<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX High Availability + OSPF in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18788#M3375</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you first converted this cluster to VSX, you were presented with the security policy for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, for VS0, these rules are present:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H4 class="" style="color: #333333; background-color: inherit; font-weight: 200; text-decoration: none; font-size: 20px; margin: 0.5cm 0px 0em; padding: 15px 0pt 1px;"&gt;VSX Gateway Management&lt;/H4&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;VSX Gateway Management&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window, define security policy rules that protect the VSX Gateway. This policy is installed automatically on the new VSX Gateway.&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Note&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This policy applies&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;only&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to traffic destined for the VSX Gateway. Traffic destined for Virtual Systems, other virtual devices, external networks, and internal networks is not affected by this policy.&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;The security policy consists of predefined rules for these services:&lt;/P&gt;&lt;UL class="" style="color: #333333; margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;UDP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SNMP requests&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;TCP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SSH traffic&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;ICMP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Echo-request (ping)&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;TCP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;HTTPS traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless you've added OSPF to this policy at the time of creation, it may not be permitted from VS0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have not yet created other VS' and installed policies on those, try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;[Expert@HostName:&lt;EM&gt;VSID&lt;/EM&gt;]# vsenv 0&lt;/CODE&gt;&lt;/STRONG&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 14px;" /&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;[Expert@HostName:0]# fw unloadlocal&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To see if it'll change the behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Otherwise, try unloading policies from other VS' first, and then from VS0 and repeat your experiment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For the life of me, I cannot recall how, or even if, it is possible to adjust VS0 (VSX) policy after conversion is completed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Good luck,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vladimir&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 28 Apr 2018 01:51:40 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-04-28T01:51:40Z</dc:date>
    <item>
      <title>VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18783#M3370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to configure ospf on VSX Cluster in HA mode.&lt;/P&gt;&lt;P&gt;I need to make OSPF adjacency with external system over Wrap link and checkpoint virtual switch.&lt;/P&gt;&lt;P&gt;GAIA version is r77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that it seems, that OSPF process does not go up on wrp interface.&lt;/P&gt;&lt;P&gt;My configuration:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;GW01:0&amp;gt; show configuration ospf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;show instance 0 configuration ospf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;set ospf area backbone on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;set ospf interface wrp2 area backbone on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;set ospf interface wrp2 priority 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;set ospf area backbone range 10.4.126.0/29 on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;--------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;GW01:0&amp;gt; show ospf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;show instance 0 ospf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;OSPF Router with ID 10.10.10.1 Instance default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;SPF schedule delay: 2 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Hold time between two SPFs: 5 secs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Number of Areas in this router: 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; Normal: 1 Stub: 0 NSSA: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;RFC1583 compability mode is on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Number of Virtual Links in this router: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Number of UpEvents: 0 Number of DownEvents: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Default ASE Cost: 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Default ASE Type: 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Area: 0.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;Number of Interfaces in this area: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; Number of ABRs: 0 Number of ASBRs: 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; Number of times SPF Algorithm executed: 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; Area ranges are:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; 10.4.126.0/29 Advertise,Passive&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt; No Area Stubnets Configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN&gt;--------------------------------&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;GW01:0&amp;gt; show ospf interfaces&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;show instance 0 ospf interfaces&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;GW01:0&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am missing?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 14:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18783#M3370</guid>
      <dc:creator>Boris_Uskov</dc:creator>
      <dc:date>2018-04-26T14:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18784#M3371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Aren't you supposed to configure OSPF from the context of VS/VR instead of the VS0?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 14:33:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18784#M3371</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-26T14:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18785#M3372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Vladimir. I'm not going to use Virtual Systems or Virtual Routers at this point of time.&lt;/P&gt;&lt;P&gt;I need only VS0 and Virtual Switch currently.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 14:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18785#M3372</guid>
      <dc:creator>Boris_Uskov</dc:creator>
      <dc:date>2018-04-26T14:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18786#M3373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Virtual switch is the Layer 2 device, so there will be no OSPF options.&lt;/P&gt;&lt;P&gt;Also, the warp interfaces attached to the virtual switch should have "wrpj" preffix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"A Warp Link is a virtual point-to-point connection between a Virtual System and a Virtual Router or Virtual Switch. Each side of a Warp Link represents a virtual interface with the appropriate virtual device."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So warp link is not exposed to the outside connectivity.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 17:29:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18786#M3373</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-26T17:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18787#M3374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Vladimir.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for support.&lt;/P&gt;&lt;P&gt;Actually, I'm trying to configure OSPF between VS0 and outside router through the Virtual Switch. I'm trying to use VS0 wrp2 interface, which points to Virtual Switch. IP connectivity between wrp2 and outside router exists: I can ping outside router from wrp2 interface.&lt;/P&gt;&lt;P&gt;I attached the schema to the question for best understanding, please, take a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/64869_OSFP adj.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2018 06:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18787#M3374</guid>
      <dc:creator>Boris_Uskov</dc:creator>
      <dc:date>2018-04-27T06:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18788#M3375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you first converted this cluster to VSX, you were presented with the security policy for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, for VS0, these rules are present:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H4 class="" style="color: #333333; background-color: inherit; font-weight: 200; text-decoration: none; font-size: 20px; margin: 0.5cm 0px 0em; padding: 15px 0pt 1px;"&gt;VSX Gateway Management&lt;/H4&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;In the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;VSX Gateway Management&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window, define security policy rules that protect the VSX Gateway. This policy is installed automatically on the new VSX Gateway.&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Note&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This policy applies&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;only&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to traffic destined for the VSX Gateway. Traffic destined for Virtual Systems, other virtual devices, external networks, and internal networks is not affected by this policy.&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;The security policy consists of predefined rules for these services:&lt;/P&gt;&lt;UL class="" style="color: #333333; margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;UDP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SNMP requests&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;TCP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;SSH traffic&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;ICMP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Echo-request (ping)&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;TCP -&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;HTTPS traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless you've added OSPF to this policy at the time of creation, it may not be permitted from VS0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have not yet created other VS' and installed policies on those, try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;[Expert@HostName:&lt;EM&gt;VSID&lt;/EM&gt;]# vsenv 0&lt;/CODE&gt;&lt;/STRONG&gt;&lt;BR style="color: #000000; background-color: #ffffff; font-size: 14px;" /&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;[Expert@HostName:0]# fw unloadlocal&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To see if it'll change the behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Otherwise, try unloading policies from other VS' first, and then from VS0 and repeat your experiment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For the life of me, I cannot recall how, or even if, it is possible to adjust VS0 (VSX) policy after conversion is completed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Good luck,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Vladimir&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Apr 2018 01:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18788#M3375</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-04-28T01:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: VSX High Availability + OSPF</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18789#M3376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;great idea, thank you!&lt;/P&gt;&lt;P&gt;I'll check default security policy. But I'll be able to do it a little bit later.&lt;/P&gt;&lt;P&gt;Thanks for support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Apr 2018 09:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-High-Availability-OSPF/m-p/18789#M3376</guid>
      <dc:creator>Boris_Uskov</dc:creator>
      <dc:date>2018-04-28T09:42:12Z</dc:date>
    </item>
  </channel>
</rss>

