Limitations of Cloud Firewall for Azure VMSS
-
IPv6-only Virtual Machines (VMs) or Virtual Machines Scale Sets (VMSS) are not supported. IPv6/IPv4 VMs or VMSS are supported. Refer to sk170760 and sk163313 for more information.
-
Only Azure Resource Manager (ARM
Microsoft Azure Resource Manager. Technology to administer assets using Resource Group.) and Terraform deployments are supported.Deployment in the Azure classic environment is not supported.
-
Azure Load Balancers have limits on the number of supported front-end IP addresses.
See Microsoft documentation on Azure Networking Limits.
-
East-West traffic inspection between peered VNETs is supported only for RFC 1918 private networks (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
-
Anti-Spoofing is disabled by default on the VMSS instances eth0 and eth1 and must not be enabled.
-
Cloud Firewall metrics are available in a subset of Azure regions. For more information, see the Azure Monitor Supported Regions documentation.
-
If the Endpoint Policy Management
Software Blade on a Management Server to manage an on-premises Endpoint Security environment. Software Blade
Specific security solution (module): (1) On a Check Point Firewall, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities. is enabled on the Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server., the Autoprovision feature is not supported. -
The local Threat Emulation
Software Blade on a Check Point Firewall that monitors the behavior of files in a sandbox to determine whether or not they are malicious. Acronym: TE. blade is not supported on Check Point Cloud Firewall Gateways. -
Azure DNS does not replace client DNS servers. It can be used in addition to public and ISP DNS servers. For more information, see Microsoft Azure DNS documentation.
-
Policy Server (Desktop Policy) is not supported.
-
For Endpoint Security managed clients, enforcement of the Firewall policy from the SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. is not supported. -
For Endpoint Security managed clients, configuration of SCV checks from the Cloud Firewall Gateway
Check Point Virtual Security Gateway that protects dynamic virtual environments with policy enforcement. Cloud Firewall Gateway inspects traffic between Virtual Machines to enforce security, without changing the Virtual Network topology. is not supported.
-
Hub Mode (Route-All-Traffic) is not supported.
-
Editing of Login Options and Legacy Authentication is not supported.
-
Automatic MEP Topology is not supported.
-
Machine Authentication is not supported.
-
For Endpoint Security VPN, SecuRemote flavor is not supported.
-
Connection enhancements for Cloud Firewall Gateways with multiple external interfaces (also knows as "magic button") are not supported.
-
Site to Site VPN is not supported.
-
Creating a VMSS environment with a name for the Load Balancer that is different from the default ("frontend-lb" or "backend-lb") is not supported.
-
Remote Access VPN is not supported.
-
Modifying NIC names in Azure is not supported. The NIC names must remain "eth0", "eth1".
-
Connection draining is not supported for scale-in events.
-
SAM rules are not supported on Virtual Machine Scale Sets (VMSS) deployments in Azure. Due to an Azure environment limitation, interface aliases cannot be configured automatically in these solutions, which prevents SAM rules from being created either automatically or manually.
-
Browser Zero Phishing
Software Blade on a Check Point Firewall (R81.20 and higher) that provides real-time phishing prevention based on URLs. Acronym: ZPH. is not supported in Cloud Firewall Auto Scale solutions. -
Identity Collector is not supported in Cloud Firewall Auto Scale solutions.
-
Instance Level Public IP (ILPIP) Address Management
Because of Microsoft Azure
Collection of integrated cloud services that developers and IT professionals use to build, deploy, and manage applications through a global network of data centers managed by Microsoft. design, if you deploy a Check Point Cloud Firewall Gateway with an ILPIP address to manage the VMSS by its public IP addresses:-
Each instance is configured in Check Point SmartConsole with the original (first) ILPIP address.
-
If the deployed Cloud Firewall Gateway is restarted, the ILPIP address could be released by Microsoft Azure and a new IP address is dynamically allocated.
In this case:
-
The Cloud Firewall Gateway continues to work.
-
The Security Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. is no longer able to communicate with the Cloud Firewall Gateway (this affects policy installation, receiving logs, and monitoring).
To fix communication issues:
-
Delete the instance in Azure portal and let Azure bring up a new instance (which is then automatically recognized by the Security Management Server)
-
a. Reset SIC in SmartConsole and on the Cloud Firewall Gateway instance.
b. In SmartConsole, manually change the IP address of the Cloud Firewall Gateway object to the new dynamically assigned IP address.
c. In SmartConsole, manually initialize SIC.
-
|
|
Notes:
|
Cloud Firewall for Azure China and ICP Filing
What is ICP?
ICP stands for Internet Content Provider. China requires an ICP Filing for websites hosted on servers in mainland China. This includes all public clouds.
Every customer of a public cloud must have an ICP Filing, because the Chinese government requires it by law. The filing identifies the website owner. It also lets the website legally provide online content or services in mainland China.
Without an ICP Filing, the Chinese authorities can block a website hosted in mainland China or prevent it from going online.
Impact on Cloud Firewall without an ICP Filing
If you host a Check Point-related service in mainland China and make it available on the public Internet through a domain name, you usually must have an ICP Filing. Without the filing, these problems can occur:
-
Users cannot access the Gaia Portal
Web interface for the Check Point Gaia operating system., Remote Access VPN, or Mobile Access
Software Blade on a Check Point Firewall that provides a Remote Access VPN access for managed and unmanaged clients. Acronym: MAB. by domain name. Instead, they must use the IP address. -
Domain-based protection of North-South public network traffic is affected when end users provide web content in public(for example,
www.example.com > Azure China Public IP > Cloud Firewall > Application). -
The user experience is affected when end users provide the Cloud Firewall portal in public. When a user accesses the portal, the certificate does not match the IP address. As a result, the browser shows a security alert. This applies to these components:
-
Captive Portal
-
UserCheck Portal
-
Mobile Access Portal
-
HTTPS Inspection
Feature on a Check Point Firewall that inspects traffic encrypted by the Secure Sockets Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection. Acronyms: HTTPSI, HTTPSi. block page or user notification
-
Suggested Approach
ICP is required if the users must access Cloud Firewall by domain, or if the business must host public web services. In this case, complete the ICP registration.
To learn more, see Azure China for ICP.