- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: CloudGuard AWS - Multiple Public IPs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CloudGuard AWS - Multiple Public IPs
In a Active/Passive HA environment, how do you manage adding multiple public IPs to the cluster? Do I have to create one Network Load Balancer per EIP (due to the one EIP per NLB limitation), or is there a way of assigning the EIPs to the active EC2 instance directly, and these EIPs move to the Secondary node when a failver is detected (FortiGate HA works in this way)?. Thank you.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can in Azure (depending on your Image version and you need to modify a configuration file in the GW according to the admin guide - https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_...
in GCP it's not supported.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Our clustering only supports a single IP per virtual interface.
I believe this limitation applies in public cloud as well.
Which means you'll probably need to do this with NLBs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Our VIP is used as a secondary IP on the ACTIVE member eth0 interface so you can add another "secondary IP" the the ACTIVE member eth0 and attach a new Public IP to it.
It will move between the members , depending who is the ACTIVE one.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, I can add multiple secondary IP on front/outside interface (as much as supported by the instance size), and all these secondary Interface will move to the secondary node in the event of failover, right? if yes, does this apply also to other Cloud Providers like Azure and GCP?
I know that we have the External Load Balancer in Azure, which supports multiple FrontEnd IPs, but we need to open multiple ports on the External Load Balancer (LB rules), which increase a lot the cost.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can in Azure (depending on your Image version and you need to modify a configuration file in the GW according to the admin guide - https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_...
in GCP it's not supported.