Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gusa2727
Contributor
Jump to solution

CloudGuard AWS - Multiple Public IPs

In a Active/Passive HA environment, how do you manage adding multiple public IPs to the cluster? Do I have to create one Network Load Balancer per EIP (due to the one EIP per NLB limitation), or is there a way of assigning the EIPs to the active EC2 instance directly, and these EIPs move to the Secondary node when a failver is detected (FortiGate HA works in this way)?. Thank you.

0 Kudos
1 Solution

Accepted Solutions
Nir_Shamir
Employee Employee
Employee

You can in Azure (depending on your Image version and you need to modify a configuration file in the GW according to the admin guide - https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_...

in GCP it's not supported.

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Our clustering only supports a single IP per virtual interface.
I believe this limitation applies in public cloud as well.
Which means you'll probably need to do this with NLBs. 

0 Kudos
Nir_Shamir
Employee Employee
Employee

Our VIP is used as a secondary IP on the ACTIVE member eth0 interface so you can add another "secondary IP" the the ACTIVE member eth0 and attach a new Public IP to it.

It will move between the members , depending who is the ACTIVE one.

0 Kudos
Gusa2727
Contributor

So, I can add multiple secondary IP on front/outside interface (as much as supported by the instance size), and all these secondary Interface will move to the secondary node in the event of failover, right? if yes, does this apply also to other Cloud Providers like Azure and GCP?

I know that we have the External Load Balancer in Azure, which supports multiple FrontEnd IPs, but we need to open multiple ports on the External Load Balancer (LB rules), which increase a lot the cost. 

Thanks!

0 Kudos
Nir_Shamir
Employee Employee
Employee

You can in Azure (depending on your Image version and you need to modify a configuration file in the GW according to the admin guide - https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_...

in GCP it's not supported.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.