<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Funny IP on show configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87531#M9182</link>
    <description>What precise version is this?</description>
    <pubDate>Mon, 08 Jun 2020 02:52:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-06-08T02:52:22Z</dc:date>
    <item>
      <title>Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87352#M9181</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i'm trying to export "show configuration" from one of my Virtual System to a third party device for auditing purposes and i noticed that it shows the funny IP as show below:&lt;/P&gt;&lt;P&gt;set interface bond1.100 state on&lt;BR /&gt;set interface bond1.100 mtu 1500&lt;BR /&gt;set interface bond1.100 ipv4-address 192.168.196.49 mask-length 28&lt;BR /&gt;set interface bond1.101 state on&lt;BR /&gt;set interface bond1.101 mtu 1500&lt;BR /&gt;set interface bond1.101 ipv4-address 192.168.196.65 mask-length 28&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Is this how it should be or i'm i missing something. Ironically, doing ifconfig shows the actual IP associated with each bond as well as on the Management Station.&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 20:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87352#M9181</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2020-06-04T20:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87531#M9182</link>
      <description>What precise version is this?</description>
      <pubDate>Mon, 08 Jun 2020 02:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87531#M9182</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-08T02:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87601#M9183</link>
      <description>&lt;P&gt;R80.30 and R80.10&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 13:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87601#M9183</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2020-06-08T13:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87647#M9184</link>
      <description>Is it by any chance a VSX System?</description>
      <pubDate>Mon, 08 Jun 2020 17:16:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87647#M9184</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-06-08T17:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87651#M9185</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1459"&gt;@Enyi_Ajoku&lt;/a&gt;&amp;nbsp;you wrote "&lt;SPAN&gt;my Virtual System&lt;/SPAN&gt;".&lt;/P&gt;
&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;&amp;nbsp;indicates, looks like a VSX system.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;192.168.196.0/255.255.252.0 is the default subnet for VSX internal network. Every virtual system has an IP in this subnet.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can see this on the VSX object.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wolfgang&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 18:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87651#M9185</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-08T18:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87671#M9186</link>
      <description>&lt;P&gt;Yes it is&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 21:50:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87671#M9186</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2020-06-08T21:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87672#M9187</link>
      <description>&lt;P&gt;I am aware of the internal IP address on VSX system but what i am referring to is an ip associated with a bond that is configured on Management Station on VSX.&lt;/P&gt;&lt;P&gt;ifconfig shows actual ip associated with bond, same as on the management station but when i do show configuration on for example vs1 is shows funny ip as i have stated in the configuration snippet above&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 21:56:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87672#M9187</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2020-06-08T21:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87693#M9188</link>
      <description>That is still one of the problems with VSX, ifconfig only shows the real IP's since R80, before it also showed the 192.168.x addresses.&lt;BR /&gt;So there is at least 1 point to find the real IP's.&lt;BR /&gt;To be honest, on a VSX box I rarely connect in clish, as there is very little you can/need to do there.</description>
      <pubDate>Tue, 09 Jun 2020 06:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/87693#M9188</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-06-09T06:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/139204#M21229</link>
      <description>&lt;P&gt;In my R80.40 VSX setup I see the external IPs not the internal (funny) ones.&amp;nbsp; I've not see this since pre-R77 VSX, and even then you could toggle this display to external IPs.&lt;/P&gt;
&lt;P&gt;It makes allot of sense to display the external IPs i.e. IPs defined in the topology in Smartconsole purely from a track and troubleshooting prospective.&lt;/P&gt;
&lt;P&gt;I've got a VSX R81 setup which has this problem and just logged a TAC case, which is purely a cosmetic issue, rather then functional.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 18:54:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/139204#M21229</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-23T18:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/275746#M105023</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1459"&gt;@Enyi_Ajoku&lt;/a&gt;&amp;nbsp;, No it should not be like this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this issue too and this resolved the issue for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Set vsx on&lt;/P&gt;&lt;P&gt;2. Save config&lt;/P&gt;&lt;P&gt;3. Reboot cluster Member.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should be mindful to do this during a maintenance window lol but if you do not mind rebooting that cluster member then you should be fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check Point R&amp;amp;D is still looking into the issue as to why the member has to be rebooted before it takes effect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 07:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/275746#M105023</guid>
      <dc:creator>oh_mhari</dc:creator>
      <dc:date>2026-04-20T07:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Funny IP on show configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/275777#M105037</link>
      <description>&lt;P&gt;Technically, it's the other way around. The&amp;nbsp;192.168.196.0/22 block is the real addresses the interfaces actually have. 'ifconfig' by itself is an alias to /bin/cp-ifconfig.sh, which lies to you and shows the cluster VIPs instead of the real IP on the interfaces. You can see this by running the real ifconfig binary located at&amp;nbsp;/usr/sbin/ifconfig.&lt;/P&gt;
&lt;P&gt;This can be important to know, since the IPs you assign to virtual systems have all the same limitations and concerns as VIPs on a non-VSX cluster. They're claimed via the same mechanism, and you can use off-net VIPs with normal clusters, too.&lt;/P&gt;
&lt;P&gt;VSNext in R82 changes this. On an ElasticXL cluster (and VSNext requires ElasticXL), all the members actually have the addresses on their interfaces, and they use virtual MACs to control which member gets traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 14:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Funny-IP-on-show-configuration/m-p/275777#M105037</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-04-20T14:58:33Z</dc:date>
    </item>
  </channel>
</rss>

