<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Synchronization of VSs in VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260884#M51195</link>
    <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;I have a question which is related to synchronization interface on VSX running within VSLS mode.&lt;/P&gt;
&lt;P&gt;If sync interface is not reachable between 2 VSX cluster members, one member will be Active, second Down. But what about status of VSs ? Sync interface is configured on VS0, but does it have impact also on every VS itself ? If sync interface is down on second VSX member, will also all VSs on second member go into down state ?&lt;/P&gt;
&lt;P&gt;Another related question - if I reboot second VSX member (in down state) which cannot sync with active member due to issue with sync interface, will rebooted VSX go into active state including all VS? Means, split brain since former active node is all the time active, but second VSX member cannot check state of another VSX member, thus will go into active ?&lt;/P&gt;
&lt;P&gt;Or is sync on all VSs done over lowest/highest VlANs, independent from sync interface configured on VS0 ?&lt;/P&gt;</description>
    <pubDate>Sun, 26 Oct 2025 09:46:39 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2025-10-26T09:46:39Z</dc:date>
    <item>
      <title>Synchronization of VSs in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260884#M51195</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;I have a question which is related to synchronization interface on VSX running within VSLS mode.&lt;/P&gt;
&lt;P&gt;If sync interface is not reachable between 2 VSX cluster members, one member will be Active, second Down. But what about status of VSs ? Sync interface is configured on VS0, but does it have impact also on every VS itself ? If sync interface is down on second VSX member, will also all VSs on second member go into down state ?&lt;/P&gt;
&lt;P&gt;Another related question - if I reboot second VSX member (in down state) which cannot sync with active member due to issue with sync interface, will rebooted VSX go into active state including all VS? Means, split brain since former active node is all the time active, but second VSX member cannot check state of another VSX member, thus will go into active ?&lt;/P&gt;
&lt;P&gt;Or is sync on all VSs done over lowest/highest VlANs, independent from sync interface configured on VS0 ?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Oct 2025 09:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260884#M51195</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2025-10-26T09:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of VSs in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260894#M51196</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The status of a VS (Active / Standby / Down / Ready / Init / Backup) is determined through the Cluster Control Protocol (CCP) mechanism, combined with local health checks and internal synchronization logic.&lt;/P&gt;
&lt;P&gt;The Cluster Control Protocol (CCP) operates on Layer 2 or Layer 3, depending on the configured ClusterXL mode (now only Unicast). It is managed by the cphad daemon and periodically exchanges Hello and State messages between cluster members. These messages include key data such as the Cluster ID, Member ID, VSX Instance ID, interface and synchronization status, and the cluster role (Active or Standby). Each Virtual System (VS) maintains its own unique Cluster ID and Member ID combination within CCP, ensuring logical separation between VS instances.&lt;/P&gt;
&lt;P&gt;If the Sync interface fails, the VS instances should continue to maintain their cluster status Active, Standby, Backup (in configurations with three or more gateways) through the CCP protocol on the remaining interfaces.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Oct 2025 12:10:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260894#M51196</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2025-10-26T12:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Synchronization of VSs in VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260960#M51200</link>
      <description>&lt;P&gt;Sync being down will be an interface down and also sync failing, so the VSs will go Active(!)/Down/Down/Down. Also a failure of sync will cause any cluster to go Active(!)/Down, VS or SG.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 02:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Synchronization-of-VSs-in-VSX/m-p/260960#M51200</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-27T02:31:56Z</dc:date>
    </item>
  </channel>
</rss>

