<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX bridge interface monitoring in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154791#M26312</link>
    <description>&lt;P&gt;This is an area where SmartConsole could be more descriptive/helpful, and the documentation is unclear. &amp;nbsp;I had to switch the VSX Cluster to "ClusterXL" for the VSX bridge configuration. &amp;nbsp;That puts the VSX Cluster in Active/Standby bridge mode. &amp;nbsp;By default it was STP, which I now know is Active/Active bridge mode. &amp;nbsp;This is irrespective of the VSX *gateway* in cpconfig, which I also made sure was enabled for Bridge A/S mode.&lt;/P&gt;
&lt;P&gt;Now I see L3 BVI configuration. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sigh. &amp;nbsp;Quite unclear all around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Aug 2022 15:44:27 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2022-08-09T15:44:27Z</dc:date>
    <item>
      <title>VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154780#M26304</link>
      <description>&lt;P&gt;I'm going through some VSX lab configurations and working with VSX Bridge Mode. &amp;nbsp;Following along the VSX Admin Guide, I created a new VS, but on the interface configuration window there's no option to configure "L3 Bridge Interface Monitoring" to enable/configure the BVI.&lt;/P&gt;
&lt;P&gt;My VSX Cluster properties are using the Active/Active bridge mode (STP), but that shouldn't matter, right?&lt;/P&gt;
&lt;P&gt;I'm using Multi-Domain, so the VSX Cluster is in one domain and the VS itself is in another (which shouldn't matter either).&lt;/P&gt;
&lt;P&gt;Interestingly, the "VSX Supported Features" SK (&lt;SPAN&gt;sk79700) says "VS with bridged interface" is only R81 and higher. &amp;nbsp;However,&amp;nbsp;I see this was an option in the R77 documentation as well as the R80.40 documentation. &amp;nbsp;Is this a documentation error?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 13:20:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154780#M26304</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-08-09T13:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154783#M26305</link>
      <description>&lt;P&gt;I believe prior to R81, if you used L2 in a VS, it could only be L2 mode.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 14:21:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154783#M26305</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-08-09T14:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154785#M26307</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;is correct this came in with R81&lt;/P&gt;
&lt;P&gt;Subsequently R80.40 JHF T53 is the minimum that allows a VS to have L2 bridge interfaces and L3 interfaces on the same VS per&amp;nbsp;&lt;SPAN&gt;sk101371.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 14:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154785#M26307</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-09T14:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154786#M26308</link>
      <description>&lt;P&gt;Hmm, interesting. This is R80.40 JHF 158. &amp;nbsp;(VSX gateways are R80.40 JHF 161). &amp;nbsp;I currently am using just two interfaces on the Bridge VS, but these are VLAN trunk interfaces (eth2 and eth3) and I have a VLAN selected on each interface (and I noticed multi-bridge is in use).&lt;/P&gt;
&lt;P&gt;So regardless, apparently an L3 "monitoring" interface (aka: BVI) isn't really available until R81 now? &amp;nbsp;So the R77 and R80.x documentation for that is an error? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 14:55:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154786#M26308</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-08-09T14:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154788#M26309</link>
      <description>&lt;P&gt;Can you share a link to the documentation reference in question?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154788#M26309</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-09T15:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154789#M26310</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_VSX_AdminGuide/Topics-VSXG/Bridge-Mode-Virtual-System.htm?tocpath=Bridge%20Mode%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_VSX_AdminGuide/Topics-VSXG/Bridge-Mode-Virtual-System.htm?tocpath=Bridge%20Mode%7C_____1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Also snippet screenshot attached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154789#M26310</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-08-09T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154790#M26311</link>
      <description>&lt;P&gt;The heading there is Active/Standby.&lt;/P&gt;
&lt;P&gt;I'm not seeing the same option for Active/Active implying L2 only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:25:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154790#M26311</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-09T15:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: VSX bridge interface monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154791#M26312</link>
      <description>&lt;P&gt;This is an area where SmartConsole could be more descriptive/helpful, and the documentation is unclear. &amp;nbsp;I had to switch the VSX Cluster to "ClusterXL" for the VSX bridge configuration. &amp;nbsp;That puts the VSX Cluster in Active/Standby bridge mode. &amp;nbsp;By default it was STP, which I now know is Active/Active bridge mode. &amp;nbsp;This is irrespective of the VSX *gateway* in cpconfig, which I also made sure was enabled for Bridge A/S mode.&lt;/P&gt;
&lt;P&gt;Now I see L3 BVI configuration. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sigh. &amp;nbsp;Quite unclear all around.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 15:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-bridge-interface-monitoring/m-p/154791#M26312</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-08-09T15:44:27Z</dc:date>
    </item>
  </channel>
</rss>

