<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX Shared Vlan Interfaces and ARP Issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57829#M9617</link>
    <description>For each VLAN you need to connect to more than 1 VS you create a virtual switch, this Virtual switch can also be connected to a VLAN in a trunk port. This is not limited to a physical interface.</description>
    <pubDate>Tue, 09 Jul 2019 20:25:58 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-07-09T20:25:58Z</dc:date>
    <item>
      <title>VSX Shared Vlan Interfaces and ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57824#M9616</link>
      <description>&lt;P&gt;We are deploying VSX and getting some difficulties implementing it to customer's environment whether we use vSwitch or vRouter.&lt;/P&gt;&lt;P&gt;Both VSes need to have an access to shared vlan interfaces (internal &amp;amp; DMZ). eth5 (internal) has 4 vlans and eth6 (DMZ) has 1 vlan only. I believe vSwitch can have only 1 vlan tag, it seems we don't have other options but to use vRouter or create multiple vSwitch for each vlan.&lt;/P&gt;&lt;P&gt;The second problem is after creating vSwitch and connecting to VS0&amp;nbsp; (warp link) with the ip address of 10.10.1.254, the gateway or VS0 is not responding to arp request.&lt;BR /&gt;"arp who-has 10.10.1.254 tell 10.10.1.210" Clearly, that IP belongs to virtual device.&lt;/P&gt;&lt;P&gt;Did I miss anything? Any suggestion are welcome and appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached the topology for reference.&amp;nbsp;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="VSX Diagram.png" style="width: 488px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1840i99C77EE6941B9F74/image-dimensions/488x233?v=v2" width="488" height="233" role="button" title="VSX Diagram.png" alt="VSX Diagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 18:28:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57824#M9616</guid>
      <dc:creator>LOcfemia</dc:creator>
      <dc:date>2019-07-09T18:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Shared Vlan Interfaces and ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57829#M9617</link>
      <description>For each VLAN you need to connect to more than 1 VS you create a virtual switch, this Virtual switch can also be connected to a VLAN in a trunk port. This is not limited to a physical interface.</description>
      <pubDate>Tue, 09 Jul 2019 20:25:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57829#M9617</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-09T20:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: VSX Shared Vlan Interfaces and ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57857#M9618</link>
      <description>&lt;P&gt;As said earlier vSwitch can only handle one VLAN. So technically you could spin up 5 vSwitches one for each VLAN. But I struggle to understand the purpose of two firewalls connecting to the same interfaces (all) I understand if they shared one or two, but not all. Seems a bit strange.&lt;/P&gt;
&lt;P&gt;ARP issue is probably related to VLAN tagging not set correctly or check your trunk between VSX and next hop&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 07:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-Shared-Vlan-Interfaces-and-ARP-Issue/m-p/57857#M9618</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-07-10T07:54:44Z</dc:date>
    </item>
  </channel>
</rss>

