<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with 12000, VSX, VSWITCH &amp;amp; R80.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63344#M9692</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We have 2 VSX issues:&lt;/P&gt;
&lt;P&gt;1. With VS-VSW / VS-VR, when the external interface of the VSW/VR is bond interface. - for more info please refer&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk160352&amp;amp;partition=Advanced&amp;amp;product=SecureXL," target="_blank"&gt;sk160352&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This fix was integrated to R80.30 JHF take 50.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;We have another issue with secureXL on -&amp;nbsp;&lt;A id="key-val" class="issue-link" href="https://jira-prd.checkpoint.com/browse/PRJ-4956" rel="441455" data-issue-key="PRJ-4956" target="_blank"&gt;PRJ-4956&lt;/A&gt;&lt;BR /&gt;CLONE - R80.30 jumbo hf | gogo_heat_188_main T296 | VS-VSW-VS | TP + SXL | HTTP packets are not passing&lt;BR /&gt;&lt;BR /&gt;This issue solves particular case only when all of the following conditions are met&amp;nbsp;&lt;BR /&gt;a. VSX setup&amp;nbsp;&lt;BR /&gt;b. VS-VSW-VS Or VS-VR-VS topology&amp;nbsp;&lt;BR /&gt;c. One of the threat-prevention blades are enable on VSs (e.g. ips, threat extraction, anti virus, anti bot...)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;This fix was integrated in R80.30 JHF take 51 (still not included in ongoing take)&lt;/P&gt;
&lt;P&gt;Following &lt;A href="http://taskmanager/TaskView.asp?TaskId=97283" target="_blank"&gt;Task 97283&lt;/A&gt;, There is a private fix on top of take 50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New hotfix has been provided: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;\\galaxy\ckp\pkg\fw1_wrapper\R80_30_jhf_t50_168_main\latest_linux50\release.dynamic.ping&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Sep 2019 10:52:27 GMT</pubDate>
    <dc:creator>matangi</dc:creator>
    <dc:date>2019-09-22T10:52:27Z</dc:date>
    <item>
      <title>Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63317#M9689</link>
      <description>&lt;P&gt;I will open a case for this but I wonder if someone has seen this already.&lt;/P&gt;&lt;P&gt;I upgraded a 12600 VSX cluster from R80.20 Take 47 to R80.30. All went well but there was a strange issue afterwards.&lt;/P&gt;&lt;P&gt;Two VS talk to each other via a "front" VSWITCH used for inter-VS communication. These VS also have "back" VSWITCH for the networks which are located behind them. I'd rather use tagged interfaces but it's another story and there's a reason why they're present.&lt;/P&gt;&lt;P&gt;After upgrade to Take 19, some traffic never makes it through a backend LAN on VS-A to the backend of VS-B.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Smart Console, the traffic is seen as accepted. With fw monitor, the traffic is seen but stays in the "i" part on VS-B.&lt;/P&gt;&lt;P&gt;The weird thing is that only specific protocols didn't go through, for the other ones we could see the full "iI-oO" and they worked normally. Failing protocols were RDP &amp;amp; HTTPS, but maybe there were others (no HTTPS inspection blade runs on any of the VS, and this is internal traffic only).&lt;/P&gt;&lt;P&gt;Now the interesting bit: uninstalling Take 19 actually solves the issue. We tried with the second cluster member which exhibited the exact same behaviour: OK with R80.30.0, fails with R80.30.19.&lt;/P&gt;&lt;P&gt;We're now in full production on both systems with R80.30 and no Take. I guess I will need to replicate issue with TAC but it's challenging as we need to install the Take on a production system and take live traces which isn't always easy to arrange, so I thought I'd check if anyone here would have seen that kind of behavior and had an idea.&lt;/P&gt;&lt;P&gt;The chassis themselves are all OK in terms of CPU, RAM, I/O and so on so I think it's really a software issue.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2019 12:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63317#M9689</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2019-09-21T12:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63324#M9690</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you are doing fine, I was planning an upgrade to R80.30 to a customer with a similar architecture as you described, when I was going to through possible issues I found this issue that was solved in Take 50 of 80.30&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Opera Snapshot_2019-09-21_121058_supportcenter.checkpoint.com.png" style="width: 830px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2576iC973291F014B103F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Opera Snapshot_2019-09-21_121058_supportcenter.checkpoint.com.png" alt="Opera Snapshot_2019-09-21_121058_supportcenter.checkpoint.com.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When looking at the described sk (sk160352) it seems that the issue is quite similar as the one that you are having since it involves drops when using virtual switches.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20190921_121511.png" style="width: 848px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2577i74D617F6438BBA8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20190921_121511.png" alt="Screenshot_20190921_121511.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You may want to point the TAC in this direction to try to sort this out more quickly since the fix is to install JHF Take 50.&lt;/P&gt;&lt;P&gt;Please let me know how it goes, personally I have suspended the migation until that hotfix becomes EA.&lt;/P&gt;&lt;P&gt;Hope it helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2019 15:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63324#M9690</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-21T15:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63330#M9691</link>
      <description>&lt;P&gt;We had major issues when upgrading to R80.30 with VSX.&lt;/P&gt;&lt;P&gt;also with bond interface connected to vswitch. After installing ongoing take 50 we got connections back up and running again.&lt;/P&gt;&lt;P&gt;instead all site to site vpn failed.&lt;/P&gt;&lt;P&gt;needed to get a privet Hotfix from support that was included in R80.20 but then removed in R80.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so with vsx, bond interface with VR or VSwitch I would not upgrade to R80.30 before more HFA is released to fix basic functions.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2019 19:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63330#M9691</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2019-09-21T19:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63344#M9692</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We have 2 VSX issues:&lt;/P&gt;
&lt;P&gt;1. With VS-VSW / VS-VR, when the external interface of the VSW/VR is bond interface. - for more info please refer&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk160352&amp;amp;partition=Advanced&amp;amp;product=SecureXL," target="_blank"&gt;sk160352&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This fix was integrated to R80.30 JHF take 50.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;We have another issue with secureXL on -&amp;nbsp;&lt;A id="key-val" class="issue-link" href="https://jira-prd.checkpoint.com/browse/PRJ-4956" rel="441455" data-issue-key="PRJ-4956" target="_blank"&gt;PRJ-4956&lt;/A&gt;&lt;BR /&gt;CLONE - R80.30 jumbo hf | gogo_heat_188_main T296 | VS-VSW-VS | TP + SXL | HTTP packets are not passing&lt;BR /&gt;&lt;BR /&gt;This issue solves particular case only when all of the following conditions are met&amp;nbsp;&lt;BR /&gt;a. VSX setup&amp;nbsp;&lt;BR /&gt;b. VS-VSW-VS Or VS-VR-VS topology&amp;nbsp;&lt;BR /&gt;c. One of the threat-prevention blades are enable on VSs (e.g. ips, threat extraction, anti virus, anti bot...)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;This fix was integrated in R80.30 JHF take 51 (still not included in ongoing take)&lt;/P&gt;
&lt;P&gt;Following &lt;A href="http://taskmanager/TaskView.asp?TaskId=97283" target="_blank"&gt;Task 97283&lt;/A&gt;, There is a private fix on top of take 50&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New hotfix has been provided: &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;\\galaxy\ckp\pkg\fw1_wrapper\R80_30_jhf_t50_168_main\latest_linux50\release.dynamic.ping&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 10:52:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63344#M9692</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2019-09-22T10:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63345#M9693</link>
      <description>&lt;P&gt;&lt;A id="link_385761eb79462c" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384" target="_self"&gt;&lt;SPAN class=""&gt;Alex_Gilis&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regarding the strange issue which reproduced on R80.30 JHF take 19 and not R80.30 GA&lt;/P&gt;
&lt;P&gt;We had a bug in specific packet flow with VS-VSW-VS, probably in R80.30 The packet goes on different flow comparing R80.30 JHF 19.&lt;/P&gt;
&lt;P&gt;Anyway this issue shouldn't reproduce on take 50 + the private fix.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 10:56:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63345#M9693</guid>
      <dc:creator>matangi</dc:creator>
      <dc:date>2019-09-22T10:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with 12000, VSX, VSWITCH &amp; R80.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63361#M9694</link>
      <description>&lt;P&gt;Thank you for the explanation, I hope that the JHF isn't too far away as this is quite an issue.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2019 19:09:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-12000-VSX-VSWITCH-amp-R80-30/m-p/63361#M9694</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2019-09-22T19:09:50Z</dc:date>
    </item>
  </channel>
</rss>

