Cloud Firewall High Availability Cluster for Azure Stack Hub

Microsoft AzureClosed Collection of integrated cloud services that developers and IT professionals use to build, deploy, and manage applications through a global network of data centers managed by Microsoft. Stack Hub now provides the ability to move remote data center capabilities to on-premises. For more information about Azure Stack Hub, see Microsoft's Azure Stack Hub documentation.

Prerequisites

Before setting up your system, you must be familiar with the these topics:

Microsoft Azure Stack Hub:

Check Point

Setting Up Check Point Clusters in Azure

About Clusters:

A clusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. is a group of Virtual Machines that work together in High Availability Mode. One Cluster MemberClosed Security Gateway that is part of a cluster. is the Active, and the second Cluster Member is the Standby. The cluster fails over from the Active Cluster Member to the Standby Cluster Member when necessary.

  • Cluster Members communicate with each other w unicast IP addresses.

  • For inbound, outbound, and East-West traffic, Cluster Members rely on Azure Load Balancer to represent their external and internal Virtual IP addresses. Load Balancers only forward traffic to the Active Cluster Member.

When cluster failover occurs, the Cluster Member that is promoted to the active member uses an Azure API to reconfigure the routing tables to send traffic to itself.

Azure Stack Hub API authentication:

To make API calls to Azure Stack Hub automatically, Cluster Members need Azure Active Directory or Azure Stack Hub Federation Services credentials. Use the Role-Based Access Control (RBAC) to enable Active Directory.

Supported Azure VM Instances (Gen1 and Gen2)

 

2 vCPUs

4 CPUs

8 CPUs

16 CPUs

20 CPUs

32 CPUs

48 CPUs

64 CPUs

D-v5-series D2 v5 D4 v5 D8 v5 D16 v5 - D32 v5 - -
DS-v5-series D2s v5 D4s v5 D8s v5 D16s v5 - - - -
Dd-v5-series D2d v5 D4d v5 D8d v5 D16d v5 - D32d v5 - -
DdS-v5-series D2ds v5 D4ds v5 D8ds v5 D16ds v5 - D32ds v5 - -
D-v4-series - D4 v4 D8 v4 D16 v4 - D32 v4 D48 v4 D64 v4
Ds-v4-series - D4s v4 D8s v4 D16s v4 - D32s v4 D48s v4 D64s v4

Notes:

  • The Azure VM instances listed above are supported in both Gen1 and Gen2 deployments.

  • Gen1 deployments are supported in all Check Point versions.

  • Gen2 deployments are supported starting from R82.10 and higher.

  • Gen2 is supported only for Cloud Firewall Gateways.

  • Azure V6 and V7 VM series are not supported.