<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Purpose of Checkpoint VSX technology in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201230#M37828</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for replying Rock. I think I need some more clarity though.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 19:08:33 GMT</pubDate>
    <dc:creator>Kakarot</dc:creator>
    <dc:date>2023-12-20T19:08:33Z</dc:date>
    <item>
      <title>Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201218#M37822</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am trying to understand the reason for using Checkpoint's VSX technology. If you already have employed concepts such as, Multi-Domain management and have gateways installed on some Open Server. Do you really need VSX service or license? Will you not get the same functionality of VSX by implementing Multi-Domain and Virtual gateways on an open server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below extract from included link in checkpoint's community:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/VSX.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/VSX.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Extract:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;H1&gt;&lt;SPAN class=""&gt;VSX&lt;/SPAN&gt;&lt;/H1&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Virtual System&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;eXtension&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;product runs several virtual&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;firewalls&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the same hardware. Each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Virtual System&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;works as a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/VSX.htm#" target="_blank" rel="noopener"&gt;Security Gateway&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 16:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201218#M37822</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T16:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201225#M37824</link>
      <description>&lt;P&gt;I think below explains it real well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.eginnovations.com/documentation/CheckPoint-Smart-Appliance/CheckPoint-Virtual-System.htm#:~:text=VSX%20(Virtual%20System%20Extension)%20is,or%20VLANs%20within%20complex%20infrastructures" target="_blank"&gt;https://www.eginnovations.com/documentation/CheckPoint-Smart-Appliance/CheckPoint-Virtual-System.htm#:~:text=VSX%20(Virtual%20System%20Extension)%20is,or%20VLANs%20within%20complex%20infrastructures&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 17:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201225#M37824</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T17:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201228#M37826</link>
      <description>&lt;P&gt;In a nutshell:&lt;/P&gt;&lt;P&gt;Multi-domain is management virtualisation. Each domain is independent of the other so you can manage clients from the same multi-domain management server without mixing their data, each one has their own domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VSX is gateway virtualisation: you can use a dedicated appliance or server to run virtual firewalls which have their own IP space and each can use a different set of blades. Unlike virtual machines, the OS and patches are common since they run at the appliance/server level. So a single cluster could run for example 10 VS which do each their own routing and have their own policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use VSX with a multi-domain manager or an SMS. With an MDS, you could have each VS or multiple VS in a dedicated domain and some others in other ones. Without MDS, with SMS, you have one base domain and all VS share all objects but still have their own IP/blades configuration.&lt;/P&gt;&lt;P&gt;Please note this is really a basic explanation, the CCVS course for instance goes into much details of what VSX is.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 18:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201228#M37826</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-12-20T18:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201229#M37827</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much thanks for this. I believe i understand better now. Multi-domain is for management and VSX is for gateways. I guess where I am at now is, If I have a server and want to install several gateways on that server. Do I need to use VSX technology to accomplish this?&lt;/P&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;Thanks for the suggested training. I will add that to my list of training to complete after I sit the CCSE.&lt;/P&gt;&lt;P&gt;&lt;A href="https://training-certifications.checkpoint.com/#/courses/VSX%20Specialist%20R81.1%20(CCVS)" target="_blank"&gt;https://training-certifications.checkpoint.com/#/courses/VSX%20Specialist%20R81.1%20(CCVS)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201229#M37827</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T19:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201230#M37828</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for replying Rock. I think I need some more clarity though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:08:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201230#M37828</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T19:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201231#M37829</link>
      <description>&lt;P&gt;Personally, I would say no. If you are dealing with several gateways, regular mgmt is 100% fine. P-1 (MDS) and VSX are way more relevant for large-scale deployments where you wish to separate policies/objects. Its sort of like VDOMs with Fortinet, if you are familiar with that.&lt;/P&gt;
&lt;P&gt;Essentially, every virtual "entity" would have their own policy as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;indicated.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201231#M37829</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T19:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201232#M37830</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is exactly what I was comparing the VSX and multi-domain concept to. The Fortinet VDOMs. So i really don't need to implement VSX then.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;you also agree here right?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201232#M37830</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T19:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201234#M37831</link>
      <description>&lt;P&gt;Lets start with basics...how many locations? Gateways? Users? Approximate numbers would help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:21:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201234#M37831</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T19:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201235#M37832</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below approximate figures.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Locations: 3&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateways: 12&lt;/P&gt;&lt;P&gt;users: no more than 1000&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201235#M37832</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T19:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201236#M37833</link>
      <description>&lt;P&gt;Personally, I would not bother with VSX in that case. I had seem customers run way more than 12 gateways on single mgmt server and there was never an issue. Just make sure management is powerful enough (as far as memory, cpu, space). I would say if its VM, I always reocmmend SSH hdd, at least 12 or 16 GB of ram and 8 cores, but you can always scale it.&lt;/P&gt;
&lt;P&gt;Just my honest opinion.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:28:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201236#M37833</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T19:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201237#M37834</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Much thanks for this. Well appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201237#M37834</guid>
      <dc:creator>Kakarot</dc:creator>
      <dc:date>2023-12-20T19:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201238#M37835</link>
      <description>&lt;P&gt;Any time. Again, thats just my honest feedback, but you are certainly welcome to verify via an official TAC case or through your local Sales person.&lt;/P&gt;
&lt;P&gt;Best regards and happy holidays&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":victory_hand:"&gt;✌️&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 19:34:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201238#M37835</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T19:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201240#M37836</link>
      <description>&lt;P&gt;I personally think "virtualization" is a deeply misleading term to use in marketing for VSX. It has nothing to do with VMs as most people think of them.&lt;/P&gt;
&lt;P&gt;It's exactly like OpenBSD rdomains, Linux network namespaces (in fact, this is the exact technology which backs VSX), Arista/Cisco/Extreme/Juniper VRFs, Fortinet vdom, Palo Alto vsys, and so on. It gives you the ability to run multiple routing tables on a single physical firewall or cluster.&amp;nbsp;As &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;mentioned, all VSs have the same view of the same OS and the same hardware. You can't patch or upgrade one VS at a time. Logs from all VSs go to the same volume on the drive.&lt;/P&gt;
&lt;P&gt;There are four fundamental types of VS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Layer 2 with no firewalling - virtual switch&lt;/LI&gt;
&lt;LI&gt;Layer 2 with firewalling - bridge mode VS&lt;/LI&gt;
&lt;LI&gt;Layer 3 with no firewalling - virtual router&lt;/LI&gt;
&lt;LI&gt;Layer 3 with firewalling - normal VS&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Switches do not consume a license slot. The other three types all consume license slots.&lt;/P&gt;
&lt;P&gt;All firewall licenses come with the ability to run one VS. This is so you can separate to-traffic routing (i.e, traffic to the firewall to manage it) from through-traffic routing (i.e, routing for traffic the firewall handles but doesn't terminate).&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 20:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201240#M37836</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-12-20T20:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Purpose of Checkpoint VSX technology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201241#M37837</link>
      <description>&lt;P&gt;All excellent and valid points&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 20:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Purpose-of-Checkpoint-VSX-technology/m-p/201241#M37837</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-20T20:25:38Z</dc:date>
    </item>
  </channel>
</rss>

