- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Cloudguard HA failover issues Azure (NAT)
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cloudguard HA failover issues Azure (NAT)
Hello,
I'm building a HA cluster in Azure. During testing I've noticed issues with the failover.
The connection to Azure has been configured and I see the changes happen in the Azure cloud.
But I see issue with the public NAT for the VPN tunnel.
Normally traffic is being NATted from the external IP to the VIP address.
But from time to time the failover happens and traffic is being NATted to 169.254.x.y random addresses.
The Check Point cases sent me to Microsoft, but support is slow there...
Did anybody had the same issue and how did you resolve it?
Kind Regards,
Sander Zumbrink
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Sander,
just to let you know, that I had the same problem. It only has happened with VPN Traffic . Doing e.g. a SSH connection to the VIP after failover did work (NATed correctly). I tried to use NAT-T instead of ESP but no difference. Check Point TAC also asked me to contact Microsoft wich is not very customer oriented in my opinion. It should be Checkpoint and MS to fix the problem in a combined effort.
"Unfortunately" the problem disappeared after a week or so at the customer (i was still able to replicate it in my Azure environment), so we did close this case.
Matthias