<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX-Virtual switch issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198204#M37063</link>
    <description>&lt;P&gt;Did you set Link Selection in the relevant VS to the correct IP?&lt;BR /&gt;I presume this will be required since you're not using the main IP of the VS...&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2023 21:43:01 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-11-16T21:43:01Z</dc:date>
    <item>
      <title>VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198124#M37045</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am working on a project in a VSX Cluster environment (16200 appliances)&lt;/P&gt;&lt;P&gt;I created three virtual systems. One of them is VPN concentrator.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I created a virtual switch and&amp;nbsp;&amp;nbsp;and I assigned a public IP address. I will use it for Remote Access.&lt;BR /&gt;I put together a remote access VPN which si basic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a few difficulties:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;First when I try to connect with the VPN client, it tells me the server is unavailable.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;Again, we are talking about a fairly simple setup that I have done many times.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Added IP address as if it doesn't exist outside the VSX segment.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Arp entries show nothing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The second issue is that I can't assign VPN Office Mode (using IP pool)&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried with solution&amp;nbsp;sk111785 and&amp;nbsp;described in:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Configure-Client-VPN-on-VSX/td-p/94678" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Configure-Client-VPN-on-VSX/td-p/94678&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No result at all!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BUT when I remove/delete the Virtual switch from Virtual system/VSX Cluster and add a physical interface to the virtual system with same IP public address everything works as it should.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried several times to create a new Virtual switch and I get the same results.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;I need a Virtual switch because later I will share that interface with another virtual system.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;The port that I want to share contains a range of public IP addresses so that it can be used on multiple virtual machines&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Does anyone have any suggestions, whether this is a limitation, a bug or something else?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sinisa&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 11:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198124#M37045</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-11-16T11:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198128#M37048</link>
      <description>&lt;P&gt;Please share the version &amp;amp; jumbo take applied to the environment for context?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198128#M37048</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-16T12:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198129#M37049</link>
      <description>&lt;P&gt;Sorry I forgot to write that&lt;/P&gt;&lt;P&gt;R81.20, take 26&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:05:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198129#M37049</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-11-16T12:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198147#M37055</link>
      <description>&lt;P&gt;I don't know if it is useful information;&lt;/P&gt;&lt;P&gt;I have a similar setup on a &lt;STRONG&gt;Multidomain&lt;/STRONG&gt; environment with VSX and everything works as it should.&amp;nbsp; So the problem is present only with the virtual switch on VSX on one tenant/domain&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 13:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198147#M37055</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-11-16T13:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198204#M37063</link>
      <description>&lt;P&gt;Did you set Link Selection in the relevant VS to the correct IP?&lt;BR /&gt;I presume this will be required since you're not using the main IP of the VS...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 21:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198204#M37063</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-16T21:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198237#M37070</link>
      <description>&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;Link Selection is set&amp;nbsp;to that IP address.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As far as I can see I have two options;&lt;/P&gt;&lt;P&gt;Delete the existing VS create it from the start and test it again (not exactly a proper solution for production) OR involve the TAC team for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 08:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198237#M37070</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-11-17T08:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198241#M37071</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/90937"&gt;@SinisaZG&lt;/a&gt;&amp;nbsp;did you checked twice the assignment of interface/bond and/or VLAN to the vswitch and your VS ? Was a policy install done to the specific VS after changing the interface topology to the vswitch ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 08:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198241#M37071</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-11-17T08:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198245#M37074</link>
      <description>&lt;P&gt;Maybe you're using Proxy ARP and need to adapt the relevant local.arp files.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 09:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198245#M37074</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-11-17T09:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198251#M37077</link>
      <description>&lt;P&gt;I found where the problem is/was.&amp;nbsp;The link selection option does not work&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; When creating VS, the first interface created is Main. I usually create the LAN side first.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Later I added the WAN interface.&amp;nbsp;&lt;BR /&gt;The IP on the WAN interface is also the address of the VPN concentrator.&amp;nbsp;I set that IP address to Link Selection.&amp;nbsp;&lt;BR /&gt;After several checks, VS persistently puts the address from the interface I created first (LAN side)&amp;nbsp; &lt;STRONG&gt;And this only applies when we use a virtual switch. &lt;/STRONG&gt;Link Selection&amp;nbsp;works when I use a&amp;nbsp;&lt;STRONG&gt;physical port&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I deleted VS and created a new one, but this time the WAN interface was created first.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Everything works now.&lt;/P&gt;&lt;P&gt;I recreated the first scenario again&amp;nbsp;and it doesn't work again.&lt;/P&gt;&lt;P&gt;The lesson of the story is that link selection does not work when we want to use another connection and we have only virtual switches on VS.&lt;/P&gt;&lt;P&gt;Over the weekend I will create this scenario in the LAB and test it again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 10:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/198251#M37077</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-11-17T10:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: VSX-Virtual switch issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/200604#M37678</link>
      <description>&lt;P&gt;I tested in the lab on some versions, R81.10 and R81.20. The error occurred at our client with version R81.20 with Take 26. When multiple public IP addresses are used in combination with multiple Virtual Switches,&lt;BR /&gt;For some reason, Link Selection IP address remains stuck regardless of whether we change the IP address in Smart Console.&lt;/P&gt;&lt;P&gt;I did not research the issue in detail, but the only solution was to reinstall the Virtual System again.&lt;BR /&gt;The problem is not present in the latest version, Take 41.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 11:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-switch-issue/m-p/200604#M37678</guid>
      <dc:creator>SinisaZG</dc:creator>
      <dc:date>2023-12-14T11:58:01Z</dc:date>
    </item>
  </channel>
</rss>

