Support Center > Search Results > SecureKnowledge Details
VSX supported features Technical Level
Solution

The VSX mode is supported only on Security Gateways that run on these Operating Systems:

  • Check Point Gaia OS (from R75.40VS and higher)
  • X-Series XOS (from R75.40VS to R77.30)

The table below shows the Software Blades and Features supported in the VSX mode (read the notes under the table).

Enter the string to filter this table:

Blade / Feature R75.40VS
Gaia
R76 (9)
Gaia
R76SP.X
Gaia
R77
Gaia
R77.10
Gaia
R77.20
Gaia
R77.30
Gaia
R80.10
Gaia
R80.20 / R80.30 / R80.40
Gaia

R81
Gaia

Software Blades
Firewall Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
IPS Blade Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes
IPSec VPN Blade Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Anti-Bot Blade Yes (1 , 2) Yes (1 , 2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes
Anti-Virus Blade Yes (1 , 2) Yes (1 , 2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes (2) Yes
Traditional Anti-Virus Blade No No No No No No No No No No
Threat Emulation Blade No No Yes (2 , 17) No No Yes (2) Yes (2) Yes (2) Yes (2) Yes
Threat Extraction Blade (sk101553) No No No No No No No Yes Yes Yes
Anti-Spam and Email Security Blade No No No No No No No No No No
Data Loss Prevention (DLP) Blade No No No No No No No No No No
Application Control Blade Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes
URL Filtering Blade Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes (10) Yes
Content Awareness No No No No No No No Yes Yes Yes
Legacy URL Filtering Blade No No No No No No No No No No
Identity Awareness Blade Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Monitoring Blade Yes (1) Yes (1)   Yes Yes Yes Yes Yes Yes Yes
Mobile Access Blade Supported
partially (1 , 3)
Supported
partially (1 , 3)
No Supported
partially (1 , 3)
Yes Yes Yes Yes Yes Yes
QoS, Light Weight (CPQOS) (11)
(VSX has native QoS support)
Yes Yes No Yes Yes Yes Yes Yes Supported:
  • R80.20
  • R80.30 with 2.6.18 kernel
Not Supported:
  • R80.40
  • R80.30 with 3.10 kernel
No
QoS blade (Floodgate) No No No No No No No No No Yes
Compliance Blade No No No No No Yes (16) Yes (16) Yes (16) Yes (16) Yes
All Management Blades No No No No No No No No No No
Global Features
Network Address Translation (NAT) Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
SecureXL Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
CoreXL Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Dynamic Routing Yes (4) Yes (4) Yes Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes (4) Yes
Source Based Routing on Virtual Router Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Policy Based Routing (PBR) on Virtual Router Yes (14) Yes (14) Yes (14) Yes (14) Yes (14) Yes (14) Yes (14) Yes (14) Yes (14) Yes
SNMP Per Virtual System using SNMPv3 Yes (1) Yes (1) Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes
DHCP Client No No No No No No No No No No
DHCP Relay Yes Yes (1) Yes Yes (1) Yes Yes Yes Yes Yes Yes
DHCP Server Yes (1 , 5) Yes (1 , 5) Yes (5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1 , 5) Yes (1,5)
NTP Client Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
NTP Server No (12) No (12) No (12) No (12) No (12) No (12) No (12) No (12) No (12) No
Security Servers Yes (1) Yes (1) Yes Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes (1) Yes
Jumbo Frames Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes (15) Yes
Rule Hit Count Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
UserCheck
(supported for Application Control / URL Filtering / Identity Awareness blades)
Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes
Gaia Portal Yes (1 , 6) Yes (1 , 6) No Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes (1 , 6) Yes
Gaia OS "Cloning Groups" No (13) No (13) No (13) No (13) No (13) No (13) No (13) No (13) No (13) No
StandAlone Configuration No No No No No No No No No No
IPv6 No Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes (7) Yes
VRRP No (8) No (8) No (8) No (8) No (8) No (8) No (8) No (8) No (8) No
VPN Link Selection No No No No No No No No No No
VPN VTI No No No No No No No No No Yes
Suspicious Activity Monitoring (SAM) Rules No No No No No No No No No No
Malicious Activity Detection (MAD) No No No No No No No No No No
Connect Control No No No No No No No No No No
ISP Redundancy No No No No No No No No No No
SmartUpdate No No No No No No No No No No
SmartProvisioning / SmartLSM No No No No No No No No No No
SmartWorkflow on Security Management Server /
Multi-Domain Security Management Server
No No No No No No No No No No
Database Revision Control on Security Management Server /
Multi-Domain Security Management Server (sk65420)
No No No No No No No No No No
Multi Bridge (support for multiple bridge interfaces
on a Virtual System in Bridge Mode)
No No No No No No Yes (11) Yes (11) Yes (11) Yes
Anti-Virus archive scanning No No No No No No Yes Yes Yes Yes
Threat Emulation archive scanning No No No No No No Yes Yes Yes Yes
Mail Transfer Agent (MTA) support for Threat Emulation No No No No No No No Yes Yes Yes
SecureXL Penalty Box No No No No No No No No Yes Yes
Resource Control

CPU monitoring per Virtual System

(the 'vsx resctrl' command)

Yes Yes Yes Yes Yes Yes Yes Yes

Supported

  • R80.10
  • R80.20
  • R80.30 with kernel 2.6.18

Not Supported

  • R80.40 - use the CPView utility
  • R80.30 with kernel 3.10

No

Use the CPView utility

Memory monitoring per Virtual System

(the 'vsx mstat' command)

Yes Yes Yes Yes Yes Yes Yes Yes

Yes

From R80.40, use the CPView utility

Yes

Use the CPView utility

CPU enforcement per Virtual System
(known as Resource Control Enforcer in VSX R6x versions)

No No No No No No No No No No

Memory enforcement per Virtual System
(known as Resource Control Enforcer in VSX R6x versions)

No No No No No No No No No No
Virtual System in Bridge Mode
Refer to sk101371 - Bridge Mode on Gaia OS and SecurePlatform OS.
Additional Features
Merging VSX objects using cp_merge utility (sk33751) No No No No No No No No No No
Alias / Secondary IP address No No No No No No No No No No
ECMP (Static Routes) No No No No No No No No No No
CoreXL Dynamic Dispatcher (sk105261) No No No No No No No No Yes Yes
CoreXL Dynamic Balancing (sk164155) No No No No No No No No No No
LLDP N / A N / A N / A N / A N / A N / A N / A N / A N / A No

Notes:

  1. This Software Blade / Feature is not supported on X-Series XOS.

  2. Refer to sk106496 - Software Blades updates - FAQ.

  3. Mobile Access Software Blade is supported partially.
    Refer to:

  4. X-Series XOS uses its own routing suite (Gaia OS uses the RouteD daemon).

  5. DHCP Server is supported only for the VSX Gateway itself - in the context of VS0.

  6. Gaia Portal is supported only to run the Gaia 'First Time Configuration Wizard'.

  7. IPv6 is supported with these limitations:

    • Pure IPv6 is not supported (must have IPv4 addresses assigned) - applies only to Clusters.
    • IPv6 is not supported on Virtual Routers.
  8. VRRP cluster in VSX mode is supported only on X-Series XOS.

  9. For information about 60000 / 40000 Security Systems, refer to the corresponding Release Notes (41000, 44000, 61000, 64000) - chapter "System Requirements" - section "Gateway Requirements" - subsection "Supported Software Blades".

  10. Refer to sk106496 - Software Blades updates - FAQ and to R77 versions VSX Administration Guide.

  11. Refer to the VSX Administration Guide for your version (R80.40 and lower).

  12. Refer to sk32027 - NTP Server support on Gaia and SecurePlatform OS.

  13. Refer to sk97494 - Gaia "Cloning Groups" are not supported on Security Gateway in VSX mode.

  14. Refer to sk100500 - Policy-Based Routing (PBR) on Gaia OS.

  15. Refer to sk110351 - Traffic latency on VSX Gateway if MTU larger than 4096 (Jumbo Frames) is configured on an interface.

  16. Because "Compliance" Software Blade is a Management blade, it cannot be activated in a VSX Gateway / VSX Cluster object.
    "Compliance" Software Blade supports VSX Gateways / VSX Clusters running R77.20 and higher.
    By design, the "Security Best Practices" for "Gaia OS" are not checked on VSX Gateways / VSX Clusters.
    Refer to sk92861 - ATRG: Compliance Blade.

  17. This Software Blade is supported only by R76SP.40 and higher.
    Follow the instructions in sk111405 - 60000 / 40000 Appliances - How to enable Threat Emulation blade on R76SP.40 and R76SP.50.

 

Related documentation:

Related solutions:

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment