<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX configuration output interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10006#M588</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to supply full details Ahmed so we can see all IPs, errors etc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Mar 2019 09:41:06 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2019-03-06T09:41:06Z</dc:date>
    <item>
      <title>VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/9999#M581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;output of interface vsx :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hello evry body&amp;nbsp;&lt;/P&gt;&lt;P&gt;can someone explain to me why i have difference IP in output between the two commande in the same FW For the same interface alos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the same CHASSIS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i&amp;nbsp;use show configuration i see this output for the interface&amp;nbsp;&lt;SPAN&gt;eth3-01.403&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set interface eth3-01.403 state on&lt;BR /&gt;set interface eth3-01.403 mtu 1500&lt;BR /&gt;set interface eth3-01.403 ipv4-address &lt;SPAN style="color: #ff6600;"&gt;&lt;STRONG&gt;192.168.196.66&lt;/STRONG&gt;&lt;/SPAN&gt; mask-length 28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and when i use show interface eth3-01.403 i see the different IP .&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;show interface eth3-01.403&lt;BR /&gt;state on&lt;BR /&gt;mac-addr 00:4c:7f:85:c3:9c&lt;BR /&gt;type vlan&lt;BR /&gt;link-state not available&lt;BR /&gt;instance 35&lt;BR /&gt;mtu 1500&lt;BR /&gt;auto-negotiation Not configured&lt;BR /&gt;speed 10G (eth3-01)&lt;BR /&gt;ipv6-autoconfig Not configured&lt;BR /&gt;duplex full (eth3-01)&lt;BR /&gt;monitor-mode Not configured&lt;BR /&gt;link-speed Not configured&lt;BR /&gt;comments&lt;BR /&gt;ipv4-address &lt;STRONG style="color: #ff0000; "&gt;10.126.111.45/27&lt;/STRONG&gt;&lt;BR /&gt;ipv6-address Not Configured&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 10:53:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/9999#M581</guid>
      <dc:creator>ahmed_bousta</dc:creator>
      <dc:date>2019-03-05T10:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10000#M582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;192.168.196.0 is your internal communications network, see from VSX admin guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internal Communication Network&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;The internal communication network is a virtual network that is required for ClusterXL environments, in addition to the synchronization network. The internal communication network is invisible to external networks and lets cluster members communicate and recognize the state of the environment.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;VSX assigns an IP address to the internal communication network during the cluster creation process. This eliminates the need to manually assign an IP address to each cluster member:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;IPv4 address: 192.168.196.0, netmask: 255.255.252.0 (A range of four class C networks).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;IPv6 address and netmask: FD9A::1FFE:0:0:0/80&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;You can modify the default IP address using the Gateway Cluster Properties &amp;gt; Cluster Members page of the VSX cluster object, but only before creating Virtual Systems. Once Virtual Systems have been created, the IP range of the internal communication network cannot be modified.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Note: To avoid overlapping IP addresses, before creating any virtual devices, make sure the default IP address range of the Internal Communication network is not used anywhere else in the external network&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;IMG class="image-1 jive-image" height="389" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79788_pastedImage_3.png" width="469" /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you shouldn't&amp;nbsp;worry too much about it unless your own internal real networks overlap with that range&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 12:10:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10000#M582</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-03-05T12:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10001#M583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you but i can't ping from the Ip that in configuered on smartdashbord&amp;nbsp;10.126.111.105&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i ping the interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 10.126.111.105&lt;BR /&gt;PING 10.126.111.105 (10.126.111.105) 56(84) bytes of data.&lt;BR /&gt;From 192.168.196.194 icmp_seq=2 Destination Host Unreachable&lt;BR /&gt;From 192.168.196.194 icmp_seq=3 Destination Host Unreachable&lt;BR /&gt;From 192.168.196.194 icmp_seq=4 Destination Host Unreachable&lt;BR /&gt;From 192.168.196.194 icmp_seq=6 Destination Host Unreachable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and on the smartview traker i see the&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;192.168.196.194&amp;nbsp; as source .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 16:29:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10001#M583</guid>
      <dc:creator>ahmed_bousta</dc:creator>
      <dc:date>2019-03-05T16:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10002#M584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the machine you do the ping on the master for this VS, are you in the correct VS while doing this ping?&lt;/P&gt;&lt;P&gt;To find out which VSLS member each VS is active on you can run the following commands in expert:&lt;/P&gt;&lt;P&gt;vsenv 0&lt;/P&gt;&lt;P&gt;vsx stat -v&lt;/P&gt;&lt;P&gt;cphaprob stat&lt;/P&gt;&lt;P&gt;The vsx stat command will show you the names and VS number of each VS, cphaprob will show you the active / standby / backup state of each VS for each member in a cluster.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 21:58:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10002#M584</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-05T21:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10003#M585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Additionally source may be NATed to the real IP, we had a discussion before but didn't get to conclusion why does it sometimes use internal comms as a source and sometimes NATs it, here's an example from two different VSes with different results in the log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79824_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10003#M585</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-03-06T08:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10004#M586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In this case the actual IP was shown in his ping response as that is the interface IP that reports the Host Unreachable:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;From 192.168.196.194 icmp_seq=6 Destination Host Unreachable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;What is even more confusing is that the range the interface is in does not comply with the network of the pinged host:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;ipv4-address&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; border: 0px; font-weight: bold;"&gt;10.126.111.45/27 and 10.126.111.105&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;STRONG style="background-color: #ffffff; border: 0px; color: #333333; font-weight: 400; "&gt;So if they are not in the same network&lt;SPAN&gt;&amp;nbsp;why does it try to access the host directly, this can only be when the host is on another interface than the interface mentioned, which also complies with the different IP that we see in the first post .66 and .196 in the ping post.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10004#M586</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-06T08:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10005#M587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i'm in the correct VS . and i try to ping from both active/standby. but i can't ping the self interface from the vs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from outside i can ping the IP&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;10.126.111.105 .&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;but when i ping from vs i can't ping other equipements from&amp;nbsp; the VS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 09:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10005#M587</guid>
      <dc:creator>ahmed_bousta</dc:creator>
      <dc:date>2019-03-06T09:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10006#M588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to supply full details Ahmed so we can see all IPs, errors etc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 09:41:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10006#M588</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-03-06T09:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10007#M589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79827_Capture00.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a take an exempl for the one vlan i have the same issue for all valn&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as you can see on smartdashbord i can see this ip for this interface .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show interface eth3-01.405&lt;BR /&gt;state on&lt;BR /&gt;mac-addr 00:5c:7c:95:d5:2d&lt;BR /&gt;type vlan&lt;BR /&gt;link-state not available&lt;BR /&gt;instance 33&lt;BR /&gt;mtu 1500&lt;BR /&gt;auto-negotiation Not configured&lt;BR /&gt;speed 10G (eth3-01)&lt;BR /&gt;ipv6-autoconfig Not configured&lt;BR /&gt;duplex full (eth3-01)&lt;BR /&gt;monitor-mode Not configured&lt;BR /&gt;link-speed Not configured&lt;BR /&gt;comments&lt;BR /&gt;ipv4-address 10.126.111.12/27&lt;BR /&gt;ipv6-address Not Configured&lt;BR /&gt;ipv6-local-link-address Not Configured&lt;/P&gt;&lt;P&gt;______________&lt;/P&gt;&lt;P&gt;and for show configuration command i see&lt;/P&gt;&lt;P&gt;set interface eth3-01.405 mtu 1500&lt;BR /&gt;set interface eth3-01.405 ipv4-address 192.168.196.98 mask-length 28&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;--------&lt;BR /&gt;in my netwok i don't want this ip to be reacheable&lt;/P&gt;&lt;P&gt;ping 192.168.196.98&lt;BR /&gt;PING 192.168.196.98 (192.168.196.98) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 192.168.196.98: icmp_seq=1 ttl=64 time=0.021 ms&lt;BR /&gt;64 bytes from 192.168.196.98: icmp_seq=2 ttl=64 time=0.010 ms&lt;BR /&gt;64 bytes from 192.168.196.98: icmp_seq=3 ttl=64 time=0.011 ms&lt;BR /&gt;64 bytes from 192.168.196.98: icmp_seq=4 ttl=64 time=0.011 ms&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;:33&amp;gt; ping 10.126.111.12&lt;BR /&gt;PING 10.126.111.12 (10.126.111.12) 56(84) bytes of data.&lt;BR /&gt;From 192.168.196.98 icmp_seq=2 Destination Host Unreachable&lt;BR /&gt;From 192.168.196.98 icmp_seq=3 Destination Host Unreachable&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; show route&lt;/P&gt;&lt;P&gt;-------------&lt;BR /&gt;Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),&lt;BR /&gt; O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA)&lt;BR /&gt; A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,&lt;BR /&gt; U - Unreachable, i - Inactive&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;C 10.126.111.0/27 is directly connected, eth3-01.405&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can ping the reel ip fro outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 10:39:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10007#M589</guid>
      <dc:creator>ahmed_bousta</dc:creator>
      <dc:date>2019-03-06T10:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10008#M590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal behavior, it is a virtual IP and cannot be pinged from the machine itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 10:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10008#M590</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-06T10:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: VSX configuration output interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10009#M591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you very much i do same check for an other VS working fine and i see the same result we can't ping a virtual ip from the VS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 10:56:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-configuration-output-interface/m-p/10009#M591</guid>
      <dc:creator>ahmed_bousta</dc:creator>
      <dc:date>2019-03-06T10:56:12Z</dc:date>
    </item>
  </channel>
</rss>

