Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vas
Contributor

CloudGuard Firewalls Permission- Azure

Hi There,

I believe firewalls require 'Contributor' role in Azure HA to move the VIP of the cluster between members during a failover. 

We're planning to provision dedicated 'Inbound' firewalls to protect the workload traffic from the Internet. We don't have the permission to create a system managed identity during the template deployment, and I'm aware that service principal can be associated.

Since it doesn't need to move the VIP as they're Inbound firewalls, does it still require 'contributor' role for the failover to happen..?

0 Kudos
1 Reply
Nir_Shamir
Employee Employee
Employee

If you're not planning to use the VIP then it shouldn't affect the deployment.

you will only need to use the Load Balancers to route traffic to the ACTIVE member.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.