- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am trying to advertise a non-connected network on the checkpoint virtual system in OSPF. Usually we would just add a blackhole/null0 static route and redistribure that in OSPF but I cannot find a way to add this type of static route in VSX
Can you point me in the right direction please or if there is a better way to advertise this in OSPF
Also how do I go about configuring a loopback interface in VSX ?
Many thanks
From clish, you should be able to add a loopback interface: add interface lo loopback <IP Address>/<Mask>
Many Thanks Dameon; however the command is not available in clish (note this is VSX gateway)
fw1> add interface lo loopback 10.1.1.1 255.255.255.255
CLINFR0329 Invalid command:'add interface lo loopback 10.1.1.1 255.255.255.255'
fw1> add
aaa - Authentication authorization and accounting
allowed-client - Add allowed client
arp - Add ARP entries
backup - Start a backup of the system
backup-scheduled - Determine the type of scheduled-backup of the system
bonding - Configure bonding interfaces
cloning-group - Configure Gaia Cloning Group
command - Add extended command.
cron - Add new scheduling for a command
dhcp - Configure or view DHCP settings.
group - Specify group name
host - Static host configuration
netflow - NetFlow export of traffic information
rba - Role-based administration configuration
snapshot - Take snapshot
snmp - Simple Network Management Protocol Information
syslog - System log configuration
upgrade - Upgrade of Check Point OS and Products
user - A user name
vpn - vpn configuration
Any ideas for VSX ?
Also what about the blackhole route piece ?
Have you tried adding the loopback to the VSX itself and then choosing it from the VS context?
Sorry for the late response.. but i have tried to add it via VS0 but unable to do so..
vsxgw1:TACP-15:0> add interface lo loopback 10.1.1.1/32
CLINFR0699 Invalid command.
Any more ideas ?
I believe that you supposed to perform "set vsx off" before adding new interface and "set vsx on" once it is done.
Hello Usman,
Did you ever get this to work? I am trying the same thing but in a cluster. With set vsx off I can actually create the interface, but I have to set and IP and it shows up in all the VSs (not in SmartConsole thought). Thanks, RK
I need this too... in VSX mode, is there any updates?
Using a loopback interface with Dynamic Routing in ClusterXL environments (including VSX) is supported starting with Check Point R81.10.
Check Point R81.10 was released (July 6, 2021). For more information, see sk170416.
sk117794 has been updated accordingly.
Simon
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY