- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Dear Check Mates,
Recently we started with the provisioning of virtual systems using the provisioning tool, because the Check Point API (version 1.3) does not support VSX/VSLS (yet). We have to provision 50+ virtual systems.
One of the features in R80.20 is Network defined by routes: it really works well (compared with the specific option). See screenshot.

Unfortunately, the Network defined by routes can't be configured using the vsx_provision_tool:
add interface vd <vd name>[name <physical or VLAN interface name>] [leads_to <Virtual Router|Virtual Switch>] [ip <ipv4 address>[/<ipv4 prefix>]] [netmask <IPv4 netmask>] [prefix <IPv4 prefix>]] [propagate <true|false>] [ip6 <ipv6 address>[/<ipv6 prefix>]] [netmask6 <IPv6 netmask>] [prefix6 <IPv6 prefix>]] [propagate6 <true|false>] [topology <external|internal_undefined|internal_this_network|internal_specific>] specific_group <group name>]] [mtu MTU]
We have to update the topology settings for 50+ virtual systems. A cumbersome task that can easily take two hours, which only is rewarding when you are paid per hour!
Hence: automation/orchestration becomes a manual tasks.
We would appreciate if Check Point can add the following features to its next release of R80:
Many thanks.
Kind regards,
Kris
Does it not work for you or is it simply missing from the documentation, what do you see in the output of the following?
[Expert@hostname:0]# vsx_provisioning_tool -h | grep defined_by_routes
Gateway objects in general (including VSX) need better API support and I know it’s planned.
Updating vsx_provisioning_tool in the meantime seems reasonable but not sure if/when that’s planned.
But just to mention:
VSX is using routing information for anti-spoofing anyway!
That's nothing new and available for a long time as routing is configured through management.
Just make sure the checkbox is active on the virtual system.
(On by default, but can be changed with parameter calc_topo_auto in provisioning tool)
Jumping on to this thread.
How can I create an interface but ensure the anti-spoofing is set to detect and not prevent via the provisioning tool?
R80.20 JHF T208
PRJ-32530, PMTR-74770
VSX: UPDATE: It is now possible to define interface topology as "defined by routes" using the VSX provisioning tool.
R80.20 JHF T202
PRJ-21258, VSX-2520
VSX: Allow the addition of routes with specific group of type "Group with Exclusion" when using VSX Provisioning tool.
I remember that! I was the one that raised it with TAC.
That said - my question related to just adding an interface and ensuring Anti-spoofing did not default to 'prevent'. Is there a parameter for Anti-Spoofing that can set the mode to detect, rather then prevent?
Hi @Chris_Atkinson ,
in the VSX r81.10 admin guide there is no option to configure an interface with topology "defined by routes" with vsx provisonning tool. This is strange because it's written that is now available since r81.10 take 38
PRJ-32534,
PMTR-74770
https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/Take_38.htm
thank you in advance for your lights
Does it not work for you or is it simply missing from the documentation, what do you see in the output of the following?
[Expert@hostname:0]# vsx_provisioning_tool -h | grep defined_by_routes
I find it with "vsx_provisioning_tool -h".
So it's only missed in the documentation.
THX !
topology defined_by_routes did the job !
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 10 | |
| 10 | |
| 10 | |
| 10 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 6 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY