Scale In and Scale Out Events in Cloud Firewall for Azure VMSS GWLB

Each VMSS must have Scale In and Scale Out events configured.

You can edit or see the configuration in Azure Portal > VMSS > Scaling.

Default triggers for the firewall VMSS:

  • Scale Out on more than 80% CPU usage, for an average of five minutes.

  • Scale In on less than 60% CPU usage, for an average of five minutes.

Scale Out

A scale out event occurs, if the current load increases. When a scale out event is triggered:

  • Azure Autoscale launches one or more new instances of Check Point Cloud Firewall Gateways.

  • The new instances of Cloud Firewall Gateways automatically run the Check Point First Time Configuration Wizard and then reboot.

During the scale-out, the Check Point Security Management ServerClosed Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. detects that new instances of Cloud Firewall Gateways have launched. The Security Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. waits until the Cloud Firewall Gateways complete to deploy, and then the Security Management Server automatically:

After a Security Policy installation, these Cloud Firewall Gateways start to respond to health probes. The Load Balancer then starts to forward new connections to them. The newly created Cloud Firewall Gateways report their status and send logs to the Security Management Server.

Note -

  • Newly provisioned Cloud Firewall Gateways automatically receive the latest published Security Policy. You have to install the policy on the existing Cloud Firewall Gateways to update their Security Policy.

  • The system automatically creates and deletes Auto Scaling Cloud Firewall Gateway objects according to the current environment. Therefore, we do not recommend to use specified objects in rules or to manually edit those objects.

  • By default, you can access each Check Point Cloud Firewall Gateway and Security Management Server's Gaia PortalClosed Web interface for the Check Point Gaia operating system. from the Internet at https://<virtual-machine-public-ip>. It is possible to control the access to the GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Portal. Configure a Network Security Group, or configure the Cloud Firewall Gateway and Security Management Server settings.

  • Updated Virtual Machines:

    1. In the case of a scale-out event, the latest available Check Point image (the most recent build within the same major version of Cloud Firewall for Azure VMSS) is used to deploy the new Virtual Machine.

    2. Check Point recommends using the latest image for the best security and performance, but you can deploy a specific version of Azure image using this guide for reference.

    3. The system uses Fast Deployment Images (Blink) with a pre-installed Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA..

For more information, see these SK articles:

  • CloudGuard for Azure Latest Updates - see sk132192.

  • Blink - Gaia Fast Deployment - see sk120193.

Components of the Check Point Deployed Solution

The diagram below depicts an Azure Virtual NetworkClosed Environment of logically connected Virtual Machines. (VNET) with the Check Point solution deployed.

There is one user deployed VNET - Services VNET with its own external Standard Load Balancer.

The Check Point deployed solution has these components:

  • Security VNET

  • Virtual Machine Scale Set (VMSS)

The number of instances that you can deploy in the Cloud is dynamic.

  • Gateway Load Balancer

  • VMSS subnet

  • Public IP address for each VMSS instance (optional)

  • You cannot deploy other VMs in the VMSS subnet