CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 8 of 8

Thread: VSX inter communication network funny IP

  1. #1
    Join Date
    2016-10-31
    Posts
    53
    Rep Power
    7

    Default VSX inter communication network funny IP

    If we deploy Cluster XL on security gateway we need to assign physical and virtual IP address to make it working.
    If we deploy VSX and configure the virtual system we do not need to assign physical IP address its automatically assign address from inter communication network (192.168.192.0/23) which can be change to any network but has to be /24.
    The question I got here are following
    Can inter communication network and virtual IP be different network ?
    Is inter communication network and virtual ip needs to be within same subnet ?
    How virtual IP stick on cluster if inter communication network different than VIP ?


    Thanks for your help

  2. #2
    Join Date
    2007-06-04
    Posts
    3,314
    Rep Power
    20

    Default Re: VSX inter communication network funny IP

    Quote Originally Posted by ba3113 View Post
    If we deploy Cluster XL on security gateway we need to assign physical and virtual IP address to make it working.
    If we deploy VSX and configure the virtual system we do not need to assign physical IP address its automatically assign address from inter communication network (192.168.192.0/23) which can be change to any network but has to be /24.
    The question I got here are following
    Can inter communication network and virtual IP be different network ? YES, the Virtual IP should be a real IP on the Network that the interface is connected too.
    Is inter communication network and virtual ip needs to be within same subnet e ? NO and shouldn't be
    How virtual IP stick on cluster if inter communication network different than VIP ? NOT SURE, it just works for me. VSX is not the same as physical hardware. Sorry cannot answer tact more then that. I presume is something to do with the way that VSX communicates on the vs0 rather then the actual virtual systems themselves however.


    Thanks for your help
    Answered as best I can along the questions

  3. #3
    Join Date
    2016-10-31
    Posts
    53
    Rep Power
    7

    Default Re: VSX inter communication network funny IP

    Thanks for your reply.

    VS0 means you are talking about the VSX Gateway Cluster not the virtual system ?

  4. #4
    Join Date
    2006-03-08
    Location
    Lausanne
    Posts
    1,030
    Rep Power
    18

    Default Re: VSX inter communication network funny IP

    "funny IP network" addresses are to perform provisioning and to maintain clusterXL parameters locally on each physical device in the cluster. In fact, your VIP addresses SHOULD be different from that network.

    More, make sure "funny IP network" is not used in any other part of your network. that segment should not be routed in your network at all.
    -------------

    Valeri Loukine
    CCMA, CCSM, CCSI
    http://checkpoint-master-architect.blogspot.com/

  5. #5
    Join Date
    2016-10-31
    Posts
    53
    Rep Power
    7

    Default Re: VSX inter communication network funny IP

    Thank you

    Can VSX Gateway(VS0) pass any traffic ? How we can use VS0 to treat as virtual system ? Is it possible ?

  6. #6
    Join Date
    2006-03-08
    Location
    Lausanne
    Posts
    1,030
    Rep Power
    18

    Default Re: VSX inter communication network funny IP

    Quote Originally Posted by ba3113 View Post
    Thank you

    Can VSX Gateway(VS0) pass any traffic ? How we can use VS0 to treat as virtual system ? Is it possible ?
    Yes you can, you just don't want to. VS0 is used for provisioning of other VSs and for handling MGMT to VS communications for the whole system. With actual production traffic running through it, you need to be very careful not to install security policy that would affect other VSs. Also in MDSM environment VS0 belongs to so called Main Domain while other Virtual Systems are managed by other security doman servers, called Target domains. Main Domain server MGMT DB should not be locked, otherwise provisioning from target domain fails.

    Bottom line - don't use it for production traffic, ever.
    -------------

    Valeri Loukine
    CCMA, CCSM, CCSI
    http://checkpoint-master-architect.blogspot.com/

  7. #7
    Join Date
    2016-10-31
    Posts
    53
    Rep Power
    7

    Default Re: VSX inter communication network funny IP

    It means if we need to build internet facing VS then we need to have two VS connected to internet world one is VS0 which is going to share all UTM's update , DNS , etc to other VS and another VS going to be your Virtual System which will host internet world.Based on SK its not advisable to have direct internet connection to each VS as VS0 shared all updates to other VS.

  8. #8
    Join Date
    2006-03-08
    Location
    Lausanne
    Posts
    1,030
    Rep Power
    18

    Default Re: VSX inter communication network funny IP

    Quote Originally Posted by ba3113 View Post
    It means if we need to build internet facing VS then we need to have two VS connected to internet world one is VS0 which is going to share all UTM's update , DNS , etc to other VS and another VS going to be your Virtual System which will host internet world.Based on SK its not advisable to have direct internet connection to each VS as VS0 shared all updates to other VS.
    It is only a question of internal routing. VS0 does not have to be directly connected to the internet.
    -------------

    Valeri Loukine
    CCMA, CCSM, CCSI
    http://checkpoint-master-architect.blogspot.com/

Similar Threads

  1. Checkpoint inter-community vpn MEP
    By jimbul in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 0
    Last Post: 2010-07-02, 04:07
  2. Checkpoint - Inter VLAN routing
    By eightzero in forum Miscellaneous
    Replies: 5
    Last Post: 2010-04-30, 02:59
  3. Sun V20z with Inter Pro 100/1000 MT quad card, R60_03
    By waldi in forum Check Point SecurePlatform (SPLAT)
    Replies: 1
    Last Post: 2006-09-18, 07:08
  4. Funny SSH issues (well, not funny)
    By gfont96 in forum Services (TCP, UDP, ICMP, etc.)
    Replies: 3
    Last Post: 2006-09-05, 08:00
  5. Inter Pro 100/1000 GT quad card
    By Hitman in forum Check Point SecurePlatform (SPLAT)
    Replies: 12
    Last Post: 2006-08-07, 10:42

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •