- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi ,
Trying to create a Bridge Mode VS in a VSX HA Cluster. This Cluster contains other Layer 3 VS's. I have read the User Manual and bit confused what options I need to choose . I assume following are correct.
VSX is running on R80.10 Take 203 Active/Standby
1. Go to each Cluster member, cpconfig and Enable ClusterXL for Bridge Active/Standby, Reboot.
2. Go to Smart Console, Cluster Object Properties, Other, VSX Bridge Configuration, Select "Check Point ClusterXL", install the VSX Policy
3. Create a VS with Bridge Mode selected and configure 2 interfaces.
Could you confirm above steps are correct ?
Also which file contains the VSX Cluster specific configuration ( I mean file name in the VSX Member) ?
Thanks for your help
Suggest also reviewing sk121451 and the fwkern.conf parameters.
Answering the last question in the post:
There are several special provisioning files on each of VSX cluster members, called local.vs, local.vsall, local.vskeep.
However, they are used and updated only in conjunction with management server operations. In a nutshell, if SIC is up and MDS/SMS available, VSX cluster members always contact management domain first to get most up to date provisioning info.
For implementation part, I strongly suggest you following the admin manual for your VSX version.
Hi @_Val_ , I have similar setup but I just wanted to know if my interface configuration is correct. My intention is to allow all VLANs to pass through the firewall, now my interface config is non-trunk physical port (the trunk is not checked) for both of physical interface participating in the bridge link. So far, all it passes it all and well but I am just wondering if this is correct or do I need to tag the VLANs? However, if I tag each VLANs, VSX will not accept it because I am currently in Active/Standby mode. Is this how CP behaves in VSX bridge mode? Thanks a lot.
If you are talking about bridge mode, you need to create all interfaces with VLANs. there is not trunk mode there
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 17 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY