<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different Management server in maestro environment in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225071#M2810</link>
    <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;Thank You for your insight, we have two management server(Smart -1 600S in core and one in VM for perimeter for maestro) and licenses. The perimeter environment is of maestro&amp;nbsp; orchestrator with SMO,SGM's and SMS whereas in core we have CP-Cluster in Active standby deployment, now we are planning to migrate this in perimeter to achieve active-active load balancing by segregating the traffic using different security group or lets say different SMO.&lt;/P&gt;&lt;P&gt;To achieve this we were planning to use management server of core to manage new SMO integrated in maestro orchestrator.&lt;/P&gt;&lt;P&gt;As you suggested using same management server for deployment, in long run it would be easy to handle and minimize the cost as well. To achieve this either we need to manually create database or as far as i know migrating database would be easy but it might have issue in production environment considering all the configuration will be replicated.&lt;/P&gt;&lt;P&gt;So what would you suggest in this scenario, also if you know how to migrate policy and objects only without using migrate database tool, please let me know. Also kindly suggest which approach would be better in this situation.&lt;/P&gt;&lt;P&gt;Again, thank you for your response.&lt;/P&gt;&lt;P&gt;Rabin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2024 01:44:04 GMT</pubDate>
    <dc:creator>Rabin</dc:creator>
    <dc:date>2024-08-30T01:44:04Z</dc:date>
    <item>
      <title>Different Management server in maestro environment</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225005#M2808</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I just want to know is it possible to use different checkpoint management server for managing the SMO of different security Group created in same Maestro Orchestrator and what challenges or issue it might occur in production environment ??&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 17:40:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225005#M2808</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-08-29T17:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Different Management server in maestro environment</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225014#M2809</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me clarify this a litle bit with my words:&lt;/P&gt;
&lt;P&gt;Every Security Group has one SMO which one is dedicated SGM among the SGM-s. This is the "boss".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One Security Group -&amp;gt; one SMO -&amp;gt; and the simple SGMs&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Segmentation:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I prefer to create a new LAN for the MAESTRO management, to mix it with other traffic (other cluster management stc.) This was a prerequisite earlier.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;To create a new Management server:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I don't think so. Why should I build a new SMS (think about the license cost only) for managing the Security Groups? Not necessary. I have implementations where 10+ cluster and MAESTRO are handled by one SmartCenter.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt;Except:&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;the hardware is not able to handle the inceased log quantity (high lograte)
&lt;UL&gt;
&lt;LI&gt;to small Smart-1 hardware&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;security concerns&lt;/LI&gt;
&lt;LI&gt;HA is not implemented, and&amp;nbsp;necessary&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If only the LOGrate is the issue consider to buy a logserver software license only and install it on a VM. In this case the resources almost endless. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It is only &lt;EM&gt;the surface&lt;/EM&gt;, to make a decision about the architecture, more info needed.&lt;/P&gt;
&lt;P&gt;If you have any question just drop an update on this, then we can go into details.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225014#M2809</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T18:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Different Management server in maestro environment</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225071#M2810</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;Thank You for your insight, we have two management server(Smart -1 600S in core and one in VM for perimeter for maestro) and licenses. The perimeter environment is of maestro&amp;nbsp; orchestrator with SMO,SGM's and SMS whereas in core we have CP-Cluster in Active standby deployment, now we are planning to migrate this in perimeter to achieve active-active load balancing by segregating the traffic using different security group or lets say different SMO.&lt;/P&gt;&lt;P&gt;To achieve this we were planning to use management server of core to manage new SMO integrated in maestro orchestrator.&lt;/P&gt;&lt;P&gt;As you suggested using same management server for deployment, in long run it would be easy to handle and minimize the cost as well. To achieve this either we need to manually create database or as far as i know migrating database would be easy but it might have issue in production environment considering all the configuration will be replicated.&lt;/P&gt;&lt;P&gt;So what would you suggest in this scenario, also if you know how to migrate policy and objects only without using migrate database tool, please let me know. Also kindly suggest which approach would be better in this situation.&lt;/P&gt;&lt;P&gt;Again, thank you for your response.&lt;/P&gt;&lt;P&gt;Rabin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 01:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225071#M2810</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-08-30T01:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Different Management server in maestro environment</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225072#M2811</link>
      <description>&lt;P&gt;Yes, each security group is a separate entity with separate SIC and hence security groups sharing MHOs can be managed by different management servers. There's no additional challenges or issues expected in this scenario, it's fully supported, it's the same as having two different gateway clusters on two different management servers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 01:59:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225072#M2811</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-08-30T01:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Different Management server in maestro environment</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225097#M2812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That was not clear for me, that you have two managements. In this case I understand you. As you mentioned, one Management would be enough is a far future, and budget-proof. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I would addressed two questions here:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Cluster and Active Active setup:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Az I think you are in the plannig phase. Please read the limitations &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content/Topics-CXLG/Active-Active-Mode.htm?TocPath=Active-Active%20Mode%20in%20ClusterXL%7C_____0#Active-Active_Mode_in_ClusterXL" target="_self"&gt;here.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Two Managament into one:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;From what you have written, this tool would be useful for you. This helps you in the hardest part -&amp;gt; migrating the policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180923" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180923&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;About the Smart-1 600S and the VM license&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;Hard to compare the physical appliance with the VM, because both have advantages and disadvantages too.&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;The largest difference is for me:&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;The Smart-1 has a hard limit in performace, and yo can't extend it. &lt;A href="https://www.checkpoint.com/downloads/products/smart-1-security-management-platform-datasheet.pdf" target="_self"&gt;Datasheet here&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;The VM does not have such kind of limit, because the resources of the host are always extendable. An another feature of the VM, is the snapshot. By upgrades it is a huge feature, and extend the safety.&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;These are my opinions, from the small amount of information that I have.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;I hope this helps you to find the right way.&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;I have installation with Smart-1 and VM too. Somewhere was requirement that, the Management must be a physical appliance in HA...&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="D5aOJc vJwDU"&gt;Akos&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 07:56:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Different-Management-server-in-maestro-environment/m-p/225097#M2812</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-30T07:56:49Z</dc:date>
    </item>
  </channel>
</rss>

