- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi Expert,
Anyone can advise how can we build a Vsec CloudGuard using Terraform code.
something that can mapped original ARM template as attached.
Best Regards,
Rano
based on Javier's link https://community.checkpoint.com/docs/DOC-3027
I managed to get some progress:
- bring up 2 Vsec Gateway
- apply correct API
- test API
$FWDIR/scripts/azure_ha_test.py
- register to MDM (manual step)
what is missing:
1. cluster VIP integration 'cluster-vip'
2. failover testing
anyone has any input.
Thanks for sharing Ranokarno, it looks promising. Feel free to share your code once you feel it is mature through the codepoint 😉 BTW, why didn't you try the VMSS setup directly instead of the cluster one?
Hi Javier,
My understanding that VMSS relies on Azure Loadbalancer which then defeat the purpose of Cloudguard gateway to identify source/destination rules. especially since we are moving toward Identity awareness with Azure Datacenter objects.
However I am interested how can we automate security gateway registration via autoprov-cfg script without enabling VMSS.
The azure LB does not source NAT, so the CG gateways do see the original source addresses.
Thanks for your advise Jonathan Lebowitsch , I am currently testing it with dual instance vsec gateway and loadbalancer.
I think this approach much better than building cluster Vsec.
it reduce the overhead of API request, UDR change, etc.
Hi I am working on using the ARM templates directly in Terraform to build the environment
The advantage is you don't need to manually convert the Check Point supplied templates to terraform each time they are updated. Might help you with what you are attempting.
This is my first pass, bit rough but here it is https://github.com/rcove/terraform-az-demo-1
Comments will be appreciated
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Thu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASEThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY