Scale In and Scale Out Events in Cloud Firewall for Azure VMSS GWLB
Each VMSS must have Scale In and Scale Out events configured.
You can edit or see the configuration in Azure Portal > VMSS > Scaling.
Default triggers for the firewall VMSS:
-
Scale Out on more than 80% CPU usage, for an average of five minutes.
-
Scale In on less than 60% CPU usage, for an average of five minutes.
Scale Out
A scale out event occurs, if the current load increases. When a scale out event is triggered:
-
Azure Autoscale launches one or more new instances of Check Point Cloud Firewall Gateways.
-
The new instances of Cloud Firewall Gateways automatically run the Check Point First Time Configuration Wizard and then reboot.
During the scale-out, the Check Point Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. detects that new instances of Cloud Firewall Gateways have launched. The Security Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. waits until the Cloud Firewall Gateways complete to deploy, and then the Security Management Server automatically:
-
Initializes a Secure Internal Communication (SIC
Secure Internal Communication. The Check Point proprietary mechanism with which Check Point computers that run Check Point software authenticate each other over SSL, for secure communication. This authentication is based on the certificates issued by the ICA on a Check Point Management Server.) channel with theseCloud Firewall Gateways. -
Adds 2 VXLAN Bridge Mode
Security Gateway or Virtual System that works as a Layer 2 bridge device for easy deployment in an existing topology. interfaces (internal and external). -
Creates automatic Access Rules to allow tunnel traffic between the Gateway Load Balancer and the Cloud Firewall Gateways:
Source Destination Services & Applications
Action
Installed on
A host that represent the Gateway Load Balancer Frontend IP.
UDP services with the VXLAN tunnel interfaces port numbers (internal & external).
Accept
Policy Targets
To control the location of the automatic Access rules, see section Step 7: Automatic Rule Placement (Optional).
-
Installs a Security Policy
Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection. on these Cloud Firewall Gateways.
After a Security Policy installation, these Cloud Firewall Gateways start to respond to health probes. The Load Balancer then starts to forward new connections to them. The newly created Cloud Firewall Gateways report their status and send logs to the Security Management Server.
|
|
Note -
For more information, see these SK articles: |
Components of the Check Point Deployed Solution
The diagram below depicts an Azure Virtual Network
Environment of logically connected Virtual Machines. (VNET) with the Check Point solution deployed.
There is one user deployed VNET - Services VNET with its own external Standard Load Balancer.
The Check Point deployed solution has these components:
-
Security VNET
-
Virtual Machine Scale Set (VMSS)
The number of instances that you can deploy in the Cloud is dynamic.
-
Gateway Load Balancer
-
VMSS subnet
-
Public IP address for each VMSS instance (optional)
-
You cannot deploy other VMs in the VMSS subnet