<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 23500 and/or 23800 appliances in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10659#M679</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a screenshot of the VSX topology with bridge present, VS with the bridge attached to it as well as sanitized gaia config?&lt;/P&gt;&lt;P&gt;If you have more than one VS configured, can you check if this pre-defined interface is present in the context of each VS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am curious to see how it looks.&lt;/P&gt;&lt;P&gt;When you are saying that WebUI configured bridge is present in CLI, are you implying that the one configured in SmartConsole is not?&lt;/P&gt;&lt;P&gt;Have you published and installed the policy and then confirmed its absence from config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Apr 2018 22:32:24 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-04-25T22:32:24Z</dc:date>
    <item>
      <title>23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10635#M655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi checkmates,&lt;/P&gt;&lt;P&gt;anyone had experience with 23.5, and 23.8k appliances? If yes in what configuration?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 06:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10635#M655</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-03-30T06:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10636#M656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;23800, R80.10 VSX,&amp;nbsp; &amp;lt; 10 VSes, static routing, peaking 10 Gbps, bond to the core. Nothing too much with fancy blades. FW, ips, ia. So far so good. Nothing to complain about. Just ordered another pair to replace 13800 &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 07:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10636#M656</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-30T07:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10637#M657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it single 23800 VSX or cluster?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 14:56:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10637#M657</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-03-30T14:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10638#M658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kaspar, I assume your configuration is single 238k model? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Apr 2018 04:40:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10638#M658</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-01T04:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10639#M659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, Easter break from work.. no it's a cluster.:)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2018 20:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10639#M659</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-04-02T20:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10640#M660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have 2 VRRP Clusters on 23800 Appliances as datacenter core firewalls with a lot of VLANs (150+) on 10GB Bonds and actually have issues with the VRRP failover (routed seems to hang, case open) as well as some false positives on the power supply monitoring via snmp. Other than that, those applicances are very fast, but cost a fortune &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2018 11:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10640#M660</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2018-04-06T11:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10641#M661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why vrrp not ccp?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 21 Apr 2018 06:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10641#M661</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-21T06:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10642#M662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've deployed a number of those with R77.30 VSX in ClusterXL. Number of VS' on each cluster with variety of configurations.&lt;/P&gt;&lt;P&gt;Generally, all is well. The only thing of note was an incorrect memory reporting by show asset all command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Apr 2018 17:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10642#M662</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-22T17:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10643#M663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have many 23500/23800 deployments, in&amp;nbsp;several&amp;nbsp;different scenarios (with and without Blades, clusters -usually ClusterXL-, regular Gateways and VSX...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you looking for anything specific? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;Hardware related issues maybe?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 04:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10643#M663</guid>
      <dc:creator>Victor_MR</dc:creator>
      <dc:date>2018-04-23T04:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10644#M664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Needed to know memory/CPU concerns/considerations and performance before purchase commitment. I settled with 2x23.5(s). Now configuration fun: since VS licensing comes as VSLS, does it mean to fully utilize functionality VSX gateways have to be configured in load sharing mode, not HA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 13:23:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10644#M664</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-23T13:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10645#M665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would look at it differently: when and if you'll get to the third appliance, you'll have an option of taking advantage of VSLS.&lt;/P&gt;&lt;P&gt;With 2 appliances, the HA is a better option (personal opinion). Otherwise, you'll have to keep track on utilization in order to avoid overloading the systems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 13:39:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10645#M665</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-23T13:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10646#M666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Valid point however theoretically,  if gateway has enough power to run 10 VM(s) in VLSM mode it should be fine since only half of active VS(s) will be running on one gateway at given time (5act and 5 standby on each? What would be the breaking point to consider 3rd VSX gateway?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 21:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10646#M666</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-23T21:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10647#M667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When VS' were 32 bit, it was easier to answer this question, since we knew the maximum allocated vRAM.&lt;/P&gt;&lt;P&gt;With 64 bit VSX memory consumption is dynamic, so you'll have to monitor total active (non-cached) memory consumption of the each member of VSX cluster is lower than 50%. Otherwise, when one of the appliances is down, you may end-up with underperforming VS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 21:47:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10647#M667</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-23T21:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10648#M668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good info, thank  you. Anything else to watch for or be prepared for before I disappear in VSX forest?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 22:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10648#M668</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-23T22:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10649#M669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just that you'll lose the WebUI when you designate units as VSX. Not the end of the world, but for consistency sake, pre-configure both units same way and check the diff between configs. Primarily applicable to routing, if you are planning to use any advance features. And, of course, NTP sync the units before clustering them. If your Check Point infrastructure is not huge, consider configuring static DNS entries for all of its components on each unit as well as verify access to the Internet for licensing and CPUSE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best of luck!&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 22:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10649#M669</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-23T22:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10650#M670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool stuff, info I was looking for, thank you. One more Q: I am planning to have 2 VSX gateways in SL mode with VS(s) in HA mode on them. Theoretically should work? Crazy, stupid or potential subside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 03:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10650#M670</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-24T03:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10651#M671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean VSX' in LS and VS' in HA? I'd suggest asking Kaspars Zibarts, as he is working with VSX more than I do, but if my recollection is correct, VSLS is enabling 3 instances of the same VS, active, standby and a backup. Not sure what that does to resource consumption, but I think it'll be on par with HA with the backup version being normally suspended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only advantages to this approach is the ability to rapidly expand the cluster without changing its mode and equal stress of the hardware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the point of view of redundancy and failover time, I do not believe you'll gain anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to find an ARTG articles on VSX, those may come handy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2018 12:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10651#M671</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-24T12:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10652#M672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vladimir, you are correct regarding configuration. Do you know where I can find information on why some VSX CLI commands blocked? There is no explanation why, it is simply blocked? Particular command I need is to add brdge.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 19:46:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10652#M672</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-25T19:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10653#M673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could it be that you have chosen one of the preset VSX models instead of "Custom Properties"?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64836_pastedImage_1.png" style="width: 620px; height: 357px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And are those interfaces defined as "Physical Interfaces"?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64837_pastedImage_2.png" style="width: 620px; height: 318px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 19:58:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10653#M673</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-25T19:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: 23500 and/or 23800 appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10654#M674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes and yes :only custom template and can see physical interfaces but no love from bridging side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 20:04:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/23500-and-or-23800-appliances/m-p/10654#M674</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2018-04-25T20:04:57Z</dc:date>
    </item>
  </channel>
</rss>

