<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109948#M15048</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Does anyone knows if a VS on a VSX cluster (VSLS mode) can be on active/active mode in normal or in a split brain scenario?&lt;/P&gt;&lt;P&gt;In case of split brain scenario is a way to force a VS that is on down state on that VSX( VSLS&amp;nbsp; mode) become active?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
    <pubDate>Fri, 05 Feb 2021 17:03:10 GMT</pubDate>
    <dc:creator>KostasGR</dc:creator>
    <dc:date>2021-02-05T17:03:10Z</dc:date>
    <item>
      <title>VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109948#M15048</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Does anyone knows if a VS on a VSX cluster (VSLS mode) can be on active/active mode in normal or in a split brain scenario?&lt;/P&gt;&lt;P&gt;In case of split brain scenario is a way to force a VS that is on down state on that VSX( VSLS&amp;nbsp; mode) become active?&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 17:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109948#M15048</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-02-05T17:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109959#M15052</link>
      <description>&lt;P&gt;It's theoretically possible, but only if neither one can see cluster heartbeats from the other, and both can ping something on every interface. I could contrive such an environmental disruption, but it would be extraordinarily unlikely for random failures to result in both members claiming to be active.&lt;/P&gt;
&lt;P&gt;I don't know of a way to force a down member to become active.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 19:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109959#M15052</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-02-05T19:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109980#M15058</link>
      <description>&lt;P&gt;What is the hardware platform &amp;amp; version&amp;nbsp; involved, also is this for L2 or L3 virtual systems?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 10:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/109980#M15058</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-06T10:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115607#M16278</link>
      <description>&lt;P&gt;Hello Chris&lt;/P&gt;&lt;P&gt;The version is r80.30 and they are L3 VS and not bridge VS L2.&lt;/P&gt;&lt;P&gt;Consider a scenario you have two data centers with Layer 2 Data Center Interconnection and one site is totally destroyed by a meteor or a flood for example or the lines that interconnect them are out of service (most probable scenario).&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 16:20:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115607#M16278</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2021-04-08T16:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115748#M16308</link>
      <description>&lt;P&gt;vsenv &amp;lt;id&amp;gt;&lt;/P&gt;
&lt;P&gt;clusterXL_admin down&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 14:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115748#M16308</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-10T14:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115752#M16310</link>
      <description>&lt;P&gt;That forces an active context in VSLS to become down. 'clusterXL_admin up' clears the artificially-down status, but does not force the member to become active. If the member thinks it is unhealthy for another reason and the active contention mechanism has failed, it will refuse to take over, and I don't know of a way to force it to.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 18:09:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115752#M16310</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-10T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115753#M16311</link>
      <description>&lt;P&gt;One site being destroyed isn't really split-brain. If one whole datacenter is gone, then the other member should take over because it's still there.&lt;/P&gt;
&lt;P&gt;If the interconnect between the datacenters fails, that would be split-brain, sure. Depending on the rest of the environment (in particular, whether there are things in both datacenters which respond to pings from the firewalls), that &lt;EM&gt;could&lt;/EM&gt; result in both members becoming active, though they wouldn't conflict with each other, as the link between the datacenters is down.&lt;/P&gt;
&lt;P&gt;This has complicated implications if the two cluster members have totally independent connectivity to the same things outside the datacenters. For example, if they each have their own Internet connection, and they talk BGP with the telco, that&amp;nbsp;&lt;EM&gt;could&lt;/EM&gt; result in both of them trying to claim to be the right path for the AS, which &lt;EM&gt;could&lt;/EM&gt; result in anycast-style traffic flow.&lt;/P&gt;
&lt;P&gt;If the DC-to-DC link goes down, and one member decides it isn't healthy enough to take over, I don't know of a way to force it to take over anyway.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 18:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115753#M16311</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-10T18:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115774#M16316</link>
      <description>&lt;P&gt;so the scenario is DC to DC link gone down, both members now active and you need to force the traffic down one of the member only, so we are attempting to treat the symptom here and not address the root cause.&lt;/P&gt;
&lt;P&gt;Possible things to try:&lt;/P&gt;
&lt;P&gt;- cpstop on the member you want down?&lt;/P&gt;
&lt;P&gt;- Shutdown all interfaces except Management on the member?&lt;/P&gt;
&lt;P&gt;- cphastop?&lt;/P&gt;
&lt;P&gt;- shutdown the node via LOM.&lt;/P&gt;
&lt;P&gt;- Clearly - resolve the DC to DC issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Above is all I think of unless TAC have another suggestion.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 09:20:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115774#M16316</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-11T09:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: VS on a VSX cluster (VSLS mode) can be on active active mode in normal or split brain scenario</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115788#M16320</link>
      <description>&lt;P&gt;Again, that works to force a member down. That wasn't the question asked, though. The original post asks if there is a way to force a VS which is currently down to become active.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Apr 2021 14:59:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VS-on-a-VSX-cluster-VSLS-mode-can-be-on-active-active-mode-in/m-p/115788#M16320</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-11T14:59:37Z</dc:date>
    </item>
  </channel>
</rss>

