<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150062#M24182</link>
    <description>&lt;P&gt;If there are other VSs which you don't want to try to become active on both members, this isn't possible. Sync and cluster monitoring on VSX is a whole-box thing.&lt;/P&gt;
&lt;P&gt;If you're okay with all VSs trying to become active on two or more members, you just have to prevent those members from seeing each other.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Jun 2022 20:54:09 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2022-06-02T20:54:09Z</dc:date>
    <item>
      <title>How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150055#M24179</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is any way&amp;nbsp; to manually force split brain on 2 VSes created on 2 VSXes on VSLS mode?&lt;/P&gt;&lt;P&gt;I want to achieve 2 VSes active on VSXA and the same 2 VSes active on VSXB in a lab environment.&lt;/P&gt;&lt;P&gt;BR,&lt;BR /&gt;Kostas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 19:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150055#M24179</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2022-06-02T19:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150056#M24180</link>
      <description>&lt;P&gt;I'm pretty sure the answer is no.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can certainly load share between different VSX Nodes but you can't have any one VS active on two different nodes, at least too my knowledge.&lt;/P&gt;
&lt;P&gt;If you want true resource balancing then perhaps Maestro may be a better option.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another idea, would be to have two different VS's using the same policy file but perhaps an external load balancing to share the load (a bit over kill, but could also be an option with some design considerations).&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 19:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150056#M24180</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-06-02T19:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150057#M24181</link>
      <description>&lt;P&gt;I do not think that you can selectively achieve that, but to have all VSes running in split brain, move the networks of one of the unit to the separate vSwitches, (loose the sync) and reboot the unit.&lt;/P&gt;
&lt;P&gt;In theory, it'll come up looking for other cluster member and, not finding one, run VSes to Active mode.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 19:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150057#M24181</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-06-02T19:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150062#M24182</link>
      <description>&lt;P&gt;If there are other VSs which you don't want to try to become active on both members, this isn't possible. Sync and cluster monitoring on VSX is a whole-box thing.&lt;/P&gt;
&lt;P&gt;If you're okay with all VSs trying to become active on two or more members, you just have to prevent those members from seeing each other.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 20:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150062#M24182</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-06-02T20:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150295#M24382</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;Finally i have managed to cause split brain by p&lt;SPAN&gt;reventing those members from seeing each other.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Apart from preventing VSes to see each other through their interfaces (inside,outside,DMZ etc) I had to disable SYNC connectivity and also shutdown the management interface of the 2 VSXes. By disabling the management interfaces of the 2 VSXes i had no logging towards the log server (management server),&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kostas&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 08:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150295#M24382</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2022-06-07T08:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150296#M24383</link>
      <description>&lt;P&gt;What is achieved by this outside a lab?&amp;nbsp; In a production environment you could not really do the above and most certainly Checkpoint would not support it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 08:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150296#M24383</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-06-07T08:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150303#M24385</link>
      <description>&lt;P&gt;A DR scenario that cuts layer 2 connectivity between MAIN DC and REMOTE DC for example. Why Check point wouldn't support it?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 09:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150303#M24385</guid>
      <dc:creator>KostasGR</dc:creator>
      <dc:date>2022-06-07T09:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150304#M24386</link>
      <description>&lt;P&gt;I don't believe this is a supported scenario, but Checkpoint would be better to respond.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 09:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150304#M24386</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-06-07T09:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150316#M24387</link>
      <description>&lt;P&gt;Technically if VSX nodes lose L2 completely then both will become Active as they will assume that other node is dead based on clustering protocol. So your two DCs should continue to work independently. Obviously you won't be able to manage them i.e push rules our routing. But I suggest you test in the lab&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 11:51:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150316#M24387</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-06-07T11:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150330#M24396</link>
      <description>&lt;P&gt;That depends. Other problems such as monitored interfaces which don't have anything available to ping (e.g, a new highest VLAN or lowest VLAN which doesn't have any endpoints on it yet) can cause both members to refuse to become active because they each think they are the device with the failure.&lt;/P&gt;
&lt;P&gt;Spanning layer 2 between datacenters is a really bad idea.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 12:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/150330#M24396</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-06-07T12:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/187287#M34518</link>
      <description>&lt;P&gt;Hehe. There are lots of bad ideas &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;&amp;nbsp;but in reality you are forced to accept legacy solutions that take years to move on from &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:18:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/187287#M34518</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2023-07-24T07:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to manually force split brain on VSes with 2 VSXes on VSLS mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/187356#M34523</link>
      <description>&lt;P&gt;I've personally seen more people trying to span layer 2 between datacenters in each of the last five years than I had even heard about in the ten years before. It's a recent phenomenon. People need to be told it's a terrible idea which will lead to awful problems.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:36:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-manually-force-split-brain-on-VSes-with-2-VSXes-on-VSLS/m-p/187356#M34523</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-07-24T13:36:34Z</dc:date>
    </item>
  </channel>
</rss>

