- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi,
i'm trying to export "show configuration" from one of my Virtual System to a third party device for auditing purposes and i noticed that it shows the funny IP as show below:
set interface bond1.100 state on
set interface bond1.100 mtu 1500
set interface bond1.100 ipv4-address 192.168.196.49 mask-length 28
set interface bond1.101 state on
set interface bond1.101 mtu 1500
set interface bond1.101 ipv4-address 192.168.196.65 mask-length 28
Is this how it should be or i'm i missing something. Ironically, doing ifconfig shows the actual IP associated with each bond as well as on the Management Station.
Thank You
R80.30 and R80.10
@Enyi_Ajoku you wrote "my Virtual System".
As @Maarten_Sjouw indicates, looks like a VSX system.
192.168.196.0/255.255.252.0 is the default subnet for VSX internal network. Every virtual system has an IP in this subnet.
You can see this on the VSX object.
Wolfgang
I am aware of the internal IP address on VSX system but what i am referring to is an ip associated with a bond that is configured on Management Station on VSX.
ifconfig shows actual ip associated with bond, same as on the management station but when i do show configuration on for example vs1 is shows funny ip as i have stated in the configuration snippet above
In my R80.40 VSX setup I see the external IPs not the internal (funny) ones. I've not see this since pre-R77 VSX, and even then you could toggle this display to external IPs.
It makes allot of sense to display the external IPs i.e. IPs defined in the topology in Smartconsole purely from a track and troubleshooting prospective.
I've got a VSX R81 setup which has this problem and just logged a TAC case, which is purely a cosmetic issue, rather then functional.
Technically, it's the other way around. The 192.168.196.0/22 block is the real addresses the interfaces actually have. 'ifconfig' by itself is an alias to /bin/cp-ifconfig.sh, which lies to you and shows the cluster VIPs instead of the real IP on the interfaces. You can see this by running the real ifconfig binary located at /usr/sbin/ifconfig.
This can be important to know, since the IPs you assign to virtual systems have all the same limitations and concerns as VIPs on a non-VSX cluster. They're claimed via the same mechanism, and you can use off-net VIPs with normal clusters, too.
VSNext in R82 changes this. On an ElasticXL cluster (and VSNext requires ElasticXL), all the members actually have the addresses on their interfaces, and they use virtual MACs to control which member gets traffic.
Yes it is
Hello @Enyi_Ajoku , No it should not be like this.
I had this issue too and this resolved the issue for me.
1. Set vsx on
2. Save config
3. Reboot cluster Member.
You should be mindful to do this during a maintenance window lol but if you do not mind rebooting that cluster member then you should be fine.
Check Point R&D is still looking into the issue as to why the member has to be rebooted before it takes effect.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 63 | |
| 19 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY