Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gongya_Yu
Collaborator
Jump to solution

Cloudguard LoadBalancer question

Almost all the videos from Youtube discuss the cloudguard deployment with load balancers.  Deep-dive Workshop: CloudGuard Network Security on Azure (Canada) explains why load balancers is used.

From Marketplace, I came  across a few different versions recently

1. there is an option to enable LB  (unfortunately I did not screenshot it) 

2. option for LB floating IP only
before.PNG

3. no option at all  LB.

current-0612.PNG

All the templates will deploy a LB by default automatically ?

Option 3  (this is the latest version I saw) deploys a LB ?

Cluster failover via API or LB are selective ?

thanks !!

1 Solution

Accepted Solutions
LeonardHavekost
Employee Employee
Employee

The route should always point to the LB IP. Can be found as well in the Deployment guide:

 

https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...

 

And yes the LB is always deployed as @Shay_Levin already stated. If not needed, you can also delete the Ingress LB. 

View solution in original post

6 Replies
Shay_Levin
Admin
Admin

Hi, 

The High Availability  template deploy External and Internal NLB.

If you are not using Ingress , you can safely delete the external load balancer post deployment.

For the VMSS , you have the option to select in the template, if you want to deploy  External or Internal or Both.

Gongya_Yu
Collaborator

I watched your multiple videos. thanks !!
The deployment forms above related to LB are different, any reasons ?
Ingress you referred to is Northbound ? ( we do not use it)
Southbound has to use LB ? if yes. Can we still fail over via API instead of LB ?

thanks !!!

LeonardHavekost
Employee Employee
Employee

Cluster Failover always depends on which features / traffic flows you are using. Some are relying on API calls (e.g. for movement of Public IP addresses) and some on LB Healthprobes or both. But those are not selective.  

Gongya_Yu
Collaborator

We only use southbound, the deployment template always deploys LB, right ? if yes, the UDR should point to LB, not the active node, or can we selectively point to either active node or LB ?

thanks !!

LeonardHavekost
Employee Employee
Employee

The route should always point to the LB IP. Can be found as well in the Deployment guide:

 

https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_HA_Clust...

 

And yes the LB is always deployed as @Shay_Levin already stated. If not needed, you can also delete the Ingress LB. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.