> Source: [sk174006](https://support.checkpoint.com/results/sk/sk174006)

# sk174006 - Cloud Firewall for Public Cloud - Frequently Asked Questions

| Property | Value |
|----------|-------|
| Solution ID | sk174006 |
| Date Created | 2021-06-13 |
| Last Modified | 2026-09-01 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |
| Platform | AWS, Azure, Alibaba Cloud, Yandex Cloud, GCP, OCI |

## Solution

Below is a list of frequently asked questions about Cloud Firewall (formerly, CloudGuard Network) for Public Cloud.  
Show the entire FAQ

1. **How to upgrade a Cloud Firewall Instance?**  
   > Upgrade paths for each Cloud Firewall for Public Cloud solution are documented in [sk162365 - Upgrade documentation for Cloud Firewall in Public Cloud](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162365).
2. **Is it possible to convert a Cloud Firewall Gateway/Cluster to an AutoScaling/VMSS/MIG instances?**  
   > There is currently no supported method for this type of conversion.
   >
   > For instructions on how to deploy an autoscaling/VMSS/MIG, refer to the Administration Guide for the specific version and platform.
3. **Is it possible to convert a Cloud Firewall Gateway to a Cloud Firewall Cluster?**  
   > There is currently no support method for this type of conversion.
4. **How to keep a public IP for a public cloud instance?**  
   > * In AWS: [Associate static public IP address](https://aws.amazon.com/premiumsupport/knowledge-center/ec2-associate-static-public-ip/)
   >
   > * In Azure: [sk173632 - Convert Azure Basic Public IP address to Standard Public IP address](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk173632)
   >
   > * In GCP: [Reserve static external IP address](https://cloud.google.com/compute/docs/ip-addresses/reserve-static-external-ip-address)

5. **How to keep an internal IP for a public cloud instance?**  
   > * In AWS: [custom private primary address](https://aws.amazon.com/premiumsupport/knowledge-center/custom-private-primary-address-ec2/)
   >
   > * In Azure: [static private IP address](https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-static-private-ip-arm-pportal)
   >
   > * In GCP: [reserve static internal IP address](https://cloud.google.com/compute/docs/ip-addresses/reserve-static-internal-ip-address)

6. **How to backup a Cloud Firewall Public Cloud instance?**  
   > Refer to [sk169814 - Back up Cloud Firewall Public Cloud instances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk169814)
7. **How to access Maintenance mode?**  
   > Refer to [sk170732 - Maintenance mode for Cloud Firewall for Public Cloud](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170732)
8. **How to increase disk size?**  
   > Refer to [sk156552 - Increasing disk size of CloudGuard Network for Public Cloud instances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk156552)
9. **How to add additional network interfaces?**  
   > * In AWS: [sk92916 - Adding a Network Interface to the Virtual Appliance for AWS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92916)
   >
   > * In Azure: Not supported
   >
   > * In GCP: [sk121637 - Deploy a Cloud Firewall for GCP with Multiple Network Interfaces](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk121637)
   >
   > * In Oracle: Not supported
10. **How to use the real source IP (not the Load Balancer's IP) in policy and logs using XFF?**  
    > Refer to:  
    >
    > [sk115532 - IPS Geo protection based on "X-Forwarded-For" HTTP header in Cloud Firewall for Public Cloud](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115532)
    >
    > [sk167578 - XFF Header injection over source NATed HTTP/S connections](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk167578&partition=Advanced&product=Quantum)  
    >
    > <br />
    >
    > Notes:  
    >
    > 1. Works only with IPS Geo Protection - The enforcement is based on countries' IP ranges.
    >
    > 2. Access and Threat Prevention policy enforcement based on XFF header IP is not supported.

11. **Why is North-South traffic not being accelerated?**  
    > This is a known limitation.
    >
    > All packets that match a rule, whose source or destination is the Security Gateway itself, are not being accelerated.
    >
    > See [sk32578 - SecureXL Mechanism](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk32578)
12. **How to connect on-prem and cloud environments?**  
    > * In AWS: [sk108281 - VPN between on-premises Security Gateway and CloudGuard for AWS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108281)
    >
    > * In Azure: [sk110993 - Securing ExpressRoute traffic in Microsoft Azure](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110993)
    >
    >   [sk101275 - VPN between on-premises Security Gateway and Cloud Firewall for Azure](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101275&partition=Basic&product=IPSec)
    > * In GCP: [sk123602 - VPN Between on-premises Security Gateway and Google Cloud VPN](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk123602)

13. **Why does Cluster VIP not transfer between members during failover?**  
    > When public cloud Security Clusters that has a VIP failover, an API call to the cloud platform is made in order to change the VIP association to the promoted member.  
    >
    > In order to perform this API call, special credentials are required for the cluster member instances.  
    >
    > If the Cloud Firewall Cluster deployment was made into an existing vNET/VPC, verify that the Cluster Members instances have contributor/IAM roles.
14. **Is Azure Live Migration supported for Cloud Firewall deployments?**  
    > Yes. Check Point Cloud Firewall supports Azure Live Migration, provided the gateway is deployed on a VM size that Azure marks as eligible for Live Migration.  
    >
    > For new deployments, we recommend using newer-generation VM sizes, such as:  
    >
    > Standard_DS\*_v4  
    > Standard_D\*ds_v5  
    >
    > Earlier Standard_DS\* sizes are commonly used but have known limitations and should be avoided for new deployments where possible.  
    >
    > Per Azure, most VM sizes are eligible - the main exceptions are the G, L, N, and H series (not supported), while the M series is supported only on a subset of its SKUs.  
    >
    > You can confirm eligibility for a specific VM size in Microsoft's [documentation](https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-and-updates#live-migration)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
