- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello Fine Community!
Quick question regarding VSX provisioning tool. I've used this tool over the years to build/manage interfaces on Virtual Systems - but more recently have been utilizing Security Zones on interfaces. Is anyone aware of support for tagging an interface with a Security Zone via VSX provisioning tool? I've searched some documentation, but haven't found much (perhaps I'm just missing it, or perhaps this is not available [yet?]). Any insights appreciated. Below is a basic example of a command I use; but ideally could also tag the eth0.123 interface with "InternalZone" on the same line. Apologies if I've missed a similar post on this topic!
add interface name eth0.123 ip x.x.x.x/24 topology internal_this_network
In future versions there will be a shift towards APIs for VSX.
With that said the last I saw regarding the VSX provisioning tool pertained to "defined by routed" behavior... i.e.
|
PRJ-32534, |
VSX |
UPDATE: It is now possible to define interface topology as "defined by routes" using the VSX provisioning tool. |
Will check the status regarding Zones and revert.
Just to make sure, we are now working on VSX Pro - a completely new architecture for virtualized security, and it will have native APIs for management. You will not need the provisioning tool with it anymore, AFAIK.
That said, it will not be available before some time the next year.
Not see anything myself, I would also like to know if there is a way to enable anti-spoofing in detect and log mode per interface.
In future versions there will be a shift towards APIs for VSX.
With that said the last I saw regarding the VSX provisioning tool pertained to "defined by routed" behavior... i.e.
|
PRJ-32534, |
VSX |
UPDATE: It is now possible to define interface topology as "defined by routes" using the VSX provisioning tool. |
Will check the status regarding Zones and revert.
Got it, yea a shift towards APIs makes sense and I was kind of wondering how much more new functionality will be added to the VSX provisioning tool if that was the case. But didn't know if APIs would leverage the provisioning tool on the backend or be independent. I have more questions than answers 🙂 Thanks for your input.
Just to make sure, we are now working on VSX Pro - a completely new architecture for virtualized security, and it will have native APIs for management. You will not need the provisioning tool with it anymore, AFAIK.
That said, it will not be available before some time the next year.
Would be really good to get more info on VSX Pro!
I promise we will talk about that as soon as we can 🙂 But before, please let R&D do their magic.
Just wanted to say thanks to @_Val_ and @Chris_Atkinson for the comments! Will certainly look forward to hearing more about VSX Pro and native Mgmt APIs.
Hello,
Any news regarding this feature/project? is there any other way to configure security zone/anti-spoofing for VSX virtual system interfaces?
Further changes are expected with the release of R82.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 19 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY