<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro Masters Round Table - Selected Questions, Part 1 in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152987#M1036</link>
    <description>&lt;P&gt;Penalty - Bandwidth use for actual traffic - 90%, if 10% is set aside for MHO to SGM traffic.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2022 13:39:14 GMT</pubDate>
    <dc:creator>d1d7baba-eaca-4</dc:creator>
    <dc:date>2022-07-14T13:39:14Z</dc:date>
    <item>
      <title>Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/151464#M976</link>
      <description>&lt;P&gt;Before our &lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-Masters-Round-Table-June-2022-Video-Slides-and-Q-amp-A/m-p/151394#M959" target="_self"&gt;Maestro Masters Round Table event&lt;/A&gt;, we have asked you to send us some questions in advance.&lt;BR /&gt;&lt;BR /&gt;We will gradually post those questions and answers to them in this space. Here is the first batch.&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp;What would be the best way to size the Maestro environment?&lt;/P&gt;
&lt;P&gt;A:&amp;nbsp;It depends on metrics. Regarding Throughput and connection rate - the penalty is 1% of the total per each additional SGM in the security group. That means, if one SGM is 100%, 2x SGMs would be 200% -2%(200%)=196%&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp;How do I use tcpdump if traffic is being distributed between gateways?&lt;/P&gt;
&lt;P&gt;A:&amp;nbsp;In Maestro, we created global commands, such as g_tcpdump and g_fw commands. Using global commands, you can get a result from all SGMs simultaneously.&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp;Do you recommend taking Gaia snapshots of security groups as a best practice?&lt;/P&gt;
&lt;P&gt;A:&amp;nbsp;Definitely yes, and there is an option to run a snapshot command. You can also elect to take just a snapshot of a single appliance or to take snapshots of all members of the Security Group. You can use a snapshot from a single appliance of one to restore others.&lt;/P&gt;
&lt;P&gt;Q:&amp;nbsp;Is dynamic scaling supported?&amp;nbsp; If not, when will it be?&lt;/P&gt;
&lt;P&gt;A:&amp;nbsp;Auto-scaling will be supported for the next version, which is R81.20.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Stay tuned for more!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 12:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/151464#M976</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-06-22T12:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152830#M1032</link>
      <description>&lt;P&gt;Hi - From another Maestro Tech Talk, I think, I thought the penalty was 10% per interface that was devoted to MHO information shared with the SGMs.&amp;nbsp; Am I off on this thought?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 19:14:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152830#M1032</guid>
      <dc:creator>d1d7baba-eaca-4</dc:creator>
      <dc:date>2022-07-12T19:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152851#M1033</link>
      <description>&lt;P&gt;About the snapshots...&amp;nbsp; Snapshot is a disk image, which means that it is always local to an SGM. They should &amp;nbsp;be taken in CLISH instead of gclish as usually you don't want to take a snapshot simultaneously of all SGMs. While you do can take a snapshot of each SGM it's usually not necessary. SGMs are clones of each other and as long as you can restore one, the others will clone configuration and binaries including JHF from it. My recommendation typically is to take a snapshot of the SMO and save it on external location. If you want to take snapshots of all your SGMs, that's also fine, but takes a lot of disk space and most of the time is not necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 05:26:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152851#M1033</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2022-07-13T05:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152858#M1035</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6793"&gt;@d1d7baba-eaca-4&lt;/a&gt;&amp;nbsp;Penalty on what?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 06:44:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152858#M1035</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-13T06:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152987#M1036</link>
      <description>&lt;P&gt;Penalty - Bandwidth use for actual traffic - 90%, if 10% is set aside for MHO to SGM traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 13:39:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152987#M1036</guid>
      <dc:creator>d1d7baba-eaca-4</dc:creator>
      <dc:date>2022-07-14T13:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152997#M1037</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;&amp;nbsp;can you advise?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 14:05:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/152997#M1037</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-14T14:05:17Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153027#M1038</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6793" target="_blank"&gt;@d1d7baba-eaca-4&lt;/A&gt;&amp;nbsp;I think you mean the 10% bandwidth reservation on the downlinks for the MHO - SGM communication. But the penalty Val mentions in the Q&amp;amp;A is the 1% degradation per appliance when adding an appliance(s) to a Security Group. Basically those are two different things: One is a reservation on a downlink and the other is a cumulative penalty on a Security Group's overall performance.&lt;/P&gt;
&lt;P&gt;However, as far as I know we don't do the 10% reservation anymore.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 17:23:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153027#M1038</guid>
      <dc:creator>Sidney_Ross</dc:creator>
      <dc:date>2022-07-14T17:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153029#M1039</link>
      <description>&lt;P&gt;Sidney - Thanks for the clarification.&amp;nbsp; With respect to '&lt;SPAN&gt;bandwidth reservation on the downlinks for the MHO - SGM communication', if there is no 10% reservation, do you happen to know what it is, or what has taken it's place?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 17:49:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153029#M1039</guid>
      <dc:creator>d1d7baba-eaca-4</dc:creator>
      <dc:date>2022-07-14T17:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153201#M1041</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;honestly im new on Maestro and i got question from my existing customer :&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;if they have 2x5200 and wanna implement maestro, is it still possible? because i check on some literature, minimum of fw to implemented hyperscale is 3 fw. so need i buy MHO-140 + one more 5200?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If you have a link basic concept or free training for Maestro, please share with me.&amp;nbsp;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 09:52:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153201#M1041</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-07-18T09:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153205#M1042</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76092"&gt;@MtxMan&lt;/a&gt;, unfortunately, 5200 are not supported with Maestro. You need at least 5600. Please refer to&amp;nbsp;&lt;SPAN&gt;sk162373 for the list of all supported appliances and their combinations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That said, you can start with MHO and just two GW appliances, and then add them as needed, you do not have to have three of those from the start.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 10:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153205#M1042</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-18T10:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153208#M1043</link>
      <description>&lt;P&gt;Also, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76092"&gt;@MtxMan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the courses, we have Maestro Jump Start courses, available with multiple learning platforms free of charge.&lt;BR /&gt;&lt;BR /&gt;Look here to choose your options:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/Free-Online-Training-Choose-Your-Options/ba-p/89766?cat=10" target="_blank"&gt;https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/Free-Online-Training-Choose-Your-Options/ba-p/89766?cat=10&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 10:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153208#M1043</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-18T10:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153247#M1044</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou so much!&lt;/P&gt;&lt;P&gt;so if customer only have 2 GW, the behaviour just like clusterxl active-active?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 13:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153247#M1044</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-07-18T13:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Masters Round Table - Selected Questions, Part 1</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153254#M1045</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/76092"&gt;@MtxMan&lt;/a&gt;&amp;nbsp;Not "just like", much better than physical active-active clustering, thanks for MHO balancing and hypersync.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 14:22:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Masters-Round-Table-Selected-Questions-Part-1/m-p/153254#M1045</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-18T14:22:56Z</dc:date>
    </item>
  </channel>
</rss>

