<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Typical Check Point Maestro Project in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103604#M388</link>
    <description>&lt;P&gt;I must have missed this when it was originally posted. Very interesting!&lt;/P&gt;
&lt;P&gt;Is the sync between the Maestro boxes directly connected? I know with firewalls this is a very bad idea. Firewall sync should go through a switch to avoid problems when rebooting one of the members (when they're directly connected and you reboot member A, member B sees its interface go down, and has to go into contention to see if its peer failed or it failed; a failure in contention can cause B to refuse to take over). How do the Maestro boxes handle that?&lt;/P&gt;</description>
    <pubDate>Sun, 29 Nov 2020 15:02:50 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2020-11-29T15:02:50Z</dc:date>
    <item>
      <title>Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/79291#M180</link>
      <description>&lt;P&gt;Hi. Just decided to share our typical Maestro project. Here you can see the topology. I hope it will help someone to create their own project or just for better understanding how Maestro works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;L1 scheme:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="L1.png" style="width: 816px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5009iA5DCC47D8AE075EB/image-dimensions/816x461?v=v2" width="816" height="461" role="button" title="L1.png" alt="L1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;L2 shceme:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="L2.png" style="width: 808px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5010i80A7AFE38C32BE4D/image-dimensions/808x523?v=v2" width="808" height="523" role="button" title="L2.png" alt="L2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;L3 scheme:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="L3.png" style="width: 814px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5011iB67C38EF54EB0DAE/image-dimensions/814x354?v=v2" width="814" height="354" role="button" title="L3.png" alt="L3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;If you have any question feel free to ask.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 07:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/79291#M180</guid>
      <dc:creator>Evgeniy_Olkov</dc:creator>
      <dc:date>2020-03-23T07:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83753#M190</link>
      <description>Hi Evgeniy, thank you for this valuable information.&lt;BR /&gt;&lt;BR /&gt;You know how it would be a topology with two sites and a single MHO in each? and if the deployment with 3 MHO is supported? (2 in one site and just 1 in the other site)</description>
      <pubDate>Thu, 30 Apr 2020 14:21:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83753#M190</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-04-30T14:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83884#M194</link>
      <description>Hi! Thanks for the feedback!&lt;BR /&gt;Unfortunately, I don't have the dual site topology. But I know for sure, that it should be symmetrical (1 and 1 or 2 and 2).</description>
      <pubDate>Sat, 02 May 2020 03:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83884#M194</guid>
      <dc:creator>Evgeniy_Olkov</dc:creator>
      <dc:date>2020-05-02T03:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83908#M195</link>
      <description>Dual site with 3 MHO's is not supported at all. The dual site situation is setup with either 1 MHO on each site or 2 on each site. For the Dual site to work you need to duplicate the drawing and make sure all VLAN's are stretched over to the other location. On top of that you need to create portchannels/bonding groups for all ports used in the dual MHO setups, single site-dual MHO or dual site-dual MHO.</description>
      <pubDate>Sat, 02 May 2020 17:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/83908#M195</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-02T17:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103583#M387</link>
      <description>&lt;P&gt;Hi Evgeniy,&lt;/P&gt;&lt;P&gt;thank you for sharing your topology design and the outstanding diagrams!&lt;/P&gt;&lt;P&gt;In this topology is the Maestro being used to inspect east-west traffic (between local vlans) in addition to north-south traffic (to/from internet)? - or is it used only for north-south traffic inspection ?&lt;/P&gt;&lt;P&gt;If the Maestro is used to inspect east-west traffic, are the local vlans gateways on the core-switch or are they (moved) onto the Maestro (security appliances) ?&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Sherif&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 18:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103583#M387</guid>
      <dc:creator>Sherif</dc:creator>
      <dc:date>2020-11-28T18:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103604#M388</link>
      <description>&lt;P&gt;I must have missed this when it was originally posted. Very interesting!&lt;/P&gt;
&lt;P&gt;Is the sync between the Maestro boxes directly connected? I know with firewalls this is a very bad idea. Firewall sync should go through a switch to avoid problems when rebooting one of the members (when they're directly connected and you reboot member A, member B sees its interface go down, and has to go into contention to see if its peer failed or it failed; a failure in contention can cause B to refuse to take over). How do the Maestro boxes handle that?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 15:02:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103604#M388</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2020-11-29T15:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103628#M389</link>
      <description>&lt;P&gt;Hi Evgeniy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nice diagram. Relatively easy to understand and interpret your diagram. Could you please share what tools you are using to draw this network diagram?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Darren&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 04:08:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/103628#M389</guid>
      <dc:creator>Darren_Phang</dc:creator>
      <dc:date>2020-11-30T04:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/183681#M2017</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Evgeniy,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have used this topology with VSX, and I have issues with connection between security group (SG) with VSX. I have config one VSX for management zone (include SG management and others management devices), and all devices have default gateway is IP of VSX. All devices on management zone could ping and connect but only IP of SG couldn't ping or connect to IP of VSX. I have show arp on SG and see mac address of VSX but on I don't see mac address of SG on VSX.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 04:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/183681#M2017</guid>
      <dc:creator>Outis</dc:creator>
      <dc:date>2023-06-09T04:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Typical Check Point Maestro Project</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/183690#M2018</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/80602"&gt;@Outis&lt;/a&gt;,&amp;nbsp;this is a very old post. I suggest you to open a new discussion and ask community for help&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 12:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Typical-Check-Point-Maestro-Project/m-p/183690#M2018</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-06-09T12:52:57Z</dc:date>
    </item>
  </channel>
</rss>

