<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint management plane data plane in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235161#M5100</link>
    <description>&lt;P&gt;In case it's unclear hit the following link in the article intro section and you'll see more "&lt;SPAN&gt;Click Here to Show the Entire Article" as it appears to be collapsed by default.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Dec 2024 11:53:28 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-12-10T11:53:28Z</dc:date>
    <item>
      <title>Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235152#M5097</link>
      <description>&lt;P&gt;Hi is there a resource that explains the basics about Checkpoint management plane data plane clearly and simply (including cli setup) for a beginner ? I can't find anything.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 10:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235152#M5097</guid>
      <dc:creator>daz10</dc:creator>
      <dc:date>2024-12-10T10:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235155#M5098</link>
      <description>&lt;P&gt;this SK does&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk138672" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk138672&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 10:28:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235155#M5098</guid>
      <dc:creator>toblun</dc:creator>
      <dc:date>2024-12-10T10:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235159#M5099</link>
      <description>&lt;P&gt;I was after more of an explanation/theory with say an example rather than 'cold' commands.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 11:01:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235159#M5099</guid>
      <dc:creator>daz10</dc:creator>
      <dc:date>2024-12-10T11:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235161#M5100</link>
      <description>&lt;P&gt;In case it's unclear hit the following link in the article intro section and you'll see more "&lt;SPAN&gt;Click Here to Show the Entire Article" as it appears to be collapsed by default.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 11:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235161#M5100</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-10T11:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235173#M5101</link>
      <description>&lt;P&gt;Is this in a specific CSP (AWS, Azure or GCP)?&lt;/P&gt;
&lt;P&gt;Do you have a requirement or a use case for it?&lt;/P&gt;
&lt;P&gt;It doesn't seem like something that would be commonly demanded in CloudGuard (the question is posted is the CloudMates Forum).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 12:55:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235173#M5101</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2024-12-10T12:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235240#M5103</link>
      <description>&lt;P&gt;I asked&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41528"&gt;@CheckMatesAI&lt;/a&gt;&amp;nbsp;for an answer, and it provided little more than a link to &lt;A href="https://support.checkpoint.com/results/sk/sk138672" target="_self"&gt;sk138672&lt;/A&gt;&amp;nbsp;and to CheckMates &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In simple terms, MDPS dedicates one of the cores on the security gateway to the following functions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Access to the Gateway Itself&lt;/STRONG&gt;: SSH, FTP, and more&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Provisioning&lt;/STRONG&gt;: Policy installation, Gaia Portal, REST API&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Monitoring&lt;/STRONG&gt;: Logs, SNMP&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Normally, these functions run on processes on cores that are shared with cores that process traffic.&lt;BR /&gt;MDPS also provides a separate routing table for these functions as well as others you can configure.&lt;/P&gt;
&lt;P&gt;If you're experiencing issues with these functions and the gateways operate under significant load, MDPS can be helpful.&lt;BR /&gt;It's important to understand the known limitations should you choose to enable it.&lt;BR /&gt;In most situations, MDPS is not necessary.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 19:59:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235240#M5103</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-10T19:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint management plane data plane</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235420#M5106</link>
      <description>&lt;P&gt;Here's an explanation from another LLM:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Understanding Management Dataplane Separation (MDPS)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;U&gt;Core Concept&lt;/U&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Management Data Plane Separation (MDPS) is a security feature that separates administrative traffic from regular network traffic on Check Point Security Gateways, similar to having dedicated lanes on a highway for different types of vehicles.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;STRONG&gt;The Two Planes&lt;/STRONG&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;U&gt;Management Plane&lt;/U&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Handles all administrative functions:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; System access (SSH, FTP)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Policy installation and configuration&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; System monitoring (logs, SNMP)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;U&gt;Data Plane&lt;/U&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Manages regular network operations:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; User traffic (web, email, files)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Application communications&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Network services&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;STRONG&gt;Implementation Methods&lt;/STRONG&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;1.&lt;/SPAN&gt; &lt;SPAN&gt;**Routing Separation**&lt;/SPAN&gt;&lt;SPAN&gt;: Creates a dedicated routing domain for management traffic, preventing any cross-communication between planes.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;SPAN&gt;2.&lt;/SPAN&gt; &lt;SPAN&gt;**Resource Separation**&lt;/SPAN&gt;&lt;SPAN&gt;: Allocates dedicated CPU resources for management functions (requires 4+ CPU cores).&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;U&gt;Key Benefits&lt;/U&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Enhanced security through traffic isolation&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Improved performance by preventing management tasks from affecting regular operations&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt; Easier troubleshooting with clear separation of functions&lt;/SPAN&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV&gt;&lt;BR /&gt;So basically you separate the 'brain' and 'muscle' (veeery vaguely) on the gateway so that bad guys have to work twice as hard to get into management related parts and make bad changes. Implementation and configuration details will be in &lt;A href="https://support.checkpoint.com/results/sk/sk138672" target="_self"&gt;sk138672&lt;/A&gt;.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Dec 2024 07:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Checkpoint-management-plane-data-plane/m-p/235420#M5106</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-12-12T07:35:58Z</dc:date>
    </item>
  </channel>
</rss>

