<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances) in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276052#M4198</link>
    <description>&lt;P&gt;The MHO's address is 172.30.47.251. This is accessible from a different subnet in which my Windows host is located.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The routing table looks like this:&lt;BR /&gt;[Expert@Bravo_SG-ch01-01:0]# netstat -rn&lt;BR /&gt;Kernel IP routing table&lt;BR /&gt;Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Genmask&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Flags&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MSS&amp;nbsp; &amp;nbsp;Windows&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;irtt&amp;nbsp; Iface&lt;BR /&gt;0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;172.30.47.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;UG&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-Mgmt1&lt;BR /&gt;172.30.47.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 255.255.255.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-Mgmt1&lt;BR /&gt;192.0.2.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Sync&lt;BR /&gt;198.51.101.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp;255.255.255.128&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-CIN&lt;/P&gt;&lt;P&gt;The icmp packets does not make it to the destination interface in a regular basis. So, now it seems for me that Layer 1 is somewhat affected. But not sure.&lt;/P&gt;&lt;P&gt;The IP of the Security Group is 172.30.47.247.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2026 13:53:47 GMT</pubDate>
    <dc:creator>Yasushi_Kono1</dc:creator>
    <dc:date>2026-04-24T13:53:47Z</dc:date>
    <item>
      <title>Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275983#M4182</link>
      <description>&lt;P&gt;Dear Check Point Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering whether you have seen this kind of issue: You configure a single site/single orchestrator (show maestro configuration [orchestrator-amount | orchestrator-site-amount]) environment. As I have configured a Security Group with an IP address in the same IP subnet as my Windows host is located, the next step would be to launch that Security Group via https. But the TLS connection cannot be established. This is misbehaviour I have never seen before.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Do you have any hints?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 09:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275983#M4182</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-23T09:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275984#M4183</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;are you able to ping the Security Group IP? Did you try a tcpdump on the management interface configured with the Security Group IP? Could you also perform a netstat -tapn | grep 443 when connected to the Security Group via ssh?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 10:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275984#M4183</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-23T10:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275987#M4184</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;What version are you on? What kind of setup? Gateway, VSX Gateway or VSNext Gateway?&lt;BR /&gt;&lt;BR /&gt;I would work my way up the OSI layers to see what is wrong.&lt;BR /&gt;&lt;BR /&gt;I assume cabling has been checked by you. &lt;BR /&gt;Did you configure a bonding group (MAGG0) for management? If so, make sure this is Active/Backup with a Primary Interface configured. The ports on the switch should be normal access ports.&lt;BR /&gt;&lt;BR /&gt;Does your computer learn the MAC-address of the Security Group?&lt;BR /&gt;Packets captures with tcpdump would be the next to investigate.&lt;BR /&gt;&lt;BR /&gt;Did you manage to create the SMO in SmartConsole and install policy?&lt;BR /&gt;If so, do you see drops in SmartLog? Perform a zdebug if needed.&lt;BR /&gt;&lt;BR /&gt;Hope these tips point you in the right direction. Let us know how it goes.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 10:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/275987#M4184</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-04-23T10:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276005#M4187</link>
      <description>&lt;P&gt;Thanks to Simone and Martijn,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I could extract the SG configuration from the MHO CLI with&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;show maestro security-group id 1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;and tried to ping the ip of the sg. And I established a second SSH connection to the MHO and did a&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;tcpdump -i Mgmt2 -n arp&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;and could see a series of "ARP: who-has" entries.&lt;BR /&gt;So, Layer 1 is fine, but Layer 2 not. I put the interfaces in question to the appropriate VLAN in Cisco Catalyst, but the behaviour remained the same. I am not yet in the phase of configuring the SMO object on the Management Server.&amp;nbsp;&lt;BR /&gt;Because of these issues, I am not able to SSH to the SG.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 15:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276005#M4187</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-23T15:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276007#M4188</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Interface Mgmt2 seems to me a management interface of the MHO. The management interface of a Security Group is eth1-mgmt or magg0 if you have created a bonding group.&lt;BR /&gt;&lt;BR /&gt;Are you performing the tcpdump on the MHO or on a SGM within the Security Group?&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 16:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276007#M4188</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-04-23T16:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276008#M4189</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;... You should connect to the Security group (through the MHO) and then start TCPDUMP using the management interface of the Security Group to check if you received any traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 16:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276008#M4189</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-23T16:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276048#M4194</link>
      <description>&lt;P&gt;I get an "ARP who-has" entry in a quite irregular basis. But, ifconfig eth1-Mgmt1 reveals the receipt of packets. Quite interesting behaviour!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 12:58:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276048#M4194</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-24T12:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276049#M4195</link>
      <description>&lt;P&gt;Well ... do you see any mac address using the command arp -an | grep eth1-Mgmt1?&lt;/P&gt;
&lt;P&gt;Are you able to ping any host on the network connected to&amp;nbsp;eth1-Mgmt1?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 13:06:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276049#M4195</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-24T13:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276050#M4196</link>
      <description>&lt;P&gt;No, what I noticed now is that when I ping the Security Group from the MHO, you can see increasing amount of RX bytes but no changes to TX bytes. So, it gets the ping packets but does not reply to them. Never noticed this behaviour before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 13:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276050#M4196</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-24T13:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276051#M4197</link>
      <description>&lt;P&gt;What is the IP address of the MHO?&lt;/P&gt;
&lt;P&gt;Could you provide the routing table (netstat -r) of the security group?&lt;/P&gt;
&lt;P&gt;So using TCPDUMP on the Security Group, when pinging from the MHO you should see these icmp request arriving, right?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 13:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276051#M4197</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-24T13:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276052#M4198</link>
      <description>&lt;P&gt;The MHO's address is 172.30.47.251. This is accessible from a different subnet in which my Windows host is located.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The routing table looks like this:&lt;BR /&gt;[Expert@Bravo_SG-ch01-01:0]# netstat -rn&lt;BR /&gt;Kernel IP routing table&lt;BR /&gt;Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Genmask&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Flags&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MSS&amp;nbsp; &amp;nbsp;Windows&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;irtt&amp;nbsp; Iface&lt;BR /&gt;0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;172.30.47.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;UG&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-Mgmt1&lt;BR /&gt;172.30.47.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 255.255.255.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-Mgmt1&lt;BR /&gt;192.0.2.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;255.255.255.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Sync&lt;BR /&gt;198.51.101.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0.0.0.0&amp;nbsp; &amp;nbsp;255.255.255.128&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;U&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; eth1-CIN&lt;/P&gt;&lt;P&gt;The icmp packets does not make it to the destination interface in a regular basis. So, now it seems for me that Layer 1 is somewhat affected. But not sure.&lt;/P&gt;&lt;P&gt;The IP of the Security Group is 172.30.47.247.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 13:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276052#M4198</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-24T13:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276054#M4200</link>
      <description>&lt;P&gt;another question ... what is the ouput of ethtool&amp;nbsp;eth1-Mgmt1?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 13:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276054#M4200</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-24T13:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276056#M4201</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMG_2604.JPEG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34092iC5C1E7DFD679132B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IMG_2604.JPEG" alt="IMG_2604.JPEG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 14:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276056#M4201</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-24T14:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276057#M4202</link>
      <description>&lt;P&gt;Does your MHO has an ARP entry for 172.30.47.247? If not, I would check layer 1.&lt;BR /&gt;&lt;BR /&gt;- Cables&lt;BR /&gt;- SFP&lt;BR /&gt;- Switch port configuration&lt;BR /&gt;&lt;BR /&gt;You mention increasing amount of RX packets, but no TX packets. Can you verify with tcpdump? Can you share the output?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 14:04:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276057#M4202</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-04-24T14:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276058#M4203</link>
      <description>&lt;P&gt;What I have noticed thanks to your question is that the auto-speed setting does not work. It says that the link speed is 10000base/full, but the switch is a Cisco Catalyst 8350 and does only support 1G. So, I set it to auto, but still remains at 10G. And manually configuring to 1G lead to an error message saying that config is locked. Although I entered "lock database override" many times.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 14:10:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276058#M4203</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-04-24T14:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276059#M4204</link>
      <description>&lt;P&gt;As I remember you can set it to 10 or 1G not auto.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 14:13:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276059#M4204</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-24T14:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276060#M4205</link>
      <description>&lt;P&gt;Can you perform the following in the MHO?&lt;BR /&gt;&lt;BR /&gt;show maestro port 1/1/1 qsfp-mode&lt;BR /&gt;It is 10G by default.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;You can set it to 1G if you have the right SFP installed.&lt;BR /&gt;&lt;BR /&gt;set maestro port 1/1/1 qsfp-mode 1G&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 14:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276060#M4205</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-04-24T14:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group not accessible via https (MHO 140 with 5600 Appliances)</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276581#M4217</link>
      <description>&lt;P&gt;It turned out that the transceiver used was defective. So, some time, you got the MAC address in the ARP cache and some time, the cache remained empty! Now, everything works as designed. One odd think was that SIC to a Security Group could not be established, so I had to decrease the MTU size to 1486 Bytes. How odd is that?&lt;BR /&gt;Anyway, thanks a lot to you guys for your assistance!&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 12:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-not-accessible-via-https-MHO-140-with/m-p/276581#M4217</guid>
      <dc:creator>Yasushi_Kono1</dc:creator>
      <dc:date>2026-05-06T12:35:48Z</dc:date>
    </item>
  </channel>
</rss>

