Support Center > Search Results > SecureKnowledge Details
VSX supported features on R75.40VS and above
Solution

VSX mode on Security Gateways is supported in R75.40VS and above only on these Operating Systems (refer to Release Notes - R75.40VS, R76, R77 - chapter "Operating System Requirements"):

  • Check Point Gaia OS
  • X-Series XOS

The following table lists blades / features that are supported on Gaia OS and on X-Series XOS (read the notes under the table).

Enter the string to filter this table:

Blade / Feature R75.40VS
Gaia
R76 (9)
Gaia
R76SP.X
Gaia
R77
Gaia
R77.10
Gaia
R77.20
Gaia
R77.30
Gaia
R80.10
Gaia
R80.20
Gaia
Software Blades
Firewall Yes Yes Yes
Yes
Yes
Yes
Yes
Yes
Yes 
IPS Blade Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2)
IPSec VPN Blade Yes Yes Yes Yes Yes Yes Yes Yes Yes 
Anti-Bot Blade Yes (1 , 2) Yes (1 , 2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2)
Anti-Virus Blade Yes (1 , 2) Yes (1 , 2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2)
Traditional Anti-Virus Blade No No No No No No No No  No
Threat Emulation Blade No No Yes (2 , 18) No No Yes (2) Yes (2) Yes (2) Yes (2)
Threat Extraction Blade (sk101553) No No No No No No No Yes Yes 
Anti-Spam and Email Security Blade No No No No No No No No  No
Data Loss Prevention (DLP) Blade No No No No No No No No  No
Application Control Blade Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10)
URL Filtering Blade Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10)
Content Awareness No No No No No No No Yes Yes 
Legacy URL Filtering Blade No No No No No No No No  No
Identity Awareness Blade Yes (11) Yes (11) Yes (11) Yes (11) Yes (11) Yes (11) Yes (11) Yes (11) Yes (11)
Monitoring Blade Yes (1) Yes (1)   Yes Yes Yes Yes Yes  Yes
Mobile Access Blade Supported
partially (1 , 3)
Supported
partially (1 , 3)
No Supported
partially (1 , 3)
Yes Yes Yes Yes  Yes
QoS, Light Weight (CPQOS) (12)
(VSX has native QoS support - it does not support the QoS Blade (FloodGate-1))
Yes Yes No Yes Yes Yes Yes Yes Yes 
Compliance Blade No No No No No Yes (17) Yes (17) Yes (17) Yes (17)
All Management Blades No No No No No No No No  No
Global Features
Network Address Translation (NAT) Yes Yes Yes Yes Yes Yes Yes Yes  Yes
SecureXL Yes Yes Yes Yes Yes Yes Yes Yes Yes 
CoreXL Yes Yes Yes Yes Yes Yes Yes Yes  Yes
Dynamic Routing Yes (4) Yes (4) Yes Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4)
Source Based Routing on Virtual Router Yes Yes Yes Yes Yes Yes Yes Yes Yes 
Policy Based Routing (PBR) on Virtual Router Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15)
SNMP Per Virtual System using SNMPv3 Yes (1) Yes (1) Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
DHCP Client No No No No No No No No  No
DHCP Relay Yes Yes (1) Yes Yes (1) Yes Yes Yes Yes  Yes
DHCP Server Yes (1 , 5) Yes (1 , 5) Yes (5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5)
NTP Client Yes Yes Yes Yes Yes Yes Yes Yes  Yes
NTP Server No (13) No (13) No (13) No (13) No (13) No (13) No (13) No (13) No (13)
Security Servers Yes (1) Yes (1) Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
Jumbo Frames Yes (16) Yes (16) Yes (16) Yes (16) Yes (16) Yes (16) Yes (16) Yes (16) Yes (16)
Rule Hit Count Yes Yes Yes Yes Yes Yes Yes Yes Yes 
UserCheck
(supported for Application Control / URL Filtering / Identity Awareness blades)
Yes Yes Yes Yes Yes Yes Yes Yes  Yes
Gaia Portal Yes (1 , 6) Yes (1 , 6) No Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6)
Gaia OS "Cloning Groups" No (14) No (14) No (14) No (14) No (14) No (14) No (14) No (14) No (14)
StandAlone Configuration No No No No No No No No  No
IPv6 No Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7)
VRRP No (8) No (8) No (8) No (8) No (8) No (8) No (8) No (8) No (8)
VPN Link Selection No No No No No No No No  No
VPN VTI No No No No No No No No  No
Suspicious Activity Monitoring (SAM) Rules No No No No No No No No  No
Malicious Activity Detection (MAD) No No No No No No No No  No
Connect Control No No No No No No No No  No
ISP Redundancy No No No No No No No No No 
SmartUpdate No No No No No No No No  No
SmartProvisioning / SmartLSM No No No No No No No No  No
SmartWorkflow on Security Management Server /
Multi-Domain Security Management Server
No No No No No No No No  No
Database Revision Control on Security Management Server /
Multi-Domain Security Management Server (sk65420)
No No No No No No No No  No
Multi Bridge (support for multiple bridge interfaces
on a Virtual System in Bridge Mode)
No No No No No No Yes (12) Yes (12) Yes (12)
Anti-Virus archive scanning No No No No No No Yes Yes  Yes
Threat Emulation archive scanning No No No No No No Yes Yes  Yes
Mail Transfer Agent (MTA) support for Threat Emulation No No No No No No No Yes  Yes
SecureXL Penalty Box No No No No No No No No Yes 
Resource Control
CPU monitoring per Virtual System Yes Yes Yes Yes Yes Yes Yes Yes Yes 
Memory monitoring per Virtual System Yes Yes Yes Yes Yes Yes Yes Yes Yes 
CPU enforcement per Virtual System
(a.k.a. Resource Control Enforcer in VSX R6x)
No No No No No No No No No 
Memory enforcement per Virtual System
(a.k.a. Resource Control Enforcer in VSX R6x)
No No No No No No No No  No
Virtual System in Bridge Mode
Refer to sk101371 - Bridge Mode on Gaia OS and SecurePlatform OS.
Additional Features
Merging VSX objects using cp_merge utility (sk33751) No No No No No No No No No 
Alias / Secondary IP address No No No No No No No No  No
ECMP No No No No No No No No No 
Dynamic Dispatcher  No No No No No No No No Yes

Notes:

  1. This blade / feature is not supported on X-Series XOS.

  2. Refer to sk106496 - Software Blades updates on VSX R75.40VS and above - FAQ.

  3. Mobile Access Blade is supported partially.
    Refer to:

  4. X-Series XOS uses its own routing suite (Gaia OS uses RouteD daemon).

  5. DHCP Server is supported only for the VSX Gateway itself - in the context of VS0.

  6. Gaia Portal is supported only to run the 'First Time Configuration Wizard'.

  7. IPv6 is supported with the following limitations:

    • Pure IPv6 is not supported (must have IPv4 addresses assigned) - applies only to Cluster.
    • IPv6 is not supported on Virtual Router.
  8. VRRP cluster in VSX mode is supported only on X-Series XOS.

  9. For information about 60000 / 40000 Security Systems, refer to the corresponding Release Notes (41000, 44000, 61000, 64000) - chapter "System Requirements" - section "Gateway Requirements" - subsection "Supported Software Blades".

  10. Refer to sk106496 - Software Blades updates on VSX R75.40VS and above - FAQ and to R77 versions VSX Administration Guide.

  11. Refer to sk101558 - Identity Awareness in VSX environment.

  12. Refer to VSX Administration Guide (R77.X, , R80.10).

  13. Refer to sk32027 - NTP Server support on Gaia and SecurePlatform OS.

  14. Refer to sk97494 - Gaia "Cloning Groups" are not supported on Security Gateway in VSX mode.

  15. Refer to sk100500 - Policy-Based Routing (PBR) on Gaia OS.

  16. Refer to sk110351 - Traffic latency on VSX Gateway if MTU larger than 4096 (Jumbo Frames) is configured on an interface.

  17. Since "Compliance" blade is a Management blade, it cannot be activated in VSX Gateway / VSX Cluster object.
    "Compliance" blade supports VSX Gateways / VSX Clusters running R77.20 and above.
    By design, the "Security Best Practices" for "Gaia OS" are not checked on VSX Gateways / VSX Clusters.
    Refer to sk92861 - ATRG: Compliance Blade.

  18. This blade is supported only by R76SP.40 and above.
    Follow the instructions in sk111405 - 60000 / 40000 Appliances - How to enable Threat Emulation blade on R76SP.40 and R76SP.50.

 

Related documentation:

Related solutions:

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment