- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Never done it that way but I assume so - it's just a regular firewall in that sense. (traffic/interfaces)
We always had another VS in front of VS0 for traffic coming from internet. I guess you are worried if VSX goes down then you won't be able to reach VS0? Out of band option?
exactly.
Kaspars Zibarts wrote:
I guess you are worried if VSX goes down then you won't be able to reach VS0? Out of band option?
i don't have spare interfaces on the VSX , currently bond1 is my dedicated management interface.
what should be the proccess of moving the ip from bond1 to bond1.10 and adding another interface to vs0 bond1.20 ?
thanks
In all honesty I don't see it as a big problem having VS0 exposed to internet directly - as long as you have good rulebase and password policy in place ![]()
It will be as good as having another firewall in front of it. Minus DDOS - you would be exposed unless you have some external device to protect you from floods.
Kaspars,
How do you access a VS0 policy post-installation?
I recall being presented with default VSX policy configuration options when converting gateways or clusters to VSX, but cannot figure out where it is hiding once you are operating the unit or cluster.
Hi Vlad! I'm not entirely sure if I understand your question. VS0 (VSX cluster object) policy is accessible just like any other, from appropriate CMA (in case you use MDM).
I might have misunderstood you ![]()
We may be speaking of different things, but just in case we are not, please verify this:
During initial VSX configuration you have an opportunity to define this policy:

Looking under the VSX Cluster object, you do not see the VS0 (at least I do not see it in the R77.30 demo mode and VSX is not available as an object in R80.10 demo):

So I m not sure how you could specify it as an installation target for the dedicated policy or rules in the common one.
VSX cluster object is your VS0 ![]()

Here's view from command line

and install targets

That's what I thought, but the initial policy created during installation/conversion is not visible as a stand-alone name policy package.
So you are able to create an additional policy and use cluster object as a target, but where is the policy that was originally created?
If you are to create a new VSX object and look at it via CLI in the context of VS0, what policy will be shown?
Could it be opened and edited?
If you refer to this one (had to create a test VM just for you
as our VSXes were created million years ago..)


and here's the policy it created "testvsx_VSX"


Thanks! Exactly what i was looking for.
It's just happen to be missing from the Demo Mode in R77.30 and there are no VSX objects in R80.10 Demo, hence the confusion.
Appreciate you going an extra mile to clear the fog ![]()
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 41 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY