<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add Interfaces To VSX Bond Group? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14201#M96378</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running in a similar situation where we want to reconfigure a&amp;nbsp;bonding group&amp;nbsp;that now contains&amp;nbsp;8x 1Gbps links. We are planning to&amp;nbsp;add&amp;nbsp;2x 10Gbps SFP's to that bonding group and offcourse remove the&amp;nbsp;8x 1Gbps interfaces from that group. This environment&amp;nbsp;is based on VSX (R80.10).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone please explain the following to me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is the answer provided by &lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;‌ supported by Check Point?&lt;/P&gt;&lt;P&gt;1.1 Is there a SK describing this?&lt;/P&gt;&lt;P&gt;2. Why is the "set vsx off/on" command issued?&lt;/P&gt;&lt;P&gt;3. What would happen to the affinity settings if we add the 2x 10Gbps modules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only SK i discovered and was recommended to me by support is&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk69180 but this is not VSX "specific" and is updated more than 2 years ago when R80.10 was not yet released...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;-J&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Jul 2018 13:24:55 GMT</pubDate>
    <dc:creator>_Jelle</dc:creator>
    <dc:date>2018-07-10T13:24:55Z</dc:date>
    <item>
      <title>Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14189#M96366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Afternoon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plan&amp;nbsp;to add additional 10GB interfaces to an existing bond group in a VSX VSLS cluster. Is there any trick to doing this that may not be obvious?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I planned on gracefully migrating all the VS's to a single cluster member using &lt;STRONG&gt;&lt;EM&gt;vsx_util vsls&lt;/EM&gt;&amp;nbsp;&lt;/STRONG&gt;via the management server. Once failed over, I was going to issue a&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;cpstop&lt;/STRONG&gt;&lt;/EM&gt; to the vacated Gateway to shut everything down.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, in CLISH run:&lt;/P&gt;&lt;P&gt;add bonding group 0 interface eth1-03&lt;BR /&gt;add bonding group 0 interface eth1-04&lt;BR /&gt;add bonding group 0 interface eth2-03&lt;BR /&gt;add bonding group 0 interface eth2-04&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that, I was planning on rebooting the Gateway given its long uptime. Once it came back up, I was going to verify the cluster integrity with the new interfaces with&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, rinse and repeat with the other cluster member.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I need to do to make sure this goes as smoothly as possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2018 19:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14189#M96366</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-09T19:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14190#M96367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's a fairly safe approach Dan.&lt;/P&gt;&lt;P&gt;Depending on&amp;nbsp;where your bond is attached in VSX, you may check each bond member state with ether&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cphaconf show_bond bond0&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;cat /proc/net/bonding/bond0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 06:34:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14190#M96367</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-04-10T06:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14191#M96368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/47831"&gt;Kaspars Zibarts&lt;/A&gt;‌, I'll check that once we bring everything up!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One question for &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Tim Hall&lt;/A&gt;‌: We are carrying&amp;nbsp;the majority of the traffic flowing in and out of this VSX Cluster (a few dozen VLANs) from this bonded Interface. When we first configured these Gateways, we enabled multi-queueing to help distribute the processing for these interfaces. Does&amp;nbsp;&lt;SPAN&gt;multi-queueing have to be manually enabled on the Interfaces we add to the bond group? Or will that happen automatically once they join the bond group? My recollection of how all that works is a bit fuzzy!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-Dan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;vsx&amp;nbsp;multi-queue‌ bond‌&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 15:13:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14191#M96368</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-10T15:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14192#M96369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Multi-Queue (MQ) is enabled per physical interface, so adding a physical interface to a bonded (ae) interface will not influence the MQ settings for that physical interface.&amp;nbsp; MQ is not even aware of bonds and only concerns itself with physical interfaces.&amp;nbsp; The maximum number of physical interfaces MQ can be enabled for is 5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said MQ should not be enabled indiscriminately on an interface, as it causes extra overhead in the SND/IRQ cores as they must now "stick" all packets associated with a particular connection/stream to the same queue every time to avoid out-of-order delivery of frames.&amp;nbsp; Generally if more SND/IRQ cores can be assigned to avoid RX-DRPs without overloading the remaining Firewall Worker cores, doing so is more desirable than enabling MQ.&amp;nbsp; However if there are not enough total available core resources to assign more SND/IRQ cores, or &lt;STRONG&gt;sim affinity -l&lt;/STRONG&gt; shows that a single SND/IRQ core dedicated to handling a physical interface's ring buffer is still experiencing &amp;gt;0.1% RX-DRPs, enabling MQ is the right call.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 16:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14192#M96369</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-04-10T16:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14193#M96370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the point of adding the interfaces to the bond, you don't even need to do a cpstop, I do think however that you will need to set vsx off before changing anything to your interface settings, make the changes and then set vsx on.&lt;/P&gt;&lt;P&gt;From the VSX perspective make sure the added interfaces are not in your VSX cluster interface list, if so remove them from the list before you start.&lt;/P&gt;&lt;P&gt;So your steps again:&lt;/P&gt;&lt;P&gt;check interfaces in VSX Cluster object&lt;/P&gt;&lt;P&gt;ssh to management&lt;/P&gt;&lt;P&gt;vsx_util vsls - move all to member A&lt;/P&gt;&lt;P&gt;SSH to member B&lt;/P&gt;&lt;P&gt;set vsx off&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;add bonding group 0 interface eth1-03&lt;BR /&gt;add bonding group 0 interface eth1-04&lt;BR /&gt;add bonding group 0 interface eth2-03&lt;BR /&gt;add bonding group 0 interface eth2-04&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;set vsx on&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;save config&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;go to management&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;vsx_util vsls - move all to member B&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;SSH to member A&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;set vsx off&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;add bonding group 0 interface eth1-03&lt;BR /&gt;add bonding group 0 interface eth1-04&lt;BR /&gt;add bonding group 0 interface eth2-03&lt;BR /&gt;add bonding group 0 interface eth2-04&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;set vsx on&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;save config&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;go to management&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;vsx_util vsls - distribute load&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;&lt;/P&gt;&lt;P style="color: #3d3d3d;"&gt;all done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 18:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14193#M96370</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-10T18:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14194#M96371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As always, thanks for your insight on this. After seeing your response, I went back and calculated the per-interface RX-DRP% for each Gateway. &lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;Interfaces eth1-01, &lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;eth&lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;1-02, &lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;eth&lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;2-01, and &lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;eth&lt;/SPAN&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;2-02 are the ones currently in bond1 with MQ enabled. (all eth1 and eth2 line card interfaces are 10GB in a CP 23800 Appliance with R77.30.)&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64455_vsx-stats.jpg" style="height: auto;" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It became pretty apparent to me that these Gateways are not suffering from RX-DRP issues whatsoever! Given that the maximum interfaces MQ can be enabled on is 5, and that we would end up with a total of 8 interfaces in the bond group after this change is made, do you consider it more advisable to remove MQ entirely from this configuration? &lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;We never experienced any performance / CPU issues that had us enable MQ in the first place.&lt;/SPAN&gt; Someone merely suggested we enable MQ when these Gateways were built new.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it doesn't appear to be solving any problems, and reduces our overall configuration complexity, it seems to me like it may make more sense to disable it. What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 19:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14194#M96371</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-10T19:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14195#M96372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're right... I think you do need to do "set vsx off" and then "set vsx on" when making these types of changes. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 19:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14195#M96372</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-10T19:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14196#M96373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting. Seemed to work just fine for us without turning vsx off. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;We did it on the "fly" - add on standby member, fail over and do the other standby. But we were a bit of cowboys&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 20:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14196#M96373</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-04-10T20:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14197#M96374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You only need to set vsx off when you need to change other interface settings (the MQ settings??).&lt;/P&gt;&lt;P&gt;What I did not try though is if you add a space character at the beginning of the line if that then still works, as it does in a cloning group configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 20:22:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14197#M96374</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-10T20:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14198#M96375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know that you can turn VSX mode off to regain access to the GAIA WebUI. So, if you were looking to make these kinds of changes through the WebUI and not clish, you'd have to turn VSX mode off. (I'm also not suggesting&amp;nbsp;&lt;EM&gt;that&lt;/EM&gt; method is officially supported by CP. It is just something I've observed while working with VSX!)&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 20:25:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14198#M96375</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-10T20:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14199#M96376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my book I mention a goal of having RX-DRP be &amp;lt; 0.1%.&amp;nbsp; You are well beneath that, so I'd say disable MQ.&amp;nbsp; Assuming RX-DRP's remain below 0.1% leave MQ off.&amp;nbsp; No point in increasing configuration complexity if you can help it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 12:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14199#M96376</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-04-11T12:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14200#M96377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All this discussion prompted me to re-read Chapter 7 yesterday, and that was pretty much my takeaway! &amp;nbsp;I'll plan on shutting down MQ when I add the extra interfaces. Thanks for taking the time to look over my data and weigh in! Its always reassuring to have a second opinion!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to everyone who replied in this thread. I think I've got a solid game plan now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 12:25:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14200#M96377</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-04-11T12:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14201#M96378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running in a similar situation where we want to reconfigure a&amp;nbsp;bonding group&amp;nbsp;that now contains&amp;nbsp;8x 1Gbps links. We are planning to&amp;nbsp;add&amp;nbsp;2x 10Gbps SFP's to that bonding group and offcourse remove the&amp;nbsp;8x 1Gbps interfaces from that group. This environment&amp;nbsp;is based on VSX (R80.10).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone please explain the following to me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Is the answer provided by &lt;A href="https://community.checkpoint.com/migrated-users/50921"&gt;Maarten Sjouw&lt;/A&gt;‌ supported by Check Point?&lt;/P&gt;&lt;P&gt;1.1 Is there a SK describing this?&lt;/P&gt;&lt;P&gt;2. Why is the "set vsx off/on" command issued?&lt;/P&gt;&lt;P&gt;3. What would happen to the affinity settings if we add the 2x 10Gbps modules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only SK i discovered and was recommended to me by support is&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk69180 but this is not VSX "specific" and is updated more than 2 years ago when R80.10 was not yet released...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;-J&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:24:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14201#M96378</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2018-07-10T13:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14202#M96379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1 Yes it is.&lt;/P&gt;&lt;P&gt;1.1 here you have 2 examples I cound find in a couple of minutes:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From SK101165&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Remove the problematic route:&lt;/P&gt;&lt;P&gt;HostName:0&amp;gt; set vsx off&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set virtual-system 0&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set static-route default nexthop gateway address 192.168.1.254 off&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set vsx on&lt;/P&gt;&lt;P&gt;HostName:0&amp;gt; save config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From SK92425:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;HostName:0&amp;gt; set vsx off&lt;/P&gt;&lt;P&gt;HostName&amp;gt; show vsx&lt;/P&gt;&lt;P&gt;VSX Disabled&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set static-route default off&lt;/P&gt;&lt;P&gt;HostName&amp;gt; delete interface eth0 ipv4-address&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set interface eth0 ipv4-address 192.168.0.1 mask-length 24&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set static-route default nexthop gateway address 192.168.0.4 on&lt;/P&gt;&lt;P&gt;HostName&amp;gt; set vsx on&lt;/P&gt;&lt;P&gt;HostName:0&amp;gt; show vsx&lt;/P&gt;&lt;P&gt;VSX Enabled&lt;/P&gt;&lt;P&gt;HostName:0&amp;gt; save config&lt;BR /&gt;&lt;BR /&gt;2. The set vsx on command is issued to lock interface and routing configuration from clish and to disable the WebUI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;3. I don't know maybe Tim can tell us?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2018 20:39:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14202#M96379</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-10T20:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14203#M96380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all, &lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;thanks for the provided answers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After reviewing the SK's you provided i am not really convinced that this is the way to go... Are we not talking about different kinds of situations here?&lt;/P&gt;&lt;P&gt;Is the "set vsx off" command really needed for editing the bonding configuration? Looking at &lt;STRONG&gt;SK92425 &lt;/STRONG&gt;(important note) i would say yes... but why is this not described in &lt;SPAN style="background-color: #ffffff; color: #000000; font-size: 14px;"&gt;&lt;STRONG&gt;SK69180&lt;/STRONG&gt;&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, &lt;STRONG&gt;SK101165&lt;/STRONG&gt; seems to be outdated and not relevant to R80.10 environments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #000000; font-size: 14px;"&gt;&lt;STRONG&gt;SK69180 &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;- Seems to be the most accurate for this situation (But also outdated) at the moment and i don't see the "set vsx off" listed anywhere... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;In the mean time, I simulated this in my lab and it also worked as &lt;SPAN style="background-color: #ffffff; color: #000000; font-size: 14px;"&gt;&lt;STRONG&gt;SK69180 &lt;/STRONG&gt;&lt;/SPAN&gt; described. This was also mentioned by &lt;A href="https://community.checkpoint.com/migrated-users/47831"&gt;Kaspars Zibarts&lt;/A&gt;‌ in a previous reply. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2018 21:36:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14203#M96380</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2018-07-10T21:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14204#M96381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it is most likely an omission error from the SK articles mentioned. I also think the "set vsx off" command is a little misleading because to the average observed, it seems like you are literally disabling VSX once that command is issued. Which, obviously, isn't the case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like Maarten said, it is more just a way to "unlock" the GAIA configuration to allow you to make changes to it. We run a lot of VSX, so I would love to see the day where you could just access the WebUI in VSX the same way without having to issue separate commands to "disable" VSX mode. I can also play devil's advocate here and understand why that one extra step may be an ounce of prevention to keep people from tinkering with settings they may not fully understand the ramifications of changing in a production VSX environment.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 12:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14204#M96381</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2018-07-12T12:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14205#M96382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eventually, i had to use the "set vsx off" command to edit my interface configuration and enable the new interfaces. Also, i had to use this command to add these interfaces to a existing bond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks like Maarten was indeed right!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jelle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2018 15:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/14205#M96382</guid>
      <dc:creator>_Jelle</dc:creator>
      <dc:date>2018-07-26T15:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/65233#M96383</link>
      <description>few concerns-&lt;BR /&gt;disable vsx - its optional, w/o set vsx off we can add extra interface to the existing bond interface.&lt;BR /&gt;After adding the interface, we need to update the physical interface from cluster object and provision the VSX cluster</description>
      <pubDate>Thu, 17 Oct 2019 18:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/65233#M96383</guid>
      <dc:creator>Abinash_Sahoo</dc:creator>
      <dc:date>2019-10-17T18:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Add Interfaces To VSX Bond Group?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/150596#M96384</link>
      <description>&lt;P&gt;Hello Maarten,&lt;/P&gt;&lt;P&gt;i'm planning to move 1gb bond to 10gb.&lt;/P&gt;&lt;P&gt;Is that possible without outage?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 10 Jun 2022 18:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Add-Interfaces-To-VSX-Bond-Group/m-p/150596#M96384</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-10T18:02:04Z</dc:date>
    </item>
  </channel>
</rss>

