- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
Until now all my questions have been answered by the various Checkmate Posts.
This week I will be migrating a VSX R80.20 system from dedicated physical interfaces, as internal and external to a combined internal bond, and a combined external bond interface for all the virtual systems to share. In order to do this, I have to delete the VLAN interfaces from the current physical interfaces. I have created a little script to do this. No problems there, but I also have to delete the static routes before I can delete the VLAN from the interface.
The routes are visible in the routedx.conf files at OS level. But this file is created by a Checkpoint process that probably will overwrite the file when I change it. SO - NO GO. The clish config also displays the routes.
Adding a route here displays an error telling me that routes need to be added in the GUI.
During the migration I have to delete and add about 50 routes since the interfaces will change.
Is there a way to prepare this so I can do this using the CLI?
I have read about the "run-script" option but that only looks useful to show information from the system.
I don't want to use the GUI for this task because it takes a lot of time and a lot of mouse clicks.
Currently, I can't add images because its a sunday and somebody killed my management VM.
Hope you can help me on this one.
Hi,
Have a look at the VSX provisioning tool - sk100645
"The VSX Provisioning Tool allows the VSX administrator to add and remove Virtual Devices (VS, VR, VSW), interfaces and routes from the command line of a Security Management Server / Multi-Domain Security Management Server. This allows the automation of the required VSX Provisioning operations in the environment."
Regards,
Chris
Hi,
Have a look at the VSX provisioning tool - sk100645
"The VSX Provisioning Tool allows the VSX administrator to add and remove Virtual Devices (VS, VR, VSW), interfaces and routes from the command line of a Security Management Server / Multi-Domain Security Management Server. This allows the automation of the required VSX Provisioning operations in the environment."
Regards,
Chris
Hi Chris,
Thank you very much for the reply.
This will make my day tomorrow.
I prepared the entire change using as much of the provisioning tool as I can.
Best regards,
Bram
Are there any plans to migrate this to the official API?
I'm getting questions from customers with VERY large environments, and who are investing in automation + orchestration, and it seems that currently the only way to do operations like this are to use the API run-script command. In my eyes, VSX and MDM seem to be ideal candidates for being fully managed via API.
Not part of R81.20 but it was hinted at during CPX as a future project for the reasons stated.
Another Vote to make this happen sooner rather than later.... Adding/Removing routes from VSX instances in the only thing we haven't been able to automate via the API for more than 2 years now.
Since all VSX configuration must be done via the Management server I just don't understand why this wasn't in the first wave of APIs available.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY