VSNext
R82 VSX Administration Guide
VSNext
| Notes: - Starting in R82, there are two modes: - "VSNext" (new). This configuration is described below. - "Traditional VSX" (in versions R81.20 and lower, it is called just "VSX"). See other chapters in this Administration Guide. - You can enable the VSNext mode only in these: - ElasticXL Cluster. - MaestroSecurity Group. See the R82 Scalable Platforms Administration Guide. |
Limitations
- The acceleration card hardware does not accelerate connections that pass through more than one Virtual Gateway.
Introduction to VSNext
Introduced in the R82 version, VSNext is an enhanced VSX mode that allows simpler configuration, easier provisioning, and a similar experience to a physical Security Gateway.
The benefits of the VSNext mode are:
Unified management experience between Check Point physical Security Gateways and Virtual Gateways, including the capability to manage each Virtual Gateway from a different Management Server.
Improves VSX provisioning performance and provisioning experience - creating, modifying, and deleting Virtual Gateways and Virtual Switches in Gaia Portal, Gaia Clish, or with Gaia REST API.
Management feature and API parity between Virtual Gateways (VGW) and physical Security Gateways.
| Important - Installation of CPUSE packages applies to the entire ElasticXL / MaestroSecurity Group. |
Configuration Methods for VSNext
You can configure the required Virtual Gateways and Virtual Switches in one of these ways:
- Gaia Portal:
Configure the required Virtual Gateways and Virtual Switches objects on the page Virtual Systems.
In the top filter Virtual System, select the required Virtual Gateway.
Configure the required Gaia OS settings on the available pages in Gaia Portal.
- Gaia Clish:
- Add the required objects with these commands:
| |
| --- |
| add vsnext virtual-gateway interfaces <Name of Interface> id {auto | <1-511>} one-time-password <SIC Activation Key> instances <Number of IPv4 CoreXL Firewall Instances> instances6 Number of IPv6 CoreXL Firewall Instances wait-for-task {true | false} |
| add vsnext virtual-switch name <Name of Virtual Switch> id <ID of Virtual Switch> wait-for-task {true | false} |
| add vsnext virtual-link virtual-gateway <ID of Virtual Gateway> virtual-switch <ID of Virtual Switch> wrp-id <0-63> |
- Configure the required settings with these commands:
| |
| --- |
| set vsnext interfaces <Name of Interface> virtual-system <ID of Virtual Gateway> |
| set vsnext corexl-instances virtual-gateway <ID of Virtual Gateway> ipv4-instances Number of IPv4 CoreXL Firewall Instances wait-for-task {true | false} |
| set vsnext corexl-instances virtual-gateway <ID of Virtual Gateway> ipv6-instances Number of IPv6 CoreXL Firewall Instances wait-for-task {true | false} |
| set vsnext corexl-instances virtual-gateway <ID of Virtual Gateway> ipv4-instances Number of IPv4 CoreXL Firewall Instances ipv6-instances Number of IPv6 CoreXL Firewall Instances wait-for-task {true | false} |
- View the configured settings with these commands:
| |
| --- |
| show vsnext overview virtual-system <VS ID> |
| show vsnext overview virtual-systems |
| show vsnext recent-tasks limit <Number> |
| show vsnext running-task <Press the Tab Key to select Task ID> |
| show vsnext running-tasks |
| show vsnext state |
- Delete the configured settings with these commands:
| |
| --- |
| delete vsnext virtual-link virtual-gateway <ID of Virtual Gateway> virtual-switch <ID of Virtual Switch> |
| delete vsnext virtual-gateway <ID of Virtual Gateway> options {skip_cpstop_on_delete | none} wait-for-task {true | false} |
| delete vsnext virtual-switch <ID of Virtual Switch> options {skip_cpstop_on_delete | none} wait-for-task {true | false} |
- Gaia REST API:
Refer to the Check Point Gaia API Reference (at the top, select the correct version), or the local Gaia REST API Reference (https://<IP Address of Gaia Management Interface>/gaia_docs/#introduction).
- Add the required objects with these API commands:
| |
| --- |
| add-virtual-gateway |
| add-virtual-switch |
- Configure the required settings with these API commands:
| |
| --- |
| set-virtual-gateway |
| set-virtual-switch |
- View the configured settings with these API commands:
| |
| --- |
| show-vsnext-state |
| show-virtual-systems |
| show-virtual-gateways |
| show-virtual-switches |
| show-virtual-gateway |
| show-virtual-switch |
- Delete the configured settings with these API commands:
| |
| --- |
| delete-virtual-gateway |
| delete-virtual-switch |
Procedure for Gaia Portal
- Perform a Clean Install of a supported platform and configure it as VSNext in the First Time Configuration Wizard.
| | | | --- | --- | | | Warning - It is not supported to convert an existing platform to the VSNext mode. |
See the R82 Release Notes > Chapter " Supported Environments" > Section " VSNext and Traditional VSX".
- Install the required platform. - For an ElasticXL Cluster:
See the R82 Scalable Platforms Administration Guide > Chapter " Working with ElasticXL Cluster".
- For a MaestroSecurity Group:
See the Maestro Getting Started Guide. 2. Run the First Time Configuration Wizard.
During the First Time Configuration Wizard on the first appliance, you must configure these settings (other appliances copy these settings when they join this ElasticXL Cluster):
- In the "Management Connection" window, select and configure the main Gaia Management Interface.
You connect to this IP address to open the Gaia Portal or CLI on the ElasticXL Cluster. 2. In the Installation Type window, select Security Gateway and/or Security Management. 3. In the Products window: 1. In the Products section, select Security Gateway only. 2. In the Clustering section, select Unit is a part of a cluster and select ElasticXL. 3. In the Gateway Virtualization section, select Install as VSNext. 4. In the Secure Internal Communication window, enter the applicable Activation Key (between 4 and 127 characters long).
03. Connect to Gaia Portal on the ElasticXL Cluster / MaestroSecurity Group.
You must connect to the same main IP address that you configured during the First Time Configuration Wizard.
To configure IPv6 addresses on interfaces and IPv6 CoreXL settings, you must enable the IPv6 support in Gaia OS:
In the left panel, click System Management > System Configuration.
In the IPv6 Support section, select On.
Click Apply.
Click Yes to reboot now (recommended).
Click No to reboot later. Configure Virtual Gateway objects only after you reboot.
On the top toolbar, after the field Virtual System, if you see the padlock icon, then click the padlock icon, and click Yes to override the lock.
The padlock icon must change to the pencil icon.
In the left panel, click Virtual Systems.
This page shows these default predefined objects:
The default Virtual Switch with ID 500 (with the assigned interface "magg1").
This Virtual Switch is attached to the predefined bonding group "magg1" that contains the port "Mgmt".The default Virtual Gateway object with ID 0 (with the assigned interface "wrp0").
The default Virtual Gateway (the interface "wrp0") is connected to the default Virtual Switch.
| Important - Do not change these default predefined objects. |
- Optional: Configure the default Virtual Gateway.
| | | | --- | --- | | | Best Practice - Configure the default Virtual Gateway to ensure secure access to the GaiaOperating System on the ElasticXL Cluster. |
The purpose of this default Virtual Gateway is to protect the management context, to which you connect to configure other Virtual Gateways and their settings.
The main IP address of this default Virtual Gateway is the IP address you assigned to the Management Interface in the First Time Configuration Wizard.
- Configure the required Virtual Gateways and Virtual Switches.
You can create many Virtual Gateways and manage all of them through the default Virtual Switch.
The IP addresses of all these Virtual Gateways must be in the same subnet as:
- The "MGMT" port of the ElasticXL Cluster.
- The Management port assigned to the MaestroSecurity Group.
Example topology:
| Item | Description |
|---|---|
| 1 | ElasticXL Cluster in the VSNext mode. |
| 2 | Network #1 that sends traffic through the Virtual Gateway (3) to Network #2 (6). |
| 3 | Virtual Gateway that inspects traffic between Network #1 (2) and Network #2 (6). Ports LAN1 and LAN2 are assigned to the Virtual Gateway. |
| 4 | Default Virtual Switch that connects the Virtual Gateway (3) to the Management Server (5). - The Virtual Gateway connects to the Virtual Switch over an internal virtual link from wrp64 to wrpj64.- "MGMT" is the name of the physical port on the Check Point appliance. - "wrp0" is the internal name of the "MGMT" port in the Gaiaoperating system. |
| 5 | Management Server that manages the Virtual Gateway (3) through its interface wrp64. |
| 6 | Network #2 that sends traffic through Virtual Gateway (3) to Network #1 (2). |
Legend
Interfaces and IP addresses
| Interface | IP Address / Net Mask | Description |
|---|---|---|
| eth0 | 192.168.3.57 / 24 | Interface of the Management Server |
| wrp0 | 192.168.3.242 / 24 | Management interface for the ElasticXL Cluster in the VSNext mode |
| wrp64 | 192.168.3.250 / 24 | Management interface for the Virtual Gateway |
| LAN1 | 172.16.44.250 / 24 | Interface of the Virtual Gateway that connects it to Network #1 |
| LAN2 | 172.16.55.250 / 24 | Interface of the Virtual Gateway that connects it to Network #2 |
Configuration:
From toolbar, click Add > Virtual Gateway.
In the section Network interfaces:
- Click Add interface.
Select the checkboxes of the interfaces that you need to assign to this Virtual Gateway.
Click Add.
In the section Establish trust with Management server:
- In the Activation Key field, enter a one-time password.
You use this password later, when you create a Security Gateway object in SmartConsole. 2. In the Re-type Activation Key field, enter the one-time password again. 3. In the Interface field, select an interface, to which you need to assign an IPv4 address.
You use this IPv4 address later, when you create a Security Gateway object in SmartConsole.
- Optional: In the section Advanced settings:
- On the right end of the section heading, click the arrow icon to expand this section.
- In the Manually assigned VS ID field, enter the applicable ID between 1 and 511.
If you do not enter an ID, it is assigned automatically (the next available sequentical number). 3. In the Assign IPv4 Instances field, enter the applicable number of IPv4 CoreXLFirewall instances. 4. In the Assign IPv6 Instances field, enter the applicable number of IPv6 CoreXLFirewall instances. 5. Click OK.
Monitor the progress in the bottom panel Tasks.
In the left panel, click Network Management > Network Interfaces. Configure the interfaces you assigned to the Virtual Gateway:
Select the interface LAN1 > click Edit > configure the IPv4 address 172.16.44.250 and IPv4 Subnet mask 255.255.255.0 > click OK.
- Select the interface LAN2 > click Edit > configure the IPv4 address 172.16.55.250 and IPv4 Subnet mask 255.255.255.0 > click OK.
In the left panel, click Network Management > IPv4 Static Routes. Add the required static routes for this Virtual Gateway.
In SmartConsole, configure the Security Gateway object for each Virtual Gateway.
In SmartConsole, configure and install the applicable Security Policies for each Virtual Gateway.
Add the additional required appliances to this ElasticXL Cluster / MaestroSecurity Group.
[Note: You can assign additional interfaces to a Virtual Gateway later.]