read further.&lt;/P&gt;&lt;P&gt;Did you create a source NAT rule for the ALB subnet so it comes from a IP not in your VPC CIDR? A different IP for each AZ subnet which you would then have a route on the app subnet that routes the traffic to each firewalls ENI in each AZ. Also, your firewall rule will have to allow the inbound traffic.&lt;/P&gt;&lt;P&gt;Also...&lt;/P&gt;&lt;P&gt;1. Check the firewalls SG and subnet NACL attached to the subnet of the ALB...Need a SG rule to allow for the health check&lt;/P&gt;&lt;P&gt;2. Check the SG, subnet NACL and Subnet route table attached to the firewalls second interface in the routing subnet.&lt;/P&gt;&lt;P&gt;3. Check the SG, subnet NACL and Subnet Route Table where the application is located. Also, you need to route return traffic to the firewalls internal ENI.&lt;/P&gt;&lt;P&gt;4. You have to add static routes to the firewalls as well to route to the backend subnets since the firewalls do not know about the AWS routes. Example, to get to 192.168.2.0/25 GW 192.168.2.1 and obviously different GW for a firewall on another subnet.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 05:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Health-Check-Fails-on-AWS-External-Application-Load-Balancer-for/m-p/184706#M106</guid>
      <dc:creator>JoSec</dc:creator>
      <dc:date>2023-06-25T05:51:37Z</dc:date>
    </item>
  </channel>
</rss>

