@PhoneBoy
We will see what @emmap will reply.
But I will add something to you query from my side.
In case of user that has access to VS0 and other VSs he will go directly to VS0.
In case other user that has a role that allows access only to one or more VSs ... he will go to this one with the lowest number (ex. he has VS1 VS2 VS3 ... them he will login to VS1) ... when he will login to IP address of VS0.
But .. with VSNext we have management switch so I thought that why not ssh directly to the management IP of chosen VS (not this one that VS0 has) ? ... and this is not working for me.
A little lab on TechPoint (ElasticXL environment) - everybody can do that easly.
1) EXL-Member-1 (10.160.0.15) was removed from ElasticXL.
2) After reboot:
add vsnext virtual-gateway interfaces eth5 id 2 one-time-password 1234 instances 1 instances6 0 wait-for-task true
3) Then:
set virtual-system 2
show interfaces
eth5
wrp128
set interface wrp128 ipv4-address 10.160.0.99 mask-length 24
show interface wrp128 ipv4-address
1_01:
ipv4-address 10.160.0.99/24
4) Testing time:
first try - VS0:
C:\Users\Administrator>ssh admin@10.160.0.15
The authenticity of host '10.160.0.15 (10.160.0.15)' can't be established.
ECDSA key fingerprint is SHA256:uKy0ADO+rxnnrTBGxsV7AJdbRjlngok2U0MbEIxYYLU.
Are you sure you want to continue connecting (yes/no)?
so it works
now VS2:
C:\Users\Administrator>ssh admin@10.160.0.99
ssh: connect to host 10.160.0.99 port 22: Connection refused
so it doesn't work
meanwhile on VS2:
[Expert@gw-1-s01-01:2]# cppcap -i any -f "port 22 and host 10.160.0.99"
05:38:35.285471 In [Mgmt] 10.160.0.100:53234 > 10.160.0.99:22 IPP 6
05:38:35.285488 In [magg1] 10.160.0.100:53234 > 10.160.0.99:22 IPP 6
05:38:35.285500 Out [wrpj128] 10.160.0.100:53234 > 10.160.0.99:22 IPP 6
05:38:35.285512 In [wrp128] 10.160.0.100:53234 > 10.160.0.99:22 IPP 6
05:38:35.285711 Out [wrp128] 10.160.0.99:22 > 10.160.0.100:53234 IPP 6
05:38:35.285733 In [wrpj128] 10.160.0.99:22 > 10.160.0.100:53234 IPP 6
05:38:35.285737 Out [magg1] 10.160.0.99:22 > 10.160.0.100:53234 IPP 6
05:38:35.285744 Out [Mgmt] 10.160.0.99:22 > 10.160.0.100:53234 IPP 6
[Expert@gw-1-s01-01:2]# fw ctl zdebug + drop | egrep ':22|,22'
(nothing)
BTW
I received information from one of Check Point's employee that he can directly login to management IP of chosen VS ... but it was on phisical appliance, not virtual ... it would be really strange ...
So ... I'm confused right now a little bit ... will need to check it on phisical appliance when it will be possible 🙂
--
Best
m.