<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX cluster problem - are we alone? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18664#M9850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No we are at 64 bits&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jan 2019 14:43:15 GMT</pubDate>
    <dc:creator>Raphael_Cote</dc:creator>
    <dc:date>2019-01-03T14:43:15Z</dc:date>
    <item>
      <title>VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18647#M9833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hey Check Point community, I need to know if we are alone in the world having so much difficulty implementing Check Point in a VSX cluster mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's our setup, two 15 600 in a VSX load Sharing mode. 6 vs and about 5000 users. We are using the FW, Anti-Bot, Ant-Virus, URL Filtering, SSL Inspection, and VPN blade. Pretty simple.&amp;nbsp; Version 80.10 jhf 112.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first time, we did the installation by ourselves, but as we had many problems, Check Point sent here their professionnal service to do the installation beacause the thought we were the problem. A week after he left, the exact same problem came back. They sent a second PS for antoher week without any results. It's been 15 months since we start the installation of Check Point and in the&amp;nbsp;last 8 months I spoke almost daily with level 3 engineer to solve all the problem and after all this time, we still have many bugs. Here's a list :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- DNS problem (Firewall - Domain resolving error. Check DNS configuration on the gateway) - still in problem a year after opening a ticket&amp;nbsp;&lt;BR /&gt;- Management console problem, the logs were not displaying. Had to reinstall the management from scratch.&lt;BR /&gt;- Update problem, corrution in the registry&lt;BR /&gt;- We see the VSX internal IP on our network, which we are not supposed as in the documentation. Problem is still there and no one has been able to explain it to me yet.&lt;BR /&gt;- Identity collector stop collecting data from the DC for 5 minutes interrmittently. Never completely resolve, found a parameter to drop&amp;nbsp;the outage at 1 min instead of 5. As we have 3 collectors, it's okay for us not causing us incident, but...&lt;BR /&gt;- When we push our Internet security policy, we cause an outage to our TPV transaction. This was a crazy one. An allowed rule was actually dropping trafic but only when we push the policy. Had to add the block destination into the rule to solve the problem!&amp;nbsp;&lt;BR /&gt;- Identity awarness problem. This is by far our worst one. Random user lost their Internet access because of the Pepd process that was choking, so missing&amp;nbsp;important information about the user. It tooks 8 months and countless hours to find a solution, a hotfix. &lt;BR /&gt;- Unable to update the Ant-Bot, Anti-Virus or URL filtering. There was a problem with Epoch time&amp;nbsp;&lt;BR /&gt;- Many problem with process crash. We had core dump for the Fw_full, dnsd, pepd, fw_vsnumber. Some hotfixes created to solve the problem.&lt;BR /&gt;- MUH agent on our server was disconnecting. Had to change a key in the registy&lt;BR /&gt;- Had to change many parameter in the fwkern.conf because the gateway were choking. This is not a bug as is, but the problem is that it's not documented anywhere how to fine tune the box for 5000 users, even the PS didn't know that.&lt;BR /&gt;- Usercheck page problem, it wasn't displaying. It wasn't configured for 5000 users as well, to many request had to change parameter in the httpd.conf file.&lt;BR /&gt;- SNMP trap we reveive were incomplete. Had to wait for 4 months to have a fix.&amp;nbsp;&lt;BR /&gt;- RAD problem, the service stop respondig (URL Filtering - Rad Service not available). The problem is still there, Check Point is supposed to upgrade&amp;nbsp;their cloud during the Holidays break..&lt;BR /&gt;- In the main page of the management, we see a red X saying Identity Awarness serious error for no reason&lt;BR /&gt;- In the main page of the management, we see a red X saying Anti-Bot db update fail&lt;BR /&gt;- As of now, our SSL inspection is not working well (Internal system error in HTTPS Inspection (Couldn't start inspection)). Our Internet access is slow as ....&lt;BR /&gt;- As of now, the NTP synchronozation as stop working on our gateway. The configuration is there, but there just nothing happening. Was working before but stop all of a sudden&lt;BR /&gt;- As of now, if I do a cpinfo -y all on my gateway, I can't see all the hotfix that are installed on it.&amp;nbsp; Problem with the build.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to tell you that it's exaggerated, but in fact I probably forgot some bug that we had, this list is the strict minimum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there someone who has pretty much that setup and it's working well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18647#M9833</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2018-12-20T14:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18648#M9834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running a similar setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2x 15400 VSX VSLS, 80.10 JHF T154&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- DNS problem (Firewall - Domain resolving error. Check DNS configuration on the gateway) - still in problem a year after opening a ticket&amp;nbsp;&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Seeing this sometimes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Management console problem, the logs were not displaying. Had to reinstall the management from scratch.&lt;/SPAN&gt;&amp;nbsp;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;- Update problem, corrution in the registry&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Did not have&amp;nbsp;those&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- We see the VSX internal IP on our network, which we are not supposed as in the documentation. Problem is still there and no one has been able to explain it to me yet.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Same here. Annoying&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Identity collector stop collecting data from the DC for 5 minutes interrmittently. Never completely resolve, found a parameter to drop&amp;nbsp;the outage at 1 min instead of 5. As we have 3 collectors, it's okay for us not causing us incident, but...&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;No problems so far&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- When we push our Internet security policy, we cause an outage to our TPV transaction. This was a crazy one. An allowed rule was actually dropping trafic but only when we push the policy. Had to add the block destination into the rule to solve the problem!&amp;nbsp;&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Identity awarness problem. This is by far our worst one. Random user lost their Internet access because of the Pepd process that was choking, so missing&amp;nbsp;important information about the user. It tooks 8 months and countless hours to find a solution, a hotfix.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Unable to update the Ant-Bot, Anti-Virus or URL filtering. There was a problem with Epoch time&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Many problem with process crash. We had core dump for the Fw_full, dnsd, pepd, fw_vsnumber. Some hotfixes created to solve the problem.&lt;/P&gt;&lt;P&gt;- MUH agent on our server was disconnecting. Had to change a key in the registy&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Did not have&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;those, either&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Had to change many parameter in the fwkern.conf because the gateway were choking. This is not a bug as is, but the problem is that it's not documented anywhere how to fine tune the box for 5000 users, even the PS didn't know that.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;same here&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Usercheck page problem, it wasn't displaying. It wasn't configured for 5000 users as well, to many request had to change parameter in the httpd.conf file.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;what did you change? We see similar things (200 Users...)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- SNMP trap we reveive were incomplete. Had to wait for 4 months to have a fix.&amp;nbsp;&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- RAD problem, the service stop respondig (URL Filtering - Rad Service not available). The problem is still there, Check Point is supposed to upgrade&amp;nbsp;their cloud during the Holidays break..&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- In the main page of the management, we see a red X saying Identity Awarness serious error for no reason&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- In the main page of the management, we see a red X saying Anti-Bot db update fail&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- As of now, our SSL inspection is not working well (Internal system error in HTTPS Inspection (Couldn't start inspection)). Our Internet access is slow as ....&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- As of now, the NTP synchronozation as stop working on our gateway. The configuration is there, but there just nothing happening. Was working before but stop all of a sudden&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #ffffff;" /&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- As of now, if I do a cpinfo -y all on my gateway, I can't see all the hotfix that are installed on it.&amp;nbsp; Problem with the build.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yeah, some of this sounds familiar...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 15:51:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18648#M9834</guid>
      <dc:creator>cstueckrath</dc:creator>
      <dc:date>2018-12-20T15:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18649#M9835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any TAC case(s) on the above issues?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 02:21:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18649#M9835</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-21T02:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18650#M9836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Christian.&amp;nbsp; Check&amp;nbsp;&lt;SPAN style="font-size: 11.0pt;"&gt;sk85040 for your usercheck page problem&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 12:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18650#M9836</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2018-12-21T12:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18651#M9837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes most of them have a TAC case, you want more detail?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 12:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18651#M9837</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2018-12-21T12:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18652#M9838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please send the TAC cases in PM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 14:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18652#M9838</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-21T14:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18653#M9839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help Dameon!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And it'd still be interesting to know if you are aware of other deployment of this kind in the world. Like Raphael said, we are under the impression that we are pretty much alone… and most of the errors encountered seems to require new hotfix to be resolved. So it's easy to feel like lonely guinea pigs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 16:47:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18653#M9839</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2018-12-21T16:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18654#M9840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Every setup is a little different and thus the issues may either be non-existent or different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue with VSX "funny IPs" has come up a couple times on CheckMates threads, the other ones I'm personally less familiar with.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 17:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18654#M9840</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-21T17:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18655#M9841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I totally understand that every setup is a little different and I agree.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I can ask my question in a different way. In organizations having more than 5000 users browsing the web, do you have an idea of how common is a VSX Cluster running R80.10 with all the aformentioned blades active?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are organizations still on R77.30? Or are they not using VSX? What is the most common setup these days?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 17:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18655#M9841</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2018-12-21T17:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18656#M9842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All of mentioned issues started after upgrading to R80.10, or were present also on R77.30 ?&lt;/P&gt;&lt;P&gt;What about R80.20 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Dec 2018 21:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18656#M9842</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-12-22T21:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18657#M9843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;which fwkern.conf parameters were suggested to be modified and why?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2018 08:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18657#M9843</guid>
      <dc:creator>Martin_Valenta</dc:creator>
      <dc:date>2018-12-27T08:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18658#M9844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for posting this. I have had similar issues with a 2 * 23500 VSX cluster with 11 * VS and 5000 users. We are also using all the blades you mention plus Application Control.&amp;nbsp; We have had many of the issues that you mention. Many of the VS'es are small but we have 1 VS that is our Internet gateway and there are definite performance issues with it when there is an increase in the number of users. Case in point is the past week. During the holidays, we have less than half our users in offices and there have been no issues accessing Internet sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was installed originally by a CP partner, who I do have complete faith in. However, even they were unaware of some fundamental "gotchas". For example, it took several weeks to discover that the VS were all in 32 bit mode by default (Why???) but this is not documented very well. Switching to 64-bit, obviously improved things considerably but we still have various issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have had various TAC calls open and almost always get pointed to an SK article to make a CLI tweak, in particular fwkern.conf. I have also installed a newer JHF 3 times in the past 6 months at there recommendation. There seems to have been improvements but next week will be the real test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is nice to know that I'm not alone with this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Roy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2018 12:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18658#M9844</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2018-12-31T12:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18659#M9845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to be clear, not ALL of these issues are necessarily related to VSX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 32-bit VS issue is definitely VSX-specific and goes away in R80.20 since it is no longer possible to run VSes in 32-bit mode &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2018 19:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18659#M9845</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-31T19:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18660#M9846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As it's a new deployment, we started at version 80.10&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 12:53:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18660#M9846</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2019-01-03T12:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18661#M9847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those parameter were change because of general performance problem, I can't be more specific I did it with the TAC and I don't have much more detail :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwha_enable_state_machine_by_vs=1&lt;/P&gt;&lt;P&gt;fwha_freeze_state_machine_timeout=200&lt;/P&gt;&lt;P&gt;fwha_add_vsid_to_ccp_mac=1&lt;/P&gt;&lt;P&gt;fwha_forw_packet_to_not_active=1&lt;/P&gt;&lt;P&gt;fwmultik_input_queue_len=4096&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 12:59:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18661#M9847</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2019-01-03T12:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18662#M9848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let's keep in touch Roy in the next week to see how it goes.&amp;nbsp; All I can say is that even with a bigger model of appliance than ours you have the same problem, so the problem is most likely due to software problem than a physical one..&amp;nbsp; BTW we are pretty much like you, one big Internet VS with all the problem and all the other small one doesn't have them.&amp;nbsp; During the holidays everything is fine and when the load will be bigger next week the problem should reappear.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 13:14:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18662#M9848</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2019-01-03T13:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18663#M9849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your vs bits also set to 32?&lt;/P&gt;&lt;P&gt;64 bit VS is definitely needed if you have a large VS (As is support for more than 10 cores in a VS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 14:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18663#M9849</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-03T14:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18664#M9850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No we are at 64 bits&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2019 14:43:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18664#M9850</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2019-01-03T14:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18665#M9851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Raphael&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far this week, everything is actually running great. I am now seeing the level of users, connections and traffic that I would expect with everyone back to work. Performance of the VS is fine and accessing internet sites is as snappy as I would expect.&amp;nbsp;I'm hesitant to say the issues are resolved so will&amp;nbsp;continue monitoring the situation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing I did do, the week before the holidays, was to install JHF Take 154. It may be that there are some performance enhancements in the hotfix, which have helped things. I guess it's just a waiting game for the rest of the week&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 17:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18665#M9851</guid>
      <dc:creator>Roy_Smith</dc:creator>
      <dc:date>2019-01-08T17:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: VSX cluster problem - are we alone?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18666#M9852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the follow up Roy!&amp;nbsp; Unfortunately, on my side there is no improvement for my SSL problem, more than 100K errors today.&amp;nbsp; I'll try to install a fix this evening, hopefully it will help.&amp;nbsp; I can't install the latest JHF either as we have 5-6 personalized hotfix to solve other problem that we had, so we are stuck.&amp;nbsp; I'd also like to migrate to 80.20, but everybody are scared of it, even the TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 18:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-cluster-problem-are-we-alone/m-p/18666#M9852</guid>
      <dc:creator>Raphael_Cote</dc:creator>
      <dc:date>2019-01-08T18:49:08Z</dc:date>
    </item>
  </channel>
</rss>

