> Source: [sk182448](https://support.checkpoint.com/results/sk/sk182448)

# sk182448 - Outbound Internet connectivity is not accessible after configuring Hide NAT on vNET in the Cloud Firewall for Azure High Availability solution

| Property | Value |
|----------|-------|
| Solution ID | sk182448 |
| Date Created | 2024-06-30 |
| Last Modified | 2026-05-11 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |
| Platform | Azure |

## Symptoms

- After configuring Hide NAT on the entire vNET in the Cloud Firewall for Azure High Availability (HA) solution, the outbound Internet connectivity is not accessible when a failover occurs in the HA cluster.

## Cause

This behavior is a system limitation when Hide NAT is configured for the entire vNET instead of specific subnets within the vNET.  

Because of this configuration, API calls to Azure are NATed (Network Address Translated). This means the IP address of the cluster's Virtual IP (VIP) is changed instead of the IP address of the actual Security Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
