<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sync single site through sw l2 in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213823#M2563</link>
    <description>&lt;P&gt;This isn't a supported setup for a single-site deployment, and what's more is that you have to connect each SGM directly to both MHOs as well, so it's more than just the MHO sync issue.&lt;/P&gt;
&lt;P&gt;If you don't have sufficient direct connectivity between your two racks you can look at a dual-site deployment, which would be active/standby failover between the stack in each rack.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2024 06:16:31 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2024-05-10T06:16:31Z</dc:date>
    <item>
      <title>Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213802#M2558</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a dual maestro deployment in single site. Each maestro is separated from the other and we cannot connect them directly so we tried to connect Sync ports (48 port MHO140) using 10G sfp multimode passing through a L2 SW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically is like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mho.drawio.png" style="width: 548px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25616i9D703325DE8A9BC6/image-size/large?v=v2&amp;amp;px=999" role="button" title="mho.drawio.png" alt="mho.drawio.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our problem is, they dont see each other:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@MHO-ML-1:0]# tcpdump -nni Sync-int&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on Sync-int, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;12:36:03.789415 ARP, Request who-has 192.0.2.2 tell 192.0.2.1, length 28&lt;BR /&gt;12:36:04.791420 ARP, Request who-has 192.0.2.2 tell 192.0.2.1, length 28&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;arp is never answered and sw&amp;nbsp; says they see mac fomr dl48, not the one from Sync-int port. Anyone knows if some configuration is missing or a clue on where to put the full troubleshooting power?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 18:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213802#M2558</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2024-05-09T18:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213808#M2559</link>
      <description>&lt;P&gt;if the orchestrators are connected through switches, is not single site deployment is dual site. you can enable or disable the Q-in-Q or connect directly using SFP+ and fiber between them without switches in the middle.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 21:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213808#M2559</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-05-09T21:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213813#M2561</link>
      <description>&lt;P&gt;Hi Dario,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So using port 48 in this is not supported? what im trying to understand is why i can reach 192.0.2.1 from 192.0.2.2 if both ports on both sw have the same vlan in access mode and the trunk between sw propagate that VLAN, is there any vlan tagged from packets going from .2 to .1? the obvious test was to put 2 PCS on same topology and they reach each other, but syncs cant reach each other, so it has to be some VLAN thing behind this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 22:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213813#M2561</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2024-05-09T22:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213815#M2562</link>
      <description>&lt;P&gt;port 48 is supported,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we use more than 1 VLAN for Sync, that's why leaving only 1 VLAN on switch is not enough to sync them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 23:09:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213815#M2562</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-05-09T23:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213823#M2563</link>
      <description>&lt;P&gt;This isn't a supported setup for a single-site deployment, and what's more is that you have to connect each SGM directly to both MHOs as well, so it's more than just the MHO sync issue.&lt;/P&gt;
&lt;P&gt;If you don't have sufficient direct connectivity between your two racks you can look at a dual-site deployment, which would be active/standby failover between the stack in each rack.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 06:16:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213823#M2563</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-05-10T06:16:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213845#M2564</link>
      <description>&lt;P&gt;Hi emmap,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wold like to understand why isn't supported. What would be the difference from having a directly connected fiber to having them connected through 2 L2 SW and encapsulation disabled, all sync VLANs being recognized and accepted by the trunk ports where the traffic crosses. From my PoV that's like having the cable connected directly, isn't it? Well, LLDP won't recognize the other orch, but if I have full connectivity between sync interfaces, won't work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your answer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2024 12:11:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213845#M2564</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2024-05-10T12:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sync single site through sw l2</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213986#M2565</link>
      <description>&lt;P&gt;It's not a scenario that we have tested or QA'd, hence it isn't supported. It may be that you can get it to work, but it won't be a setup that we can support if there are any issues that arise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 02:05:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Sync-single-site-through-sw-l2/m-p/213986#M2565</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-05-13T02:05:40Z</dc:date>
    </item>
  </channel>
</rss>

