<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX: Moving VLAN to another VS within the same VSX-Cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162096#M28782</link>
    <description>&lt;P&gt;&lt;EM&gt;"You are not allowed to add the same VLAN to multiple virtual systems using the same bond interface."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi, i know about this limitation, but it seems that is not mentioned on VSX Admin Guide. Am i correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 15 Nov 2022 08:46:19 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-11-15T08:46:19Z</dc:date>
    <item>
      <title>VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/127497#M18514</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;in my daily business I am faced with a problem for years now and would like to hear if you guys have a better solution to overcome my problem.&lt;/P&gt;&lt;P&gt;I am running serveral VSX environments with a bunch of virtual systems.&lt;BR /&gt;Regularly I have the need to move a VLAN from one virtual system to another virtual system within the same VSX-Cluster.&lt;BR /&gt;The VLAN is not connected to a virtual switch as it would too expensive to connect all VLANs to a seperate virtual switch.&lt;BR /&gt;All VLANs are behind the same bond interface except the external interface.&lt;/P&gt;&lt;P&gt;Example setup:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example setup" style="width: 859px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13417i616C5A4B3C676799/image-size/large?v=v2&amp;amp;px=999" role="button" title="vlanmove.png" alt="example setup" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;example setup&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When moving a VLAN from one virtual system to another within the same VSX-Cluster I am facing the following problems:&lt;BR /&gt;You are not allowed to add the same VLAN to multiple virtual systems using the same bond interface.&lt;/P&gt;&lt;P&gt;I consequence I know two possibilities to overcome this problem, but both don't make me happy:&lt;/P&gt;&lt;P&gt;1. Deleting the VLAN on VS2, installing policy on VS2, adding VLAN on VS3, installing policy on VS3.&lt;BR /&gt;As VS2 and VS3 are running in the same SmartCenter/Domain this means downtime of minimum 10 minutes.&lt;/P&gt;&lt;P&gt;2. Adding a new physical link to the same Switch, configuring the new VLAN to VS3 with duplicate IP address using the new physical link and moving the VLAN on switch side from the old physical link to the new one.&lt;BR /&gt;In this scenario the downtime is acceptable, but you always need two links the the same switch and you a loosing flexibility as you need support of the switch guys.&lt;BR /&gt;Moreover in some environements I do not have free interfaces on firewall side so I don't have the possibility to add a second link to the same switch.&lt;/P&gt;&lt;P&gt;Any ideas how to overcome this problem?&lt;BR /&gt;The coolest thing would be a nice and smooth solution provided by Check Point.&lt;BR /&gt;I started asking Check Point years ago, but didn't get a solution, yet.&lt;/P&gt;&lt;P&gt;Looking forward to read your ideas.&lt;/P&gt;&lt;P&gt;Cheers&lt;BR /&gt;Sven&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 11:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/127497#M18514</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2021-08-20T11:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/127640#M18532</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6311"&gt;@Sven_Glock&lt;/a&gt;&amp;nbsp;I think you have answered your own question here. Option one is the way to go. It causes downtime on the particular VLAN, which is, however, expected event for moving a physical interface from one GW to another.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Aug 2021 14:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/127640#M18532</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-08-22T14:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128166#M18642</link>
      <description>&lt;P&gt;Having a short downtime is an accaptable thing, but 10 mins+ is out of accaptable range.&lt;/P&gt;&lt;P&gt;As accelerated policy installation is still far away for my environment do you have any ideas how to accelerate option one?&lt;/P&gt;&lt;P&gt;I am struggeling with the policy installation on vs3.&lt;BR /&gt;Policy installation is necassary when adding a new interface with a new ip network, because of spoofing objects, etc.&lt;BR /&gt;&lt;BR /&gt;But how about this scenario:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I add the new network with a dummy VLAN to VS3. --&amp;gt; Apply --&amp;gt; Install policy.&lt;/LI&gt;&lt;LI&gt;Now spoofing, routing etc. is fine.&lt;/LI&gt;&lt;LI&gt;Next I delete VLAN on VS2 --&amp;gt; Apply --&amp;gt; Install policy&lt;/LI&gt;&lt;LI&gt;Then just changing the dummy VLAN to the final VLAN ID and Apply. Will the new network be up and running without policy installation?&lt;BR /&gt;&lt;BR /&gt;Its just guessing, but is there a need to install policy when just changing a VLAN?&lt;BR /&gt;If not this would reduce downtime by 30%. It's still a lot but less worse.&lt;BR /&gt;&lt;BR /&gt;More ideas welcome&amp;nbsp;8)&lt;/img&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 26 Aug 2021 19:56:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128166#M18642</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2021-08-26T19:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128168#M18644</link>
      <description>&lt;P&gt;Is the VLAN you are moving the highest or lowest VLAN ID on the interface for the VS which is currently handling it?&lt;/P&gt;
&lt;P&gt;Will it be the highest or lowest VLAN ID on the interface on the new VS you're moving it to?&lt;/P&gt;
&lt;P&gt;If the answer to both questions is no, you may be able to get away with removing it from the old VS, provisioning (but not pushing policy), adding it to the new VS, provisioning, pushing policy to the new VS, then pushing policy to the old VS. The outage would last from when you provision the old VS to when you finish pushing policy to the new VS.&lt;/P&gt;
&lt;P&gt;If the answer to either question is yes, this may not be safe. By default, ClusterXL monitors the highest and lowest VLAN IDs on each interface. If it's the highest or lowest on the old VS, provisioning the removal there could cause spontaneous failover. If it's the highest or lowest on the new VS, you should be fine, but may see failovers when policy is first installed. Depending on how you do sync, the failovers could trigger active contention which could result in&amp;nbsp;&lt;EM&gt;neither&lt;/EM&gt; firewall taking over the cluster (direct-wired sync is particularly bad for this).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would test this a lot. Like a &lt;EM&gt;&lt;STRONG&gt;LOT&lt;/STRONG&gt;&lt;/EM&gt; a lot. ClusterXL &lt;EM&gt;should&lt;/EM&gt; only care about VIP uniqueness within a VS, but I may be misremembering.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 20:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128168#M18644</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-08-26T20:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128203#M18656</link>
      <description>&lt;P&gt;I am always monitoring all vlans - even it it costs some ressources - never trust a switch guy&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I will test it in my lab after some vacation and will keep you updated about the outcome.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 07:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128203#M18656</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2021-08-27T07:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128206#M18658</link>
      <description>&lt;P&gt;We experienced instability/flapping when only removing and provisioning on the source vs, so be careful with that approach.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 07:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128206#M18658</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2021-08-27T07:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128266#M18674</link>
      <description>&lt;P&gt;Thanks for your advice!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 22:32:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128266#M18674</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2021-08-27T22:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128271#M18677</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Okay, then your only option is to provision the removal, push the removal, provision the new interface, push the new interface. There’s not a faster way.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 00:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128271#M18677</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-08-28T00:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128434#M18714</link>
      <description>&lt;P&gt;I'm not facing this problem, but I think that you can create dedicated TMP VLAN for migration and always ask switching guys to map migrated vlan to this TMP vlan.&lt;/P&gt;&lt;P&gt;After that migration should be faster:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create TMP vlan (with all configuration) on target VS&lt;/LI&gt;&lt;LI&gt;Removing migrated vlan from previous VS&lt;/LI&gt;&lt;LI&gt;Change TMP vlan to migrated on target VS&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 10:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/128434#M18714</guid>
      <dc:creator>Michal_Gans</dc:creator>
      <dc:date>2021-08-31T10:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162096#M28782</link>
      <description>&lt;P&gt;&lt;EM&gt;"You are not allowed to add the same VLAN to multiple virtual systems using the same bond interface."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi, i know about this limitation, but it seems that is not mentioned on VSX Admin Guide. Am i correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 08:46:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162096#M28782</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-11-15T08:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162139#M28790</link>
      <description>&lt;P&gt;If you want to have the same VLAN on the same BOND to multiple VS. you will use a virtual switch within VSX. And connect both the VS to the virtual switch.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 15:07:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162139#M28790</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2022-11-15T15:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162140#M28791</link>
      <description>&lt;P&gt;Thank you very much Magnus; last question, the only alternative is to create the same vlan to different physical interface/bond, it is right?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 15:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162140#M28791</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-11-15T15:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162141#M28792</link>
      <description>&lt;P&gt;Virtual switch or virtual router or diff physical interfaces / bond.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Virtual switch would be the most common way to solve it, if it’s to the same L2 environment and actually the same VLAN.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 15:29:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162141#M28792</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2022-11-15T15:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: VSX: Moving VLAN to another VS within the same VSX-Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162152#M28794</link>
      <description>&lt;P&gt;I do not understand why you need an alternative to a virtual switch. This is a widely used and stable solution for your requirement.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 17:06:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Moving-VLAN-to-another-VS-within-the-same-VSX-Cluster/m-p/162152#M28794</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2022-11-15T17:06:55Z</dc:date>
    </item>
  </channel>
</rss>

