- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi All,
We're aware on how to remove an interface on a VS by using the vsx_provisioning_tool; but what would be the best way to just disable a bond "sub-interface" on a VS -in a VSX cluster.
Is it by using the below commands:
On VSX member 1 (where our VS is active)
set vsx off
set interface bond2.15 state off
set vsx on
And repeat the above on VSX member 2 (where our VS is standby)
That sounds logical, based on below as well
Best,
Andy
https://community.checkpoint.com/t5/Security-Gateways/Remove-interface-from-VSX-systems/td-p/65004
You want to delete only VLAN 15 configured on bond2, or delete complete bond2 logical interface ?
Hi Jozko,
Not delete, rather disable vlan15 on bond2, i.e. bond2.15 -we need to re-enable back in some time.
The correct way is to delete VLAN from Topology tab within affected VS in SmartConsole. Do not forget to install policy afterwards.
Once the VLAN is needed again, just add it back.
To get you right:
1- disable the interface from clish
2- delete it from the Topology tab for the affected VS in SmartConsole
3- push the policy
To reactivate it, just reverse the above steps
Disable interface from CLI within VS is not needed. SmartConsole will remove it during provisioning proccess (once you click OK with deleted VLAN on VS object).
Hello
Is it possible to disable an interface that is part of a VSX Cluster?
I have a lab environment, where the Eth2 interface is the SYNC interface between my VSX1 and VSX2 box
My Cluster does not “wake up”, and emphasizes that the problem is the Eth2 interface
I have done everything at VMWARE level but I still can't fix it
I want to logically shut down the Eth2 interface from each box
Is this possible?
Could you guide me with the steps to follow?
Thanks
I believe generic linux command would be if eth2 down
Andy
I have tested setting vsx wrp-interface down simply with ifconfig. It won't survive reboot though, but will work.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 22 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 |
Thu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASEThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY