<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why doesn't Checkpoint failover without manual interaction in Azure? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14075#M96348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have setup checkpoint cluster in Azure using the new template (using cluster-vip) and it seems during the failover Checkpoint is not able to move the VIP until I manually release it from the Loadbalancer. Manual release means I disassociate it from the machine. As soon as I do it the failover continues and finishes successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without loadbalancer everything is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise. Possible bug in the python script?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Apr 2018 06:24:35 GMT</pubDate>
    <dc:creator>Attila_Bakos</dc:creator>
    <dc:date>2018-04-10T06:24:35Z</dc:date>
    <item>
      <title>Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14075#M96348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have setup checkpoint cluster in Azure using the new template (using cluster-vip) and it seems during the failover Checkpoint is not able to move the VIP until I manually release it from the Loadbalancer. Manual release means I disassociate it from the machine. As soon as I do it the failover continues and finishes successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without loadbalancer everything is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise. Possible bug in the python script?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 06:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14075#M96348</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-04-10T06:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14076#M96349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have you installed vSec controller on your Mgmt &amp;nbsp;server?&lt;/P&gt;&lt;P&gt;what do you get when you run&amp;nbsp;$FWDIR/scripts/azure_ha_test.py &amp;nbsp;?&lt;/P&gt;&lt;P&gt;please note.&amp;nbsp;It takes 3-5 minutes for UDRs to get updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can reference SK110194 for the step by step.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 17:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14076#M96349</guid>
      <dc:creator>Neil_ZInk</dc:creator>
      <dc:date>2018-04-10T17:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14077#M96350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Neil Zink,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We deployed the cluster from Azure check point cluster template based on the reference you provided.&lt;/P&gt;&lt;P&gt;We do not use vsec controller and it wasn't a requirement on the reference you provided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failover modifies the internal and external routes as well. When it tries to move the cluster-vip from NODE1 to NODE2 it fails because the loadbalancer nat rule locks the cluster-vip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could easily reproduce with a fresh install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 09:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14077#M96350</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-04-11T09:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14078#M96351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you get when you run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# $FWDIR/scripts/azure_ha_test.py&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 12:56:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14078#M96351</guid>
      <dc:creator>Neil_ZInk</dc:creator>
      <dc:date>2018-04-11T12:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14079#M96352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I missed to answer that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All tests were successful!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 13:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14079#M96352</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-04-11T13:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14080#M96353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you verify the front-end Load balancer Is pointing to public IP for each gateway vs the VIP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2018 13:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14080#M96353</guid>
      <dc:creator>Neil_ZInk</dc:creator>
      <dc:date>2018-04-13T13:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14081#M96354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;You're not alone!&amp;nbsp; I've got the same issue on a new template gateway deployed about 6-Apr-2018.&amp;nbsp; Working through support at both CP and MS on this. &amp;nbsp; I've been able to reproduce on USEAST new deploys several times in my test subscriptions. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed&amp;nbsp;&lt;SPAN style="color: #000000; font-family: DIN; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;sk110194&lt;/SPAN&gt; for the build / deploy&lt;/P&gt;&lt;P&gt;all azure_ha_test.py elements pass&lt;/P&gt;&lt;P&gt;As soon as an inbound nat rule on the loadbalancer is added, fail-over hangs with the cluster-vip on the nic never moving and the loadbalancer is never updated.&lt;/P&gt;&lt;P&gt;Delete the nat rule, and fail-over will complete&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2018 16:05:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14081#M96354</guid>
      <dc:creator>Randall_Norris</dc:creator>
      <dc:date>2018-04-13T16:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14082#M96355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its is connected to cluster-vip as stated in the guide. I cannot connect it to anything other than the private IP's on the public side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2018 08:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14082#M96355</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-04-14T08:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14083#M96356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. I assumed its a bug from CP side, but it puzzles me how this was not found by CP before their release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know the outcome of the support as I cannot go forward with my build and tests and my deadline is close.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I might have choose a different vendor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2018 08:13:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14083#M96356</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-04-14T08:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14084#M96357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have two clusters setup the same way. This is my understanding on how it works (I could be wrong)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cluster VIP is only used for communication to management server not for actual traffic flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fronted  IP -&amp;gt;  points to FW1 public IP and FW2 public IP  (not the VIP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inbound Nat Rules on load balancer:&lt;/P&gt;&lt;P&gt;Load Balancer IP  -&amp;gt; service points to Active Member front end Private IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On cluster policy you need create manual NAT rules for each of the Front End IPs to translate to internal Load balancer/server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Failover the  MGMT API  changes:&lt;/P&gt;&lt;P&gt;1.NAT rule to new active member Front End internal IP&lt;/P&gt;&lt;P&gt;2.changes UDR default route new active member  Back End IP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2018 13:29:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14084#M96357</guid>
      <dc:creator>Neil_ZInk</dc:creator>
      <dc:date>2018-04-16T13:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14085#M96358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Neil,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your Cluster flow is correct for the old version. There are two version of Azure Cloud Deployment. The version you have describe is the older template. To clarify the main reason for the VIP in the old template is for VPN. It can also be used for natting traffic leaving the environment also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two SK's referenced for this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;New Azure Cluster template:&lt;/STRONG&gt;&lt;BR /&gt;Solution Title: Deploying a Check Point Cluster in Microsoft Azure &lt;BR /&gt;Solution ID: sk110194 &lt;BR /&gt;&lt;SPAN&gt;Solution Link:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194" rel="nofollow"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Old Azure Cluster template:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Solution Title: Deploying a Check Point Cluster in Microsoft Azure - for templates older than 20180301 &lt;BR /&gt;Solution ID: sk122793 &lt;BR /&gt;&lt;SPAN&gt;Solution Link:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122793" rel="nofollow"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122793&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;Dan Morris, &lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;Technology Leader&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;, Ottawa Technical Assistance Center&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2018 20:22:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14085#M96358</guid>
      <dc:creator>Dan_Morris</dc:creator>
      <dc:date>2018-04-17T20:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14086#M96359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Attila and Randall,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm from the $FWDIR/log/azure_had.elg if you are getting any error such as "RequestException: HTTP/1.1 400 Bad Request"&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Azure Portal are you see error such&amp;nbsp;as&amp;nbsp;","Microsoft.Network/networkInterfaces/write","Failed","Error"," ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if so this&amp;nbsp;issue is currently under investigation. The problem&amp;nbsp;is related to the translation of the&amp;nbsp;API call is being made to the Azure portal.&amp;nbsp;Unsure at this time what may have changed but it is currently being investigated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend to open up a support ticket for this issue. If you have please e-mail the SR number to me. My e-mail address is &lt;A href="mailto:dmorris@checkpoint.com"&gt;dmorris@checkpoint.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;Dan Morris, &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;Technology Leader&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;, Ottawa Technical Assistance Center&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2018 20:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14086#M96359</guid>
      <dc:creator>Dan_Morris</dc:creator>
      <dc:date>2018-04-17T20:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14087#M96360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, at least until the issue is resolved here's a decent workaround for allowing automatic failover that supports also inbound traffic:&amp;nbsp;&lt;/P&gt;&lt;P&gt;The steps are&lt;BR /&gt;1) Create some “basic” external loadbalancer (the name and resource group are not relevant here…the failover script will not change anything on this LB. This will work also if you use an app gateway) with some static public ip address as its frontend&lt;BR /&gt;2) On the LB, Create a backend pool with the private ip addresses of eth0 of the cluster members&lt;BR /&gt;3) On the LB, Create a TCP health check on the port of the service you want to path through the cluster (e.g., 8090)&lt;BR /&gt;4) On the LB, Create a loadbalancing rule (not a NAT rule!) for the service you want to allow inbound&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/64685_Loadbalancing rule.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;5) On SmartConsole, create an access rule allowing traffic on this port to the private eth0 IP addresses of the members&lt;BR /&gt;6) On SmartConsole, for each clustere member, create a NAT rule from that port on eth0 to the native port on the application server&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;a. At minimum, you should source NAT the LB healthprobes (globally originating from 168.63.129.16) to the address on eth1 of the respective member&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;b. If you don’t mind stateless failover&amp;nbsp; you can source NAT everything (hide NAT) to the address of eth1 &lt;BR /&gt; &lt;IMG alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/64686_NAT rule.png" style="width: 620px; height: 48px;" /&gt;&lt;BR /&gt;With this setup I tested that the UDR and cluster IP address do move automatically (it takes 1-2 mins) and at least new connections (inbound and outbound) succeed after the failover.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 13:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14087#M96360</guid>
      <dc:creator>Jonathan_Lebowi</dc:creator>
      <dc:date>2018-04-18T13:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14088#M96361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have created this and as a workaround its fine, but I do not see this solution in any documentation.&lt;/P&gt;&lt;P&gt;And also this only works with TCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened the following:&lt;/P&gt;&lt;H2 class="" style="padding-top: 10px; padding-left: 10px;"&gt;Service Request # 3-0150691191&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 23:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14088#M96361</guid>
      <dc:creator>Attila_Bakos</dc:creator>
      <dc:date>2018-05-11T23:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14089#M96362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Attila,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you heard anything back from your SR?&amp;nbsp; I have the same problem in my dev environment too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2018 13:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14089#M96362</guid>
      <dc:creator>russell_perera</dc:creator>
      <dc:date>2018-05-21T13:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14090#M96363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Russell,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk125435&amp;amp;partition=Advanced&amp;amp;product=CloudGuard"&gt;sk125435 &lt;/A&gt;was created for this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;DIV class="" style="color: #333333; font-weight: bold; font-size: 22px;"&gt;Cause&lt;/DIV&gt;&lt;DIV class="" style="color: #000000; font-size: 14px;"&gt;&lt;P&gt;Microsoft Azure has changed the API permissions that are used for updating a Public IP address. The API calls that are made from the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;azure_had.py&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;script are no longer able to make the required calls to update the Public IP adress to the new active member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="" style="color: #333333; font-weight: bold; font-size: 22px;"&gt;Solution&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;This issue will be addressed in a new Microsoft Azure for deployment template. The new published template version will be released within 1-2 weeks as of April 23rd 2018.&lt;/P&gt;&lt;P&gt;If an immediate fix is required,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.checkpoint.com/support-services/contact-support/" style="color: #905690; text-decoration: none;" target="_blank"&gt;contact Check Point Support&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and a Support Engineer will assist with a workaround for this issue.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Yonatan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2018 08:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14090#M96363</guid>
      <dc:creator>Yonatan_Philip</dc:creator>
      <dc:date>2018-05-29T08:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14091#M96364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just updated the SK. This is resolved in Version template&amp;nbsp;20180417.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dan Morris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2018 15:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14091#M96364</guid>
      <dc:creator>Dan_Morris</dc:creator>
      <dc:date>2018-05-29T15:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why doesn't Checkpoint failover without manual interaction in Azure?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14092#M96365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Daniel!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a similiar problem. Everything works until I create a NAT rule in the loadbalance, but instead of getting permission errors in the logs, I get the same 400 bad request error but the message is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;2018-11-26 02:53:33,777-AZURE-CP-HA-INFO- Traceback (most recent call last):&lt;BR /&gt; File "/opt/CPsuite-R80/fw1/scripts/azure_had.py", line 557, in poll&lt;BR /&gt; setLocalActive()&lt;BR /&gt; File "/opt/CPsuite-R80/fw1/scripts/azure_had.py", line 535, in setLocalActive&lt;BR /&gt; todo |= set_cluster_ips()&lt;BR /&gt; File "/opt/CPsuite-R80/fw1/scripts/azure_had.py", line 391, in set_cluster_ips&lt;BR /&gt; body=json.dumps(peer_nic))[1]&lt;BR /&gt; File "/opt/CPsuite-R80/fw1/scripts/rest.py", line 503, in arm&lt;BR /&gt; max_time=self.max_time)&lt;BR /&gt; File "/opt/CPsuite-R80/fw1/scripts/rest.py", line 136, in request&lt;BR /&gt; headers['proto'], headers['code'], headers['reason'], response)&lt;BR /&gt;RequestException: HTTP/1.1 400 Bad Request&lt;BR /&gt;{&lt;BR /&gt; "error": {&lt;BR /&gt; "code": "InvalidResourceReference",&lt;BR /&gt; "message": "Resource /subscriptions/ddf46c4a-8920-403a-8e11-8561e1a7b7e9/resourceGroups/SECFW/providers/Microsoft.Network/networkInterfaces/SECFW1-eth0/ipConfigurations/cluster-vip referenced by resource /subscriptions/ddf46c4a-8920-403a-8e11-8561e1a7b7e9/resourceGroups/SECFW/providers/Microsoft.Network/virtualNetworks/Transit_VNET/subnets/WAN was not found. Please make sure that the referenced resource exists, and that both resources are in the same region.",&lt;BR /&gt; "details": []&lt;BR /&gt; }&lt;BR /&gt;}&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried everything. Out of ideas..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thiago Bujnowski&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 05:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Why-doesn-t-Checkpoint-failover-without-manual-interaction-in/m-p/14092#M96365</guid>
      <dc:creator>Thiago_Bujnowsk</dc:creator>
      <dc:date>2018-11-26T05:44:19Z</dc:date>
    </item>
  </channel>
</rss>

