Тёмный

Check Point VSX - Training Lab 1 | VSX Cluster Install 

Magnus Holmberg
Подписаться 10 тыс.
Просмотров 14 тыс.
50% 1

Within this video we install a VSX cluster in the MAIN01 located in our MDS

Опубликовано:

 

12 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 37   
@syedshohidahmed9880
@syedshohidahmed9880 3 года назад
Thank you Magnus. really appreciate your videos. I too was really looking forward to the VSX video series
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
I hope that you will enjoy the next videos then :)
@starkporfavorreviewdelelep756
@starkporfavorreviewdelelep756 3 года назад
hey bro, I wanted to thank you for the great contribution that you make, the truth that 2 years ago I had to implement a vsx there were no guides / tutorials like the ones you have shared in the way you explain things and that just to give an example. at the same time I wanted to tell you that It would be great in some of your future videos a lab on how to detect latencies or overloads of the intrefaces bandwidth in Checkpoint firewalls or another good lab could implement and troubleshoot Checkpoint firewall in the cloud. thanks again, your videos are of great value.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
Thank you! I felt the same way when i started with check point almost 10 years ago, there was alot of content for cisco but more or less none for check point. And the content excisting for check point was all written, (like CPUG). Thankfully i work for a large company where there was some ppl that had work with check point for a long period of time and i also got the possibility to join some officiall courses. planning for alot of videos, but it will take some time to release them, so in regards to VSX the training lab its made to learn and not a guide on how it should be installed if you are deploying a new cluster. so there are misstakes in them to make the lab more interesting in the future videos :) I will release a video with a full installation on a production vsx cluster within our enviroment including how we normally specifiy the boxes and why. In regards to public cloud its nothing that i normally work with, as we have built our own "cloud" where we host customers. But i will think about it, if there is possibility for creating some videos on it. i belive there are some labs for that on check points website, that i could do and record them.
@anonymous4298
@anonymous4298 3 года назад
There's a few things about VSX you need to know if you are rebuilding due to failed hardware: 1) You only need an IP on your management interface because everything else will be fetched from the management during vsx_util reconfigure 2) You need to setup all bond interfaces as defined management "physical interfaces" section on the gateway object 3) If you are using bootp / dhcp relay you will need to reconfigure this per VS 4) If you are using dynamic routing you will need to reconfigure this per VS 5) You must ensure ports 18191, 18210, 18211 and 18264 between gateway and management
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
Vsx_util reconfigure is one of the prettiest things with VSX. There are some more things that need to be fixed aswell, but it get less the newer software that you are running (Thinking of things like multiq) This will be a dedicated video, same as dynamic routing :)
@vinodsrinivasan9077
@vinodsrinivasan9077 2 года назад
Wowwww. Anonymous sir and Magnus sir. It's great that u guys have listed some things down. What else we need to keep it in mind and what are the tools available for troubleshooting vsx ? Do we have any video or any specific link where I can go through from scratch ??
@joescott7480
@joescott7480 3 года назад
Thanks Magnus, your videos are brilliant! They have helped me massively deploying some complex systems.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
Thank you, just dont use lab1 as a reference for live environment :D there are some changes in the later labs that i recommend to have from start in a prod environment.
@rizwanrashid172
@rizwanrashid172 3 года назад
Very informative and excellent explanation on VSX topic. well done Magnus
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
thank you rizwan :)
@afbraganza
@afbraganza 3 года назад
Wonderful explanation Magnus. Was waiting anxiously for the VSX videos from you. On another note, you mentioned that one cannot access GAIA portal when you turn on vsx mode for anything below R80.40. Does this mean R80.40 now supports access to the GAIA portal in VSX mode?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
R80.40 release notes include the statement "Support for VSX upgrade with CPUSE in Gaia Portal." Am not sure how much features are available within R80.40 as i dont have any production clusters running r80.40 for VSX. So thats something that will be interesting to see :)
@afbraganza
@afbraganza 3 года назад
@@MagnusHolmberg-NetSec - I checked this on a new VSX cluster running R80.40 and can confirm that you can login to the GAIA portal. However, it only has the Overview and CPUSE tab to download and upgrade and nothing else. But still, this is a good start for the VSX. Maybe in future, they will have more options.
@marguelles
@marguelles 2 года назад
Hi Magnus, when working with VMware Distributed Switches (vCenter needed), you can set a port-group as a trunk interface and tag multiple VLANs through it, so if you later define an interface as a trunk interface during VSX Cluster configuration wizard, you'll be able to add sub-interfaces for the VS and even for the cluster itself. I know, you are working with VMware workstation, I'm just throwing my 2 cents here. Keep up the good work!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
Yes, within standard esxi VMware you are able to have trunk ports to VM boxes that run check point software. So there is no need to have a lot of interfaces. I don’t think VSX is supported to run in VMware for production, but for lab and test it works really good.
@ricardoinfante5001
@ricardoinfante5001 Год назад
Man, This is amazing information. Thank u a lot.
@adityapadhi20
@adityapadhi20 3 года назад
Thank you Magnus for the lovely video..Could you also add troubleshooting video for VSX , like packet capture and other troubleshooting steps..
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
some troubleshooting will be included in the videos, but am not planning to make anything dedicated for troubleshooting. but am pretty sure we will have some issues during the labs that need to be fixed :D
@anonymous4298
@anonymous4298 3 года назад
26:30 and it was at this moment when he realized he %@#&ed up (classic)
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
Yes it is :) Honestly i dont prepp very much when i do my videos and i actually think its better not to remove issues from the videos. Because everyone of us working with IT do misstakes and something always dosn´t go to plan. google is your best friend :) You learn from your failures!
@tahersadeghi6773
@tahersadeghi6773 Год назад
Mr. Magnus. Are you speaking English or talking jibberish? Where did you learn it?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec Год назад
Haha, yes am hoping I speak English, possible some strange words in between, jibberish or Swedish no idea :D
@fovadadami7270
@fovadadami7270 3 года назад
Thank you for a great video.
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
Thank you!
@randyrozo
@randyrozo Месяц назад
Thanks Bro!!!! where Can I download Packages and DA? this is need?
@stargategoku
@stargategoku 2 года назад
thanks a lot for posting! do you have video how to install checkpoint from the scratch?
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
Sure it’s within the CCSA playlist
@cristianof1881
@cristianof1881 2 года назад
Hello Magnus Your content is awesome!! Are you planning to make a video about upgrading a VSX VSLS cluster from r80.30,r80,40--->r81.10 using the MVC method? What is your opinion about VSX gateways on production running r81.10 (now the recommended version?) BR Kostas
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 2 года назад
Thank you :) Yea but I haven’t had the time to fix any labs for it the last weeks. My personal recommendation as of Q1 2022 is to run r80.40 for VSX Standard gateways is no problem to run R81. Mgmt servers I would aim for R81.10 Currently only have one prod MDS running r81.10
@saurabhsenger9541
@saurabhsenger9541 3 года назад
Your videos are very informative. I have a query & this may be off topic, i just want to know for doing SNMP configuration in VSX, do we have do it for VS0 only or we require to configure it individually to that virtual system in question. Thanks..!!
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
By default it’s to VS0 My recommendation is to do snmp per vs, especially if you going to do VSLS. Because then you can poll the VS IP directly. If you do for VS0 and VSLS you need to figure out where each VS is located. As they then can move around based on load etc. The configuration itself is by default same for all VS, (you need to use snmpv3 for per vs) then you specify what user can reach what VS id. I will make a video about it :)
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_VSX_AdminGuide/Content/Topics-VSXG/SNMP-Monitoring.htm
@poseidon8510
@poseidon8510 3 года назад
Thanks Mag....
@MagnusHolmberg-NetSec
@MagnusHolmberg-NetSec 3 года назад
your welcome :)
Далее
Китайка и Зеленый Слайм😂😆
00:20
Check Point Firewall - fw monitor
15:22
Просмотров 15 тыс.
Check Point | Backups
26:24
Просмотров 7 тыс.
Check Point MDS | Basic CLI commands
17:01
Просмотров 4,9 тыс.
Cursor Is Beating VS Code (...by forking it)
18:00
Просмотров 95 тыс.
Understanding fw monitor utility
27:13
Просмотров 10 тыс.