<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change VSX management interface to a bond with same IP Address in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202168#M38045</link>
    <description>&lt;P&gt;Hello Alex,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer. I already looked at vsx_util, but there is no option to change the physical management interface of vs0.&lt;/P&gt;&lt;P&gt;you can change the management IP Address and will have to do some tasks from&amp;nbsp;&lt;SPAN&gt;sk9242, but there is no way to change the interface from Mgmt to bond4 in my case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The vsx_util change_interfaces only works for physical interfaces used by virtual systems, not for management Interface of vs0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;KR, Peter&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jan 2024 11:07:40 GMT</pubDate>
    <dc:creator>Peter_Thome</dc:creator>
    <dc:date>2024-01-04T11:07:40Z</dc:date>
    <item>
      <title>Change VSX management interface to a bond with same IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202157#M38040</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;our customer has the need to change Cabling from copper to fiber links in their DC.&lt;/P&gt;&lt;P&gt;Their VSX Cluster is configured with the builtin Mgmt copper interface as VS0 Management Interface.&lt;/P&gt;&lt;P&gt;Is there a possibility to change the physical interface to a bond interface, which is built out of 2 fiber interfaces?&lt;/P&gt;&lt;P&gt;I tried it in our lab with setting vsx off in Clish, delete Mgmt Interface IP Address, set the same IP Address to the new bond interface and then enable vsx again.&lt;/P&gt;&lt;P&gt;Was able to do that, but when accessing the VSX Cluster in SmartConsole, I'm not able to change the Interface from Mgmt to the bond and the VSX operation end with errors:&lt;/P&gt;&lt;P&gt;pt-vsx-02 error :Internal Error - Failed to commit changes in the OS.. 10.10.32.82 is already in use as the local address of bond4..&lt;BR /&gt;pt-vsx-01 error :Internal Error - Failed to commit changes in the OS.. 10.10.32.81 is already in use as the local address of bond4..&lt;/P&gt;&lt;P&gt;These are the management IP Addresses, which I switched from Mgmt to bond4 in clish .&lt;/P&gt;&lt;P&gt;Any hints how we can get this done ?&lt;/P&gt;&lt;P&gt;Many thanks - Peter&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 08:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202157#M38040</guid>
      <dc:creator>Peter_Thome</dc:creator>
      <dc:date>2024-01-04T08:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: Change VSX management interface to a bond with same IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202158#M38041</link>
      <description>&lt;P&gt;You don't change interfaces with clish when using VSX.&lt;/P&gt;&lt;P&gt;Use vsx_util to display and change interfaces configuration.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ScalablePlatforms_VSX_AdminGuide/Topics-SP-VSX/209207.htm?tocpath=Command%20Line%20Reference%7Cvsx_util%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ScalablePlatforms_VSX_AdminGuide/Topics-SP-VSX/209207.htm?tocpath=Command%20Line%20Reference%7Cvsx_util%7C_____0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 09:10:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202158#M38041</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-01-04T09:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Change VSX management interface to a bond with same IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202168#M38045</link>
      <description>&lt;P&gt;Hello Alex,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer. I already looked at vsx_util, but there is no option to change the physical management interface of vs0.&lt;/P&gt;&lt;P&gt;you can change the management IP Address and will have to do some tasks from&amp;nbsp;&lt;SPAN&gt;sk9242, but there is no way to change the interface from Mgmt to bond4 in my case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The vsx_util change_interfaces only works for physical interfaces used by virtual systems, not for management Interface of vs0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;KR, Peter&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 11:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202168#M38045</guid>
      <dc:creator>Peter_Thome</dc:creator>
      <dc:date>2024-01-04T11:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change VSX management interface to a bond with same IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202193#M38048</link>
      <description>&lt;P&gt;Right, the Management interface is defined per the physical topology of each cluster member in the VS0 object in Smart Console and this doesn't seem to be editable.&lt;/P&gt;&lt;P&gt;Maybe add a new bond with new IP on fibre links and use the vsx_util utility to change management IP to that one could be an option.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 14:22:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202193#M38048</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-01-04T14:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change VSX management interface to a bond with same IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202233#M38053</link>
      <description>&lt;P&gt;Depends on the version. I just checked, and my R81.20 managements can do this (older versions lack the option for step 3), but &lt;EM&gt;&lt;STRONG&gt;it will require an outage&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Run 'vsx_util change_interfaces -s 127.0.0.1' on the management and log in&lt;/LI&gt;
&lt;LI&gt;Select the cluster you want to work on&lt;/LI&gt;
&lt;LI&gt;Select the option to apply changes to the management database only&lt;/LI&gt;
&lt;LI&gt;Select the old management interface, and replace it with the bond&lt;/LI&gt;
&lt;LI&gt;Rebuild one VSX member. Be sure to create the bond(s).&lt;/LI&gt;
&lt;LI&gt;Use 'vsx_util reconfigure -s 127.0.0.1' on the management to reestablish SIC with, push policy to, and provision the member&lt;/LI&gt;
&lt;LI&gt;Repeat steps 5 and 6 for each other member in the VSX cluster&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I highly, highly recommend replacing&amp;nbsp;&lt;STRONG&gt;all&lt;/STRONG&gt;&amp;nbsp;references to individual interfaces references with references to bonds. Bonds can have one member, and don't have to participate in LACP.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: Thinking about it some more, I don't know if the first rebuilt member will be able to sync with an original member. It might be possible. If sync works, it may be possible to do without an outage. You should still assume there will be an outage when you fail over from the original member(s) to the first rebuilt member.&lt;/P&gt;
&lt;P&gt;You probably need to build the bond on the command line of both members and add the bond to the VSX cluster object's list of known physical interfaces before starting the above process. I'm pretty sure change_interfaces only lets you change to an interface which is listed there.&lt;/P&gt;
&lt;P&gt;Keep these&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/unable-to-delete-VS-firewalls-when-VSX-members-are-offline/m-p/148913/highlight/true#M23839" target="_self"&gt;management-side debugs for VSX provisioning&lt;/A&gt; handy. They can let you make changes on the management without needing working communications with the cluster members. Very useful if the physical member can't meet the requirements of the object on the management. For example, if the management expects to see both eth1 &lt;STRONG&gt;and&lt;/STRONG&gt; bond1 which has eth1 as a member, this set of debugs lets you delete the interface from the management's list of interfaces on the VSX cluster.&lt;/P&gt;
&lt;P&gt;Take a snapshot on everything before you start.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2024 19:55:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-VSX-management-interface-to-a-bond-with-same-IP-Address/m-p/202233#M38053</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-01-04T19:55:47Z</dc:date>
    </item>
  </channel>
</rss>

