<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro dual site site sync in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91363#M255</link>
    <description>&lt;P&gt;Thank you for the response &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;, I have reviewed the guide you mentioned and this only discusses the the maestro configuration and does not indicate what the configuration needs to be on the switch side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch configuration is what I am looking to find out and understand.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have had the appliances directly attached whne they were in the lab with no issues and now they are mounted in there final resting place they are not able to see each other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this leads me to believe that perhaps there is a requirement that maestro needs fulfilling to be able to connect via a switch. The link between sites is less than 100ms in latency and has 0 packet loss. So I know these are not the issue. I have also installed a relatively new jumbo hotfix so I know that I am on a version that supports the dual site configuration via a switch&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 19:12:49 GMT</pubDate>
    <dc:creator>Northy</dc:creator>
    <dc:date>2020-07-13T19:12:49Z</dc:date>
    <item>
      <title>Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91340#M253</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking to understand what kind of configuration is required to interconnect 2 site sync interfaces in a dual site configuration.&lt;/P&gt;&lt;P&gt;I have followed the configuration guide found here on checkmates and altered configuration on port 1/47/1 at each site to be a site_sync, but the MHOs are saying they cannot reach one another.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My setup looks similar to below&lt;/P&gt;&lt;P&gt;------------ Site 1------------&amp;nbsp; &amp;nbsp;|&amp;nbsp; &amp;nbsp; ------------ Site 2&amp;nbsp;------------&amp;nbsp;&lt;/P&gt;&lt;P&gt;MHO 1 &amp;lt;---&amp;gt; SW1 &amp;lt;-------Inter-site link-------&amp;gt;SW2&amp;lt;---&amp;gt;MHO2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From each MHO to each local switch I have configured a dot1q (VLAN) tunnel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any suggestions to set up in this way?&lt;/P&gt;&lt;P&gt;Thanks for any assistance&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 14:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91340#M253</guid>
      <dc:creator>Northy</dc:creator>
      <dc:date>2020-07-13T14:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91360#M254</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28600"&gt;@Northy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have look at&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165774&amp;amp;partition=Advanced&amp;amp;product=Maestro" target="_blank" rel="noopener"&gt;How to configure Single Site Dual MHO Cluster, Dual Site Single MHO Cluster, or Dual Site Dual MHO Cluster&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;option B is your example.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 18:12:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91360#M254</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-07-13T18:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91363#M255</link>
      <description>&lt;P&gt;Thank you for the response &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;, I have reviewed the guide you mentioned and this only discusses the the maestro configuration and does not indicate what the configuration needs to be on the switch side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch configuration is what I am looking to find out and understand.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have had the appliances directly attached whne they were in the lab with no issues and now they are mounted in there final resting place they are not able to see each other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this leads me to believe that perhaps there is a requirement that maestro needs fulfilling to be able to connect via a switch. The link between sites is less than 100ms in latency and has 0 packet loss. So I know these are not the issue. I have also installed a relatively new jumbo hotfix so I know that I am on a version that supports the dual site configuration via a switch&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 19:12:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91363#M255</guid>
      <dc:creator>Northy</dc:creator>
      <dc:date>2020-07-13T19:12:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91368#M256</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28600"&gt;@Northy&lt;/a&gt;&amp;nbsp;, do you have your VLANs on your switch interconnect configured?&lt;/P&gt;
&lt;P&gt;You have to have the VLANs from site A too on the site B. Meaning you need a VLAN-trunk on the switches between your site's.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 19:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91368#M256</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-07-13T19:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91379#M257</link>
      <description>On the link between the 2 interfaces connecting to the MHOP you need to configure QinQ which kinda creates a tunnel between the 2 portsand all VLANs used will be forwarded to the othe side without the switches actually seeing them.</description>
      <pubDate>Mon, 13 Jul 2020 21:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91379#M257</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-07-13T21:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91382#M258</link>
      <description>&lt;P&gt;Correct, I have the interfaces that connect to each MHO configured as a dot1q tunnel so this will tunnel any traffic on that interface via the vlan 957 which is trunked through to both sites.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any MTU requirements that people are aware of? Currently it is standard 1500 but I'm thinking ill need to support jumbo frames for this to work properly and to account for the additional headers from VLAN tags.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the off chance it needs to perform some form of lldp discovery I also have the lldp packets tunneling inside of the dot1q tunnel but that doesn't seem to make a difference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 21:19:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91382#M258</guid>
      <dc:creator>Northy</dc:creator>
      <dc:date>2020-07-13T21:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91383#M259</link>
      <description>Check the official guide from Check Point for that part, but as far I am aware you need Jumbo frames enabled on that link.</description>
      <pubDate>Mon, 13 Jul 2020 21:23:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/91383#M259</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-07-13T21:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96240#M290</link>
      <description>&lt;P&gt;Are there any working examples for fully redundant configuration with three sites with each Maestro having dual sync links (If this is even possible).&lt;/P&gt;&lt;P&gt;It would be great if someone can post a training video of how to setup single and dual site configuration with fully redundant inter-site links.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 21:35:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96240#M290</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2020-09-07T21:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96243#M291</link>
      <description>&lt;P&gt;A 3 site setup is not supported and cannot be configured. As far as I've been told it is on the roadmap but nobody knows for which month of which year.&lt;/P&gt;
&lt;P&gt;There are no video's available yet to my knowledge. You can use my Maestro&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Maestro-Hyperscale-Security/Maestro-basic-setup-documentation/m-p/95634" target="_self"&gt;basic setup manual for now.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 05:14:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96243#M291</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-09-08T05:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site site sync</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96253#M292</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes, you will need to adjust MTU - QinQ adds a bit - I cant remember the exact number - but I think it is 1518 that is needed.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 07:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-site-sync/m-p/96253#M292</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2020-09-08T07:23:45Z</dc:date>
    </item>
  </channel>
</rss>

