> Source: [sk109776](https://support.checkpoint.com/results/sk/sk109776)

# sk109776 - Option to allow out of state packets per VS

| Property | Value |
|----------|-------|
| Solution ID | sk109776 |
| Date Created | 2016-01-24 |
| Last Modified | 2019-11-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * When choosing to allow out of state packets on a specific object, the object is identified by its IP addresses. On VSX machines, interfaces can be shared between the VSs causing different VSs to have the same IP addresses. Then, choosing one VS will enable out of state packets on other VSs.  

* The `fw getifs` command prints interface with IP address as "no IP":   

  Example:

  ```
  
  [Expert@HostName]# fw -d getifs
  [ PID ...[DATE TIME] run_full_fw: running original fw:
  ...
  [ PID ...[DATE TIME]  fw_getifs: filter interface eth0 - no IP    
  [ PID ...[DATE TIME]  fw_getifs: filter interface eth1 - no IP
  localhost eth0 10.26.1.16 255.255.255.0
  localhost eth1 10.26.2.26 255.255.255.0   
  ```

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
