<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX VSLS: Interface active check in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131763#M19443</link>
    <description>&lt;P&gt;Hi Chris,&lt;BR /&gt;&lt;BR /&gt;Thanks for your answer, and wow - I did not realize this could have been a bug, I was thinking this was somehow a design choice. Thanks a lot for pointing this out, will upgrade right away.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Oct 2021 11:25:16 GMT</pubDate>
    <dc:creator>Marcovb</dc:creator>
    <dc:date>2021-10-14T11:25:16Z</dc:date>
    <item>
      <title>VSX VSLS: Interface active check</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131744#M19438</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I have an issue in VSX. I wonder what's the logic behind this, and maybe you could help me out.&lt;BR /&gt;&lt;BR /&gt;I have an R80.40 VSX cluster (jumbo 120) running in VSLS mode. For the sake of argument I have the following simplified example, in my real setup there are a few more VS'es:&lt;BR /&gt;&lt;BR /&gt;VS0 uses interfaces Mgmt for DMI and bond0 for sync&lt;BR /&gt;VS1 only uses bond1 as a VLAN trunk, multiple VLAN interfaces are created here&lt;BR /&gt;VS2 only uses bond2 as a VLAN trunk, multiple VLAN interfaces are created here&lt;BR /&gt;&lt;BR /&gt;- bond1 is currently shutdown (on the adjecent switch) because VS1 will not be put into production yet. We can't enable this interface.&lt;BR /&gt;- bond2 is currently active and VS2 is handling traffic.&lt;BR /&gt;&lt;BR /&gt;Now the issue: cphaprob stat shows Active(!)/Down on VS2 because bond1 is down. (interface active check)&lt;BR /&gt;&lt;BR /&gt;When I check "cphaprob -a if" on VS2, I don't see any mention of bond1 here, as expected. Why does this VS suffer from the fact that an interface for a different VS is down?&lt;BR /&gt;&lt;BR /&gt;As a workaround, could I use the discntd.if file to circumvent this? Its only temporarily since bond1 will be enabled in a few weeks. I read somewhere else that using this file in VSX is not recommended.&lt;BR /&gt;&lt;BR /&gt;I hope someone can shed some light on this.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 08:03:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131744#M19438</guid>
      <dc:creator>Marcovb</dc:creator>
      <dc:date>2021-10-14T08:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: VSX VSLS: Interface active check</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131762#M19442</link>
      <description>&lt;P&gt;Have a look at reference&amp;nbsp;&lt;SPAN&gt;PRJ-30284 resolved in JHF T125.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 11:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131762#M19442</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-10-14T11:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: VSX VSLS: Interface active check</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131763#M19443</link>
      <description>&lt;P&gt;Hi Chris,&lt;BR /&gt;&lt;BR /&gt;Thanks for your answer, and wow - I did not realize this could have been a bug, I was thinking this was somehow a design choice. Thanks a lot for pointing this out, will upgrade right away.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 11:25:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VSLS-Interface-active-check/m-p/131763#M19443</guid>
      <dc:creator>Marcovb</dc:creator>
      <dc:date>2021-10-14T11:25:16Z</dc:date>
    </item>
  </channel>
</rss>

