<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switches? in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206727#M2434</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we are to deploying the Check Point Maestro with single site dual MHO. We know that Maestro is running on Active-Active mode, however the internal and external switch connected is actually a cascading switch which is not support creating any port channel or LACP like stacking switch. Meanwhile, in the design due to insufficient port, we must bond the interface from each security group to provide redundancy within MHO1 &amp;amp; MHO2, but we unable to&amp;nbsp;&lt;SPAN&gt;configure Bond&amp;nbsp;operating mode 802.3ad LACP (load sharing) with both link is Active-Active, it will have issue with cascading switch as it is not like stacking switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please refer to the diagram of the topology, MHO1 &amp;amp; MHO2 connecting straight link to switch 1 &amp;amp; switch 2 separately&amp;nbsp;without cross.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Diagram1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24588i0AA8FE955132B810/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Diagram1.png" alt="Diagram1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the first time we meet maestro with Cascade&amp;nbsp;Switches, so we are not sure whether it is supported?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any similar setup? and What is the best way to configure for this scenario?&lt;/P&gt;&lt;P&gt;Is there any concern Maestro with&amp;nbsp;bonding group connecting to cascaded switch that need to be highlighted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Maestro is running Active-Active, but the all the bonding group link is configured with Active-Backup which all active link will at MHO1 while backup link at MHO2 like normal clusterXL deployment. Its quite confusing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried to configure the bonding group with operating mode 802.3ad but it is totally not workable at all when connected to cascaded switch, unable to ping.&amp;nbsp; Therefore, when we try to change the operating mode to Active-Backup and XOR is able to ping within upstream and downstream.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="Maestro" id="Maestro"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Quantum Maestro" id="maestro"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Keon&lt;/P&gt;</description>
    <pubDate>Wed, 21 Feb 2024 17:24:48 GMT</pubDate>
    <dc:creator>teckwahlee</dc:creator>
    <dc:date>2024-02-21T17:24:48Z</dc:date>
    <item>
      <title>Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switches?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206727#M2434</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently we are to deploying the Check Point Maestro with single site dual MHO. We know that Maestro is running on Active-Active mode, however the internal and external switch connected is actually a cascading switch which is not support creating any port channel or LACP like stacking switch. Meanwhile, in the design due to insufficient port, we must bond the interface from each security group to provide redundancy within MHO1 &amp;amp; MHO2, but we unable to&amp;nbsp;&lt;SPAN&gt;configure Bond&amp;nbsp;operating mode 802.3ad LACP (load sharing) with both link is Active-Active, it will have issue with cascading switch as it is not like stacking switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please refer to the diagram of the topology, MHO1 &amp;amp; MHO2 connecting straight link to switch 1 &amp;amp; switch 2 separately&amp;nbsp;without cross.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Diagram1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24588i0AA8FE955132B810/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Diagram1.png" alt="Diagram1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the first time we meet maestro with Cascade&amp;nbsp;Switches, so we are not sure whether it is supported?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any similar setup? and What is the best way to configure for this scenario?&lt;/P&gt;&lt;P&gt;Is there any concern Maestro with&amp;nbsp;bonding group connecting to cascaded switch that need to be highlighted?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Maestro is running Active-Active, but the all the bonding group link is configured with Active-Backup which all active link will at MHO1 while backup link at MHO2 like normal clusterXL deployment. Its quite confusing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have tried to configure the bonding group with operating mode 802.3ad but it is totally not workable at all when connected to cascaded switch, unable to ping.&amp;nbsp; Therefore, when we try to change the operating mode to Active-Backup and XOR is able to ping within upstream and downstream.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="Maestro" id="Maestro"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Quantum Maestro" id="maestro"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Keon&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 17:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206727#M2434</guid>
      <dc:creator>teckwahlee</dc:creator>
      <dc:date>2024-02-21T17:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switch</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206817#M2435</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think the best option in this deployment is configure 2 bonds as active - backup.&lt;/P&gt;&lt;P&gt;Each mho will have one port active on different switches, in this way you could use both as Active-active.&lt;/P&gt;&lt;P&gt;In both ends you need to configure duplicate routes to balance between the bonds, depend on routing protocol used,&amp;nbsp; maybe you need to enable ecmp in both ends.&lt;/P&gt;&lt;P&gt;But just a guess &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cassio&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 11:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206817#M2435</guid>
      <dc:creator>cassiomaciel</dc:creator>
      <dc:date>2024-02-22T11:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switch</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206820#M2436</link>
      <description>&lt;P&gt;In order to do an LACP bond, the switches also have to be acting as a single switch (like VSS or VPC) and present a single LACP bond back to the MHOs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 12:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/206820#M2436</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-02-22T12:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switch</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/207866#M2441</link>
      <description>&lt;P&gt;Hi cassiomaciel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, we would like to configure both link as Active-backup, e.g. all link from MHO1 is Active&amp;nbsp;and connect to the Switch1 meanwhile all link from MHO2 is Backup&amp;nbsp;will connect to Switch2.&amp;nbsp;Which means the traffic coming from switch it will always go through MHO1 only, by right it wont have any traffic go through MHO2 as all the link from there is backup link just like normal clusterXL firewall even though it is Maestro with Active-Active. Theoretically/Logically it should running like this, am I right? Is there any other concern if there's VLAN trunk on the switch with this setup?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 16:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/207866#M2441</guid>
      <dc:creator>teckwahlee</dc:creator>
      <dc:date>2024-03-05T16:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is that Check Point Maestro Deployment Bonding Group Support with Connecting to Cascading Switch</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/208048#M2444</link>
      <description>&lt;P&gt;This will work fine, the ports on the switches should be set up with no bonding configuration. It should work as either Access or Trunk ports, as long as all the right VLANs are on both switch ports.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 07:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Is-that-Check-Point-Maestro-Deployment-Bonding-Group-Support/m-p/208048#M2444</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-03-07T07:27:58Z</dc:date>
    </item>
  </channel>
</rss>

