<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX routes on vs R80.20 static routes in manager but not in the gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52815#M9766</link>
    <description>Do you have VLAN's on that 10Gb interface?&lt;BR /&gt;I'm not really talking about the physical interface, the logical interface is more important in this case, I'm sure you checked that the physical interfcae is up and running, how about the VLAN, is it allowed on the switches' trunk interfaces, is the VLAN created on the switch, is the VLAN available in any uplink etc etc.</description>
    <pubDate>Tue, 07 May 2019 21:08:21 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-05-07T21:08:21Z</dc:date>
    <item>
      <title>VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52611#M9761</link>
      <description>&lt;P&gt;Hi people.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 VS in a VSX CLuster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The firstone (VS) works ok, and when I run the #vsx_util view_vs_conf I can see the statics routes was i configured, on the report, and applied in the gateways, the report represent the status vith a "V" in every vsx gateway box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;+----------------------------------------------------------+-----+-------------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|Ipv4 Routes |Mgmt |VSX GW(s) |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|Destination / Mask Length |Gateway |Interface | |nvsxgw|nvsxgw|&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|10.0.110.0/29 | |eth3 | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|10.0.160.0/29 | |eth5 | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|192.168.2.0/26 | |wrp128 | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="arial black,avant garde"&gt;&lt;STRONG&gt;|&lt;FONT color="#339966"&gt;10.100.48.27/32 |10.0.110.1 | | V | V | V |&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;|0.0.0.0/0 |192.168.2.1 | | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BUt in the secondone, when I run the same report from the Manager, the boxes say me with a "-" the static routes are not present in the gateways.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Routing table:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;+----------------------------------------------------------+-----+-------------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|Ipv4 Routes |Mgmt |VSX GW(s) |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|Destination / Mask Length |Gateway |Interface | |nvsxgw|nvsxgw|&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|10.0.16.64/26 | |eth4 | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|192.168.2.0/26 | |wrp192 | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="arial black,avant garde" color="#FF0000"&gt;|10.100.48.27/32 |10.0.16.65 | | V | - | - |&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;|0.0.0.0/0 |192.168.2.1 | | V | V | V |&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;+--------------------------+--------------------+----------+-----+------+------+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Routing Table Legend:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;V - Route exists on the gateway and matches management information (if defined on the management).&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;- - Route does not exist on the gateway.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The bahavior is that i have comunication with the first VS, but not to the second, the lastone canot be release it have a configured route with the SmartConsole, on the topology pane. And canot deliver responses to the packets from the internal network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to TS, I was delete the VS, and create again, shutdown the gateways, delete and restore the static routes needed, without expected results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;someone have any idea what can i do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks a lot for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 May 2019 12:13:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52611#M9761</guid>
      <dc:creator>Antonio</dc:creator>
      <dc:date>2019-05-05T12:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52785#M9762</link>
      <description>Recommend opening a TAC case so we can investigate as it sounds like configuration is not being pushed properly.</description>
      <pubDate>Tue, 07 May 2019 14:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52785#M9762</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-07T14:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52802#M9763</link>
      <description>If that network is on a vlan, I would double check that the VLAN is really available on that second unit, it sounds like the network is not properly connected.</description>
      <pubDate>Tue, 07 May 2019 18:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52802#M9763</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-07T18:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52804#M9764</link>
      <description>&lt;P&gt;Static routes are present but not active until interface behind which the next hop is defined connected.&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 18:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52804#M9764</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-07T18:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52806#M9765</link>
      <description>&lt;P&gt;Hi, I have visibility on the switch where the IP appliance is connected, the 10G interface is up and running. Let me know if you refer to a status on the checkpoint appliance 5800, when I do the Show interfaces all, Ifconfig, or fw getifs, the interfaces looks up and running.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 18:49:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52806#M9765</guid>
      <dc:creator>Antonio</dc:creator>
      <dc:date>2019-05-07T18:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52815#M9766</link>
      <description>Do you have VLAN's on that 10Gb interface?&lt;BR /&gt;I'm not really talking about the physical interface, the logical interface is more important in this case, I'm sure you checked that the physical interfcae is up and running, how about the VLAN, is it allowed on the switches' trunk interfaces, is the VLAN created on the switch, is the VLAN available in any uplink etc etc.</description>
      <pubDate>Tue, 07 May 2019 21:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52815#M9766</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-07T21:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52819#M9767</link>
      <description>&lt;P&gt;HI all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On first time after your responses, I try updating the Manager to R80.20M2 but the behavior remains.&lt;/P&gt;&lt;P&gt;Viewing the configuration on GAIA, (firt seting vsx off to gain acces to the web access), I say two interfaces vlans, that I don't need on my architecture, and forget to delete in the past. When I delete de two vlans, the routes appears replicated on the gateways, seeing the report with the vsx_util, and finally we can reach the internal interface of the virtual system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to all for your suggestions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 21:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52819#M9767</guid>
      <dc:creator>Antonio</dc:creator>
      <dc:date>2019-05-07T21:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: VSX routes on vs R80.20 static routes in manager but not in the gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52820#M9768</link>
      <description>really, the 10GB interfaces are configured to physically dedicated attend the traffic, without vlan tag, the switchport is in access mode.</description>
      <pubDate>Tue, 07 May 2019 21:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-routes-on-vs-R80-20-static-routes-in-manager-but-not-in-the/m-p/52820#M9768</guid>
      <dc:creator>Antonio</dc:creator>
      <dc:date>2019-05-07T21:35:00Z</dc:date>
    </item>
  </channel>
</rss>

