- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello
We've deployed a R80.40 southbound Geo Cluster in AWS environment for dealing with east-west and egress Internet traffics.
We don't want to hide nat AWS east-west traffics but only hide nat Internet egress traffics.
My nat policy is in attachment
Every thing works well until I test failover 😞
After the geo cluster failover, egress Internet traffics always match nat rule#4, so making no access to Internet ...
Some one can help ...
Hi @dinkoctlui,
You can test the following!
A) Check the cluster failover:
1) Run the script with this command (do not change the syntax):
# $FWDIR/scripts/azure_ha_test.py
2) If all tests were successful, this shows: All tests were successful!
Otherwise, an error message is displayed with information to troubleshoot the problem.
3) Simulate a cluster failover. For example, shut down the internal interface of the active cluster member:
# ip link set dev eth1 down/up
or
# clusterXL_admin down/up
B) Use an automatic hide NAT rule on the cluster object!
Hello,
Did you find a solution to your problem? I am currently trying to deploy a similar architecture and curious to know if your issue is fixed.
Regards,
Vivek
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY