<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What &amp;quot;set vsx on/off&amp;quot; actually does under hood? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66725#M9714</link>
    <description>Which GW version are you utilising?&lt;BR /&gt;Dynamic dispatcher is available only from R80.20 and above for VSX mode.</description>
    <pubDate>Wed, 06 Nov 2019 23:06:28 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2019-11-06T23:06:28Z</dc:date>
    <item>
      <title>What "set vsx on/off" actually does under hood?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/64611#M9711</link>
      <description>&lt;P&gt;Hello Guys&lt;/P&gt;&lt;P&gt;I am having trouble finding what does turning on/off vsx mode does to firewall cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 members fully configured in cluster VSLS mode, running coreXL, few virtual-systems on it and soon in production. In many guides theres suggestion to turn off vsx mode before applying some commands which otherwise cannot be accepted. I only understand that vsx mode is "interface and routes configuration protection". But is there anything beyond human factor protection in CLI?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subsequently, I have this problem:&lt;/P&gt;&lt;P&gt;automatic affinity on one cluster member is working fine, and it doesn't on another:&lt;/P&gt;&lt;P&gt;A:&lt;/P&gt;&lt;P&gt;eth1-01 : 8&lt;BR /&gt;eth1-02 : 8&lt;BR /&gt;eth1-03 : 0&lt;BR /&gt;eth1-04 : 8&lt;BR /&gt;eth2-01 : 0&lt;BR /&gt;eth2-04 : 8&lt;BR /&gt;eth2-05 : 0&lt;BR /&gt;eth2-08 : 8&lt;BR /&gt;eth3-01 : 0&lt;BR /&gt;eth3-02 : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B:&lt;/P&gt;&lt;P&gt;eth1-01 : 0&lt;BR /&gt;eth1-02 : 0&lt;BR /&gt;eth1-03 : 0&lt;BR /&gt;eth1-04 : 0&lt;BR /&gt;eth2-01 : 0&lt;BR /&gt;eth2-04 : 0&lt;BR /&gt;eth2-05 : 0&lt;BR /&gt;eth2-08 : 0&lt;BR /&gt;eth3-01 : 0&lt;BR /&gt;eth3-02 : 0&lt;/P&gt;&lt;P&gt;some CP article suggests checking "fw ctl multik get_mode" to see if dynamic dispatcher is on, but this command cannot be run in vsx mode:&lt;/P&gt;&lt;P&gt;Option not supported in VSX mode.&lt;/P&gt;&lt;P&gt;Edit: (there are 2 cores for vs:0 in my setup) after restarting and re-entering default affinity mode (automatic) all interfaces are assigned core 0 (I expected even distribution between cores 0, 8). There is no traffic passing interfaces yet.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Tomas&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 13:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/64611#M9711</guid>
      <dc:creator>Firewallteam_DE</dc:creator>
      <dc:date>2019-10-14T13:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: What "set vsx on/off" actually does under hood?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/64643#M9712</link>
      <description>&lt;P&gt;Before risking my VSX VSLS configuration i would rather involve TAC !&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:07:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/64643#M9712</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-09T14:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: What "set vsx on/off" actually does under hood?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66721#M9713</link>
      <description>&lt;P&gt;Here's link to my cpx presentation on the subject of VSX optimisation&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Member-Exclusive-Content/VSX-performance-optimisation-pdf/m-p/41513" target="_blank"&gt;https://community.checkpoint.com/t5/Member-Exclusive-Content/VSX-performance-optimisation-pdf/m-p/41513&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hard to answer without having full details of the system.&lt;/P&gt;
&lt;P&gt;As for vsx off - yes it's mainly to protect system from making silly mistakes in areas that are owned my management i.e routing and interfaces. You will learn to survive without it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; can't remember last time I turned vsx off&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 22:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66721#M9713</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-11-06T22:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: What "set vsx on/off" actually does under hood?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66725#M9714</link>
      <description>Which GW version are you utilising?&lt;BR /&gt;Dynamic dispatcher is available only from R80.20 and above for VSX mode.</description>
      <pubDate>Wed, 06 Nov 2019 23:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66725#M9714</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-11-06T23:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: What "set vsx on/off" actually does under hood?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66738#M9715</link>
      <description>And be careful not to mix up two things - affinity for SXL or interfaces and affinity for for fw workers. Your original post mixed two together. Try printing both types with fw ctl affinity -l and we can take it from there</description>
      <pubDate>Thu, 07 Nov 2019 05:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-quot-set-vsx-on-off-quot-actually-does-under-hood/m-p/66738#M9715</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-11-07T05:20:15Z</dc:date>
    </item>
  </channel>
</rss>

