CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.

First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E


Results 1 to 3 of 3

Thread: Add and change sync network in VSX

  1. #1
    Join Date
    Zurich, Switzerland
    Rep Power

    Default Add and change sync network in VSX

    Q1: How can I modify the netmask of an existing sync network in a VSX-1 Cluster?
    Q2:How can I add a 2nd sync network?

  2. #2
    Join Date
    Zurich, Switzerland
    Rep Power

    Default Re: Add and change sync network in VSX

    Found it. It's in the GUI under topology.
    Tested in the LAB with Gaia VSX R75.40VS.
    The second sync does not work in my config. I also re-bootet the whole cluster after having added the 2nd sync interface. Without re-booting, it does NOT show up in the SmartView Monitor, with a re-boot, it is beeing displayed in the SmartView Monitor.
    tcpdumping shows sync traffic on both sync interfaces (I used physical interfaces "Sync" and "Lan1").
    But when I disconnect the 1st sync crosssover Cable, the VSX cluster shows:

    Idefix:0> cphaprob state

    Cluster Mode: Virtual System Load Sharing

    Number Unique Address Assigned Load State

    1 (local) 100% Active Attention
    2 0% Down

    Cluster name: Gallier

    Virtual Devices Status on each Cluster Member

    ID | Weight| Idefix | Obelix
    | | [local] |
    1 | 10 | Active! | Down
    2 | 10 | Down | Active!
    3 | 10 | Active! | Down
    4 | 10 | Down | Active!
    5 | 10 | Active! | Down
    Active | 3 | 2
    Weight | 30 | 20
    Weight (%) | 60 | 40

    Legend: Init - Initializing, Active! - Active Attention
    Down! - ClusterXL Inactive or Virtual System is Down


    Re-attaching the 1st sync cable brings ths cluster back to normal operation.
    Has anyone ever sucessfully tested such a sync failover?

  3. #3
    Join Date
    Rep Power

    Default Re: Add and change sync network in VSX

    Did you check the documentation and release notes?

    I remember that for R67 VSX a second sync was not supported, even if it was possible to define it, and that fact was mentioned in release notes or known limitations.

    - Petter

Similar Threads

  1. Reduce and prevent sync overload on VSX
    By khungbo33 in forum VPN-1 VSX
    Replies: 6
    Last Post: 2012-07-12, 03:08
  2. Replies: 5
    Last Post: 2010-11-15, 15:37
  3. add an internal network
    By me9ki in forum SecureClient/SecuRemote
    Replies: 2
    Last Post: 2008-05-14, 09:22
  4. Replies: 8
    Last Post: 2008-05-04, 17:50
  5. Add network
    By technick22 in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 6
    Last Post: 2008-01-16, 12:20

Tags for this Thread


Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts