- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello, we are going to migrate firewall to a new VSX cluster R81 JHA t72.
In this moment, the VSX cluster is installed in "lab mode" and all interfaces are lonked but in "down" state. We have 3 SGW 7k in VSLS clusterXL.
We have 3 VS (0,1,2), the clish command "show configuration interface" from vs0,1,2 show the configuration about management interface only (bond 4). The others interfaces are not visible:
fw01:0> show configuration interface
set interface bond4 comments "MGMT bond"
set interface bond4 state on
set interface bond4 ipv4-address x.x.x.x mask-length 24
fw01:0>
If we execute:
- clish command "show interfaces"
- expert command "ifconfig"
- expert command "ip address"
- expert command "cphaprob -a if"
the system show the correct interfaces:
fw01:0> show interfaces
Mgmt
Sync
bond1
bond2
bond2.x
bond2.x
bond2.x...
This is a cosmetic bug? Probably, this issue is started after installation of JHA 72 (from 69).
Thanks
JHF T72 is an ongoing build with some VSX fixes, as I'm sure you're aware not every build becomes GA.
What have you attempted here since, policy install or vsx_util reconfigure?
Reverting to T69 isn't an option?
If the problem persists please contact TAC to investigate.
Hello, I installed jha t72 bacause the number of resolved issue is high and is relased 20 days ago.
We executed push policy to VSX cluster and vs1 and 2 but the behaviour is the same.
Yes, we can unistall t72 if this is a know issue and this isn't only "cosmetic"
I opened a dedicated SR alreday.
Hello, i uninstalled jha t72 on fw3, in this moment this gw have jha t69 and the behaviour is the same.
Hello, i uninstalled jha t72 also on SMS, in this moment the SMS have jha t69 and the behaviour is the same.
I executed also "vsx_util reconfigure" from SMS to fw03 and the behaviour is the same.
I updated TAC, I will update you.
Hi,
I see this behavior on JHF take 78 in R81.10 also.
Have you gotten an answer from TAC for this?
Hi,
The “show configuration interface” output was indeed changed in VSX context.
When you run “save configuration” in clish, you actually put what you get in “show configuration” in a file.
You can use this file to configure a new gw (not yet VSX) machine without involving the management.
This information should include only interfaces that were configured via clish. The other interfaces you saw before the fix were configured from the management.
These interfaces belong to VSs and you can’t configure them from the gateway so they are left out of the configuration file.
If you would try to configure a new machine with these interfaces in the configuration file that was generated, you would not be able to create a VSX gateway\cluster member on this machine.
I agree that this is a improvement and as you say relevent when exporting configuration from a VSX.
What I question is that no information of this change has been published. For me when noticing this change during a upgrade was more confused and thinking something was wrong.
That is why i'm asking what the TAC has answered regarding this.
Hi,
This creates a problem, because you don't get the synchronization interface anymore. This is a must have when configuring a new machine.
Secondly, when going in clish to another VS environment, you'll also don't get the interface information, but you do get the routing information. In my eyes this is confusing and not consistent.
You are correct about the routing information. This was brought to our attention a couple of weeks ago and it will be fixed and delivered to all the relevant jumbos.
Hi,
On R81.10 Jumbo Take 87 (recommended), the synchronization interface is still not visible unfortunately. Also, static routes are still visible per VS.
Hi,
We will restore the previous behavior and the interfaces will be visible again. I don't know yet which jumbo release will have the fix but I'll do my best to have it in the jumbos as soon as I possible.
@Erez_Carmel just for info, to maybe help you pinpoint, as we recently observed the same situation:
We find it useful cause we use netflow data enrichment via SNMP and this way we have all the interfaces and their names aka comments (that are manually added) in one place...
Hi Erez,
Good to hear that the interface information is coming back.
I'm using a script to filter interesting information about VSX. For VS0, to get the needed interface information for a restore, I'm using the following that I added to this partial script: uitvraag-vs0-interfaces.txt
Please note, this script will work properly again once all information is available again (like in older Jumbo Takes), so when the "comments" and the "synchronization" information is back again.
Many of us out in the field DO NOT see this as a beneficial enhancement. It makes troubleshooting more cumbersome and the first time we saw this behavior traffic wouldnt flow through the VS because it didnt see the interfaces in its config. So I would recommend reverting this "so called cosmetic change" back. This change was definitely not needed.
Robert
Hello, the systems are in production from one month and all works fine.
Also the analysys with the TAC was OK, the situation is strange but is not problematic bacause all interfaces are in the initial config and present in the OS.
We started at JHF66 installed JHF 94. Second part of the change was to remove rouge interfaces on one node with the delete interface <Name of Physical Interface> vlan <VLAN ID> from the Admin guide.
After the JHF 94 install All interfaces except Mgmt no longer show in Clish config in all contexts, the command does not work, but the interfaces are till in GAIA i.e. ifconfig.
Also, show interface <bond#.val#> still outputs the interface.
An hour of confusion I stumble on this thread
Does anyone have a link on more information about this?
PRJ-44745,PMTR-90616 listed in the upcoming fixes section of R81.10 JHF documentation
Virtual System's interfaces may be missing when running the Clish command "show/save configuration".
Oh Jolly good show. I looked through all the resolved issues and only found save config fix. Didn't think to look in upcoming
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY