- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Folks,
I have 2 Data Centers that are about to be built, consultant is recommending having 2 15400 in DC1 and another 2 in DC2. They intend to have VSX configured on both Data Centers, which we would be one cluster with four cluster members.
DC1 and DC2 are miles apart probably 50 miles apart.
My question is with regards to VSX and sync interface on the 15400.
Consultant intends to take fiber interfaces on the 15400 and use them as SYNC Interfaces/Network.
Can this be done?
Thank You
Some documents you might want to read regarding max. allowed latency (100ms) and packet loss rate (5%) on your sync network.
ClusterXL R80.10 (Part of Check Point Infinity) Administration Guide
The best would be to use fiber ports. Even better to create bond interface with 1G fibers.
As both nodes are 50 miles apart, switch-in-between needs to be used.
How do i configure bond for SYNC interface. I can't find this option in vsx_util?
By using clish commands as is described in Gaia Administration Guide - Chapter "Network Management" - Network Interfaces - Bond Interfaces (Link Aggregation).
How to view details about the bond interface
Some documents you might want to read regarding max. allowed latency (100ms) and packet loss rate (5%) on your sync network.
ClusterXL R80.10 (Part of Check Point Infinity) Administration Guide
While it is not impossible, I question the reason behind this design.
Consider: you will not only have to use Sync between sites, but shuttle internal and external traffic as well, if the cluster is failing over to another site.
So you'll saturate the link with normal site-2-site traffic, sync and everything that normally traversing local VS's.
Depending on link or interface buffer saturation, sync may get deprioritized.
Can someone tell me if I'm off in my assumptions?
Hi,
As long as you have reliable layer 2 connectivity between the sites meeting the ClusterXL requirements for timeouts, rtt, packet loss etc, you should be fine. I was running a cluster with one member in LA and the other in Dallas, which is about 2000km.
Yes i do, my layer 2 devices are fiber ports and the native sync port on the 15400 are Ethernet ports. Based on the test i've done and to my knowledge the only time this will works is in a fresh install. I tried to change or create a SYNC in my existing VSX infrastructure and that didnt work. But i could assign a different port when i tried it on my fresh out of the box 15400.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY