Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Shay_Levin
Admin
Admin

Azure Virtual Wan & CloudGuard NVA Integration - Workshop Recording

The full workshop recording is here, at the bottom of the post you will find presentation , workshop materials , guides and more.

\

 

The attached vWAN_automation_script is used for large deployment, it's a python script that will create automatically all the CP NVA gateways on the Check Point management and install policy on them.

 

  • How to Simulate GW Failure

cpstop and cpstart (cpstop will cause ILB health checks failures to tcp 8117)

• How to find current vWAN utilization for sizing

https://learn.microsoft.com/en-us/azure/virtual-wan/monitor-virtual-wan-reference#hub-router-metrics

• VWAN Documentation

https://learn.microsoft.com/en-us/azure/virtual-wan/how-to-routing-policies

Check Point Admin Guide

https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_vWAN_Adm...

• Azure Virtual WAN github for diagrams and training

  https://github.com/nehalineogi/azure-networking

3 Replies
jmaresky
Employee Alumnus
Employee Alumnus

Awesome job!

0 Kudos
Przemyslaw_Podh
Explorer

Hi,

First of all, great video, it is very helpful to see how actually such deployment can be done. Thank you for this.

and I have got a question for similar scenario 🙂

I would like to have CloudGuard in my Azure vWan. Next I would like to onboard CloudGuard  to my existing Managment Server which is located in OnPrem (in my office). However I would prefer to have a communication between these CloudGuard NVA's via Internal communication , by using private addresses. Means it would go from VWAN via Express route to my office and forward. 

Can I assume that this is not a problem for management communication on similar scenario to above? 

0 Kudos
Shay_Levin
Admin
Admin

Since the intent route will always send the traffic to the internal LB, you will need to create a UDR override the intent routes.

In addition, you should be aware of the fact that you will probably not be able to manage NVA in different hub until Microsoft will give the “explicit next hop” feature (interhub communications also passed through the internal LB).

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.