<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3 Uplink non vendor device status in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211539#M2494</link>
    <description>&lt;P&gt;Attached high level uplink design&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2024 05:03:12 GMT</pubDate>
    <dc:creator>anikaralam</dc:creator>
    <dc:date>2024-04-17T05:03:12Z</dc:date>
    <item>
      <title>L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211485#M2489</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Consider that maestro uplink l3 devices are from other vendor.&amp;nbsp; In single site dual deployment we have two rooms and it's 2 km away. We have 2 Maestro and 4 security gateway. There are 2 security group and one uplink connecting to l3 device which configured as VSX between two room. Other uplink bond planning to connect on different l3 device where no vsx between these device between two room. Will this work? Or do I need to suggest to connect uplink to same L3 devices which configured as VSX. Please share a checkpoint link for further clarification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 20:22:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211485#M2489</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-16T20:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211502#M2490</link>
      <description>&lt;P&gt;Let me try to understand&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Do you have 2 maestros? maestro is solution with orchestrator and security gateways, maybe you have 2 orchestrators and 4 Security Gateways on site one (no other side)?&lt;/LI&gt;
&lt;LI&gt;Device uplink for other vendor it does mean the SFP is other than Check Point or you mean the SFP is Check Point and connects to switch (other vendor)?&lt;/LI&gt;
&lt;LI&gt;When you say single site dual deployment you mean 2 MHO per site?&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2 Security Groups one uplink connected? are you sharing the same interface on both Security group or is one per SG?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2 SG connected to 3party device connected to L3 as VSX? this is other check point gateway with maestro VSX Dual Site?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A topology might help here&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 21:45:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211502#M2490</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-04-16T21:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211503#M2491</link>
      <description>&lt;P&gt;Please elaborate you scenario, then we can try to answer&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 21:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211503#M2491</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-04-16T21:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211516#M2492</link>
      <description>&lt;P&gt;A diagram might help to understand the proposed topology&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 23:54:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211516#M2492</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-04-16T23:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211538#M2493</link>
      <description>&lt;P&gt;High level Uplink topology&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 05:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211538#M2493</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-17T05:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211539#M2494</link>
      <description>&lt;P&gt;Attached high level uplink design&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 05:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211539#M2494</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-17T05:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211541#M2495</link>
      <description>&lt;OL&gt;&lt;LI&gt;Do you have 2 maestros? maestro is solution with orchestrator and security gateways, maybe you have 2 orchestrators and 4 Security Gateways on site one (no other side)?&amp;nbsp; ==&amp;gt; We have 2 maestro and four security gateways. In one room one maestro and 2 security gateways from two different security groups and in the other which is far from room 1 one maestro and 2 security gateway.&lt;/LI&gt;&lt;LI&gt;Device uplink for other vendor it does mean the SFP is other than Check Point or you mean the SFP is Check Point and connects to switch (other vendor)?&amp;nbsp; ==&amp;gt; Other vendor side it's vendor SFP and in checkpoint it will be checkpoint SFP&lt;/LI&gt;&lt;LI&gt;When you say single site dual deployment you mean 2 MHO per site? Yes. 1 MHO in each room.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;2 Security Groups one uplink connected? are you sharing the same interface on both Security group or is one per SG? No sharing uplink. MGMT(SMS) will be same. Please refer the diagram I attached for other reply.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;2 SG connected to 3party device connected to L3 as VSX? this is other check point gateway with maestro VSX Dual Site?&lt;/SPAN&gt;&lt;SPAN&gt;One security group will connect to 3rd part device connected as VSX. My understanding its work well. Problem with the other security group which is currently planning to connect on L3 device which not configured as VSX between two different room. Need to know best practice from 3rd party vendor side.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 17 Apr 2024 05:10:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211541#M2495</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-17T05:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211649#M2499</link>
      <description>&lt;P&gt;Ok I think I understand now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, you have single site, with dual orchestrator all 4 gateways on 2 Security Group 2km? do you have the lattency less than 100ms? else should change to Multi-room&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the VSX is I think Aruba technology to segregate VLANs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see the topology for MHO but what about Security Group?&lt;/P&gt;
&lt;P&gt;The HLD is for current or proposal?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 17:39:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211649#M2499</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-04-17T17:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211652#M2500</link>
      <description>&lt;P&gt;As the guys said, if you share network diagram, would certainly help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 18:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211652#M2500</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-17T18:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211683#M2501</link>
      <description>&lt;P&gt;UPLINK design network diagram already shared earlier.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 04:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211683#M2501</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-18T04:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211685#M2502</link>
      <description>&lt;P&gt;I'm looking for a document related to third-party L3 third-party device configuration best practices while connecting maestro uplink. That's the reason not to include downlink and related security groups. HLD is the proposed one. Would like to know what is the drawback if L3 third-party vendor is not configured as VSX/LAG. Why its recommending to configure L3 switches as one virtual switch (VSX/LAG) even its away for couple of kilometers.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 05:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211685#M2502</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-18T05:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211688#M2503</link>
      <description>&lt;P&gt;On Maestro, the uplink bonds are configured and managed at the security group level, not the MHOs. This means that when you create a bond using interfaces over both MHOs (which is recommended so that you have high availability on this bond interface in the event of an MHO going down) it has to be configured as a single bond on the neighbouring devices.&lt;/P&gt;
&lt;P&gt;If you create two separate bonds to your neighbour devices, they are just two separate interfaces onto the security group. They would need to be in separate IP address spaces and you'll need some sort of dynamic routing running to achieve proper HA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If your uplink neighbour devices cannot act as one virtual switch, you can use Active/Standby bonds at the security group. In that case you only need to have regular interfaces configured on the neighbour devices in the same VLANs. The security group will use the primary interface when it's up (make sure you configure this) by default.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 06:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211688#M2503</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-18T06:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211708#M2504</link>
      <description>&lt;P&gt;Thanks emmap. Will you able to share the URL where the checkpoint recommendation is to configure L3 switches as one virtual switch?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 10:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211708#M2504</guid>
      <dc:creator>anikaralam</dc:creator>
      <dc:date>2024-04-18T10:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: L3 Uplink non vendor device status</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211826#M2506</link>
      <description>&lt;P&gt;It's not that there's an explicit recommendation to do that, it's just understanding that if you're creating a load sharing bond with interfaces on two MHOs, it's a single bond. If those two MHOs are connected to two different switches, those switches logically have to be acting as a single switch to present back to the MHOs a single load sharing bond. It's an architectural understanding more than it is a Check Point recommendation.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2024 07:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/L3-Uplink-non-vendor-device-status/m-p/211826#M2506</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-19T07:30:36Z</dc:date>
    </item>
  </channel>
</rss>

