<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP on Maestro - Tips? in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154738#M1081</link>
    <description>&lt;P&gt;BGP configuration in Maestro does not really differ from a regular gateway (except for the limitations you already found).&lt;BR /&gt;In Maestro one SGM is a dedicated DR manager. In the current software versions it's always the SMO. It takes care of peering and adjacencies. When you run "show bgp peers" for example, you should do it on the DR manager. Also routing logs are stored on that blade. Routes are naturally synchronized to all members.&lt;BR /&gt;&lt;BR /&gt;MDPS will be supported in R81.20.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 20:54:57 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2022-08-08T20:54:57Z</dc:date>
    <item>
      <title>BGP on Maestro - Tips?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154728#M1079</link>
      <description>&lt;P&gt;I've set up BGP many times on standard Check Point gateways including clustered ones, but have a client that will be looking to configure it in a Maestro R81.10 environment that is single site with dual orchestrators and non-chassis gateways.&amp;nbsp; Any special tips/limitations to watch out for?&amp;nbsp; So far I have:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;BGP confederations are not supported&lt;/LI&gt;
&lt;LI&gt;BGP can't be used with VxLAN interfaces or GRE interfaces&lt;/LI&gt;
&lt;LI&gt;BGP Graceful Restart will need to be enabled (and timers match with the BGP peer) to avoid a flap during a Maestro failover&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any other Maestro-specific tips for BGP? Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9262"&gt;@Kim_Moberg&lt;/a&gt;&amp;nbsp;who has posted earlier about using BGP on Maestro.&lt;/P&gt;
&lt;P&gt;Has anyone had to manually affine a dedicated core for routed due to it not getting enough CPU slices and causing a flap during security policy installation to the Security Group or other kinds of high CPU load events?&amp;nbsp; Alas MDPS is not supported on Maestro...yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 15:49:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154728#M1079</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-08-08T15:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: BGP on Maestro - Tips?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154732#M1080</link>
      <description>&lt;P&gt;I think&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;can help with it, he is maestro guru.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 19:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154732#M1080</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-08T19:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: BGP on Maestro - Tips?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154738#M1081</link>
      <description>&lt;P&gt;BGP configuration in Maestro does not really differ from a regular gateway (except for the limitations you already found).&lt;BR /&gt;In Maestro one SGM is a dedicated DR manager. In the current software versions it's always the SMO. It takes care of peering and adjacencies. When you run "show bgp peers" for example, you should do it on the DR manager. Also routing logs are stored on that blade. Routes are naturally synchronized to all members.&lt;BR /&gt;&lt;BR /&gt;MDPS will be supported in R81.20.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 20:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/BGP-on-Maestro-Tips/m-p/154738#M1081</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2022-08-08T20:54:57Z</dc:date>
    </item>
  </channel>
</rss>

