<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CloudGuard HA IAAS Deployment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/134116#M20053</link>
    <description>&lt;P&gt;I've added the cluster to smart console and pushed a policy to the gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateways are now in HA mode.&lt;/P&gt;&lt;P&gt;However, the azure-ha.json remains unpopulated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also HA is not working correctly.&lt;BR /&gt;&lt;BR /&gt;On the cli, when the primary is active I can SSH to it via the cluster IP. If I reboot the primary (active) and try to SSH in to the secondary using the the cluster IP I cannot connect, even though the cluster has successfully failed over to the standby (now active). Once the primary has are booted and reenters the cluster in standby mode, I still cannot connect using the cluster IP. If I reboot the secondary (active), the cluster fails over and I can connect to the primary (now active) using the cluster IP. So I can only connect to the cluster using the cluster VIP when the primary is active.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Nov 2021 04:15:09 GMT</pubDate>
    <dc:creator>Simon_Macpherso</dc:creator>
    <dc:date>2021-11-16T04:15:09Z</dc:date>
    <item>
      <title>CloudGuard HA IAAS Deployment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/133676#M19908</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I've deployed a&amp;nbsp;CloudGuard IaaS HA cluster to Azure public cloud using Terraform.&lt;/P&gt;&lt;P class=""&gt;I’ve based my Terraform code on the latest HA configuration templates available on the CheckpointSW repo.&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://ct-url-protection.portal.checkpoint.com/v1/load/lzmT-QAbHT3C9_5aaR_GFfFnCFxwIyRuocePT0wRgyI0LENTAuJegeJqwch2tkqmB1K_T_xKLiEcMOJpgRnaZ6XhKDZG_ig6uzDNHlazUDJknJii12SbmFMX7QB-CiJO8dQdJQeqBC29Kl92GEvU_EiTh2bOScufpzOWI3qeOYigJTt020GyxBSwWpy4H4QkQT_0t3vVsgdDob7VCmpG-lNSdR5pbTPsgQ0kJpVc5Shte6fGjx90fyzex0budq1t3FOybxkVuva_osHRC7u6SSHOig9lj2oKMgjahtvPVx4bPIb-TOwACJ-5pgeOg5dTIzrMpNSV9MsolBWIZ_r3akVPgUIYpx9t03hfM6qpL9_o0yIsxdtEjl223Dxx069aZEc_dVoFcAKMU8WmuF445h2dz670" target="_blank" rel="noopener"&gt;https://github.com/CheckPointSW/CloudGuardIaaS/tree/master/terraform/azure/high-availability-new-vnet&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;I notice after deployment that the azure-ha.json file has not been updated with the required keys values.&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Simon_Macpherso_2-1636518509456.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14236iBE0D1F62D469236B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Simon_Macpherso_2-1636518509456.png" alt="Simon_Macpherso_2-1636518509456.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;Running azure_ha_test.py reports missing attributes.&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Simon_Macpherso_0-1636518491399.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14234iBE072010548CCCAF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Simon_Macpherso_0-1636518491399.png" alt="Simon_Macpherso_0-1636518491399.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;The cloud-init.sh script exists in the root module and custom_data in os_profile is references the correct path i.e. custom_data = templatefile("${path.module}/cloud-init.sh"&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should the azure-ha.json file contain the relevant values immediately after deployment or are these values added to the file once the gateways have been added and configured on the management server and received policy? I haven't added the gateways to a new cluster on the management server yet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 04:29:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/133676#M19908</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2021-11-10T04:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard HA IAAS Deployment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/133683#M19910</link>
      <description>&lt;P&gt;You're not officially in HA mode until you add the gateways and push policy, so I would presume these get added once that's happened.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 05:45:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/133683#M19910</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-10T05:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard HA IAAS Deployment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/134116#M20053</link>
      <description>&lt;P&gt;I've added the cluster to smart console and pushed a policy to the gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateways are now in HA mode.&lt;/P&gt;&lt;P&gt;However, the azure-ha.json remains unpopulated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also HA is not working correctly.&lt;BR /&gt;&lt;BR /&gt;On the cli, when the primary is active I can SSH to it via the cluster IP. If I reboot the primary (active) and try to SSH in to the secondary using the the cluster IP I cannot connect, even though the cluster has successfully failed over to the standby (now active). Once the primary has are booted and reenters the cluster in standby mode, I still cannot connect using the cluster IP. If I reboot the secondary (active), the cluster fails over and I can connect to the primary (now active) using the cluster IP. So I can only connect to the cluster using the cluster VIP when the primary is active.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 04:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-HA-IAAS-Deployment/m-p/134116#M20053</guid>
      <dc:creator>Simon_Macpherso</dc:creator>
      <dc:date>2021-11-16T04:15:09Z</dc:date>
    </item>
  </channel>
</rss>

