<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196793#M2302</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37494"&gt;@CHRO&lt;/a&gt;thanks for the feedback. What flavor can I use and how/where is the Bond configured?&lt;/P&gt;</description>
    <pubDate>Wed, 01 Nov 2023 09:32:29 GMT</pubDate>
    <dc:creator>Kilian_Huber</dc:creator>
    <dc:date>2023-11-01T09:32:29Z</dc:date>
    <item>
      <title>Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196737#M2297</link>
      <description>&lt;P&gt;Hello Maestro Masters,&lt;/P&gt;&lt;P&gt;I have a question regarding the use of bonded interfaces on the MHO for SMO management traffic.&lt;/P&gt;&lt;P&gt;consider the following setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Dual Site and Dual Orchestrator Setup (MHO-140)&lt;/LI&gt;&lt;LI&gt;2 Security Groups, deployed as VSX&lt;/LI&gt;&lt;LI&gt;Management Port 1 on the Orchestrators connected to a network switch&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The following layout illustrates the setup (for simplicity, the layout contains only one site):&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Maestro-Dual-Orch-magg.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23015iD056F66EEDAAAEFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Maestro-Dual-Orch-magg.png" alt="Maestro-Dual-Orch-magg.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this setup, both security groups share a physical Management port.&lt;/P&gt;&lt;P&gt;According to the &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Configuring-Bond-Interface-on-Management-Ports.htm" target="_self"&gt;Admin Guide&lt;/A&gt;, configuring a Bond interface on the Management port is possible. Step 3 of Use Case - Editing an Existing Security Group states:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Connect through the console port to the Security Appliance with Member ID 1 in this Security Group.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This indicates that the Bonding interface is created on the Security Group level. As a consequence, this means that the Bond is only available to one Security Group. When using LACP, this is a known limitation (ID: 02003875 and PMTR-97008).&lt;/P&gt;&lt;P&gt;My question is: is there another way to achieve the desired setup (ACTIVE/BACKUP Bond) or do we need to use physical Mgmt uplinks for every Security Group?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 15:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196737#M2297</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-10-31T15:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196752#M2298</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11725"&gt;@Kilian_Huber&lt;/a&gt;&amp;nbsp;Please check your design, are you sure you are running a dual site environment? In dual site environment there is no connection from SGMs to the MHO on the other site. In a dual site environment &amp;nbsp;you have an active/passive MGMT port between one MGMT interface (same interface on both sites). If you need a bond, you have to use only ports from one site, meaning eth1-mgmt &amp;amp; eth2-mgmt from one site. The same bond is created automatically on the other site, but this comes active only if a site failover occurs.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 18:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196752#M2298</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-10-31T18:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196784#M2299</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;. As I wrote: "for simplicity, the layout contains only one site".&lt;/P&gt;&lt;P&gt;The full setup looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Maestro-Dual-Orch-Dual-Site-magg.png" style="width: 620px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23017i29C2D554CCD5F941/image-size/large?v=v2&amp;amp;px=999" role="button" title="Maestro-Dual-Orch-Dual-Site-magg.png" alt="Maestro-Dual-Orch-Dual-Site-magg.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 07:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196784#M2299</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-11-01T07:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196785#M2300</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11725"&gt;@Kilian_Huber&lt;/a&gt;&amp;nbsp;thanks for more detailed description. As I know the limitation &lt;SPAN&gt;PMTR-97008&amp;nbsp;&lt;/SPAN&gt;exist only for a bond with LACP as bonding protocol. active/backup- or XOR-BOND should work.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;please, can you assist and confirm.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 07:45:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196785#M2300</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-11-01T07:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196792#M2301</link>
      <description>&lt;P&gt;MAGG (bond of management interfaces) working in LACP mode is supported from R81.10&lt;/P&gt;
&lt;P&gt;However, sharing between security group of this MAGG or its slaves is NOT supported you must use an alternate Bond flavor in such cases.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAGG.PNG" style="width: 532px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23018iE409E64BAC60D921/image-size/large?v=v2&amp;amp;px=999" role="button" title="MAGG.PNG" alt="MAGG.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Refer also:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topics-GAG/MAGG.htm" target="_blank"&gt;MAGG Interfaces (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 09:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196792#M2301</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-01T09:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196793#M2302</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37494"&gt;@CHRO&lt;/a&gt;thanks for the feedback. What flavor can I use and how/where is the Bond configured?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2023 09:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196793#M2302</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-11-01T09:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196973#M2303</link>
      <description>&lt;P&gt;Which flavour of the bond depends on your switch infrastructure. Active/backup does work with most of the switch vendors and setting xmit-hash-polish to MAC address will be fine for the VSX management magg. You can follow the configuration guide mentioned by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;. Magg is configured via your SG.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 20:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196973#M2303</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-11-02T20:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196974#M2304</link>
      <description>&lt;P&gt;Okay, and if the magg is shared accross several SGs, it needs to be configured on every SG. Correct?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 20:20:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196974#M2304</guid>
      <dc:creator>Kilian_Huber</dc:creator>
      <dc:date>2023-11-02T20:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196977#M2305</link>
      <description>&lt;P&gt;Yes, you have to configure this on every SG. You have to configure an own IP-address for every SecurityGroup and they get assigned an own MAC-address.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2023 20:39:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/196977#M2305</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-11-02T20:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Mastro Mgmt Bond (magg) - dual Orchestrator and multiple Security Groups</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/261229#M3756</link>
      <description>&lt;P&gt;Hello Kilian,&amp;nbsp;Could you make these stencils available in that custom pink color, matching Checkpoint's colors?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 01:22:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Mastro-Mgmt-Bond-magg-dual-Orchestrator-and-multiple-Security/m-p/261229#M3756</guid>
      <dc:creator>Tchangoloro</dc:creator>
      <dc:date>2025-10-29T01:22:47Z</dc:date>
    </item>
  </channel>
</rss>

