<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro Best Practices in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/258198#M3639</link>
    <description>&lt;P&gt;for VSX you can work on different scenarios and by default is auto-topology per-port&lt;/P&gt;
&lt;P&gt;read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108842" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108842&lt;/A&gt;&amp;nbsp;for further information&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 13:47:35 GMT</pubDate>
    <dc:creator>Dario_Perez</dc:creator>
    <dc:date>2025-09-25T13:47:35Z</dc:date>
    <item>
      <title>Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256512#M3605</link>
      <description>&lt;P&gt;Hi Everyone!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P data-start="77" data-end="367"&gt;I’m excited to share that my colleague John White and I have co-authored a new &lt;STRONG data-start="156" data-end="188"&gt;Maestro Best Practices Guide&lt;/STRONG&gt;. This document brings together lessons learnt from real-world projects and field experience, and we hope it will serve as a practical resource for anyone working with Maestro.&lt;/P&gt;
&lt;P data-start="369" data-end="653"&gt;Please feel free to save it for your own use — and more importantly, let us know your feedback. If you have additional best practices or tips from the field, share them here. I’ll be happy to incorporate them into future updates so this guide continues to grow with community input.&lt;/P&gt;
&lt;P data-start="655" data-end="708"&gt;Looking forward to your thoughts and contributions!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 18:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256512#M3605</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2025-09-03T18:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256514#M3606</link>
      <description>&lt;P&gt;Thanks for putting this together!&lt;BR /&gt;&lt;BR /&gt;I recommend running the document through a grammar checker like &lt;A href="https://languagetool.org" target="_self"&gt;LanguageTool&lt;/A&gt;&amp;nbsp;to improve clarity and correctness.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 19:05:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256514#M3606</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-03T19:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256526#M3607</link>
      <description>&lt;P&gt;Great work!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 16:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256526#M3607</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2025-09-03T16:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256531#M3608</link>
      <description>&lt;P&gt;Thanks for the feedback Danny. I replaced the file in my original post with a fixed version now. Some of them I already had fixed in the Word-version, but for some reason the version I posted had still those errors.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 18:04:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256531#M3608</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2025-09-03T18:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256532#M3609</link>
      <description>&lt;P&gt;Amazing job...super helpful!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 18:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256532#M3609</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-03T18:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256541#M3610</link>
      <description>&lt;P&gt;Looks good Lari, thanks again for your support on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Sep 2025 01:23:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256541#M3610</guid>
      <dc:creator>John_White</dc:creator>
      <dc:date>2025-09-04T01:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256681#M3611</link>
      <description>&lt;P&gt;Great stuff, I'll make sure to call it out in the next CheckMates Go episode &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 20:42:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256681#M3611</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-05T20:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256682#M3612</link>
      <description>&lt;P&gt;Jonny White...man, cant believe I see you on here...its been FOREVER lol&lt;/P&gt;
&lt;P&gt;Hows life? : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 21:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256682#M3612</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-05T21:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256685#M3613</link>
      <description>&lt;P&gt;Incredible, thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;!&amp;nbsp; I always appreciate seeing battle-hardened best practice recommendations like this, formed by dozens (if not hundreds) of complex Maestro deployments in the real world.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 23:06:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256685#M3613</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-05T23:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256686#M3614</link>
      <description>&lt;P&gt;I saw all&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;did for one of our clients for maestro deployment and they were so impressed, to say the least. Personally, I had never seen that level of knowledge and expertise from someone, its hard to even describe with right words.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 06 Sep 2025 02:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256686#M3614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-06T02:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256721#M3615</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;, great work!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 06:31:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256721#M3615</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-08T06:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256799#M3616</link>
      <description>&lt;P&gt;Thank you so much, Andy — I’m truly humbled by your kind words.&lt;/P&gt;
&lt;P&gt;It’s always a privilege to support our customers, wherever they are, and I’m glad I could contribute to a successful Maestro deployment. Seeing the impact of our work firsthand and knowing it made a difference for the client is incredibly rewarding.&lt;/P&gt;
&lt;P&gt;I’m grateful to be part of a team that values excellence and collaboration. Always happy to help!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 18:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256799#M3616</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2025-09-08T18:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256800#M3617</link>
      <description>&lt;P&gt;100%...maybe if I say RC in Ottawa, you may remember who it was : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 18:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256800#M3617</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-08T18:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256813#M3618</link>
      <description>&lt;P&gt;I would add this Key reason in point 6:&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;If shared uplink is used then each SG should have unique VLAN IDs. It's no posible to have the same VLAN ID in multiple SGs with shared UPLINKs.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;That's an important point that everyone should have in mind while designing. We are in the middle of a migration and had to change the design from 2 SG to 1 SG because of this.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 19:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256813#M3618</guid>
      <dc:creator>adelguia</dc:creator>
      <dc:date>2025-09-08T19:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256820#M3619</link>
      <description>&lt;P data-start="88" data-end="132"&gt;Good point, and thanks for bringing it up.&lt;/P&gt;
&lt;P data-start="134" data-end="408"&gt;Just to highlight: &lt;STRONG data-start="153" data-end="277"&gt;different VLAN IDs between Security Groups on shared uplinks are not only best practice, but a mandatory requirement.&lt;/STRONG&gt; The system won’t allow the same VLAN ID across multiple SGs on a shared uplink, so this needs to be accounted for during design.&lt;/P&gt;
&lt;P data-start="410" data-end="659"&gt;That said, the stronger recommendation is to &lt;STRONG data-start="455" data-end="502"&gt;use dedicated interfaces per Security Group&lt;/STRONG&gt; whenever possible. Shared uplinks can create dependencies where external issues affect every SG tied to that interface, reducing isolation and resiliency.&lt;/P&gt;
&lt;P data-start="661" data-end="774"&gt;Your example is a good reminder that planning these details upfront helps avoid costly redesigns mid-migration.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Sep 2025 22:07:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/256820#M3619</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2025-09-08T22:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/257153#M3626</link>
      <description>&lt;P&gt;Great work&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;and all contributors!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&amp;nbsp;Thank you for putting the things together and describing the key reasons behind each topic which is even more important. The key reasons behind a specific design or configuration are not obvious for everyone in first place and sometimes not part of Admin Guides.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 07:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/257153#M3626</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2025-09-12T07:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/258175#M3638</link>
      <description>&lt;P&gt;In Maestro deployment for DC traffic without any NAT, I remember from other webinars that it is recommended to use general mode.&lt;/P&gt;
&lt;P&gt;In the &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Working-with-Distribution-Mode.htm#Background" target="_blank" rel="noopener"&gt;relevant guide&lt;/A&gt;, it is mentioned not to change the distribution mode of a VS for performance reasons, without further explanations.&lt;/P&gt;
&lt;P&gt;What does this mean?&lt;/P&gt;
&lt;P&gt;- Should we change the distribution mode to general on VS0 only?&lt;/P&gt;
&lt;P&gt;- Not change it at all if we use VSX?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 11:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/258175#M3638</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-09-25T11:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Best Practices</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/258198#M3639</link>
      <description>&lt;P&gt;for VSX you can work on different scenarios and by default is auto-topology per-port&lt;/P&gt;
&lt;P&gt;read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108842" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108842&lt;/A&gt;&amp;nbsp;for further information&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 13:47:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Best-Practices/m-p/258198#M3639</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2025-09-25T13:47:35Z</dc:date>
    </item>
  </channel>
</rss>

