cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question
Highlighted

Cloudguard HA failover issues Azure (NAT)

Hello,

I'm building a HA cluster in Azure. During testing I've noticed issues with the failover.
The connection to Azure has been configured and I see the changes happen in the Azure cloud.
But I see issue with the public NAT for the VPN tunnel.

Normally traffic is being NATted from the external IP to the VIP address.
But from time to time the failover happens and traffic is being NATted to 169.254.x.y random addresses.
The Check Point cases sent me to Microsoft, but support is slow there...
Did anybody had the same issue and how did you resolve it?

Kind Regards,

Sander Zumbrink

0 Kudos
1 Reply

Re: Cloudguard HA failover issues Azure (NAT)

Hi Sander,

just to let you know, that I had the same problem. It only has happened with VPN Traffic . Doing e.g. a SSH connection to the VIP after failover did work (NATed correctly). I tried to use NAT-T instead of ESP but no difference. Check Point TAC also asked me to contact Microsoft wich is not very  customer oriented in my opinion. It should be Checkpoint and MS to fix the problem in a combined effort.

"Unfortunately" the problem disappeared after a week or so at the customer (i was still able to replicate it in my Azure environment), so we did close this case.

 

Matthias

 

0 Kudos