<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX - Virtual Switch/Router query in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218869#M41797</link>
    <description>&lt;P&gt;Overlap with IP space should not be the issue here as stated in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VSX_AdminGuide/Topics-VSXG/VSX-Routing-Concepts.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VSX_AdminGuide/Topics-VSXG/VSX-Routing-Concepts.htm&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Overlapping IP Address Space&lt;/H2&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;facilitates connectivity when multiple network segments share the same IP address range (&lt;STRONG&gt;IP address space&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;This scenario occurs when a single&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_gw variable"&gt;VSX Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;protects several independent networks that assign IP addresses to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_ends variable"&gt;endpoints&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;from the same pool of IP addresses.&lt;/P&gt;
&lt;P&gt;Thus, it is feasible that more than one&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_end variable"&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environment will have the identical IP address, provided that each is located behind different&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Overlapping IP address space in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environments is possible because each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;maintains its own unique state and routing tables.&lt;/P&gt;
&lt;P&gt;These tables can contain identical entries, but within different, segregated contexts.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vss variable"&gt;Virtual Systems&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;use NAT to facilitate mapping internal IP addresses to one or more external IP addresses.&lt;/P&gt;
&lt;P&gt;The below figure demonstrates how traffic passes from the Internet to an internal network with overlapping IP address ranges, using NAT at each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;VLAN overlap can be solve by adding indeed a virtual switch. See also this topic for more info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-VSX-Configure-same-vlan-id-on-different-bond-VS/m-p/206121#M2421" target="_blank"&gt;https://community.checkpoint.com/t5/Maestro/Maestro-VSX-Configure-same-vlan-id-on-different-bond-VS/m-p/206121#M2421&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2024 19:17:38 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-06-26T19:17:38Z</dc:date>
    <item>
      <title>VSX - Virtual Switch/Router query</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218861#M41796</link>
      <description>&lt;P&gt;Question regarding VSX...&lt;/P&gt;&lt;P&gt;I have a VS with a VLAN 20 interface on 10.1.1.1.&lt;/P&gt;&lt;P&gt;I need to create a second VS and would ideally like the same network behind it, but it won't let me use VLAN 20 as it's already is use on another VS.&lt;/P&gt;&lt;P&gt;Hugely over simplified diagram below showing what I'd like to achieve.&amp;nbsp; The reasoning (because I'm sure you're wondering) is because VPN's on VS1 are screwed, so while that's being debugged I was hoping for a really quick fix by creating a new VS and bringing certain critical VPN traffic in through VS2 and still being able to access the kit on VLAN 20 that is already behind VS1.&lt;/P&gt;&lt;P&gt;Documentation hasn't been massively helpful in explaining this scenario.&amp;nbsp; Is there a way to do what I need?&amp;nbsp; I basically need to create the 'green line' on the diagram.&lt;/P&gt;&lt;P&gt;Would a Virtual Switch allow me to do this?&lt;/P&gt;&lt;P&gt;I'm also happy to have a different VLAN and subnet on VS2 if that's easier.&amp;nbsp; I'm guessing a Virtual Router is needed in that case?&amp;nbsp; But it's running VSLS and I gather VR's and VSLS don't play nicely?&lt;/P&gt;&lt;P&gt;(R81.20, managed from Multi Domain)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Drawing2.jpg" style="width: 603px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26484i2E84AA03C3DDBDE6/image-dimensions/603x290?v=v2" width="603" height="290" role="button" title="Drawing2.jpg" alt="Drawing2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 18:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218861#M41796</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-06-26T18:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - Virtual Switch/Router query</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218869#M41797</link>
      <description>&lt;P&gt;Overlap with IP space should not be the issue here as stated in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VSX_AdminGuide/Topics-VSXG/VSX-Routing-Concepts.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_VSX_AdminGuide/Topics-VSXG/VSX-Routing-Concepts.htm&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Overlapping IP Address Space&lt;/H2&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;facilitates connectivity when multiple network segments share the same IP address range (&lt;STRONG&gt;IP address space&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P&gt;This scenario occurs when a single&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_gw variable"&gt;VSX Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;protects several independent networks that assign IP addresses to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_ends variable"&gt;endpoints&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;from the same pool of IP addresses.&lt;/P&gt;
&lt;P&gt;Thus, it is feasible that more than one&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Endpoint_SandBlast.tp_end variable"&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environment will have the identical IP address, provided that each is located behind different&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Overlapping IP address space in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx variable"&gt;VSX&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;environments is possible because each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;maintains its own unique state and routing tables.&lt;/P&gt;
&lt;P&gt;These tables can contain identical entries, but within different, segregated contexts.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vss variable"&gt;Virtual Systems&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;use NAT to facilitate mapping internal IP addresses to one or more external IP addresses.&lt;/P&gt;
&lt;P&gt;The below figure demonstrates how traffic passes from the Internet to an internal network with overlapping IP address ranges, using NAT at each&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vs variable"&gt;Virtual System&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;VLAN overlap can be solve by adding indeed a virtual switch. See also this topic for more info&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-VSX-Configure-same-vlan-id-on-different-bond-VS/m-p/206121#M2421" target="_blank"&gt;https://community.checkpoint.com/t5/Maestro/Maestro-VSX-Configure-same-vlan-id-on-different-bond-VS/m-p/206121#M2421&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 19:17:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218869#M41797</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-26T19:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - Virtual Switch/Router query</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218879#M41799</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;, thanks for your reply.&amp;nbsp; I've tried this tonight while the office is empty and it works a treat.&lt;/P&gt;&lt;P&gt;I was a bit nervous at first because I couldn't create the virtual switch on VLAN 20 - once again, it was already in use.&lt;/P&gt;&lt;P&gt;I deleted that VLAN interface from VS1, then added the virtual switch on the main VSX using VLAN 20, added a new interface "Leads to virtual switch" on VS1 and put the IP back on.&amp;nbsp; Same on VS2, then VPN'd into VS2 and I can hit the servers originally behind VS1.&amp;nbsp; Great result!&lt;/P&gt;&lt;P&gt;I've learnt to name the virtual switch something relevant as you can't rename it once it's there.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2024 20:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218879#M41799</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-06-26T20:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - Virtual Switch/Router query</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218906#M41833</link>
      <description>&lt;P&gt;Using a Virtual Switch is the usual way this is facilitated.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 01:32:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218906#M41833</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-06-27T01:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - Virtual Switch/Router query</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218929#M41841</link>
      <description>&lt;P&gt;Thanks again.&amp;nbsp; I don't have much day-to-day exposure to VSX, it's quite a simple deployment and it's sat there and ran with no problems for 10 years.&amp;nbsp; I'm glad I've learnt something new &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 07:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Virtual-Switch-Router-query/m-p/218929#M41841</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-06-27T07:44:45Z</dc:date>
    </item>
  </channel>
</rss>

