<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro dual site, dual MHO - questions in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244776#M3250</link>
    <description>&lt;P&gt;Yes and yes. Still checking the network side of all of this, as the MHO on the second site were showing that behaviour even when no SG was configured.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 09:11:30 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2025-03-26T09:11:30Z</dc:date>
    <item>
      <title>Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244735#M3244</link>
      <description>&lt;P&gt;All systems R81.20 Take 98.&lt;/P&gt;
&lt;P&gt;I'm looking at a Maestro setup configured as multi-site with direct connections between MHO (Sync-int, sync-ext) and dual MHO.&lt;/P&gt;
&lt;P&gt;All connections are up and the MHO are configured as site 1, 2, id 1, id 2 per site.&lt;/P&gt;
&lt;P&gt;Next, we have a VSX security group with Force SGM connected on the same ports on MHO1_1 and MHO1_2 on site 1, and MHO2_1 and MHO2_2 on site 2.&lt;/P&gt;
&lt;P&gt;The SG is created and works.&lt;/P&gt;
&lt;P&gt;According to the network integrator (outside my control and area of visibility), both sites have perfect replication in terms of L1/L2, since the SG work, this makes sense.&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;Site 1&lt;/TD&gt;
&lt;TD width="50%"&gt;Site 2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;MHO1_1&lt;/TD&gt;
&lt;TD width="50%"&gt;MHO2_1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;MHO1_2&lt;/TD&gt;
&lt;TD width="50%"&gt;MHO2_2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="50%"&gt;Force with uplink to each MHO&lt;/TD&gt;
&lt;TD width="50%"&gt;Force with uplink to each MHO&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The administration guides were followed to create the security group, everything was done on 1_1 and the 2 sites appear in the MHO configuration.&lt;/P&gt;
&lt;P&gt;We get an active/active system, VS0 created as singly VSX gateway with SG IP.&lt;/P&gt;
&lt;P&gt;Now the issue are as follows:&lt;/P&gt;
&lt;P&gt;On the 2nd site MHO, orchd/asg commands stall or don't produce output. Sometimes a command like "orchd stat" on the MHO or asg monitor will work then on another run in the same session will stall and hang.&lt;/P&gt;
&lt;P&gt;SSH to MHO site 2 works but not HTTPS.&lt;/P&gt;
&lt;P&gt;If we failover the SG to site 2, we get the same scenario with unreliable SSH output and policy install on VS0 fails with SSL errors in the policy installation output.&lt;/P&gt;
&lt;P&gt;I don't have other experience with dual site so I can't compare. The network should be fine, so I'm wondering if there are extra steps or something I would have missed in the process which could make sense here.&lt;/P&gt;
&lt;P&gt;As far as I know, we followed all administration guides and relevant SK.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 20:09:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244735#M3244</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-25T20:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244746#M3246</link>
      <description>&lt;P&gt;Without being able to really understand the layer 1 and layer 2 setup it's hard to say, but it seems like there's something going wrong with the site_sync stuff. How're the MHOs directly connected between sites? Do you have a sufficiently anonymised diagram you can share?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 02:22:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244746#M3246</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-03-26T02:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244758#M3247</link>
      <description>&lt;UL&gt;
&lt;LI&gt;What were the steps of creating the secondary site?&lt;/LI&gt;
&lt;LI&gt;asg stat -v shows the second site (MHO and SGMs)?&lt;/LI&gt;
&lt;LI&gt;Layer4 distribution mode is enabled or disabled?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 26 Mar 2025 08:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244758#M3247</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T08:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244767#M3248</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;Basically what is described in the multisite setup with direct connection:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Appliances/GSG_Maestro/EN/Topics/Connecting-Cables-for-Dual-Site-Direct-Connection.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Appliances/GSG_Maestro/EN/Topics/Connecting-Cables-for-Dual-Site-Direct-Connection.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Except one SGM per site. Network provider provides virtualised "dark fibre" and are adamant their configuration is fine.&lt;/P&gt;
&lt;P&gt;At least it looks like, the MHO don't complain of not seeing each other.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;Followed the admin guide, L4 distribution is off.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;--------------------------------------------------------------------------------
| VSX System Status - Maestro                                                  |
--------------------------------------------------------------------------------
| Chassis Mode                | Active Up                                      |
| Up time                     | 5 days, 19:39:31 hours                         |
| SGMs                        | 2 / 2                                          |
| Virtual Systems             | 1                                              |
| Version                     | R81.20 (Build Number 722)                      |
--------------------------------------------------------------------------------
| VS ID:  0                     VS Name:  &amp;lt;removed&amp;gt;                       |
--------------------------------------------------------------------------------
| SGM ID             Chassis 1                          Chassis 2              |
|                    ACTIVE                             STANDBY                |
--------------------------------------------------------------------------------
|  1                   ACTIVE                             ACTIVE               |
--------------------------------------------------------------------------------
| Chassis Parameters                                                           |
--------------------------------------------------------------------------------
| Unit        |        Chassis 1          |        Chassis 2          | Weight |
--------------------------------------------------------------------------------
| SGMs        |          1 / 1            |          1 / 1            |   6    |
| Ports       |                           |                           |        |
|   Standard  |          0 / 0            |          0 / 0            |  11    |
|   Bond      |          0 / 0            |          0 / 0            |  11    |
|   Other     |          0 / 0            |          0 / 0            |   6    |
| Sensors     |                           |                           |        |
|   SSMs      |          2 / 2            |          2 / 2            |  11    |
|             |                           |                           |        |
| Grade       |         28 / 28           |         28 / 28           |   -    |
--------------------------------------------------------------------------------
| Minimum grade gap for chassis failover:                               11     |
| Synchronization                                                              |
|     Sync to Active chassis:    Enabled                                       |
|     Sync to Standby chassis:   Enabled                                       |
--------------------------------------------------------------------------------
| Chassis HA mode:              Active Up                                      |
--------------------------------------------------------------------------------
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 08:49:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244767#M3248</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-26T08:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244771#M3249</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for sure, the md5sum -s of the SGMs are the same?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show smo image md5sum&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And the #lldpctl command shows the remote site on both site, right?&lt;/P&gt;
&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 08:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244771#M3249</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T08:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244776#M3250</link>
      <description>&lt;P&gt;Yes and yes. Still checking the network side of all of this, as the MHO on the second site were showing that behaviour even when no SG was configured.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:11:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244776#M3250</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-26T09:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244780#M3251</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe you have already checked the settings according to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk168092" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk168092&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The QinQ was configured correctly?&lt;/P&gt;
&lt;P&gt;Connectivity between Orchestrators on different sites:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;From MHO 1_1 ping MHO 2_1: ping 203.0.113.15&lt;/LI&gt;
&lt;LI&gt;From MHO 1_2 ping MHO 2_2: ping 203.0.113.16&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If there is no ping, examine &lt;STRONG&gt;VLAN IDs 3951 and 3952&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Connectivity between Orchestrators on the same site:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;From MHO 1_1 ping MHO 1_2: ping 192.0.2.2&lt;/LI&gt;
&lt;LI&gt;From MHO 2_1 ping MHO 2_2: ping 192.0.2.16&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If there is no ping, examine the Internal Sync cable between Orchestrators on the same site.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Connectivity between Security Group Members (appliances):&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;UL&gt;
&lt;LI&gt;From SGM 1_1 ping SGM 2_1 on the sync network: ping 192.0.2.15&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If there is no ping, examine &lt;STRONG&gt;VLAN IDs 3600 and 3601&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244780#M3251</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244782#M3252</link>
      <description>&lt;P&gt;Yes these are all peachy. We're still investigation with the relevant parties.&lt;/P&gt;
&lt;P&gt;Thanks for your feedback. &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 09:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244782#M3252</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-26T09:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244832#M3253</link>
      <description>&lt;P&gt;Problem fixed, MTU mismatch was found somewhere along the path by the network provider.&lt;/P&gt;
&lt;P&gt;Thanks for chiming in. &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 13:28:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244832#M3253</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-26T13:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244853#M3254</link>
      <description>&lt;P&gt;May I ask you to share the "good" MTU number with us? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244853#M3254</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T14:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro dual site, dual MHO - questions</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244855#M3255</link>
      <description>&lt;P&gt;The MHO have 9216 so they put 9300 on whatever equipment they have in this setup.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-dual-site-dual-MHO-questions/m-p/244855#M3255</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-26T14:26:02Z</dc:date>
    </item>
  </channel>
</rss>

