<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication between Maestro Orchestrators in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279649#M4339</link>
    <description>&lt;P&gt;As Martijn says, after the upgrade you can set up the authentication without affecting your security groups. There's a new button in the Orchestrator &amp;gt; Security Group section of the WebUI to look at it. Make sure the date and time are right on your MHOs before you upgrade them, I have seen MHOs that still think it's 2010 be upgraded and end up creating certificates that are already expired.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2026 13:27:04 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2026-07-14T13:27:04Z</dc:date>
    <item>
      <title>Authentication between Maestro Orchestrators</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279641#M4336</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hi&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;According to the&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Authentication-between-Orchestrators.htm?tocpath=Working%20with%20Quantum%20Maestro%20%7CAuthentication%20between%20Maestro%20Orchestrators%7C_____0#Authentication_between_Maestro_Orchestrators" target="_self"&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;R82 Scalable Platforms Administration Guide&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;, it is possible to activate Authentication between Maestro Orchestrators. I'd like to do this (after i upgrade from R81.20), because the site-sync is realized over a DWDM-Darkfibre connection. And i fear at some point, some auditor will ask if this connection is plain text or not - and then i can answer "Of course not. What kind of Admin do you think i am?".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;(Maybe not this exact wording&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;But in the guide states:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;To avoid synchronization issues between Orchestrators, do not configure Security Groups before making sure all Orchestrators are authenticated&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Now, my environment is in production. I can't just delete my SGs in order to facititate that. Has anyone activated this feature with existing SGs? Is there a problem?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Or is it more of a warning? If someone would change a configuration or for some reason something should fail over, then there can be a split-brain situation or something similar?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thanks for any advice,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Christian&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Some more infos:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Starting in R82, you can configure mutual authentication between all Maestro Orchestrators on your Maestro Sites to make sure their communication is secure and encrypted over Internal Sync ports (sync in the same Maestro Site) and External Sync ports (sync between Maestro Sites).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This authentication is based on SSH keys and SSL certificates. These SSL certificates are valid for one year. Orchestrators renew these SSL certificates automatically.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This authentication is a two-way mesh process - each Orchestrator authenticates all other Orchestrators.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 11:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279641#M4336</guid>
      <dc:creator>SomAustrianCity</dc:creator>
      <dc:date>2026-07-14T11:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication between Maestro Orchestrators</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279645#M4337</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have upgraded several Maestro Orchestrator appliances from R81.10 / R81.20 to R82 that are in production with Security Groups. The upgrade of the Orchestrators to R82 went without any issues. The same for the hotfix installation.&lt;/P&gt;
&lt;P&gt;After the upgrade I activated authentication between the Orchestrators and did not notice anything strange on the Security Groups.&amp;nbsp;Also no issues with network traffic through the Security Group where reported.&lt;BR /&gt;&lt;BR /&gt;I would make sure the basics are OK.&lt;BR /&gt;&lt;BR /&gt;Are the Orchestrators in sync?&lt;BR /&gt;Do they have the correct side ID?&lt;BR /&gt;Do they have the correct Orchestrator ID?&lt;BR /&gt;Check with lldpctl on both Orchestrators&lt;BR /&gt;&lt;BR /&gt;If you are not sure, perform the action in a service window.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 12:11:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279645#M4337</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-07-14T12:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication between Maestro Orchestrators</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279649#M4339</link>
      <description>&lt;P&gt;As Martijn says, after the upgrade you can set up the authentication without affecting your security groups. There's a new button in the Orchestrator &amp;gt; Security Group section of the WebUI to look at it. Make sure the date and time are right on your MHOs before you upgrade them, I have seen MHOs that still think it's 2010 be upgraded and end up creating certificates that are already expired.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 13:27:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279649#M4339</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-07-14T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication between Maestro Orchestrators</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279814#M4342</link>
      <description>&lt;P&gt;Thanks for your answers guys &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;This makes me more confident that it will work&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 08:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Authentication-between-Maestro-Orchestrators/m-p/279814#M4342</guid>
      <dc:creator>SomAustrianCity</dc:creator>
      <dc:date>2026-07-17T08:26:28Z</dc:date>
    </item>
  </channel>
</rss>

