<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [VSX] How to disable an interface in HA monitoring in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249192#M48676</link>
    <description>&lt;P&gt;Last week we got a non-critical interface (eth1-06) in a VS that was flapping constantly and, hence, so was the cluster. We wanted to exclude for HA monitoring that interface in order to avoid that scenario in the future.&lt;/P&gt;</description>
    <pubDate>Fri, 16 May 2025 09:16:15 GMT</pubDate>
    <dc:creator>Franktum</dc:creator>
    <dc:date>2025-05-16T09:16:15Z</dc:date>
    <item>
      <title>[VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/248943#M48650</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;In a regular cluster, when you want to failover when an interface goes down, you configure it as &lt;STRONG&gt;Cluster&lt;/STRONG&gt; in Network Type field. Otherwise, you choose &lt;STRONG&gt;Private&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Don't know whether in VSX env, we could configure an interface not to be monitored by HA, hence a failover won't occur if that interface goes down.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 10:30:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/248943#M48650</guid>
      <dc:creator>Franktum</dc:creator>
      <dc:date>2025-05-14T10:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: [VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249038#M48657</link>
      <description>&lt;P&gt;I believe you can add the interface to $FWDIR/conf/&lt;SPAN&gt;discntd.if and do a cprestart (both in the context of the relevant VS).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 19:24:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249038#M48657</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-14T19:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: [VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249060#M48663</link>
      <description>&lt;P&gt;Previously that would remove the IP from the interface on boot up, so I would avoid testing that in prod.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Private interfaces on SG clusters do not have VIPs, which is not an option on VSX. Essentially the IP you configure on the interface in SmartConsole is a VIP, so 'private' is not an option as you can't not have a VIP there on VSX.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the problem you are looking to solve by not monitoring the interface?&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 02:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249060#M48663</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-05-15T02:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: [VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249064#M48664</link>
      <description>&lt;P&gt;What type of interface, a specific VLAN or something else?&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 05:41:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249064#M48664</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-05-15T05:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: [VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249192#M48676</link>
      <description>&lt;P&gt;Last week we got a non-critical interface (eth1-06) in a VS that was flapping constantly and, hence, so was the cluster. We wanted to exclude for HA monitoring that interface in order to avoid that scenario in the future.&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2025 09:16:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249192#M48676</guid>
      <dc:creator>Franktum</dc:creator>
      <dc:date>2025-05-16T09:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: [VSX] How to disable an interface in HA monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249274#M48686</link>
      <description>&lt;P&gt;We don't really have an option to not monitor an access port on VSX. Ideally it would be best to understand why it was flapping and resolve that - if it's a barely used subnet, make sure there's always something in there with an IP address that will respond to ARPs and pings.&lt;/P&gt;</description>
      <pubDate>Mon, 19 May 2025 02:59:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-How-to-disable-an-interface-in-HA-monitoring/m-p/249274#M48686</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-05-19T02:59:09Z</dc:date>
    </item>
  </channel>
</rss>

