- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello,
in the future we will have more than 64 interfaces on one VS. The Interfaces are regular vlan interfaces.
Do we have to change the size of the internal network as described in sk99121 or is this only needed if we would use more than 64 Virtual Switches/Routers?
Best regards,
Jan
Hi,
You need to increase the subnet of the internal network to be able to add more then 64 vlan interfaces.
This is because VSX is using the internal network to NAT all the VS IP's set on vlan interfaces, and there isn't enough room for more addresses.
I would recommend changing the internal network sooner rather then later, as it will be faster and has less impact.
Jan,
you really need a maintenance schedule for the procedure of changing the VSX internal subnet.
There is no chance to have a sync running between the cluster nodes.
Check your policy install times, because you have to install policy to all virtual systems after changing this subnet. Without the policy install the internal NAT of the VSX system does not work properly with the new subnet. This could be a long time running process.
Wolfgang
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY