cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
VSX

Check Point's Virtual System Security Solution, otherwise known as VSX.

Jesus_Cano
Jesus_Cano inside VSX yesterday
views 64 2

Configuring in L3 interface (vsys)

Hi, We need to enable the interface eth1-03. We try to add the IP but suddenly the IP is changed to another one. We dont know why the IP for the itnerface just configured is changes. Why? We have vsys and R80.10.
Jesus_Cano
Jesus_Cano inside VSX Wednesday
views 80

Issue configuring IP in vsys

Hi, Im trying to configure IP to my interface eth2-05. We have vsys scenario. When i try to configure the IP and mask, i can not press OK., i receive this warning:  "Enter an integer between 2 and 4094" These are the steps in smartconsole: Edit vsys -> Topology -> New Interface -> Regular -> I add the IP and mask  and when i press OK i get this warning:  "Enter an integer between 2 and 4094". But im not configuring a vlan i just want a Layer 3 ip interface. Why? i dont need a vlan
jbfixurpc_cew
jbfixurpc_cew inside VSX Wednesday
views 2178 6

VSX Clustering R80.20 DNS resolving error msg

Greetings!I am seeing constant Alert error messages in our logs with reason: Firewall - Domain resolving error. Check DNS configuration on the gateway (0) .Here are the statistics: R80.20, running on VSX, JHF Take 103 applied, Initially I thought the issue was being caused by the fact that in VSX the DNS servers for each context are the same (SK152873 - a large oversight if you ask me but) so with some redesign I was able to find 3 common DNS targets that would work in this scenario. Once that was applied, I still am seeing tons of these alert errors.From the CLI I am able to confirm that all of the VSX contexts resolve DNS using dig/nslookup etc so I am not sure why I would be seeing this behavior  
Kaspars_Zibarts
Kaspars_Zibarts inside VSX a week ago
views 218 4

R80.30 VSX gateway with 3.10 kernel - yes or no

Just planning my R80.30 upgrades and mulling over if I should go with 3.10 kernel on our 23800 VSX clusters or keep it 2.6? Seen some issues reported with 3.10 and we can't afford instability. Pretty happy with current performance on R80.10 with old kernel so leaning towards the safe option.. same time there are bunch of interesting OS features Any feedback on those who run VSX and R80.30 with 3.10 kernel?
xiro
xiro inside VSX 3 weeks ago
views 236 3

Sync Bond issue during VSX upgrade

Hi,I'm currently trying to upgrade our (fortunately not yet productive) VSX environment from 80.20 to 80.30 via "Connectivity Upgrade".Unfortunately I ran into an issue, that causes me some pain and I don't know how to proceed. Following situation:The both VSX Gateways are connected via Sync-Bond (bond2 - two direct cables running between them, no switches involved).After I followed the instructions from "Installation an Upgrade Guide R80.30" for "Connectivity Upgrade of a VSX Cluster" until step 4, where I upgraded the standby member to R80.30 via clish CPUSE. At that moment, I realised that the status of the members is not as expected.As far as I understood, the primary member should stay "ACTIVE", whereas the upgraded one should go in a "READY" state.In my case, they seem to have lost the sync between them, so both sides are now active: Member 1 (not upgraded):Member 2 (upgraded):If I check the "cphaprob -a if" on the members, I see some strange behavior. Member 1 is constantly transitioning from up to down:If you repeat the command in short intervals, you see the timer going up to 5 seconds, then suddenly the status changes to following:And the next iteration is "DOWN" again.On the other member (upgraded) the status is constantly at "Inbound: UP  - Outbound: DOWN"The cabling was left untouched, the bond config seems OK on both sides.I'm not sure how to proceed further. I considered this as a connectivity-upgrade test before everything goes into production, but in that case it failed completely...  Any help is appreciated 🙂
Colin_Campbell1
Colin_Campbell1 inside VSX 4 weeks ago
views 386 10 1

VSX Performance limits

Hi,I am wondering if there are any inherent limitations in VSX that would cause a single VS to stop processing traffic at around 5000 connections/second. I saw a recent instance where a 21400 appliance did exactly that. According to the appliance comparison chart this should be able to process 130,000 connections/second. Of course I understand that those figures won't be when running VSX but 5000 conns/sec for one VS seems a bit low for me.The setup:o 21400 applianceo R77.30 GAIAo 12 CPU, 24GB RAMo 8 x VS each with one fwko 2 x SNDAny thoughts/comments?Colin
Tung_Nguyen_Son
Tung_Nguyen_Son inside VSX 2019-12-18
views 259 1

Check Point Appliance hang abnomally

My customer have VSX system and they hang abnormally. I see have some record in message log but I know what they are:ec 17 08:34:42 2019 FWHO-CORE-01 kernel: prune_dcache: reduced dcache from 10865 to 5182 entries [attempted 100]Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4];sim_db_prepare: size set to 8388608 is too big. hard limit to 1048576Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth2Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1-01Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for eth1-02Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for bond1Dec 17 08:34:54 2019 FWHO-CORE-01 kernel: [SIM4]; drv_if_prepare_interface_data: dev vsid (0) is different from config vsid (1) for bond2Please help me to solve them.Thanks! 
net-harry
net-harry inside VSX 2019-12-16
views 483 4

Disabling physical interfaces in VSX

Hi,We have some physical interfaces on a VSX cluster that are no longer used. How do I disable them?I noticed in sk92311 that "set interface INTERFACE_NAME state" is blocked in CLI. The sk says "Some settings on Security Gateway / Cluster in VSX mode should be configured only via the SmartDashboard (e.g., adding VLAN interfaces)". However, I am not able to find where to disable physical interfaces in the SmartConsole.Thanks for your help!Harry
Sigbjorn
Sigbjorn inside VSX 2019-12-16
views 281 3

Experience with VSX VSLS on R80.30 3.10 Kernel

Are there other customers running VSX clusters on R80.30 3.10 (Open Server) kernel yet?We have installed several clusters now, and are experiencing weird issues writing configuration to the gateways.A simple operation like create or delete a virtual system has caused nodes to crash and go corrupt, forcing us to reinstall or re-sic + reconfigure them to get online again.TAC and R&D are involved, but I were just wondering if anyone else has run into any problems with this setup, or if anyone else is running this setup.
net-harry
net-harry inside VSX 2019-12-06
views 308 3 2

Management interface on virtual systems

Hi,We have just enabled SNMP access to virtual systems on VSX hosts using direct SNMP access:set snmp mode vsset snmp vs-direct-access onWe have confirmed that this is working with both SNMP v2 and v3 using the internal interface of the virtual systems that is used for data traffic.We are now planning to create a separate management interface for each vs, so that the SNMP traffic is separated and routed correctly. Would you recommend using the same VLAN for this interface as the management interface of the VSX hosts or do you see any advantage of using a separate monitoring VLAN on the virtual systems?Thanks for your help!Harry
Ricki_S
Ricki_S inside VSX 2019-11-28
views 204 2

Create 2 or more vsx Gateway

Hello Check Mates, Can I create 2 or more VSX gateway from one gatewayan I create 2 or more VSX gateway from cluster gatewayif yes, how can I create ? have proccess SIC?  Thanks and Regards,Ricki
Harald_Hansen
Harald_Hansen inside VSX 2019-11-26
views 260 3

CPinfo for Virtual System

TAC sometimes asks for CPinfo for certain Virtual Systems, though the CPinfo since R80 do not support any -vs flags. When asking for guidance I usually get a non answer, so we end up using vsenv <vsid> and run cpinfo again.Is this the correct way of doing it? Why so cumbersome?We often have to send cpinfo files for multiple virtual systems, having one command collecting data for all of these will reduce both time and file size significantly. 
Maik
Maik inside VSX 2019-11-19
views 3136 8 1

Different DNS server per VS

Hello guys,I'm pretty new when it Comes to VSX deployments and the related VS configuration. I have a quite Basic setup with one VSX cluster consisting out of two physical devices. On top of the VSX cluster we have two VS running (VS #1 and #2). Each VS has two dedicated interfaces. So currently there is not virtual switch or router in place, as there was no need for VS-to-VS communication or shared interfaces.Now to my issue:Basically I just want each VS to use a different DNS server, as per default the DNS config (as well as some other GAiA paramaters) are getting synched from VS0. The issue is, that once a change in clish of VS2 is made (regarding DNS) this is also getting synched to all the other VS (including VS0). So basically I assume that there is not way to have a different dns server entries for each VS...? I found a SK that mentions this problem and offers a solution - but this is only related for the remote access vpn blade and can't be used by any other feature. Without the possibility of configuring one or multiple different dns Servers for each VS I do not see a way to get any updates or the proxy feature working, as the gateway itself needs to send dns queries here.It is also not wanted to have a shared dns in this environment as each VS should work completely independent from the other. So even if I adjust the routing so that VS2 can reach the DNS of VS0 no solution is met.I read the VSX admin guide and could not find any word regarding this issue - so it could be the case that I overlooked something. Hopefully someone can point me in the right direction. 🙂Regards,Maik
Kaland
Kaland inside VSX 2019-11-19
views 759 10 3

Jumbo on Check Point R80.30 with Gaia 3.10 Take 273 or Take300

Hi, Has anyone tried installing Jumbo Take_50 or Take_76 on Open Server with R80.30 3.10 kernel running VSX? Take does not show up in CPUSE at all. CPUSE Agent is at required build 1786 maybe we have overlooked something, but can`t seem to find any answer this.Hope someone can help. We`re moving from project into production soon, and I want to make sure at we have patched for potential bugs that may appear when load is put on the cluster.  Best regardsBjørn Andre Kaland 
Enyi_Ajoku
Enyi_Ajoku inside VSX 2019-11-15
views 306 4

Clish/Expert Access with TACACS

 Hi,I've got TACACS+ set up (VSX Cluster). I can use my AD credentials to log in to Smart Dashboard but i cant do the same for CLI or Expert on my gateways.I believe i need to do some configuration on the CLI but i cant get the appropriate SK to get this done.Would appreciate some direction/help. I tried creating a User/rba but it requires setting up a password on the gateway which defeats the purpose of syncing with AD and TACACS serverThank You