<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH to Maestro SMO Master in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258209#M3640</link>
    <description>&lt;P&gt;I have two Maestro dual-site setups that are configured very similarly. When I connect to the security group on the first Maestro setup, I always end up on the SMO Master (sg-ch01-01: 192.0.2.1), but on the other Maestro setup I always end up on sg-ch01-02: 192.0.2.2. What could be the reason for this?&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2895"&gt;@Tom_Kendrick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1009"&gt;@Laszlo_Csosza&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5357"&gt;@Jochen_Hoechner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Sep 2025 12:14:24 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2025-09-29T12:14:24Z</dc:date>
    <item>
      <title>SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258209#M3640</link>
      <description>&lt;P&gt;I have two Maestro dual-site setups that are configured very similarly. When I connect to the security group on the first Maestro setup, I always end up on the SMO Master (sg-ch01-01: 192.0.2.1), but on the other Maestro setup I always end up on sg-ch01-02: 192.0.2.2. What could be the reason for this?&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2895"&gt;@Tom_Kendrick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1009"&gt;@Laszlo_Csosza&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5357"&gt;@Jochen_Hoechner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258209#M3640</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-29T12:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258211#M3641</link>
      <description>&lt;P&gt;run lldpctl and make sure the port for MHO should be Bpeth1-01/1-03, if is pair 02 or 03 is an issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 15:20:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258211#M3641</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2025-09-25T15:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258282#M3642</link>
      <description>&lt;P&gt;Which interface are you SSH'ing into?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 03:23:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258282#M3642</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-26T03:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258305#M3643</link>
      <description>&lt;P&gt;or member&amp;nbsp;&lt;SPAN&gt;192.0.2.1 is down and is not SMO, or&amp;nbsp;192.0.2.1 is not provisioned and your SMO is&amp;nbsp;192.0.2.2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;or HW chaned, we have ti like this&lt;/P&gt;
&lt;P&gt;1 - old 6500 decomisioned, IP free&lt;/P&gt;
&lt;P&gt;2 - old 6500&amp;nbsp;decomisioned but replaced with 9100&lt;/P&gt;
&lt;P&gt;3 - was free, provisioned second 9100&lt;/P&gt;
&lt;P&gt;4&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 12:00:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258305#M3643</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2025-09-26T12:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258309#M3644</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3205"&gt;@Dario_Perez&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13122"&gt;@Martin_Raska&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I'm connecting to the magg0 interface and IP of both SG's. No hardware was changed.&lt;BR /&gt;Orchestrators are MHO-175.&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31544i4A2BC390546B0FF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;STRONG&gt;maestro2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;SSH &amp;gt; You have logged into the system.&lt;BR /&gt;&lt;BR /&gt;[Expert@sg-ch01-&lt;FONT color="#FF6600"&gt;02&lt;/FONT&gt;:0]# asg_blade_config get_smo_ip | tr -d '\n';echo -n ' ('; egrep $(gexec -t -a|tr ',' '|')[[:space:]] /etc/hosts|grep $(asg_blade_config get_smo_ip|awk '{print $NF}')|awk '{print $NF}'|tr -d '\n';echo ')'&lt;BR /&gt;[Fri Sep 26 14:41:13 CEST 2025 | &lt;STRONG&gt;192.0.2.&lt;FONT color="#FF6600"&gt;2&lt;/FONT&gt;] SMO ip is: 192.0.2.1 (1_012_01)&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;[Expert@sg-ch01-&lt;FONT color="#FF6600"&gt;02&lt;/FONT&gt;:0]# asg monitor&lt;BR /&gt;--------------------------------------------------------------------------------
| System Status - Maestro                                                      |
--------------------------------------------------------------------------------
| Chassis Mode                | Primary Up (1 2)                               |
| SGMs                        | 4 / 4                                          |
| Version                     | R81.20                                         |
--------------------------------------------------------------------------------
| SGM ID             Chassis 1                          Chassis 2              |
|                    ACTIVE                             STANDBY                |
--------------------------------------------------------------------------------
|  1                 ACTIVE                             ACTIVE                 |
|  2                 ACTIVE                             ACTIVE                 |
--------------------------------------------------------------------------------
| Chassis HA mode:              Primary Up                                     |
--------------------------------------------------------------------------------&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;maestro1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;SSH &amp;gt; You have logged into the system.&lt;BR /&gt;
[Expert@sg-ch01-&lt;FONT color="#339966"&gt;01&lt;/FONT&gt;:0]# asg_blade_config get_smo_ip | tr -d '\n';echo -n ' ('; egrep $(gexec -t -a|tr ',' '|')[[:space:]] /etc/hosts|grep $(asg_blade_config get_smo_ip|awk '{print $NF}')|awk '{print $NF}'|tr -d '\n';echo ')'
[Fri Sep 26 14:57:31 CEST 2025 | &lt;STRONG&gt;192.0.2.&lt;FONT color="#339966"&gt;1&lt;/FONT&gt;] SMO ip is: 192.0.2.1 (1_012_022_01)&lt;/STRONG&gt;

[Expert@sg-ch01-&lt;FONT color="#339966"&gt;01&lt;/FONT&gt;:0]# asg monitor
--------------------------------------------------------------------------------
| System Status - Maestro                                                      |
--------------------------------------------------------------------------------
| Chassis Mode                | Primary Up (1 2)                               |
| SGMs                        | 6 / 6                                          |
| Version                     | R81.20                                         |
--------------------------------------------------------------------------------
| SGM ID             Chassis 1                          Chassis 2              |
|                    ACTIVE                             STANDBY                |
--------------------------------------------------------------------------------
|  1                 ACTIVE                             ACTIVE                 |
|  2                 ACTIVE                             ACTIVE                 |
|  3                 ACTIVE                             ACTIVE                 |
--------------------------------------------------------------------------------
| Chassis HA mode:              Primary Up                                     |
--------------------------------------------------------------------------------&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 16:00:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258309#M3644</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-26T16:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258368#M3645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can run &lt;STRONG&gt;asg stat -i tasks&lt;/STRONG&gt; from each security group and you will see the real SMO&lt;/P&gt;</description>
      <pubDate>Sat, 27 Sep 2025 04:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258368#M3645</guid>
      <dc:creator>Anatoly</dc:creator>
      <dc:date>2025-09-27T04:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258427#M3646</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;&lt;CODE&gt;asg stat -i tasks&lt;/CODE&gt; looks almost identical on maestro2 and maestro1, but I'm still getting logged in to SGM2 when I connect to the sg of maestro2.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;maestro2:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;SSH &amp;gt; You have logged into the system.

[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;02&lt;/FONT&gt;&lt;/STRONG&gt;:0]# asg stat -i tasks
--------------------------------------------------------------------------------
| Task (Task ID)     |        Chassis 1           |        Chassis 2           |
--------------------------------------------------------------------------------
| SMO (0)            |         1                  |                            |
| General (1)        |         1                  |         1                  |
| LACP (2)           |         1                  |         1                  |
| CH Monitor (3)     |         1                  |         1                  |
| DR Manager (4)     |         1                  |                            |
| UIPC (5)           |         1                  |         1                  |
| Alert (6)          |         1                  |                            |
--------------------------------------------------------------------------------

[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;02&lt;/FONT&gt;&lt;/STRONG&gt;:0]# echo $CPHA_SMO
1
&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;maestro1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;SSH &amp;gt; You have logged into the system.

[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#339966"&gt;01&lt;/FONT&gt;&lt;/STRONG&gt;:0]# asg stat -i tasks
--------------------------------------------------------------------------------
| Task (Task ID)     |        Chassis 1           |        Chassis 2           |
--------------------------------------------------------------------------------
| SMO (0)            |         1(local)           |                            |
| General (1)        |         1(local)           |         1                  |
| LACP (2)           |         1(local)           |         1                  |
| CH Monitor (3)     |         1(local)           |         1                  |
| DR Manager (4)     |         1(local)           |                            |
| UIPC (5)           |         1(local)           |         1                  |
| Alert (6)          |         1(local)           |                            |
--------------------------------------------------------------------------------

[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#339966"&gt;01&lt;/FONT&gt;&lt;/STRONG&gt;:0]# echo $CPHA_SMO
1&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 05:52:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258427#M3646</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-29T05:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258444#M3647</link>
      <description>&lt;P&gt;It mean that everything is OK with SMO and this is SGM #1. You get into another SGM, because your connection pass distribution. And it might happen for one of 2 reasons:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. You access to management IP not from management network&lt;/P&gt;
&lt;P&gt;2. You applied&amp;nbsp;sk179005 and then traffic on management network will be distributed regardless the SMO&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 11:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258444#M3647</guid>
      <dc:creator>Anatoly</dc:creator>
      <dc:date>2025-09-29T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258454#M3649</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;, thanks for your reply.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Both Maestro environments were configured with a Magg interface, and I access it via a data interface.&lt;/LI&gt;
&lt;LI&gt;Regarding&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179005" target="_self"&gt;sk179005&lt;/A&gt;, the feature should be on by default, as my two Maestro environments run on R81.20.&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;BR /&gt;maestro2:&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;02&lt;/FONT&gt;&lt;/STRONG&gt;:0]# g_fw -a ctl get int fwha_data_mgmt_connection
-*- 4 blades: 1_01 1_02 2_01 2_02 -*-
fwha_data_mgmt_connection = &lt;STRONG&gt;1
&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;maestro1:&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;[Expert@sg-ch01-&lt;STRONG&gt;&lt;FONT color="#339966"&gt;01&lt;/FONT&gt;&lt;/STRONG&gt;:0]# g_fw -a ctl get int fwha_data_mgmt_connection
-*- 6 blades: 1_01 1_02 1_03 2_01 2_02 2_03 -*-
fwha_data_mgmt_connection = &lt;STRONG&gt;1
&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;BR /&gt;Looks like&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179005" target="_self"&gt;sk179005&lt;/A&gt;&amp;nbsp;needs a fix, as it says:&lt;BR /&gt;"In a&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;Dual-Site environment with three Security Group Members on each Site. the active Security Group Members are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1_1 (SMO), 1_&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;3&lt;/FONT&gt;&lt;/STRONG&gt;, 1_&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;4&lt;/FONT&gt;&lt;/STRONG&gt; (Active Site)"&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It should correctly say:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;1_1 (SMO), 1_&lt;STRONG&gt;&lt;FONT color="#339966"&gt;2&lt;/FONT&gt;&lt;/STRONG&gt;, 1_&lt;STRONG&gt;&lt;FONT color="#339966"&gt;3&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;(Active Site)&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Sep 2025 13:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258454#M3649</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-29T13:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258458#M3650</link>
      <description>&lt;P&gt;this is just an example. If you had security group of 4 members, and you excluded 1_2, the rest won't be renumbered: 1_1,1_3 and 1_4&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 12:15:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258458#M3650</guid>
      <dc:creator>Anatoly</dc:creator>
      <dc:date>2025-09-29T12:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258462#M3651</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;, thanks for explaining.&lt;BR /&gt;&lt;BR /&gt;Is it important that the &lt;STRONG&gt;Main IP&lt;/STRONG&gt;, as shown at the security group object in SmartConsole, &lt;STRONG&gt;matches&lt;/STRONG&gt; the management IP address of &lt;STRONG&gt;Gaia management interface &lt;/STRONG&gt;&amp;gt; magg0 ?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31561i200F8A079E1C5A60/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 551px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31562i520C98E6F6EDB565/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 13:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258462#M3651</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-29T13:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258464#M3652</link>
      <description>&lt;P&gt;Like regular GW, I think it will work even if it doesn't match&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2025 13:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258464#M3652</guid>
      <dc:creator>Anatoly</dc:creator>
      <dc:date>2025-09-29T13:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258470#M3653</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4113"&gt;@Anatoly&lt;/a&gt;. I understand. It is a best practice, not a requirement.&lt;BR /&gt;&lt;BR /&gt;FYI: If the Main IP doesn't match the Gaia management interface IP, &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204/highlight/true#M2659" target="_self"&gt;tools like this&lt;/A&gt; will fail, because &lt;CODE&gt;$FWDIR/state/local/FW1/local.set&lt;/CODE&gt; and &lt;CODE&gt;/etc/hosts&lt;/CODE&gt; don't have a match for the gateway object.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#993366"&gt;Key Considerations&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Main IP&lt;/STRONG&gt; in SmartConsole:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;This is the IP used for Secure Internal Communication (SIC) between the Security Management Server and the gateway.&lt;/LI&gt;
&lt;LI&gt;It should be reachable from the management server and typically corresponds to the interface used for management traffic.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Gaia Management Interface IP&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;This is the IP address used to access the Gaia Portal or CLI for system-level configuration.&lt;/LI&gt;
&lt;LI&gt;It may be on a different interface than the one used for SIC or policy installation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;FONT color="#993366"&gt;Best Practice&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Ideally, the Main IP in SmartConsole should match the IP of the interface used for management access, which is often the same as the Gaia management interface.&lt;/P&gt;
&lt;P&gt;However, if your gateway has multiple interfaces and you manage it through a different one (e.g., internal vs external), the Main IP can be set to whichever interface is used for SIC and policy pushes.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#993366"&gt;Important Notes&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;If you change the Main IP in SmartConsole, you’ll need to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Reset and re-establish SIC&lt;/LI&gt;
&lt;LI&gt;Possibly renew VPN certificates&lt;/LI&gt;
&lt;LI&gt;Reinstall policies to ensure proper communication&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Sep 2025 14:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/258470#M3653</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-29T14:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/262909#M3801</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;So, you’re concluding that, in order for the SSH connection to always be established with the SGM that has the SMO role within the security group, the IP address should be the management interface one? Because if you make the SSH session to a different IP, it’s possible that you’ll connect to another SGM — for example, in your case, sg-ch01-02:0?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 16:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/262909#M3801</guid>
      <dc:creator>alexgnunez2</dc:creator>
      <dc:date>2025-11-14T16:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/262917#M3802</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/78339"&gt;@alexgnunez2&lt;/a&gt;&amp;nbsp;: As Anatoly concluded I&amp;nbsp;get into another SGM, because of connection pass distribution as I access the management IP not from management network.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2025 21:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/262917#M3802</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-11-14T21:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263236#M3804</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I must say, that I really admire your excellent tools, that make my everyday live with Check Point much simpler!&lt;/P&gt;&lt;P&gt;Do you think that applying this tool would solve this issue?&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Forwarding-specific-inbound-connections-to-SMO.htm?TocPath=System%20Optimization%7C_____5" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Maestro_AdminGuide/Content/Topics-Maestro-AG/Forwarding-specific-inbound-connections-to-SMO.htm?TocPath=System%20Optimization%7C_____5&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 19:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263236#M3804</guid>
      <dc:creator>JaAnd</dc:creator>
      <dc:date>2025-11-19T19:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263253#M3805</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/79692"&gt;@JaAnd&lt;/a&gt;, I'm glad my tools are helpful for you.&lt;BR /&gt;&lt;BR /&gt;Yes, as I &lt;A href="https://community.checkpoint.com/t5/Maestro/Question-about-distribution-mode-settings/m-p/136992/highlight/true#M703" target="_self"&gt;described here&lt;/A&gt;, &lt;CODE&gt;asg_excp_conf&lt;/CODE&gt; would help to stick my SSH connection to the SMO.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2025 23:06:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263253#M3805</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-11-19T23:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263545#M3811</link>
      <description>&lt;P&gt;I experienced a similar "issue" with a one SG, but implementing asg_excp_conf successfully resolved it.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 12:05:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/263545#M3811</guid>
      <dc:creator>JaAnd</dc:creator>
      <dc:date>2025-11-24T12:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Maestro SMO Master</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/264682#M3831</link>
      <description>&lt;P&gt;We now have a new SK discussing related things:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk184326" target="_self"&gt;sk184326: SSH Connection Routing Behavior for Internal Interfaces in Maestro Security Groups&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Dec 2025 15:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SSH-to-Maestro-SMO-Master/m-p/264682#M3831</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-12-07T15:30:59Z</dc:date>
    </item>
  </channel>
</rss>

