Support Center > Search Results > SecureKnowledge Details
VSX supported features Technical Level
Solution

The table below shows the Software Blades and Features supported in the VSX mode (read the notes under the table).

Enter the string to filter this table:

Blade / Feature R81.10 R81 R80.40 R80.30SP R80.30 R80.20SP R80.20
Software Blades
Firewall Yes Yes Yes Yes Yes Yes Yes
IPS Blade Yes Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
IPSec VPN Blade Yes Yes Yes Yes (IPv4 only) Yes Yes (IPv4 only) Yes
Anti-Bot Blade Yes Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
Anti-Virus Blade Yes Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
Traditional Anti-Virus Blade No No No No No No No
Threat Emulation Blade Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1)
Threat Extraction Blade (sk101553) Yes Yes Yes Yes Yes Yes Yes
Anti-Spam and Email Security Blade No No No No No No No
Data Loss Prevention (DLP) Blade No No No No No No No
Application Control Blade Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4)
URL Filtering Blade Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4)
Content Awareness Blade Yes Yes Yes Yes Yes Yes Yes
Legacy URL Filtering Blade No No No No No No No
Identity Awareness Blade Yes Yes Yes Yes Yes Yes Yes
Monitoring Blade Yes Yes Yes Yes Yes Yes Yes
Mobile Access Blade Yes Yes Yes Yes Yes Yes Yes
QoS Feature, Light Weight (CPQOS - VSX native QoS) No No No No only R80.30 with kernel 2.6.18 Yes only R80.20 with kernel 2.6.18
QoS Blade (Floodgate) Yes Yes No No No No No
Compliance Blade Yes (9) Yes (9) Yes (9) Yes (9) Yes (9) Yes (9) Yes (9)
All Management Blades No No No No No No No
Management Features
Dedicated Management Interface (DMI) (11) Yes Yes Yes Yes Yes Yes Yes
Non-Dedicated Management Interface (Non-DMI) No No Yes Yes Yes Yes Yes
Management behind NAT (12) No No No No No No No
Management through a Virtual System (13) No No No No No No No
Global Features
Network Address Translation (NAT) Yes Yes Yes Yes Yes Yes Yes
NAT64 and NAT46 objects in Access Control Policy No No No No No No No
SecureXL Yes Yes Yes Yes Yes Yes Yes
CoreXL Yes Yes Yes Yes Yes Yes Yes
Dynamic Routing Yes Yes Yes Yes Yes Yes Yes
Source Based Routing on Virtual Router Yes Yes Yes Yes Yes Yes Yes
Policy Based Routing (PBR) on Virtual Router Yes (8) Yes (8) Yes (8) Yes (8) Yes (8) Yes (8) Yes (8)
SNMP Per Virtual System using SNMPv3 Yes Yes Yes Yes Yes Yes Yes
DHCP Client No No No No No No No
DHCP Relay Yes Yes Yes Yes Yes Yes Yes
DHCP Server No No No No No No No
NTP Client Yes Yes Yes Yes Yes Yes Yes
NTP Server No No No (6) No (6) No (6) No (6) No (6)
Mirror and Decrypt Yes Yes Yes Yes Yes Yes Yes
ICAP Client Yes Yes Yes Yes Yes Yes Yes
ICAP Server No No No No No No No
Security Servers Yes Yes Yes Yes Yes Yes Yes
Jumbo Frames Yes Yes Yes Yes Yes Yes Yes
Rule Hit Count Yes Yes Yes Yes Yes Yes Yes
UserCheck
(supported for Application Control / URL Filtering / Identity Awareness blades)
Yes Yes Yes Yes Yes Yes Yes
Gaia Portal Yes (10) Yes (10) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2)
Gaia OS "Cloning Groups" No (7) No (7) No (7) No (7) No (7) No (7) No (7)
StandAlone Configuration No No No No No No No
IPv6 Yes Yes Yes (3) Yes (3) Yes (3) Yes (3) Yes (3)
VRRP No No No No No No No
VPN Link Selection No No No No No No No
VPN VTI Yes Yes No No No No No
Suspicious Activity Monitoring (SAM) Rules No No No No No No No
Malicious Activity Detection (MAD) No No No No No No No
Connect Control No No No No No No No
ISP Redundancy No No No No No No No
SmartUpdate No No No No No No No
SmartProvisioning / SmartLSM No No No No No No No
SmartWorkflow on Security Management Server / Multi-Domain Security Management Server No No No No No No No
Database Revision Control on Security Management Server / Multi-Domain Security Management Server (sk65420) No No No No No No No
Multi Bridge (support for multiple bridge interfaces
on a Virtual System in Bridge Mode)
Yes Yes Yes (5) Yes (5) Yes (5) Yes (5) Yes (5)
Anti-Virus archive scanning Yes Yes Yes Yes Yes Yes Yes
Threat Emulation archive scanning Yes Yes Yes Yes Yes Yes Yes
Mail Transfer Agent (MTA) support for Threat Emulation Yes Yes Yes Yes Yes Yes Yes
SecureXL Penalty Box Yes Yes Yes Yes Yes Yes Yes
DNS per VS Yes Yes N / A N / A N / A N / A N / A
VS with Bridge interface Yes Yes N / A N / A N / A N / A N / A
Resource Control

CPU monitoring per Virtual System

(the 'vsx resctrl' command)

No

Use the CPView utility

No

Use the CPView utility

No

Use the CPView utility

No

Use the CPView utility

only R80.30 with kernel 2.6.18

Yes

only R80.20 with kernel 2.6.18

Memory monitoring per Virtual System

(the 'vsx mstat' command)

Yes

Use the CPView utility

Yes

Use the CPView utility

Yes

Use the CPView utility

Yes

Yes

Yes

Yes

CPU enforcement per Virtual System
(known as Resource Control Enforcer in VSX R6x versions)

No No No No No No No

Memory enforcement per Virtual System
(known as Resource Control Enforcer in VSX R6x versions)

No No No No No No No
Virtual System in Bridge Mode
Refer to sk101371 - Bridge Mode on Gaia OS and SecurePlatform OS.
Additional Features
Merging VSX objects using cp_merge utility (sk33751) No No No No No No No
Alias / Secondary IP address No No No No No No No
ECMP (Static Routes) No No No No No No No
CoreXL Dynamic Dispatcher (sk105261) Yes Yes Yes Yes Yes Yes Yes
CoreXL Dynamic Balancing (sk164155) See sk164155 See sk164155 See sk164155 No No No No
LLDP No No N / A N / A N / A N / A N / A

Notes:

  1. For this version, refer to sk106496 - Software Blades updates - FAQ.

  2. In this version, Gaia Portal is supported only to run the Gaia 'First Time Configuration Wizard'.

  3. In this version, IPv6 is supported with these limitations:

    • Pure IPv6 is not supported (must have IPv4 addresses assigned) - applies only to Clusters.
    • IPv6 is not supported on Virtual Routers.
  4. For this version, refer to sk106496 - Software Blades updates - FAQ and to the VSX Administration Guide for your version.

  5. For this version, refer to the VSX Administration Guide for your version.

  6. For this version, refer to sk32027 - NTP Server support on Gaia and SecurePlatform OS.

  7. For this version, refer to sk97494 - Gaia "Cloning Groups" are not supported on Security Gateway in VSX mode.

  8. For this version, refer to sk100500 - Policy-Based Routing (PBR) on Gaia OS.

  9. Because "Compliance" Software Blade is a Management blade, you cannot activate it in a VSX Gateway / VSX Cluster object.
    By design, the "Security Best Practices" for "Gaia OS" are not checked on VSX Gateways / VSX Clusters.
    Refer to sk92861 - ATRG: Compliance Blade.

  10. In this version, Gaia Portal is supported only to install CPUSE packages.

  11. Dedicated Management Interface (DMI) management is not supported through a physical interface (on the VSX Gateway / VSX Cluster Member) that has one or more VLAN interfaces configured.

  12. NAT is not supported between the Management Server and the managed VSX Gateway / VSX Cluster.
    It is not supported to manage a VSX Gateway / VSX Cluster in these cases:

    • When the Management Server is behind NAT
    • When the VSX Gateway / VSX Cluster is behind NAT
  13. It is not supported to manage a VSX Gateway / VSX Cluster when the management traffic passes through a Virtual System on the same VSX Gateway / VSX Cluster. Only VS0 can communicate directly with the Management Server.

 

Related documentation:

 

Related solutions:

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment