<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling interface on VS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/249510#M48730</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Is it possible to disable an interface that is part of a VSX Cluster?&lt;/P&gt;
&lt;P&gt;I have a lab environment, where the Eth2 interface is the SYNC interface between my VSX1 and VSX2 box&lt;/P&gt;
&lt;P&gt;My Cluster does not “wake up”, and emphasizes that the problem is the Eth2 interface&lt;/P&gt;
&lt;P&gt;I have done everything at VMWARE level but I still can't fix it&lt;/P&gt;
&lt;P&gt;I want to logically shut down the Eth2 interface from each box&lt;/P&gt;
&lt;P&gt;Is this possible?&lt;/P&gt;
&lt;P&gt;Could you guide me with the steps to follow?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2025 15:04:18 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2025-05-21T15:04:18Z</dc:date>
    <item>
      <title>Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202410#M38092</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We're aware on how to remove an interface on a VS by using the&amp;nbsp;vsx_provisioning_tool; but what would be the best way to just disable a bond "sub-interface" on a VS -in a VSX cluster.&lt;/P&gt;&lt;P&gt;Is it by using the below commands:&lt;/P&gt;&lt;P&gt;On VSX member 1 (where our VS is active)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;set vsx off&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;set interface bond2.15&amp;nbsp;state off&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;set vsx on&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And repeat the above on VSX member 2 (where our VS is standby)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 02:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202410#M38092</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2024-01-22T02:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202412#M38093</link>
      <description>&lt;P&gt;That sounds logical, based on below as well&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Remove-interface-from-VSX-systems/td-p/65004" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Remove-interface-from-VSX-systems/td-p/65004&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2024 23:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202412#M38093</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-07T23:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202421#M38096</link>
      <description>&lt;P&gt;You want to delete only VLAN 15 configured on bond2, or delete complete bond2 logical interface ?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 06:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202421#M38096</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-01-08T06:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202547#M38120</link>
      <description>&lt;P&gt;Hi Jozko,&lt;/P&gt;&lt;P&gt;Not delete, rather disable vlan15 on bond2, i.e. bond2.15 -we need to re-enable back in some time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 00:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202547#M38120</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2024-01-09T00:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202553#M38122</link>
      <description>&lt;P&gt;I have tested setting vsx wrp-interface down simply with ifconfig. It won't survive reboot though, but will work.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 00:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202553#M38122</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2024-01-09T00:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202572#M38124</link>
      <description>&lt;P&gt;The correct way is to delete VLAN from Topology tab within affected VS in SmartConsole. Do not forget to install policy afterwards.&lt;/P&gt;
&lt;P&gt;Once the VLAN is needed again, just add it back.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 06:47:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202572#M38124</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-01-09T06:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202653#M38131</link>
      <description>&lt;P&gt;To get you right:&lt;BR /&gt;1- disable the interface from clish&lt;BR /&gt;2- delete it from the Topology tab for the affected VS in SmartConsole&lt;BR /&gt;3- push the policy&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;To reactivate it, just reverse the above steps&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 02:49:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202653#M38131</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2024-01-10T02:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202671#M38137</link>
      <description>&lt;P&gt;Disable interface from CLI within VS is not needed. SmartConsole will remove it during provisioning proccess (once you click OK with deleted VLAN on VS object).&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:30:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/202671#M38137</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-01-10T08:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/249510#M48730</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;Is it possible to disable an interface that is part of a VSX Cluster?&lt;/P&gt;
&lt;P&gt;I have a lab environment, where the Eth2 interface is the SYNC interface between my VSX1 and VSX2 box&lt;/P&gt;
&lt;P&gt;My Cluster does not “wake up”, and emphasizes that the problem is the Eth2 interface&lt;/P&gt;
&lt;P&gt;I have done everything at VMWARE level but I still can't fix it&lt;/P&gt;
&lt;P&gt;I want to logically shut down the Eth2 interface from each box&lt;/P&gt;
&lt;P&gt;Is this possible?&lt;/P&gt;
&lt;P&gt;Could you guide me with the steps to follow?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 15:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/249510#M48730</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-05-21T15:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling interface on VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/249512#M48732</link>
      <description>&lt;P&gt;I believe generic linux command would be if eth2 down&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 15:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disabling-interface-on-VS/m-p/249512#M48732</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-21T15:07:57Z</dc:date>
    </item>
  </channel>
</rss>

