<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HCP roadmap question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229534#M38328</link>
    <description>&lt;P&gt;Hi Tal,&lt;BR /&gt;&lt;BR /&gt;Sure.&lt;/P&gt;
&lt;P&gt;There could be a CloudGuard topic in the Test area (under Gaia, System, Cluster etc.).&lt;/P&gt;
&lt;P&gt;Capturing the *-ha.json files can show the relevant details in the hcp output. For example, the Tenant ID, RG, cluster-vip, templateName etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe they can be checked for some of that content (presence).&lt;/P&gt;
&lt;P&gt;Capture these files and any other files of interest in /etc/&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;/etc/cloud-version&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;/etc/cloud-version.json&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Display Template version and refer to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk173705" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk173705&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking that the relevant HAD is up and running e.g. AZURE_HAD;&lt;/P&gt;
&lt;P&gt;Example: Check that&amp;nbsp;/etc/fw/scripts/azure_had.py is running&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;cpwd_admin getpid -name AZURE_HAD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;nbsp;cpwd_admin list | grep AZURE_HAD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Capturing public IP addresses could improve visibility in the HCP Topology view.&lt;/P&gt;
&lt;P&gt;HCP connectivity tests could include public cloud dependent URLs and/or IPs e.g.&amp;nbsp;168.63.129.16&lt;/P&gt;
&lt;P&gt;Health probe checks (?)&lt;/P&gt;
&lt;P&gt;Check or capture proxy settings.&lt;/P&gt;
&lt;P&gt;IAM permissions checks.&lt;/P&gt;
&lt;P&gt;Maybe run the *ha_test.py scripts to capture output.&lt;/P&gt;
&lt;P&gt;That could be enough to cover many of the CloudGuard Network Security/Gateway tests and capture output for HCP.&lt;/P&gt;
&lt;P&gt;Maybe a CloudGuard test could be added to the list: hcp -r CloudGuard&lt;/P&gt;
&lt;P&gt;I don't see anything like that in the list (&amp;nbsp;hcp --cli-list-tests)&lt;/P&gt;
&lt;P&gt;References:&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Content/Topics-AWS-SingleAZ-Cluster-DG/Troubleshooting.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Content/Topics-AWS-SingleAZ-Cluster-DG/Troubleshooting.htm&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Content/Topics-AWS-CrossAZ-Cluster-DG/Troubleshooting.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Content/Topics-AWS-CrossAZ-Cluster-DG/Troubleshooting.htm&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From sk175023 -&amp;nbsp;ATRG: CloudGuard Network for Azure - High Availability (HA)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="checkpoint_toggle" target="_blank"&gt;How can I know that my cluster is well configured?&lt;/A&gt;&lt;BR /&gt;
&lt;DIV id="FAQ1"&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure that the tester (&lt;CODE&gt;$FWDIR/scripts/azure_ha_test.py&lt;/CODE&gt;)passes and there are no errors in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;$FWDIR/log/azure_had.log&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on each member.&lt;/LI&gt;
&lt;LI&gt;Ensure that the cluster members use a Jumbo Hotfix that contains fixes of the relevant limitation mentioned above.&lt;/LI&gt;
&lt;LI&gt;Make sure that the daemon in charge of communicating with Azure runs on each cluster member by running:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;cpwd_admin getpid -name AZURE_HAD&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and ensuring the output is different from 0.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 12 Dec 2024 15:55:37 GMT</pubDate>
    <dc:creator>Don_Paterson</dc:creator>
    <dc:date>2024-12-12T15:55:37Z</dc:date>
    <item>
      <title>HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229324#M38304</link>
      <description>&lt;P&gt;Is there a roadmap for new features planned for hcp?&lt;/P&gt;
&lt;P&gt;One area I would be interested to know about is CloudGuard Network Security health checks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since some of the daemons are unique per CSP and there are unique troubleshooting and testing scripts for cloud it seems like a good idea to have a single command that can run the relevant cloud tests.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 21:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229324#M38304</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-10-09T21:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229424#M38313</link>
      <description>&lt;P&gt;I have forwarded your request to CloudGuard owners in R&amp;amp;D.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 18:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229424#M38313</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-10-10T18:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229520#M38327</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18248"&gt;@Don_Paterson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please elaborate which tests are missing? What features and scripts would you like HCP to cover?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2024 09:26:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229520#M38327</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-10-13T09:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229534#M38328</link>
      <description>&lt;P&gt;Hi Tal,&lt;BR /&gt;&lt;BR /&gt;Sure.&lt;/P&gt;
&lt;P&gt;There could be a CloudGuard topic in the Test area (under Gaia, System, Cluster etc.).&lt;/P&gt;
&lt;P&gt;Capturing the *-ha.json files can show the relevant details in the hcp output. For example, the Tenant ID, RG, cluster-vip, templateName etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe they can be checked for some of that content (presence).&lt;/P&gt;
&lt;P&gt;Capture these files and any other files of interest in /etc/&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;CODE&gt;/etc/cloud-version&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;/etc/cloud-version.json&lt;/CODE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Display Template version and refer to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk173705" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk173705&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking that the relevant HAD is up and running e.g. AZURE_HAD;&lt;/P&gt;
&lt;P&gt;Example: Check that&amp;nbsp;/etc/fw/scripts/azure_had.py is running&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;cpwd_admin getpid -name AZURE_HAD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-&amp;nbsp;cpwd_admin list | grep AZURE_HAD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Capturing public IP addresses could improve visibility in the HCP Topology view.&lt;/P&gt;
&lt;P&gt;HCP connectivity tests could include public cloud dependent URLs and/or IPs e.g.&amp;nbsp;168.63.129.16&lt;/P&gt;
&lt;P&gt;Health probe checks (?)&lt;/P&gt;
&lt;P&gt;Check or capture proxy settings.&lt;/P&gt;
&lt;P&gt;IAM permissions checks.&lt;/P&gt;
&lt;P&gt;Maybe run the *ha_test.py scripts to capture output.&lt;/P&gt;
&lt;P&gt;That could be enough to cover many of the CloudGuard Network Security/Gateway tests and capture output for HCP.&lt;/P&gt;
&lt;P&gt;Maybe a CloudGuard test could be added to the list: hcp -r CloudGuard&lt;/P&gt;
&lt;P&gt;I don't see anything like that in the list (&amp;nbsp;hcp --cli-list-tests)&lt;/P&gt;
&lt;P&gt;References:&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Content/Topics-AWS-SingleAZ-Cluster-DG/Troubleshooting.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CloudGuard_Network_for_AWS_Single_AZ_Cluster/Content/Topics-AWS-SingleAZ-Cluster-DG/Troubleshooting.htm&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Content/Topics-AWS-CrossAZ-Cluster-DG/Troubleshooting.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_for_AWS_Cross_AZ_Cluster/Content/Topics-AWS-CrossAZ-Cluster-DG/Troubleshooting.htm&lt;/A&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From sk175023 -&amp;nbsp;ATRG: CloudGuard Network for Azure - High Availability (HA)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="checkpoint_toggle" target="_blank"&gt;How can I know that my cluster is well configured?&lt;/A&gt;&lt;BR /&gt;
&lt;DIV id="FAQ1"&gt;
&lt;OL&gt;
&lt;LI&gt;Make sure that the tester (&lt;CODE&gt;$FWDIR/scripts/azure_ha_test.py&lt;/CODE&gt;)passes and there are no errors in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;$FWDIR/log/azure_had.log&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on each member.&lt;/LI&gt;
&lt;LI&gt;Ensure that the cluster members use a Jumbo Hotfix that contains fixes of the relevant limitation mentioned above.&lt;/LI&gt;
&lt;LI&gt;Make sure that the daemon in charge of communicating with Azure runs on each cluster member by running:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;cpwd_admin getpid -name AZURE_HAD&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and ensuring the output is different from 0.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 12 Dec 2024 15:55:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/229534#M38328</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-12-12T15:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/230199#M38413</link>
      <description>&lt;P&gt;Hi Tal,&lt;/P&gt;
&lt;P&gt;This seems like a good thread to ask if there are plans for VM Watch to be integrated into any of thw Azure CloudGuard NS solutions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/azure/virtual-machines/azure-vm-watch" target="_blank"&gt;https://learn.microsoft.com/en-us/azure/virtual-machines/azure-vm-watch&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 07:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/230199#M38413</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-10-19T07:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: HCP roadmap question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/230204#M38414</link>
      <description>&lt;P&gt;I am adding this link to a post I did last year which is related to this new post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-simplified-troubleshooting/m-p/199379" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/CloudGuard-simplified-troubleshooting/m-p/199379&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2024 19:49:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HCP-roadmap-question/m-p/230204#M38414</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-10-19T19:49:55Z</dc:date>
    </item>
  </channel>
</rss>

