VSEC - Deployment guide - Check Point CheckMates
VSEC - Deployment guide
Hi All, I have a lot of experience deploying Checkpoint HA Clusters in traditional DC's but have recently been tasked with setting up Checkpoint VPN and Checkpoint Firewalls in an Azure environment. Is it similar to running cpconfig - setup SIC - attach license - download policy etc? if not is there a guide on how to do this using a provider-1 environment then setting up SIC with the Gateways?
Apologies but I'm totally new to VSEC and wanted a brief explanation on how you do this, from what I see you manage the cluster objects in exactly the same way, can anyone help?
Many Thanks in advance
Alan
- Tags:
- vsec - azure deployment
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
10 Replies
Champion
2018-01-2410:00 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Alan,
Please check the Deploying a Check Point Cluster in Microsoft Azure for details. I've done quite a few AWS vSEC deployments, but didn't get my hands on Azure yet.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2018-01-2410:08 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Alan,
You can follow sk110194 to deploy a cluster in Azure.
The short short description.
Define a vNet
Define a Frontend Subnet within the vNet
Define a Backend Subnet within the vNet
Deploy CheckPoint vSec Cluster from the marketplace
Follow the steps to deploy. This will take about 10 minutes once you complete all the steps.
Enable vSec on the management server via CLI. Command is vsec on
Create a new cluster object in your domain. Use the public IP created for the cluster as the cluster IP
Add each object to the cluster
Set both interfaces as sync only
You will need to create a service principal that has contributor rights
Run the command azure-ha-conf --client-id (with client-id from the service principal here) --client-secret (with the key created when you created the service principal here) This needs to be done on each firewall in the cluster.
Run the command $FWDIR/scripts/azure-ha-cli.py reconf This also needs to be done on each firewall in the cluster
Install your vsec license in the domain where you are deploying vSec.
Attach the license to the CMA.
Go to CLI of the management server and change to the domain environment mdsenv domain-name-here
Run the command vsec-central-license
That is the very short version.
Hope that helps.
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Champion
2018-01-2411:41 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
John,
can you expand on "Set both interfaces as sync only"?
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2018-01-2811:33 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Vladimir,
This is done under network management in the cluster object with SmartConsole. So the cluster for the most part is created just like any other cluster. Except with the interfaces. You have options like private, cluster, sync, and cluster + sync. Here we choose sync then use Azure route tables to direct traffic to the active firewalls interface. If the firewalls fail over they will use the python script to change the route table to point to the active firewalls interface. This used to take up to 3 minutes to complete, however now I generally see times as quick as less than 1 second.
I hope that better explains.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Champion
2018-01-2812:44 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks.
Still hard to visualize: I am not getting which "both" interfaces you are referring to.
Since you've described FrontEnd and BackEnd vNets, I'd imagine each cluster member should have at least three interfaces, unless you are using Cluster + Sync, in which case it may be two.
I'll probably have to go through deployment myself in order to get a better feel for it.
Regards,
Vladimir
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2018-01-3006:42 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No each cluster will have two interfaces by default. You will have eth0 and eth1. eth0 will be your frontend interface, which is just what Azure calls it, but it will set your default route to go out this interface. eth1 will be your backend interface. There is not VIP to define. So if your frontend subnet is 10.10.10.0/24 eth0 will get assigned 10.10.10.4 for firewall1 in the cluster and firewall2 will get 10.10.10.5. Your backend subnet must be different from your frontend subnet so lets give it 10.10.20.0/24. eth1 will get 10.10.20.4 for firewall1 and firewall2 will get 10.10.20.5. There will also be a public IP set as an alias to firewall1 on eth0. You will set a route table to direct traffic from your other subnets to point to the active cluster members eth1, so lets say 10.10.20.4. If you failover the firewalls the python script on the other firewall will reach out to Azure and change the route table to point 10.10.20.5. So as you can see there are no cluster interfaces in Azure. You just set both eth0 and eth1 to sync.
I hope this better describes how it works.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Contributor
2018-01-2602:54 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many Thanks,
I shall have a look and let you know how I get on.
I'm sure there may be a few more questions due to my lack of knowledge of Azure at the moment, some terminology things like "Define Frontend subnet within Vnet" ? is this done within Azure or on Vsec?
Thanks again in advance!
Alan
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Participant
2018-01-2811:37 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Alan,
Both are done in Azure. During the deployment of the firewall cluster you can create both a new vNet(Virtual Network) and the front end and back end subnet.
I hope that helps.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Explorer
2018-09-1205:01 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Deploying vSEC fw in Azure
https://community.checkpoint.com/docs/DOC-2650-day-1-03-vsec-training-azure-lab-ptkpdf
https://www.youtube.com/watch?v=nUyTWayUGHk
Deploying vSEC on AWS
https://community.checkpoint.com/docs/DOC-2661-day-2-04-vsec-training-aws-lab-ptkpdf
https://www.youtube.com/watch?v=1h2X_PwVXw0
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Contributor
2018-09-1312:45 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Alan Camelo ,
For Starter's you can visit,
Microsoft Azure Documentation | Microsoft Docs and then move on to Check Point Reference Architecture for Azure (Single Gateway), then move to cluster Deploying a Check Point Cluster in Microsoft Azure.
As you move ahead you can refer to many other Related Solutions when you are stuck or can come back to CheckMates.
0
Kudos
Click here to give kudos to this post.
1
2
3
4
5
0.5
1.0
1.5
2.0
2.5
3.0
3.5
4.0
4.5
5.0
Post Reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
WiliRGasparetto |
13 |
Jeff_Engel |
1 |
jorgeluiznim |
1 |
Trending Discussions
Part 1 How CloudGuard Controller R82.10 Builds Dynamic Security Context
Identity Distribution, TTL, Monitoring, and Operations in CloudGuard Controller R82.10
Known R82.10 Limitations That Affect Architecture The current R82.10 documentation lists limitati
Upcoming Events
Sort by:
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats
Wed 29 Jul 2026 @ 12:00 PM (SGT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT
Wed 29 Jul 2026 @ 02:00 PM (IDT)
The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER
Wed 29 Jul 2026 @ 03:00 PM (CEST)
The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 11:30 AM (CDT)
CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On
Tue 28 Jul 2026 @ 11:00 AM (EDT)
Wed 29 Jul 2026 @ 12:00 PM (SGT)
Wed 29 Jul 2026 @ 02:00 PM (IDT)
Wed 29 Jul 2026 @ 03:00 PM (CEST)
Wed 29 Jul 2026 @ 11:00 AM (EDT)
TechTalk: On-Premise SD-WAN Management
Thu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway
Tue 11 Aug 2026 @ 11:30 AM (EDT)
New York City: Agentic AI Security Deep Dive & Hands-On
Thu 13 Aug 2026 @ 11:30 AM (EDT)
Waltham, MA: Agentic AI Security Deep Dive & Hands-On
Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA
Thu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad
Thu 27 Aug 2026 @ 09:00 AM (CEST)
Check Point Hands-On SASE and Cloud Workshop - Zurich
Wed 21 Oct 2026 @ 09:00 AM (BST)
AI Security Workshop - Glasgow
About CheckMates
Learn Check Point
Advanced Learning
Resources
Non-English Discussions
YOU DESERVE THE BEST SECURITY
We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram
©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.