<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management HA over VPN in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/97383#M78377</link>
    <description>&lt;P&gt;Management traffic itself is encrypted already.&lt;BR /&gt;Excluding management traffic from implied rules is NOT recommended.&lt;BR /&gt;See this thread and the linked discussion:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Managing-a-gateway-over-VPN/m-p/13674#M2423" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Managing-a-gateway-over-VPN/m-p/13674#M2423&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2020 22:15:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-09-23T22:15:56Z</dc:date>
    <item>
      <title>Management HA over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/97218#M78376</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;R80.30. Can you set up Management HA if the management servers are on different sites and communications goes over VPN.&lt;/P&gt;&lt;P&gt;It seems the traffic between the two management server hits the implied rules and doesn't get encrypted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Francis&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 19:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/97218#M78376</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-09-21T19:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Management HA over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/97383#M78377</link>
      <description>&lt;P&gt;Management traffic itself is encrypted already.&lt;BR /&gt;Excluding management traffic from implied rules is NOT recommended.&lt;BR /&gt;See this thread and the linked discussion:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Management-Topics/Managing-a-gateway-over-VPN/m-p/13674#M2423" target="_blank"&gt;https://community.checkpoint.com/t5/General-Management-Topics/Managing-a-gateway-over-VPN/m-p/13674#M2423&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 22:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/97383#M78377</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-23T22:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Management HA over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99312#M78378</link>
      <description>&lt;P&gt;thanks. I guess the solution would be to follow this sk &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39740" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39740&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My only issue is that the management HA is in Azure behind a CloudGuard cluster and I just can't figure out how to properly do the NATing on that side. Anyone knows of Guides or Docs to do that?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 15:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99312#M78378</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-10-16T15:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Management HA over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99324#M78379</link>
      <description>&lt;P&gt;Are you defining the object for the HA management in terms of the NAT address?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 20:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99324#M78379</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-16T20:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Management HA over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99708#M78380</link>
      <description>&lt;P&gt;Not sure I understand your question.&lt;/P&gt;&lt;P&gt;For the management HA Properties- General tab I used the private address. In the NAT tab I assigned a static NAT with the external IP of the management HA (did not apply to Security Gateway control connections)&lt;/P&gt;&lt;P&gt;I created an object representing the NATed IP of the management HA.&lt;/P&gt;&lt;P&gt;I created Manual Static NAT rules for communication between NATed (external) IP addresses of Management servers.&lt;/P&gt;&lt;P&gt;For the NATing of the management HA, I’ve tried using the Public IP assigned to the management HA by Azure. I also tried using the public IP of the frontend load balancer and adding a load balancing rule. I also tried assigning a second public IP to the load balancer and Used this IP for NATing (along with a load balancing rule).&lt;/P&gt;&lt;P&gt;None of these worked. Although I can see the properly NATed connections leaving the gateways that protect the active management server I never see anything at all reaching the Cloudguard Gateway.&lt;/P&gt;&lt;P&gt;Looking at the Effective Security Rules for the Management HA interface, I don’t see any issues with the NSG. I think I’m missing something on the Azure side of things but haven’t been able to find it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 13:24:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Management-HA-over-VPN/m-p/99708#M78380</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2020-10-21T13:24:03Z</dc:date>
    </item>
  </channel>
</rss>

