> Source: [sk183079](https://support.checkpoint.com/results/sk/sk183079)

# sk183079 - GCP MIG health checks fail for Cloud Firewall Gateways when managed by an R82 Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk183079 |
| Date Created | 2025-01-29 |
| Last Modified | 2026-05-06 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R82 |
| OS | Gaia |
| Platform | GCP |

## Symptoms

- External Load Balancer health checks in GCP MIG fail on port 8117 for Cloud Firewall (formerly CloudGuard Network) Gateways managed by an R82 Security Management Server.

## Cause

GCP's Managed Instance Group (MIG) performs periodic health checks on autoscaling Security Gateways. If a Security Gateway fails to respond promptly, GCP MIG marks it for termination.   

The Cloud Management Extension (CME) maintains a list of GCP MIG health check IP ranges in a user definition file (`user.def.FW1`) on the Security Management Server to prevent the firewall from blocking these health checks. After the Security Policy installation, the user definition file is distributed to Security Gateways.  

In R82 Security Management Server, the user definition files are split based on Security Gateway versions:

* For R82 Security Gateway: `$FWDIR/conf/user.def.FW1`

* For R81.20 and lower versions of Security Gateway: `$FWDIR/conf/user.def.R8120CMP`

When an R82 Security Management Server manages lower-version Security Gateway, CME incorrectly updates a `user.def.FW1` file instead of a `user.def.R8120CMP` file, causing health checks to fail.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
