<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283207#M4441</link>
    <description>&lt;P&gt;Hi CheckMates Community,&lt;/P&gt;&lt;P&gt;I am currently evaluating two architectural options for a Check Point R82 VSNext deployment on a Quantum Maestro Security Group and would appreciate feedback from anyone running similar topologies in production.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment &amp;amp; Requirements:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Architecture:&lt;/STRONG&gt; 3 Virtual Gateways (VGW A, VGW B, VGW C) on R82 VSNext (Maestro SG – connected to LAN infra via singe bond interface).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Downstream:&lt;/STRONG&gt; Citrix NetScaler using Traffic Domains over a shared LACP bond trunk (managed by an external team).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Upstream:&lt;/STRONG&gt; 4 distinct external environments connected over the shared trunked bond (Cisco N9K with 4 VRFs).&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Blades &amp;amp; features&lt;/STRONG&gt; - we use only FW blade (with NAT) currently, no dynamic routing. In near future we plan to add Identity Awareness using Identity Collector integrated with Active Directory.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Key Constraints:&lt;/STRONG&gt;&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;No upstream inter-VRF routing interconnect exists, meaning cross-environment transit must be bridged/routed through the firewall chassis.&lt;/LI&gt;&lt;LI&gt;Every flow strictly traverses &lt;STRONG&gt;only 1 VGW&lt;/STRONG&gt; (no multi-VGW chaining).&lt;/LI&gt;&lt;/OL&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Option 1: 4 Internal Virtual Switches (VSwitches)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Provision 1 internal VSwitch per environment in Gaia OS and attach each VGW via internal virtual warp (wrp) interfaces.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Option 2: 12 Dedicated Point-to-Point VLANs&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Provision 12 point-to-point subnets.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Looking for Feedback / Community Experience:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For those running high-throughput VSNext environments on Maestro, is the performance on wrp interfaces sufficient, or is physical VLAN sub-interfaces performance superior?&lt;/LI&gt;&lt;LI&gt;Are there any hidden operational gotchas with wrp links, internal VSwitches, or Identity Awareness tables across network namespaces in R82 VSNext?&lt;/LI&gt;&lt;/OL&gt;</description>
    <pubDate>Mon, 05 Oct 2026 11:03:33 GMT</pubDate>
    <dc:creator>andrej_kascak3</dc:creator>
    <dc:date>2026-10-05T11:03:33Z</dc:date>
    <item>
      <title>R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283207#M4441</link>
      <description>&lt;P&gt;Hi CheckMates Community,&lt;/P&gt;&lt;P&gt;I am currently evaluating two architectural options for a Check Point R82 VSNext deployment on a Quantum Maestro Security Group and would appreciate feedback from anyone running similar topologies in production.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment &amp;amp; Requirements:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Architecture:&lt;/STRONG&gt; 3 Virtual Gateways (VGW A, VGW B, VGW C) on R82 VSNext (Maestro SG – connected to LAN infra via singe bond interface).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Downstream:&lt;/STRONG&gt; Citrix NetScaler using Traffic Domains over a shared LACP bond trunk (managed by an external team).&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Upstream:&lt;/STRONG&gt; 4 distinct external environments connected over the shared trunked bond (Cisco N9K with 4 VRFs).&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Blades &amp;amp; features&lt;/STRONG&gt; - we use only FW blade (with NAT) currently, no dynamic routing. In near future we plan to add Identity Awareness using Identity Collector integrated with Active Directory.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Key Constraints:&lt;/STRONG&gt;&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;No upstream inter-VRF routing interconnect exists, meaning cross-environment transit must be bridged/routed through the firewall chassis.&lt;/LI&gt;&lt;LI&gt;Every flow strictly traverses &lt;STRONG&gt;only 1 VGW&lt;/STRONG&gt; (no multi-VGW chaining).&lt;/LI&gt;&lt;/OL&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Option 1: 4 Internal Virtual Switches (VSwitches)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Provision 1 internal VSwitch per environment in Gaia OS and attach each VGW via internal virtual warp (wrp) interfaces.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Option 2: 12 Dedicated Point-to-Point VLANs&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Provision 12 point-to-point subnets.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Looking for Feedback / Community Experience:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;For those running high-throughput VSNext environments on Maestro, is the performance on wrp interfaces sufficient, or is physical VLAN sub-interfaces performance superior?&lt;/LI&gt;&lt;LI&gt;Are there any hidden operational gotchas with wrp links, internal VSwitches, or Identity Awareness tables across network namespaces in R82 VSNext?&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 05 Oct 2026 11:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283207#M4441</guid>
      <dc:creator>andrej_kascak3</dc:creator>
      <dc:date>2026-10-05T11:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283233#M4446</link>
      <description>&lt;P&gt;Simplicity &amp;amp; routing were my first thoughts - with that said if you've gone to the trouble of separate VRFs and VS does the VSW impact the isolation you've set to achieve i.e. might it allow admins to establish traffic paths/paterns that shouldn't occur?&lt;/P&gt;
&lt;P&gt;Sounds like your target state will avoid this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk183336" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk183336: In ElasticXL in &lt;STRONG&gt;VSNext&lt;/STRONG&gt; mode, traffic does not pass between Virtual Gateways that are connected through a Virtual Switch&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Some previous discussion on vswitch performance can be found here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Firewall-Security-Management/Performance-Limitations-of-Virtual-Switches-in-a-VSX-Environment/m-p/255633#M50149" target="_blank" rel="noopener"&gt;Solved: Performance Limitations of Virtual Switches in a V... - Check Point CheckMates&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;which namely identified:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" width="910px" cellspacing="0"&gt;
&lt;THEAD&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Head-Header_Style"&gt;
&lt;TH class="TableStyle-TP_Table_Jumbo_Fixes-HeadE-Column_Style_ID-Header_Style" scope="col" width="86.9375px"&gt;
&lt;P&gt;ID&lt;/P&gt;
&lt;/TH&gt;
&lt;TH class="TableStyle-TP_Table_Jumbo_Fixes-HeadE-Column_Style_Product-Header_Style" scope="col" width="78.4844px"&gt;
&lt;P&gt;Product&lt;/P&gt;
&lt;/TH&gt;
&lt;TH class="TableStyle-TP_Table_Jumbo_Fixes-HeadD-Column_Style_Description-Header_Style" scope="col" width="743.578px"&gt;
&lt;P&gt;Description&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Release_Date" data-mc-pattern="8"&gt;
&lt;TD colspan="3" width="909px" class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_ID-Release_Date"&gt;
&lt;P&gt;&lt;STRONG&gt;R82 JHF Take 126&lt;/STRONG&gt; - &lt;STRONG&gt;Improvements and Resolved Issues&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Grey_Background" data-mc-conditions=""&gt;
&lt;TD width="86.9375px" class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-Grey_Background"&gt;
&lt;P&gt;PRJ-67772,&lt;BR /&gt;PMTR-119674&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="78.4844px" class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-Grey_Background"&gt;
&lt;P&gt;SecureXL&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="743.578px" class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-Grey_Background"&gt;
&lt;P&gt;In some scenarios, the VSX Gateway may experience poor performance when passing traffic between Virtual Systems through a Virtual Switch with SecureXL User Mode enabled.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 01:29:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283233#M4446</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-10-06T01:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283234#M4447</link>
      <description>&lt;P&gt;It depends a bit on the rest of your network architecture as that is also affected, but in general there shouldn't be any performance penalty in using VSwitches. If it's easier on your routing etc to share VLANs between VSs then I'd go with VSwitches.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 01:28:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283234#M4447</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-10-06T01:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283241#M4448</link>
      <description>&lt;P&gt;To make sure I understand correctly:&lt;/P&gt;&lt;P&gt;The result of the constraint "Every flow strictly traverses &lt;STRONG&gt;only 1 VGW&lt;/STRONG&gt; (no multi-VGW chaining)" does effectively mean that if two VRFs need to communicate through your setup, the VGW needs a leg in &lt;STRONG&gt;both&lt;/STRONG&gt; VRFs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you could clarify how the 4 VRFs map to the 3 VGWs. Is there any inter-VRF traffic expected?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 07:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/R82-VSNext-Design-Review-Cross-Environment-Transit-VSwitch-vs/m-p/283241#M4448</guid>
      <dc:creator>Arne_Boettger</dc:creator>
      <dc:date>2026-10-06T07:24:48Z</dc:date>
    </item>
  </channel>
</rss>

