<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX vsls -  Active up vs Primary up in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/206261#M38965</link>
    <description>&lt;P&gt;After reboot all VSes will return to VSX1 as it has higher priority and "Primary-UP" mode.&lt;/P&gt;
&lt;P&gt;"Active-UP" mode would have preserved VSX2 as active after reboot.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Feb 2024 06:23:59 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2024-02-16T06:23:59Z</dc:date>
    <item>
      <title>VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138831#M21122</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;Im trying to find information about the new feature starting from R80.40:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Support for Active Up mode in VSLS.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I cannot find detailed information about this setting in the R80.40 VSX documentation except that the behaviour can be changed with:&amp;nbsp;vsx_util vsls - 5. Toggle VSLS mode between Active Up and Primary Up"&lt;BR /&gt;&lt;BR /&gt;Anyone who knows more about this or where I can find the information?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 09:00:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138831#M21122</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2022-01-19T09:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138836#M21125</link>
      <description>&lt;P&gt;You're spot on - documentation does not exist to explain it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Wild guess: primary up would mean higher priority would always be active if it's available, whereas active up would keep current active member even though member with higher priority becomes available.&lt;/P&gt;
&lt;P&gt;Or in more practical example, say if you are upgrading VSX1 that has higher priority then after upgrade VSX2 will remain active even it has lower priority. Just like regular cluster setting&lt;/P&gt;
&lt;DIV id="tinyMceEditor_1c298de8daa7fKaspars_Zibarts_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 255px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14942iF90CBC4241226A23/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 09:25:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138836#M21125</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-01-19T09:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138841#M21128</link>
      <description>&lt;P&gt;That was my guess too. The documentation says:&lt;/P&gt;&lt;H2&gt;Failure Recovery&lt;/H2&gt;&lt;P&gt;When the failed&amp;nbsp;VSX Cluster Member&amp;nbsp;or&amp;nbsp;Virtual System&amp;nbsp;comes back online, the system returns to its original&amp;nbsp;Load Sharing&amp;nbsp;configuration.&lt;BR /&gt;&lt;BR /&gt;So that would be Primary Up mode, and Active Up (which is not mentioned) is that it stays on the current host.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 09:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138841#M21128</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2022-01-19T09:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138843#M21130</link>
      <description>&lt;P&gt;Nice feature by the way! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 09:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138843#M21130</guid>
      <dc:creator>Mattias_Jansson</dc:creator>
      <dc:date>2022-01-19T09:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138849#M21134</link>
      <description>&lt;P&gt;yeah, it was always a bummer during upgrades &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; or even regular restarts when you wanted to keep it on a specific cluster member, so you would always have to keep playing with vsx_util&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 09:45:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/138849#M21134</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-01-19T09:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/140471#M21564</link>
      <description>&lt;P&gt;A small but important update! We tried it in production.. please remember &lt;STRONG&gt;to book an outage window&lt;/STRONG&gt; if you are switching modes! As this is what happened&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":astonished_face:"&gt;😲&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_screaming_in_fear:"&gt;😱&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 397px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15234i0FF1D6935B61AA91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;First you will be asked to use option "6" after changing modes which does not make sense&amp;nbsp; at all:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15235i21DD48B23437368D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But then menu structure changes from 8 items to 9 and option "6" actually makes sense:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15236iC18831E8F4A88446/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now! Running it will cause &lt;STRONG&gt;multiple VS failovers and eventually all VSes will go down&lt;/STRONG&gt; briefly as shown in the first screenshot&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 06:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/140471#M21564</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-02-04T06:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/184508#M33907</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;I am failing to understand the exact behaviour here. Is this only for VS0 as indicated here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/VSX-cluster-questions-Failover-amp-updatable-objects/m-p/183924#M33750" target="_blank"&gt;VSX cluster questions: Failover &amp;amp; updatable objec... - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;or all VS ? and if it is for all VS - what does the priority setting do here? Only apply for vsls redistribute?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to accomplish that the cluster does NOT failback to the rebooted node. This has only caused issues for us.&lt;/P&gt;
&lt;P&gt;Another question, does this really bring down all virtual systems ? have you seen it on other clusters or was it a one of and for how long did you see it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;Henrik&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 09:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/184508#M33907</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2023-06-22T09:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/184510#M33909</link>
      <description>&lt;P&gt;Hi. The mode is applied on all VSes. So if you chose "Active UP" it will maintain currently active VS and will ignore any priority / weight settings. Indeed this should help you avoiding failback after reboots.&lt;/P&gt;
&lt;P&gt;Changing the mode did bring down all VSes in our case. But it was only one cluster in our case. How long - I don't remember exactly but lets say outage was roughly 5mins before all settled again.&lt;/P&gt;
&lt;P&gt;Regards, Kaspars&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 09:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/184510#M33909</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2023-06-22T09:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/206155#M38942</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a question about failover status after vsx member is recovered.&lt;/P&gt;&lt;P&gt;In this example there is a cluster of 2 members (Active-Standby) in vsls "Primary UP" mode.&lt;BR /&gt;vsx1 priority 0 (active) ,&amp;nbsp; vsx2 priority 1 (standby)&lt;/P&gt;&lt;P&gt;1) via vsx_util vsl (opt.3) move all VS from currently Active (vsx1) to Standby (vsx2).&lt;BR /&gt;This causes failover of every VS and their the traffic, and the "active" is the vsx2 now&lt;/P&gt;&lt;P&gt;2) reboot vsx1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3) -that's the unclear point-&lt;BR /&gt;After vsx1 reboot, will it be active automatically, and cause failover of the traffic from vsx2, (because of&amp;nbsp;vsls "Primary UP" mode),&amp;nbsp;&lt;BR /&gt;or there will not be any traffic failover, because it was configured in vsx_util (step 1 -above), and as per documentation "&lt;SPAN&gt;the system returns to its original&amp;nbsp;Load Sharing&amp;nbsp;configuration"?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 08:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/206155#M38942</guid>
      <dc:creator>DimitrisK</dc:creator>
      <dc:date>2024-02-15T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/206261#M38965</link>
      <description>&lt;P&gt;After reboot all VSes will return to VSX1 as it has higher priority and "Primary-UP" mode.&lt;/P&gt;
&lt;P&gt;"Active-UP" mode would have preserved VSX2 as active after reboot.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 06:23:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/206261#M38965</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2024-02-16T06:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: VSX vsls -  Active up vs Primary up</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/247938#M48433</link>
      <description>&lt;P&gt;Just an update - I was playing with this in the lab using R81.20. This issue of all members going down during the mode change did not happen there. I believe the mechanism by which they change the mode is better now and will not cause an outage.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 15:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-vsls-Active-up-vs-Primary-up/m-p/247938#M48433</guid>
      <dc:creator>CP_Chris</dc:creator>
      <dc:date>2025-05-01T15:30:59Z</dc:date>
    </item>
  </channel>
</rss>

