VSEC - Deployment guide - Check Point CheckMates

VSEC - Deployment guide

Hi All, I have a lot of experience deploying Checkpoint HA Clusters in traditional DC's but have recently been tasked with setting up Checkpoint VPN and Checkpoint Firewalls in an Azure environment. Is it similar to running cpconfig - setup SIC - attach license - download policy etc? if not is there a guide on how to do this using a provider-1 environment then setting up SIC with the Gateways?

Apologies but I'm totally new to VSEC and wanted a brief explanation on how you do this, from what I see you manage the cluster objects in exactly the same way, can anyone help?

Many Thanks in advance

Alan

6\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

10 Replies

Vladimir

Champion

‎2018-01-2410:00 AM

Show option menu

Alan,

Please check the Deploying a Check Point Cluster in Microsoft Azure for details. I've done quite a few AWS vSEC deployments, but didn't get my hands on Azure yet.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

John_Parnell

Participant

‎2018-01-2410:08 AM

Show option menu

Alan,

You can follow sk110194 to deploy a cluster in Azure.

The short short description.

Define a vNet

Define a Frontend Subnet within the vNet

Define a Backend Subnet within the vNet

Deploy CheckPoint vSec Cluster from the marketplace

Follow the steps to deploy. This will take about 10 minutes once you complete all the steps.

Enable vSec on the management server via CLI. Command is vsec on

Create a new cluster object in your domain. Use the public IP created for the cluster as the cluster IP

Add each object to the cluster

Set both interfaces as sync only

You will need to create a service principal that has contributor rights

Run the command azure-ha-conf --client-id (with client-id from the service principal here) --client-secret (with the key created when you created the service principal here) This needs to be done on each firewall in the cluster.

Run the command $FWDIR/scripts/azure-ha-cli.py reconf This also needs to be done on each firewall in the cluster

Install your vsec license in the domain where you are deploying vSec.

Attach the license to the CMA.

Go to CLI of the management server and change to the domain environment mdsenv domain-name-here

Run the command vsec-central-license

That is the very short version.

Hope that helps.

1\ \ \ Kudo

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Vladimir

Champion

‎2018-01-2411:41 AM

Show option menu

In response to John_Parnell

John,

can you expand on "Set both interfaces as sync only"?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

John_Parnell

Participant

‎2018-01-2811:33 AM

Show option menu

In response to Vladimir

Vladimir,

This is done under network management in the cluster object with SmartConsole. So the cluster for the most part is created just like any other cluster. Except with the interfaces. You have options like private, cluster, sync, and cluster + sync. Here we choose sync then use Azure route tables to direct traffic to the active firewalls interface. If the firewalls fail over they will use the python script to change the route table to point to the active firewalls interface. This used to take up to 3 minutes to complete, however now I generally see times as quick as less than 1 second.

I hope that better explains.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Vladimir

Champion

‎2018-01-2812:44 PM

Show option menu

In response to John_Parnell

Thanks.

Still hard to visualize: I am not getting which "both" interfaces you are referring to.

Since you've described FrontEnd and BackEnd vNets, I'd imagine each cluster member should have at least three interfaces, unless you are using Cluster + Sync, in which case it may be two.

I'll probably have to go through deployment myself in order to get a better feel for it.

Regards,

Vladimir

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

John_Parnell

Participant

‎2018-01-3006:42 AM

Show option menu

In response to Vladimir

No each cluster will have two interfaces by default. You will have eth0 and eth1. eth0 will be your frontend interface, which is just what Azure calls it, but it will set your default route to go out this interface. eth1 will be your backend interface. There is not VIP to define. So if your frontend subnet is 10.10.10.0/24 eth0 will get assigned 10.10.10.4 for firewall1 in the cluster and firewall2 will get 10.10.10.5. Your backend subnet must be different from your frontend subnet so lets give it 10.10.20.0/24. eth1 will get 10.10.20.4 for firewall1 and firewall2 will get 10.10.20.5. There will also be a public IP set as an alias to firewall1 on eth0. You will set a route table to direct traffic from your other subnets to point to the active cluster members eth1, so lets say 10.10.20.4. If you failover the firewalls the python script on the other firewall will reach out to Azure and change the route table to point 10.10.20.5. So as you can see there are no cluster interfaces in Azure. You just set both eth0 and eth1 to sync.

I hope this better describes how it works.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Alan_Camelo1

Contributor

‎2018-01-2602:54 AM

Show option menu

In response to John_Parnell

Many Thanks,

I shall have a look and let you know how I get on.

I'm sure there may be a few more questions due to my lack of knowledge of Azure at the moment, some terminology things like "Define Frontend subnet within Vnet" ? is this done within Azure or on Vsec?

Thanks again in advance!

Alan

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

John_Parnell

Participant

‎2018-01-2811:37 AM

Show option menu

In response to Alan_Camelo1

Alan,

Both are done in Azure. During the deployment of the firewall cluster you can create both a new vNet(Virtual Network) and the front end and back end subnet.

I hope that helps.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Fabricio_Lima

Explorer

‎2018-09-1205:01 PM

Show option menu

Deploying vSEC fw in Azure

https://community.checkpoint.com/docs/DOC-2650-day-1-03-vsec-training-azure-lab-ptkpdf

https://www.youtube.com/watch?v=nUyTWayUGHk

Deploying vSEC on AWS

https://community.checkpoint.com/docs/DOC-2661-day-2-04-vsec-training-aws-lab-ptkpdf

https://www.youtube.com/watch?v=1h2X_PwVXw0

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Nikhil_Deshmukh

Contributor

‎2018-09-1312:45 AM

Show option menu

Hi Alan Camelo ‌,

For Starter's you can visit,

Microsoft Azure Documentation | Microsoft Docs and then move on to Check Point Reference Architecture for Azure (Single Gateway), then move to cluster Deploying a Check Point Cluster in Microsoft Azure.

As you move ahead you can refer to many other Related Solutions when you are stuck or can come back to CheckMates.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

WiliRGasparetto
13

Jeff_Engel
1

jorgeluiznim
1

View All ≫

Trending Discussions

Part 1 How CloudGuard Controller R82.10 Builds Dynamic Security Context

Identity Distribution, TTL, Monitoring, and Operations in CloudGuard Controller R82.10

Known R82.10 Limitations That Affect Architecture The current R82.10 documentation lists limitati

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.