Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vinceneil666
Advisor

CheckPoint, Azure, Scaleset - not all traffic forwarded.

Hi, I have a very strange issue with a scaleset in Azure. I have implemented these several times before, pretty much the same way, but I have never had this problem before.

The setup is as of now pretty simple, I have the scaleset up n running in a VNET that also has a VirtualNetworkGateway wtih a route based vpn to onprem. And there is another VNET peered in, that has UDR's pointing it to the internal load balancer fo the scaleset.


The thing is - near everything works:

  • - I can ping both ways (from onprem serv to azure server)
  • -Run SSH from onprem to a server in the peered vnet..
  • - RDP works same way..
  • Traffic is inspected by firewall and flowing normal. (ccap verifies this, I have traffic entering and exiting on the internal nic)
  • Internet traffic from the peered vnet hits mye scaleset, natted, and works fine. Ping to internet, works fin.


But, for some reason - I am unable to getanything but the standard ports to work. :

As an example (this is the same for lots of other ports): I try to open port tcp1433 from a server in the peered vnet - the traffic enters my scaleset, is processed and then sent out towards the virtual network gateway. And then it is gone.... I am unable to see it entering the onprem checkpoint at all.... its just gone.  If I did tcp3389 or tc22 from, and to, the same IP's... it works..

So I just have an issue with some/lots of ports not working.. I have checked all NSG's and all policies, run debug.. It just seems to be lost in Azure somewhere ? 

Have anyone had this issue ? 

0 Kudos
6 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.