- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
I believe that it is true and the documentation is accurate.
The problem is that the Azure External Load Balancer (service) takes in the traffic and distributes it to the SG/s behind the LB.
Problem #2: There is no synchronisation between the SGs since they are not a cluster and only enforce same policy for the traffic that is steered towards them (which is then sticky (as far as possible (scale in events change things..) - there's other threads on that)).
By design there is no S2S VPN support.
Still worth asking though because the cloud is so dynamic and you never know what they've got in the pipeline, or in another solution.
I think this one might need to go direct to the presales team if there is a customer demand/use case.
In the newer version of the CloudGuard Blueprints they always show the VMSS in the backend at the end of the Express Route.
They used to show a cluster there so that we could assume a IPSec VPN but that changed.
Can the solution use a CloudGuard Cluster?
https://www.checkpoint.com/downloads/products/cloudguard-architecture-blueprint-diagrams.pdf
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY