<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create Maestro SG in remote site in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Create-Maestro-SG-in-remote-site/m-p/104598#M392</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a question I didn’t spot the answer to in the documentation. I need to build a Maestro solution in a location remote to the Smart Management Server and I don’t know best to proceed...&lt;/P&gt;&lt;P&gt;The target site setup is fairly straightforward, an external interface (facing the Internet) and an internal one (facing site). A pair of Maestro orchestrators (140) with a trio of 6600s. Each Maestro will connect to the internal site via interface 5 and the external site via interface 7. The internal links will be a bond, as will the external ones.&lt;/P&gt;&lt;P&gt;My confusion arises over the management interfaces and the Security Group IP address. As the site is remote, there’s no available address to assign to the management interface/Security Group. Using a regular gateway, I’d use the external interface to connect to but is that a legitimate thing to do in this scenario and if it is, how do I bond the interfaces and apply vlans before I can connect to the SG IP address to do so?&lt;/P&gt;&lt;P&gt;I hope that makes sense. Links to documentation, solutions, other similar posts would be really appreciated.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Aid&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2020 23:18:00 GMT</pubDate>
    <dc:creator>Adrian_Fullerto</dc:creator>
    <dc:date>2020-12-07T23:18:00Z</dc:date>
    <item>
      <title>Create Maestro SG in remote site</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Create-Maestro-SG-in-remote-site/m-p/104598#M392</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I have a question I didn’t spot the answer to in the documentation. I need to build a Maestro solution in a location remote to the Smart Management Server and I don’t know best to proceed...&lt;/P&gt;&lt;P&gt;The target site setup is fairly straightforward, an external interface (facing the Internet) and an internal one (facing site). A pair of Maestro orchestrators (140) with a trio of 6600s. Each Maestro will connect to the internal site via interface 5 and the external site via interface 7. The internal links will be a bond, as will the external ones.&lt;/P&gt;&lt;P&gt;My confusion arises over the management interfaces and the Security Group IP address. As the site is remote, there’s no available address to assign to the management interface/Security Group. Using a regular gateway, I’d use the external interface to connect to but is that a legitimate thing to do in this scenario and if it is, how do I bond the interfaces and apply vlans before I can connect to the SG IP address to do so?&lt;/P&gt;&lt;P&gt;I hope that makes sense. Links to documentation, solutions, other similar posts would be really appreciated.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Aid&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 23:18:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Create-Maestro-SG-in-remote-site/m-p/104598#M392</guid>
      <dc:creator>Adrian_Fullerto</dc:creator>
      <dc:date>2020-12-07T23:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Create Maestro SG in remote site</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Create-Maestro-SG-in-remote-site/m-p/104879#M393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, you can manage your security group from external interface. You can just assign some dummy IP for eth1-Mgmt interface and not use it.&lt;/P&gt;
&lt;P&gt;Please note, Security Group's web services (like WebUI) will work properly only if you disable layer-4 distribution. That is because your connection is expected to be distributed if it comes not from management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anatoly&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Create-Maestro-SG-in-remote-site/m-p/104879#M393</guid>
      <dc:creator>Anatoly</dc:creator>
      <dc:date>2020-12-10T04:19:06Z</dc:date>
    </item>
  </channel>
</rss>

