<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro SG management interfaces bond in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76627#M150</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I bonded as Magg at first, it works fine (SG is reachable) and I am able to establish SIC from the Mgmt server. But after installing the policy, SG becomes unreachable from the MGMT and vice versa. Then, I bonded with LACP but still the same issue.&lt;BR /&gt;&lt;BR /&gt;Afterward, I removed the bond and assigned the IP on the physical interface then it works.&lt;BR /&gt;&lt;BR /&gt;It is a &amp;nbsp;GW, not a VSX.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Even I detached all the GWs and configured the FTW again from the Maestro web UI for all the attached GWs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I strictly followed the admin guide as well.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2020 19:07:37 GMT</pubDate>
    <dc:creator>Nischit</dc:creator>
    <dc:date>2020-02-27T19:07:37Z</dc:date>
    <item>
      <title>Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76624#M147</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I have 2 MHO 140 Orchestrators in redundancy. Its running on r80.20 SP. I have already installed the latest hotfix during the time of installation. &amp;nbsp; It's in a production environment deployed a week ago with 4 GW's. &amp;nbsp;I have configured bond interfaces for all the uplink connections and its working fine.&lt;BR /&gt;&lt;BR /&gt;I then created a bond for SG Management interfaces ( &amp;nbsp;eth1/1/1 eth1- Mgmt1 and eth2/1/1 eth1-Mgmt2) and its working. I am able to establish SIC with the Management server with the same bond interface IP address of SG. You will be able to install the policy successfully once. However, after the successful installation of the policy, the Management Server will no longer be able to reach the IP address of SG which is configured in the bond interface.&lt;BR /&gt;&lt;BR /&gt;Even, I am unable to browse the web GUI of SG. I then removed the bond interface and assigned new bond interface for SG mgmt and again the same issue. I am able to reach the mgmt server and able to establish SIC. Then after the policy installation, the mgmt server is unable to reach the SG IP address.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Then, I removed the bond interface of SG management interfaces and assigned an IP address on the physical Mgmt Interface of SG and it worked fine.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It seems like there is an issue if we bond the SG mgmt interfaces. It's working fine with the bonds created for uplink. Has anyone tried bonding the SG Mgmt Interfaces and tried installing policy from the Mgmt Server? &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Nischit&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 18:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76624#M147</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-27T18:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76625#M148</link>
      <description>&lt;P&gt;Yes, before I deployed for a customer a dual site deployment, we had it configured as single site with 2 MHOs and had the mgmt1 of both MHOs bonded as magg.&lt;/P&gt;
&lt;P&gt;How did you configure it? How/When was FTW run?&lt;/P&gt;
&lt;P&gt;Is it a GW or VSX?&lt;/P&gt;
&lt;P&gt;Which bonding mode are you using?&amp;nbsp;&lt;BR /&gt;Did you strictly follow admin guide? Because there’s a chapter about it.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 18:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76625#M148</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-02-27T18:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76626#M149</link>
      <description>&lt;A href="https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Maestro_GettingStartedGuide/Content/Topics/Configuring-Bond-Interface-on-Management-Ports.htm?tocpath=Configuration%20Procedure%7CSpecial%20Configuration%20Scenarios%7C_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Maestro_GettingStartedGuide/Content/Topics/Configuring-Bond-Interface-on-Management-Ports.htm?tocpath=Configuration%20Procedure%7CSpecial%20Configuration%20Scenarios%7C_____3&lt;/A&gt;</description>
      <pubDate>Thu, 27 Feb 2020 18:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76626#M149</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-02-27T18:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76627#M150</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I bonded as Magg at first, it works fine (SG is reachable) and I am able to establish SIC from the Mgmt server. But after installing the policy, SG becomes unreachable from the MGMT and vice versa. Then, I bonded with LACP but still the same issue.&lt;BR /&gt;&lt;BR /&gt;Afterward, I removed the bond and assigned the IP on the physical interface then it works.&lt;BR /&gt;&lt;BR /&gt;It is a &amp;nbsp;GW, not a VSX.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Even I detached all the GWs and configured the FTW again from the Maestro web UI for all the attached GWs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I strictly followed the admin guide as well.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 19:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76627#M150</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-27T19:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76631#M151</link>
      <description>Have a look at the basic setup manual v1.2 it holds all the info regarding the MAGG bonding for 2 MHO's in 1 site.&lt;BR /&gt;But at first glance I see where you went wrong, all eth1-xxx interfaces are on MHO1 while all eth2-xxx are on MHO2 so you need to build a bond between the eth1-Mgmt1 and eth2-Mgmt1&lt;BR /&gt;The way to build this would be like this procedure (I just found some typos in this part, sorry):&lt;BR /&gt;add bonding group 1 mgmt&lt;BR /&gt;set interface eth2-Mgmt1 state on&lt;BR /&gt;add bonding group 1 mgmt interface eth2-Mgmt1&lt;BR /&gt;set bonding group 1 mode active-backup&lt;BR /&gt;set interface magg1 ipv4-address 1.2.3.11 mask-length 26&lt;BR /&gt;set management interface magg1&lt;BR /&gt;delete interface eth1-Mgmt1 ipv4-address&lt;BR /&gt;add bonding group 1 mgmt interface eth1-Mgmt1&lt;BR /&gt;set bonding group 1 primary eth1-Mgmt1</description>
      <pubDate>Thu, 27 Feb 2020 23:10:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76631#M151</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-27T23:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76635#M152</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, I am aware of this, Eth1-xxx interfaces are on MHO1 while all eth2-xxx are on MHO2. I did the same. However, while writing in this community, I mentioned eth1-mgmt1 and eth1-mgmt2. I created a bond for eth1-mgmt1 and eth2-mgmt1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I followed the same steps as you mentioned earlier on but this didn't help so I posted over here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only issue is when I install the policy in mgmt server, the SG ip becomes unreachable.&lt;/P&gt;&lt;P&gt;I will try this again today and let you know. Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 02:07:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76635#M152</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T02:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76646#M153</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do magg in the Checkpoint then what config should I do in the switch side. Cause if I do bond with lacp, I configure the port channel interface and configure protocol-mode lacp.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 06:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76646#M153</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T06:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76647#M154</link>
      <description>MAGG also supports LACP with one of the latest JHF.&lt;BR /&gt;With older JHF only A/S and XOR (static) are supported.</description>
      <pubDate>Fri, 28 Feb 2020 06:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76647#M154</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-02-28T06:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76648#M155</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have installed the jumbo hot fix 191.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 06:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76648#M155</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T06:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76649#M156</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you told that you also configured bond using xor. So, what did you do on the switch side? Did it work with lacp on switch side?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 07:01:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76649#M156</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T07:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76650#M157</link>
      <description>&lt;P&gt;I just checked the JHF docs and LACP for MAGG is only supported since JHF 210.&lt;/P&gt;
&lt;P&gt;So you have too use XOR (which is often referred to as static bonding) or Active/Standby.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 07:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76650#M157</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2020-02-28T07:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76651#M158</link>
      <description>I configured the Bond Active Backup and the switch without bonding, just 2 access ports in the same VLAN.&lt;BR /&gt;I sounds like you have a problem that you are shutting yourself out by policy. You should still be able to get to the MHO itself and then jump to the SG with: m 1 1&lt;BR /&gt;</description>
      <pubDate>Fri, 28 Feb 2020 07:16:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76651#M158</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-28T07:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76653#M159</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuring bond with active backup and just connecting it to 2 access clans didn't work. Now, I am trying to bridge the mgmt interfaces and see if it works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 08:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76653#M159</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T08:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76655#M160</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Created a bridge interface for mgmt but still it didn't work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 08:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76655#M160</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T08:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76697#M161</link>
      <description>I di failover tests with it this way and it worked just fine for me.&lt;BR /&gt;As said I still think you FW policy is not allowing you in, you say that as soon as you install the policy it fails, so to me that really sounds like the policy is not allowing you and this has nothing to do with bonding or Maestro related issues.</description>
      <pubDate>Fri, 28 Feb 2020 13:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76697#M161</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-28T13:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76698#M162</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the update. I also thought it was the issue with policy so I also tested with any any allow rule. But still it didn't work for me.&lt;/P&gt;&lt;P&gt;I will figure out if there is something missing. If it's working in your test environment then it should work in my case as well. BTW, what is the management server OS version you are using? In my case it's r80.30 in mgmt server and it's r80.20 SP in the maestro and GWs&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 13:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76698#M162</guid>
      <dc:creator>Nischit</dc:creator>
      <dc:date>2020-02-28T13:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76710#M163</link>
      <description>I am running this against a R80.30 and a R80.40 MDS, I have 2 SG's running and the first is connected to the RT80.40, the other SG is hooked up to a CMA in the R80.30 MDS.</description>
      <pubDate>Fri, 28 Feb 2020 14:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/76710#M163</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-28T14:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/81639#M181</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Apr 2020 09:38:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/81639#M181</guid>
      <dc:creator>rolf</dc:creator>
      <dc:date>2020-04-12T09:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro SG management interfaces bond</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/118950#M492</link>
      <description>&lt;P&gt;Hi Nischit, we have the exact same setup and was curious if you got this working.&amp;nbsp; We are using both&amp;nbsp;&lt;SPAN&gt;eth1/1/1 (eth1- Mgmt1) and eth2/1/1 (eth1-Mgmt2) for management connectivity, however, we don't have a bond setup.&amp;nbsp; Only&amp;nbsp;eth1- Mgmt1 has the IP configured which we establish SIC with.&amp;nbsp; It is used as the internal interface of our FW cluster.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 16:39:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-SG-management-interfaces-bond/m-p/118950#M492</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2021-05-20T16:39:23Z</dc:date>
    </item>
  </channel>
</rss>

