<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic First step with MHO and few questions about it in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/First-step-with-MHO-and-few-questions-about-it/m-p/99352#M337</link>
    <description>&lt;P&gt;hi maestro expert &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i am making my first step to implemant maetro then i have some question about it :&lt;/P&gt;&lt;P&gt;Q1 : If i am correct there is no need to configure Sync interface for the gateway and in the maestro object in management server and in the mho security group . It will be automaticly use network 192.0.2.X on a virtual interface named Sync like in my lab :&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 10&lt;/P&gt;&lt;P&gt;eth1-05 10.20.0.1 VMAC address: 00:1C:7F:81:05:C1&lt;BR /&gt;eth1-06 81.255.188.1 VMAC address: 00:1C:7F:81:06:C1&lt;BR /&gt;eth1-07 192.168.4.4 VMAC address: 00:1C:7F:81:07:C1&lt;BR /&gt;eth1-08 81.255.188.253 VMAC address: 00:1C:7F:81:08:C1&lt;BR /&gt;eth1-09 10.10.0.254 VMAC address: 00:1C:7F:81:09:C1&lt;BR /&gt;eth1-10 10.0.50.1 VMAC address: 00:1C:7F:81:0A:C1&lt;BR /&gt;eth1-Mgmt1 217.109.182.193&lt;BR /&gt;eth1-CIN 198.51.101.2&lt;BR /&gt;eth2-CIN 198.51.101.202&lt;BR /&gt;Sync 192.0.2.2&lt;/P&gt;&lt;P&gt;[Expert@OIF-ch01-02:0]# ifconfig Sync&lt;BR /&gt;Sync Link encap:Ethernet HWaddr 00:1C:7F:02:04:FE&lt;BR /&gt;inet addr:192.0.2.2 Bcast:192.0.2.255 Mask:255.255.255.0&lt;BR /&gt;UP BROADCAST RUNNING MASTER MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:136664 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:62063 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:30427407 (29.0 MiB) TX bytes:5948091 (5.6 MiB)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Q2 : all members are in active state and the first gateway in the security group will be the pivot like in A/A with cluster XL or how traffic is handle when you have 3 gateway or more in the security group ?&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 192.0.2.1 33% ACTIVE&lt;BR /&gt;2 192.0.2.2 33% ACTIVE&lt;BR /&gt;3 192.0.2.3 33% ACTIVE&lt;/P&gt;&lt;P&gt;Q3 : on the Smartcenter there is no way to check the HA status for the gateway in the secutiry group on the MHO config ?&lt;/P&gt;&lt;P&gt;Q4 : if i am correct with maestro there is only a virtual ip address configure in the smartcenter on the network management and no need to configure reel ip per node and define the interface as a cluster interface&lt;/P&gt;&lt;P&gt;Q5 : What is interface eth1-CIN and eth2-CIN with and adress IP in : 198.51.101.X ? none of this interface are set up on the mho security group :&lt;/P&gt;&lt;P&gt;In clish they not appear :&lt;/P&gt;&lt;P&gt;[Global] OIF-ch01-01 &amp;gt; show interface&lt;/P&gt;&lt;P&gt;eth1-05 eth1-06 eth1-07 eth1-08 eth1-09 eth1-10&lt;BR /&gt;eth1-11 eth1-12 eth1-Mgmt1 lo BPEth0 BPEth1&lt;/P&gt;&lt;P&gt;In Expert :&lt;/P&gt;&lt;P&gt;eth1-CIN Link encap:Ethernet HWaddr 00:1C:7F:81:42:01&lt;BR /&gt;inet addr:198.51.101.1 Bcast:198.51.101.127 Mask:255.255.255.128&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:741356 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:894418 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:226692007 (216.1 MiB) TX bytes:99844561 (95.2 MiB)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;eth2-CIN Link encap:Ethernet HWaddr 00:1C:7F:82:42:01&lt;BR /&gt;inet addr:198.51.101.201 Bcast:198.51.101.255 Mask:255.255.255.128&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:67704 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:0 (0.0 b) TX bytes:2843568 (2.7 MiB)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@OIF-ch01-01:0]# ethtool eth2-CIN&lt;BR /&gt;Settings for eth2-CIN:&lt;BR /&gt;Supported ports: [ FIBRE ]&lt;BR /&gt;Supported link modes: 10000baseT/Full&lt;BR /&gt;Supported pause frame use: Symmetric Receive-only&lt;BR /&gt;Supports auto-negotiation: Yes&lt;BR /&gt;Supported FEC modes: Not reported&lt;BR /&gt;Advertised link modes: 10000baseT/Full&lt;BR /&gt;Advertised pause frame use: Symmetric Receive-only&lt;BR /&gt;Advertised auto-negotiation: Yes&lt;BR /&gt;Advertised FEC modes: Not reported&lt;BR /&gt;Speed: 10000Mb/s&lt;BR /&gt;Duplex: Full&lt;BR /&gt;Port: FIBRE&lt;BR /&gt;PHYAD: 0&lt;BR /&gt;Transceiver: internal&lt;BR /&gt;Auto-negotiation: on&lt;BR /&gt;Current message level: 0x00000000 (0)&lt;BR /&gt;&lt;BR /&gt;thank you for reading&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Oct 2020 13:24:38 GMT</pubDate>
    <dc:creator>Lkge</dc:creator>
    <dc:date>2020-10-17T13:24:38Z</dc:date>
    <item>
      <title>First step with MHO and few questions about it</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/First-step-with-MHO-and-few-questions-about-it/m-p/99352#M337</link>
      <description>&lt;P&gt;hi maestro expert &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;i am making my first step to implemant maetro then i have some question about it :&lt;/P&gt;&lt;P&gt;Q1 : If i am correct there is no need to configure Sync interface for the gateway and in the maestro object in management server and in the mho security group . It will be automaticly use network 192.0.2.X on a virtual interface named Sync like in my lab :&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 10&lt;/P&gt;&lt;P&gt;eth1-05 10.20.0.1 VMAC address: 00:1C:7F:81:05:C1&lt;BR /&gt;eth1-06 81.255.188.1 VMAC address: 00:1C:7F:81:06:C1&lt;BR /&gt;eth1-07 192.168.4.4 VMAC address: 00:1C:7F:81:07:C1&lt;BR /&gt;eth1-08 81.255.188.253 VMAC address: 00:1C:7F:81:08:C1&lt;BR /&gt;eth1-09 10.10.0.254 VMAC address: 00:1C:7F:81:09:C1&lt;BR /&gt;eth1-10 10.0.50.1 VMAC address: 00:1C:7F:81:0A:C1&lt;BR /&gt;eth1-Mgmt1 217.109.182.193&lt;BR /&gt;eth1-CIN 198.51.101.2&lt;BR /&gt;eth2-CIN 198.51.101.202&lt;BR /&gt;Sync 192.0.2.2&lt;/P&gt;&lt;P&gt;[Expert@OIF-ch01-02:0]# ifconfig Sync&lt;BR /&gt;Sync Link encap:Ethernet HWaddr 00:1C:7F:02:04:FE&lt;BR /&gt;inet addr:192.0.2.2 Bcast:192.0.2.255 Mask:255.255.255.0&lt;BR /&gt;UP BROADCAST RUNNING MASTER MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:136664 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:62063 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:30427407 (29.0 MiB) TX bytes:5948091 (5.6 MiB)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Q2 : all members are in active state and the first gateway in the security group will be the pivot like in A/A with cluster XL or how traffic is handle when you have 3 gateway or more in the security group ?&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State&lt;/P&gt;&lt;P&gt;1 (local) 192.0.2.1 33% ACTIVE&lt;BR /&gt;2 192.0.2.2 33% ACTIVE&lt;BR /&gt;3 192.0.2.3 33% ACTIVE&lt;/P&gt;&lt;P&gt;Q3 : on the Smartcenter there is no way to check the HA status for the gateway in the secutiry group on the MHO config ?&lt;/P&gt;&lt;P&gt;Q4 : if i am correct with maestro there is only a virtual ip address configure in the smartcenter on the network management and no need to configure reel ip per node and define the interface as a cluster interface&lt;/P&gt;&lt;P&gt;Q5 : What is interface eth1-CIN and eth2-CIN with and adress IP in : 198.51.101.X ? none of this interface are set up on the mho security group :&lt;/P&gt;&lt;P&gt;In clish they not appear :&lt;/P&gt;&lt;P&gt;[Global] OIF-ch01-01 &amp;gt; show interface&lt;/P&gt;&lt;P&gt;eth1-05 eth1-06 eth1-07 eth1-08 eth1-09 eth1-10&lt;BR /&gt;eth1-11 eth1-12 eth1-Mgmt1 lo BPEth0 BPEth1&lt;/P&gt;&lt;P&gt;In Expert :&lt;/P&gt;&lt;P&gt;eth1-CIN Link encap:Ethernet HWaddr 00:1C:7F:81:42:01&lt;BR /&gt;inet addr:198.51.101.1 Bcast:198.51.101.127 Mask:255.255.255.128&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:741356 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:894418 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:226692007 (216.1 MiB) TX bytes:99844561 (95.2 MiB)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;eth2-CIN Link encap:Ethernet HWaddr 00:1C:7F:82:42:01&lt;BR /&gt;inet addr:198.51.101.201 Bcast:198.51.101.255 Mask:255.255.255.128&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:67704 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:0 (0.0 b) TX bytes:2843568 (2.7 MiB)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@OIF-ch01-01:0]# ethtool eth2-CIN&lt;BR /&gt;Settings for eth2-CIN:&lt;BR /&gt;Supported ports: [ FIBRE ]&lt;BR /&gt;Supported link modes: 10000baseT/Full&lt;BR /&gt;Supported pause frame use: Symmetric Receive-only&lt;BR /&gt;Supports auto-negotiation: Yes&lt;BR /&gt;Supported FEC modes: Not reported&lt;BR /&gt;Advertised link modes: 10000baseT/Full&lt;BR /&gt;Advertised pause frame use: Symmetric Receive-only&lt;BR /&gt;Advertised auto-negotiation: Yes&lt;BR /&gt;Advertised FEC modes: Not reported&lt;BR /&gt;Speed: 10000Mb/s&lt;BR /&gt;Duplex: Full&lt;BR /&gt;Port: FIBRE&lt;BR /&gt;PHYAD: 0&lt;BR /&gt;Transceiver: internal&lt;BR /&gt;Auto-negotiation: on&lt;BR /&gt;Current message level: 0x00000000 (0)&lt;BR /&gt;&lt;BR /&gt;thank you for reading&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 13:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/First-step-with-MHO-and-few-questions-about-it/m-p/99352#M337</guid>
      <dc:creator>Lkge</dc:creator>
      <dc:date>2020-10-17T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: First step with MHO and few questions about it</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/First-step-with-MHO-and-few-questions-about-it/m-p/99360#M338</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Based on little experience I have with Maestro I can try and answer some of your questions:&lt;/P&gt;&lt;P&gt;Q1:&amp;nbsp;&lt;SPAN&gt;192.0.2/24 is reserved for synchronization traffic&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Q3: There is not way to monitor the state in SmartConsole&lt;/P&gt;&lt;P&gt;Q4: In SmartConsole, you should add the IP of the Security Group and no need to add any other peer/node vIP ( globally, all appliances share the same network configuration received from the Security Group, only the Orchestrator in charge of the appliances, has/should have a different IP from the SG )&lt;/P&gt;&lt;P&gt;Q5:&amp;nbsp;&lt;SPAN&gt;198.51.101/24 is reserved for chassis internal networking messages&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Maybe this&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Maestro-Hyperscale-Security/Maestro-basic-setup-documentation/td-p/69907" target="_self"&gt;post&lt;/A&gt;&amp;nbsp;will help and answer more of your questions.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 15:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/First-step-with-MHO-and-few-questions-about-it/m-p/99360#M338</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-10-17T15:01:54Z</dc:date>
    </item>
  </channel>
</rss>

