Check Point's Virtual System Security Solution, otherwise known as VSX.

Tommy_Forrest inside VSX yesterday
4

80.10 VS bit-ed-ness

Does anyone know why the powers-that-be (tm) decided it was a good idea to set the default bit-ed-ness of a new 80.10 VSX instance to 32-bit when the base Gaia install is 64-bit?And why on earth that is even a thing?Just got bit, again, with workerthreads filling up and discovered this issue.  Pretty cool that you can switch it on the fly, though.
Kaspars_Zibarts inside VSX Saturday
9

VSX upgrade R80.10 to R80.20 - CPUSE or fresh install

Apart from having "fresh slate" and removing old gremlins, are there any other possible reasons to chose fresh install + vsx_util reconfigure over straight CPUSE upgrade on VSX? File system remains the same.. I would prefer simpler approach (CPUSE) unless someone can provide convincing arguments against it 🙂    
Jesus_Cano inside VSX a week ago
views 164

Issue configuring IP in vsys

Hi, Im trying to configure IP to my interface eth2-05. We have vsys scenario. When i try to configure the IP and mask, i can not press OK., i receive this warning:  "Enter an integer between 2 and 4094" These are the steps in smartconsole: Edit vsys -> Topology -> New Interface -> Regular -> I add the IP and mask  and when i press OK i get this warning:  "Enter an integer between 2 and 4094". But im not configuring a vlan i just want a Layer 3 ip interface. Why? i dont need a vlan
jbfixurpc_cew inside VSX a week ago
6

VSX Clustering R80.20 DNS resolving error msg

Greetings!I am seeing constant Alert error messages in our logs with reason: Firewall - Domain resolving error. Check DNS configuration on the gateway (0) .Here are the statistics: R80.20, running on VSX, JHF Take 103 applied, Initially I thought the issue was being caused by the fact that in VSX the DNS servers for each context are the same (SK152873 - a large oversight if you ask me but) so with some redesign I was able to find 3 common DNS targets that would work in this scenario. Once that was applied, I still am seeing tons of these alert errors.From the CLI I am able to confirm that all of the VSX contexts resolve DNS using dig/nslookup etc so I am not sure why I would be seeing this behavior  
Kaspars_Zibarts inside VSX 2 weeks ago
4

R80.30 VSX gateway with 3.10 kernel - yes or no

Just planning my R80.30 upgrades and mulling over if I should go with 3.10 kernel on our 23800 VSX clusters or keep it 2.6? Seen some issues reported with 3.10 and we can't afford instability. Pretty happy with current performance on R80.10 with old kernel so leaning towards the safe option.. same time there are bunch of interesting OS features Any feedback on those who run VSX and R80.30 with 3.10 kernel?
xiro inside VSX 4 weeks ago
3

Sync Bond issue during VSX upgrade

Hi,I'm currently trying to upgrade our (fortunately not yet productive) VSX environment from 80.20 to 80.30 via "Connectivity Upgrade".Unfortunately I ran into an issue, that causes me some pain and I don't know how to proceed. Following situation:The both VSX Gateways are connected via Sync-Bond (bond2 - two direct cables running between them, no switches involved).After I followed the instructions from "Installation an Upgrade Guide R80.30" for "Connectivity Upgrade of a VSX Cluster" until step 4, where I upgraded the standby member to R80.30 via clish CPUSE. At that moment, I realised that the status of the members is not as expected.As far as I understood, the primary member should stay "ACTIVE", whereas the upgraded one should go in a "READY" state.In my case, they seem to have lost the sync between them, so both sides are now active: Member 1 (not upgraded):Member 2 (upgraded):If I check the "cphaprob -a if" on the members, I see some strange behavior. Member 1 is constantly transitioning from up to down:If you repeat the command in short intervals, you see the timer going up to 5 seconds, then suddenly the status changes to following:And the next iteration is "DOWN" again.On the other member (upgraded) the status is constantly at "Inbound: UP  - Outbound: DOWN"The cabling was left untouched, the bond config seems OK on both sides.I'm not sure how to proceed further. I considered this as a connectivity-upgrade test before everything goes into production, but in that case it failed completely...  Any help is appreciated 🙂
Colin_Campbell1 inside VSX a month ago
10 1

VSX Performance limits

Hi,I am wondering if there are any inherent limitations in VSX that would cause a single VS to stop processing traffic at around 5000 connections/second. I saw a recent instance where a 21400 appliance did exactly that. According to the appliance comparison chart this should be able to process 130,000 connections/second. Of course I understand that those figures won't be when running VSX but 5000 conns/sec for one VS seems a bit low for me.The setup:o 21400 applianceo R77.30 GAIAo 12 CPU, 24GB RAMo 8 x VS each with one fwko 2 x SNDAny thoughts/comments?Colin
Tung_Nguyen_Son inside VSX 2019-12-18
1

Check Point Appliance hang abnomally

My customer have VSX system and they hang abnormally. I see have some record in message log but I know what they are:ec 17 08:34:42 2019 FWHO-CORE-01 kernel: prune_dcache: reduced dcache from 10865 to 5182 entries [attempted 100]Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4];sim_db_prepare: size set to 8388608 is too big. hard limit to 1048576Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth2Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1-01Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1-02Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for bond1Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for bond2Please help me to solve them.Thanks! 
net-harry inside VSX 2019-12-16
4

Disabling physical interfaces in VSX

Hi,We have some physical interfaces on a VSX cluster that are no longer used. How do I disable them?I noticed in sk92311 that "set interface INTERFACE_NAME state" is blocked in CLI. The sk says "Some settings on Security Gateway / Cluster in VSX mode should be configured only via the SmartDashboard (e.g., adding VLAN interfaces)". However, I am not able to find where to disable physical interfaces in the SmartConsole.Thanks for your help!Harry
Sigbjorn inside VSX 2019-12-16
3

Experience with VSX VSLS on R80.30 3.10 Kernel

Are there other customers running VSX clusters on R80.30 3.10 (Open Server) kernel yet?We have installed several clusters now, and are experiencing weird issues writing configuration to the gateways.A simple operation like create or delete a virtual system has caused nodes to crash and go corrupt, forcing us to reinstall or re-sic + reconfigure them to get online again.TAC and R&D are involved, but I were just wondering if anyone else has run into any problems with this setup, or if anyone else is running this setup.
net-harry inside VSX 2019-12-06
3 2

Management interface on virtual systems

Hi,We have just enabled SNMP access to virtual systems on VSX hosts using direct SNMP access:set snmp mode vsset snmp vs-direct-access onWe have confirmed that this is working with both SNMP v2 and v3 using the internal interface of the virtual systems that is used for data traffic.We are now planning to create a separate management interface for each vs, so that the SNMP traffic is separated and routed correctly. Would you recommend using the same VLAN for this interface as the management interface of the VSX hosts or do you see any advantage of using a separate monitoring VLAN on the virtual systems?Thanks for your help!Harry
Ricki_S inside VSX 2019-11-28
2

Create 2 or more vsx Gateway

Hello Check Mates, Can I create 2 or more VSX gateway from one gatewayan I create 2 or more VSX gateway from cluster gatewayif yes, how can I create ? have proccess SIC?  Thanks and Regards,Ricki
Harald_Hansen inside VSX 2019-11-26
3

CPinfo for Virtual System

TAC sometimes asks for CPinfo for certain Virtual Systems, though the CPinfo since R80 do not support any -vs flags. When asking for guidance I usually get a non answer, so we end up using vsenv <vsid> and run cpinfo again.Is this the correct way of doing it? Why so cumbersome?We often have to send cpinfo files for multiple virtual systems, having one command collecting data for all of these will reduce both time and file size significantly. 
Maik inside VSX 2019-11-19
8 1

Different DNS server per VS

Hello guys,I'm pretty new when it Comes to VSX deployments and the related VS configuration. I have a quite Basic setup with one VSX cluster consisting out of two physical devices. On top of the VSX cluster we have two VS running (VS #1 and #2). Each VS has two dedicated interfaces. So currently there is not virtual switch or router in place, as there was no need for VS-to-VS communication or shared interfaces.Now to my issue:Basically I just want each VS to use a different DNS server, as per default the DNS config (as well as some other GAiA paramaters) are getting synched from VS0. The issue is, that once a change in clish of VS2 is made (regarding DNS) this is also getting synched to all the other VS (including VS0). So basically I assume that there is not way to have a different dns server entries for each VS...? I found a SK that mentions this problem and offers a solution - but this is only related for the remote access vpn blade and can't be used by any other feature. Without the possibility of configuring one or multiple different dns Servers for each VS I do not see a way to get any updates or the proxy feature working, as the gateway itself needs to send dns queries here.It is also not wanted to have a shared dns in this environment as each VS should work completely independent from the other. So even if I adjust the routing so that VS2 can reach the DNS of VS0 no solution is met.I read the VSX admin guide and could not find any word regarding this issue - so it could be the case that I overlooked something. Hopefully someone can point me in the right direction. 🙂Regards,Maik