<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/233334#M38975</link>
    <description>&lt;P&gt;So I'm kind in the same situation but for me it's not working.&lt;BR /&gt;I separated mplane from dplane according to the (poorly documented) sk138672.&lt;/P&gt;&lt;P&gt;Right now the management plane is isolated which is good. BUT as this is done is software I have some strange issues:&lt;/P&gt;&lt;P&gt;Packets originating from the management interface traverse the management plane and lands on dplane to be processed by the firewall. dplane recognise the source IP and it's marking it as spoofed. if MDPS is to fully isolate the network. This breaks almost everything like DNS, AD for Gaia LDAP AD binding,&amp;nbsp; TACACS.&amp;nbsp; SMS still works because due to an "error" is in the same network &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but otherwise it will fail.&lt;/P&gt;&lt;P&gt;THe inbound traffic originating from inside the network (from one of many internal interfaces) arrives in DP where is processed but due to "mdps_tun" the traffic is sent over to mplane. Of course, as MDPS has a default route, traffic is sent over the default route, which lands on dplane and flow is broken due to symmetry issues.&lt;/P&gt;&lt;P&gt;So basically from the internal network I cannot access the management interface).&lt;/P&gt;&lt;P&gt;I know it's software but still.&amp;nbsp; MDPS should be a real isolation.&amp;nbsp;&lt;BR /&gt;I'm thinking on switching to a dedicated VSX just for managemnet but.. as everything is in place right now, removing mdps will be a mess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2024 20:56:50 GMT</pubDate>
    <dc:creator>melcu</dc:creator>
    <dc:date>2024-11-20T20:56:50Z</dc:date>
    <item>
      <title>Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/223926#M37322</link>
      <description>&lt;P&gt;Hello All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning to replace ASA with Check Point and are looking for an equivalent command in Check Point for the ASA management-only command.&lt;/P&gt;&lt;P&gt;We have already reviewed the information about this MDPS site,(sk138672)&lt;/P&gt;&lt;P&gt;but other threads (from 2022) mention that it has many bugs,&lt;/P&gt;&lt;P&gt;which makes us hesitant to use it. Have all these issues been resolved by lateset R81.20?&lt;/P&gt;&lt;P&gt;Do you have any information on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all the advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 03:05:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/223926#M37322</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2024-08-19T03:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/223981#M37328</link>
      <description>&lt;P&gt;What are the specific concerns you have with MDPS?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 13:35:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/223981#M37328</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-19T13:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/226292#M37779</link>
      <description>&lt;P&gt;move to vsx, same goal, much more support and reliability&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 15:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/226292#M37779</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-09-11T15:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/226299#M37784</link>
      <description>&lt;P&gt;One of my colleagues did this for a customer in R81.20 and they are happy with it. No issues so far.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 17:17:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/226299#M37784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-11T17:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns  Regarding the Use of MDPS in the Migrate  to CheckPoint</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/233334#M38975</link>
      <description>&lt;P&gt;So I'm kind in the same situation but for me it's not working.&lt;BR /&gt;I separated mplane from dplane according to the (poorly documented) sk138672.&lt;/P&gt;&lt;P&gt;Right now the management plane is isolated which is good. BUT as this is done is software I have some strange issues:&lt;/P&gt;&lt;P&gt;Packets originating from the management interface traverse the management plane and lands on dplane to be processed by the firewall. dplane recognise the source IP and it's marking it as spoofed. if MDPS is to fully isolate the network. This breaks almost everything like DNS, AD for Gaia LDAP AD binding,&amp;nbsp; TACACS.&amp;nbsp; SMS still works because due to an "error" is in the same network &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but otherwise it will fail.&lt;/P&gt;&lt;P&gt;THe inbound traffic originating from inside the network (from one of many internal interfaces) arrives in DP where is processed but due to "mdps_tun" the traffic is sent over to mplane. Of course, as MDPS has a default route, traffic is sent over the default route, which lands on dplane and flow is broken due to symmetry issues.&lt;/P&gt;&lt;P&gt;So basically from the internal network I cannot access the management interface).&lt;/P&gt;&lt;P&gt;I know it's software but still.&amp;nbsp; MDPS should be a real isolation.&amp;nbsp;&lt;BR /&gt;I'm thinking on switching to a dedicated VSX just for managemnet but.. as everything is in place right now, removing mdps will be a mess.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 20:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Concerns-Regarding-the-Use-of-MDPS-in-the-Migrate-to-CheckPoint/m-p/233334#M38975</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-11-20T20:56:50Z</dc:date>
    </item>
  </channel>
</rss>

