- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi All,
I deployed CheckPoint VSEC cluster from Microsoft Azure Market place. I see the cluster is having a public load balancer, which has two cluster gateways outside IP's as front end IPs
I would like to spin up a second internal load balancer, which will have the cluster gateways inside IP's configured
I am able to deploy the load balancer and add the gateway IPs fine, however the challenge I am facing is, in order to achieve HA in Azure, we have to configure the second load balancer name is $FWDIR/conf/azure-ha.json file and reconf it.
I tried adding the second (internal) load balancer name after the comma, the azure_ha_cli.py isn't recognizing the second load balancer name and isn't failing over.
Does anyone have tried this and can you let me know how you are achieving HA using this method
Thanks,
Chandru
In json file you can specify only public load balancer name, it doesn't count with internal load balancer. Azure template for vsec cluster is deployed per design specified here Deploying a Check Point Cluster in Microsoft Azure
I agree, in JSON file you specify the load balancer name. I have internal load balancer working fine on eth0 interface
I do understand, Azure template for vSEC cluster only supports load balancer on eth0 interface
It would be better if Check Point comes up having a load balancer on eth1 interface as well
You might want to look on Auto scale option, this will give you load balancer on eth0 and eth1 Trust me having just one load balancer in front of cluster will give you a lot of fun.
Yes Check Point Scale sets offer load balancers on both eth0 and eth1 interfaces. however they can only do stateless protocols like http and https. It works for internet facing apps.
I cant deploy them every where, since we have to inspect other stateful protocols like sql server, rdp etc.
External Load Balancer's :- They are needed when you want to Publish Web Services (Web page / Application running on any Server) over the Internet.
See as per my understanding Internal Load Balancer's are used for Balancing the Traffic loads for any server between different nodes or not to expose Server's directly to User's.
Wht is your specific requirement with Load Balancer's to be acknowledged by VSec on the Internal Azure plane.?
all,
how do you get the cluster to answer health probes from load balancers? even on internal interfaces.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY