<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX: funny IP's in different subnets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144403#M22475</link>
    <description>&lt;P&gt;Is this a new VS and are you in a position to remove and re-add the interfaces?&lt;/P&gt;
&lt;P&gt;What was the order of operations that got you to this point?&lt;/P&gt;
&lt;P&gt;Please engage TAC especially if the issue is reproducible.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 11:32:16 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-03-22T11:32:16Z</dc:date>
    <item>
      <title>VSX: funny IP's in different subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144275#M22452</link>
      <description>&lt;P&gt;Dear CheckMates,&lt;/P&gt;&lt;P&gt;I have some trouble with VSX VSLS in version R81.10 with Jumbo-30 (Mgmt is also on R81.10 with Jumbo-30).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For one of my eleven VS, I have lot's of error messages in /var/log/messages and the log file, saying "CLUS-1147-02-2: State chage: Active -&amp;gt; Standby...."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;Interface&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;Member-1&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;Member-2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;bond1.123&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.33 / 28&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.2 / 28&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;bond2.234&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.17 / 28&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.18 / 28&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%"&gt;bond3.345&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.1 / 28&lt;/TD&gt;&lt;TD width="33.333333333333336%"&gt;192.168.196.34 / 28&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we can see, the funny-ip's from bond1 and bond3 does not match the network ID of each other&lt;/P&gt;&lt;P&gt;Bond 2 is fine, as well as all other VS's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone has an idea to solve the problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks and best regars,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2022 10:40:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144275#M22452</guid>
      <dc:creator>Christian_Koehl</dc:creator>
      <dc:date>2022-03-21T10:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: funny IP's in different subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144403#M22475</link>
      <description>&lt;P&gt;Is this a new VS and are you in a position to remove and re-add the interfaces?&lt;/P&gt;
&lt;P&gt;What was the order of operations that got you to this point?&lt;/P&gt;
&lt;P&gt;Please engage TAC especially if the issue is reproducible.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 11:32:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144403#M22475</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-22T11:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: funny IP's in different subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144404#M22476</link>
      <description>&lt;P&gt;This is not a new VS. About 6-7 months ago we changed the appliance running the VSX Cluster from a 5900 units to a 26000 units and changed to configuration from bond1 and bond3.&lt;/P&gt;&lt;P&gt;This makes belive, we have the problem since that changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When running R80.40 with VSX HA everything was working. Now, we updated to R81.10 and now we running VSLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a TAC case in the past (when running R80.40), but they wanted to start debugging. Unfortunately, that systems are productive and the effected VS the "core router" of the customer. Therefore I&amp;nbsp; closed that case.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 11:39:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/144404#M22476</guid>
      <dc:creator>Christian_Koehl</dc:creator>
      <dc:date>2022-03-22T11:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: funny IP's in different subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/147941#M23590</link>
      <description>&lt;P&gt;Dear Folks,&lt;/P&gt;&lt;P&gt;last weekend I was able to have a close look into the problem.&lt;/P&gt;&lt;P&gt;It is possible to change the funny-ip's via GuiDBedit. The funny-ip's from the backup member were change. There are three positions for each funny-ip.&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-1.png" style="width: 759px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16393i4519547D86EFD978/image-dimensions/759x607?v=v2" width="759" height="607" role="button" title="screenshot-1.png" alt="screenshot-1.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="screenshot-2.png" style="width: 744px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16392iF65E8864326713E2/image-dimensions/744x619?v=v2" width="744" height="619" role="button" title="screenshot-2.png" alt="screenshot-2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After saving the changes, GuiDBedit can be close. Now open the Smart Console and do a "Publish".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the next step, I reset the VSX-cluster member with "reset_gw" via direct console connection.&lt;/P&gt;&lt;P&gt;The last step was a "vsx_util reconfigure" and a policy install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this will help, if someone else has this problem.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 10:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-funny-IP-s-in-different-subnets/m-p/147941#M23590</guid>
      <dc:creator>Christian_Koehl</dc:creator>
      <dc:date>2022-05-05T10:04:16Z</dc:date>
    </item>
  </channel>
</rss>

