Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
net-harry
Collaborator

Updatable Objects in VSX

Hi,

I have a question regarding updatable Objects in VSX. We needed to use this feature in one VS and had some trouble getting it working.

Initially we did not have DNS configured and followed sk121877 (Package of Updatable Objects is missing on the Security Gateway) to get last_revision.xml on the VSX hosts (vs 0).

However, things did not start working until we, with the help of TAC, created a NAT rule for the external interface of the VS and allowed traffic to Check Point also for that address.

My question is if/why we need to allow traffic from the VS to get Updatable Objects working in VSX? It would seem better if only the host (vs0) had access to Check Point to download updated and that the objects could then be used by any VS.

We are currently running R80.20 JHF 118.

Thanks for your help!

Best regards,

Harry

(1)
Who rated this post