<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support) in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259506#M3678</link>
    <description>&lt;P&gt;Is depending how fabric is routing/balancing traffic through sites, could be using SVI or IPN but is depending if have any other routing 3party if fabric is working on L3-out or if is using Service Graph. each scenario is different as per need.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommended reach your local SE then if you have special need. SE can work together with Solution Center where they can build the lab/PoC as customer need and create the proper design.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Oct 2025 03:00:48 GMT</pubDate>
    <dc:creator>Dario_Perez</dc:creator>
    <dc:date>2025-10-09T03:00:48Z</dc:date>
    <item>
      <title>Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259132#M3672</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P data-start="608" data-end="756"&gt;I have a few questions regarding the Check Point integration with Cisco ACI, especially in Multi-Pod deployments and when using Maestro.&lt;/P&gt;
&lt;P data-start="608" data-end="756"&gt;I’ve reviewed the following document:&lt;BR data-start="798" data-end="801" /&gt;Private Cloud Security for Cisco ACI Infrastructure – Release 2.0&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Cloud-Network-Security/Private-Cloud-Security-for-Cisco-ACI-Infrastructure-Whitepaper-2/m-p/139065" target="_blank"&gt;https://community.checkpoint.com/t5/Cloud-Network-Security/Private-Cloud-Security-for-Cisco-ACI-Infrastructure-Whitepaper-2/m-p/139065&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The whitepaper describes two firewall deployment options for Multi-Pod stretched networks:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Active-Active Firewall with different IP / MAC addresses using LPBR&lt;/LI&gt;
&lt;LI&gt;Active-Active Firewall with the same IP/MAC addresses using Cisco Anycast&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The document mentions that Maestro deployment for both scenarios was not GA at the time. Since the document dates from 2022, could someone please confirm if this is now GA and officially supported by Check Point?&lt;/P&gt;
&lt;P data-start="1654" data-end="1889"&gt;Additionally, both deployment examples describe a setup with one MHO per pod, with a sync interface between them.&lt;BR data-start="1775" data-end="1778" /&gt;From a Maestro perspective, it means as a single site / dual orchestrator configuration?&lt;/P&gt;
&lt;P data-start="1894" data-end="2185"&gt;Finally, both designs rely on Active-Active firewall operation. Considering that Check Point introduced new capabilities with ElasticXL since 2022, which Active-Active model would be recommended for Multi-Pod stretched environments — ClusterXL, ElasticXL, or Maestro?&lt;/P&gt;
&lt;P data-start="2190" data-end="2267"&gt;Any guidance or or help would be highly appreciated.&lt;/P&gt;
&lt;P data-start="2190" data-end="2267"&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 15:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259132#M3672</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-10-06T15:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259184#M3673</link>
      <description>&lt;P&gt;Active/Active dual site Maestro is available in R82 with special involvement from CP. It's considered GA but it's not available out of the box. It's similar to CXL Active/Active geo cluster, in that it's separate IPs per site, but I don't know how it applies to ACI installs. Probably best to contact your local sales office to involve our architecture team here for a full update on what we can do with ACI.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 02:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259184#M3673</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-07T02:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259453#M3674</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;Do you know if there is any doc we can check about &lt;SPAN&gt;Active/Active dual site Maestro?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If someone else has recommendation for active/active deployment in ACI i'd appreciate it. Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 14:24:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259453#M3674</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-10-08T14:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259502#M3677</link>
      <description>&lt;P&gt;I don't think we have public documentation about it at this stage.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2025 23:30:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259502#M3677</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-10-08T23:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point integration with Cisco ACI Multi-Pod (Maestro and Active-Active support)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259506#M3678</link>
      <description>&lt;P&gt;Is depending how fabric is routing/balancing traffic through sites, could be using SVI or IPN but is depending if have any other routing 3party if fabric is working on L3-out or if is using Service Graph. each scenario is different as per need.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recommended reach your local SE then if you have special need. SE can work together with Solution Center where they can build the lab/PoC as customer need and create the proper design.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 03:00:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Check-Point-integration-with-Cisco-ACI-Multi-Pod-Maestro-and/m-p/259506#M3678</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2025-10-09T03:00:48Z</dc:date>
    </item>
  </channel>
</rss>

