- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Hi All,
I recently deployed R81.10 Template in Azure with HA cluster setup. After deploying first thing I checked is my NSG on ETH1 and then Load balancing status. I found Backend Load balancer is reporting Gateways Unhealthy and Gateway's are dropping traffic from ILB :
@;2736753;[cpu_1];[fw4_2];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;
@;2736839;[cpu_3];[fw4_0];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;
@;2736912;[cpu_2];[fw4_1];fwha_cloud_should_process_probe: fw_policyloaded is 1, not replying;
NSG on Backend ILB is fine and allowing all communication.
[Expert@naspdmzcpfwl1:0]# cat /etc/cloud-version
release: R81.10
take: 335
build: 991001383
platform: azure
license: byol
deployment_method: ftw
template_name: ha
template_version: 20231002
template_type: marketplace
maas_usage: 0
[Expert@naspdmzcpfwl1:0]# cat $FWDIR/boot/modules/fwkern.conf
fwha_unicast_only=1
fwmultik_sync_processing_enabled=0
fw_aws_mode=1
fw_https_consider_nat=1
fw_xff_geo=1
cloud_balancer_ip1=0xa83f8110
fw_azure_mode=1
fwha_dead_timeout_multiplier=20
fwha_if_problem_tolerance=200
cloud_balancer_port=8117
Any help? I have open TAC case too but thought to ask experts here too for faster resolution.
Hi @ajsingh,
Let me see if I understood correctly: you are trying to create the cluster object in the smart console, but you cannot communicate with the gateway on ETH1 (SIC is failing). Is your management server trying to access the gateway through ETH1?
For the health probes, CloudGuard Gateways will only respond to them after the policy installation, and only the active member will do so (the standby member does not respond by design).
Please refer to step 5 in our guide to set up the GW objects in the SmartConsole: https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...
I hope this clarifies your question.
Thanks,
Natanel
Maybe this would help?
Kind regards,
Andy
Hi,
I am using HA cluster Template. Right now I am unable to reach my gateway on ETH1 and hence no sic is established yet. I wanted to make SIC on ETH1 only so comms to firewall stays internal.
I have default policy on firewalls yet since it is a brand new setup and i have tried to unload policy too but no success.
Ah, now I got it. Well, in that case, we need to figure out why. Can you do traceroute to see why it fails? Did you do any captures to examine where it might be getting "stuck"?
Andy
I do see traffic coming to my Eth1 on port 8117 but no reply from firewall. I just unloaded the policy too but same behavior . as soon as request reached ILB , its lost.
IS ILB supposed to send traffic from below ip or from 10.x.x.5 IP?
168.63.129.16.60721 > 10.x.x.5.8117: Flags [SEW], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0
09:46:19.059523 IP 168.63.129.16.60721 > 10.x.x.5.8117: Flags [SEW], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0
09:46:21.074660 IP 168.63.129.16.60721 > 10.x.x.5.8117: Flags [S], seq 585445089, win 64240, options [mss 1440,nop,wscale 8,nop,nop,sackOK], length 0
Wait, do you have ILB and ELB or just ILB?
Andy
Hi @ajsingh,
Let me see if I understood correctly: you are trying to create the cluster object in the smart console, but you cannot communicate with the gateway on ETH1 (SIC is failing). Is your management server trying to access the gateway through ETH1?
For the health probes, CloudGuard Gateways will only respond to them after the policy installation, and only the active member will do so (the standby member does not respond by design).
Please refer to step 5 in our guide to set up the GW objects in the SmartConsole: https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...
I hope this clarifies your question.
Thanks,
Natanel
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY