> Source: [sk122955](https://support.checkpoint.com/results/sk/sk122955)

# sk122955 - Changing private network mask of VSX Gateway/Cluster to add more interfaces fails

| Property | Value |
|----------|-------|
| Solution ID | sk122955 |
| Date Created | 2018-02-16 |
| Last Modified | 2018-02-18 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Upon execution of the `'vsx_util change_private_net'` command and following the prompt the execution exits with error:  
`"new cluster private network doesn't match private network mask v4 255.255.240.0 v6 ffff:ffff:ffff:ffff:ffff::
Aborting operation change cluster private network..."`

## Cause

When managed by an R77.X Management server you could use the 192.168.196.0 network and only change the netmask to /20.

When managed by an R80.X Management server this is no longer the case as the network 192.168.196.0 cannot be used for a /20. When using a subnet calculator it shows that you should use this network instead : 192.168.192.0/20

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
