<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283260#M4453</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Thank's&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2026 16:47:47 GMT</pubDate>
    <dc:creator>WiliRGasparetto</dc:creator>
    <dc:date>2026-10-06T16:47:47Z</dc:date>
    <item>
      <title>Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283211#M4442</link>
      <description>&lt;P&gt;While reviewing Maestro procedures, I found legacy commands that still appear in training materials and operational runbooks. When migrating from R81.20 to R82 or R82.10, review both the command syntax and the device and shell where each command must run.&lt;/P&gt;
&lt;P&gt;Deprecated does not necessarily mean removed. The R82 Release Notes classify the commands below as deprecated and replaced. This does not establish that every executable has been physically removed from every build. New procedures and automation should use the documented interface for the target release.&lt;/P&gt;
&lt;P&gt;1. Security Group Monitoring and Diagnostics&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;Legacy command&lt;/TH&gt;
&lt;TH&gt;R82/R82.10 alternative&lt;/TH&gt;
&lt;TH&gt;Purpose&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg perf&lt;/TD&gt;
&lt;TD&gt;insights&lt;/TD&gt;
&lt;TD&gt;Performance dashboard&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg conns&lt;/TD&gt;
&lt;TD&gt;cluster-cli show info connection / insights&lt;/TD&gt;
&lt;TD&gt;Connection information&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg search, asg6 search&lt;/TD&gt;
&lt;TD&gt;cluster-cli show info connection&lt;/TD&gt;
&lt;TD&gt;Search using connection parameters&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg cores_stat&lt;/TD&gt;
&lt;TD&gt;cluster-cli show info cpu&lt;/TD&gt;
&lt;TD&gt;CPU utilization and core roles&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg if, asg_if, asg6 if&lt;/TD&gt;
&lt;TD&gt;cluster-cli show info interfaces&lt;/TD&gt;
&lt;TD&gt;Interface status and metrics&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg resource, asg6 resource&lt;/TD&gt;
&lt;TD&gt;insights / specific cluster-cli queries&lt;/TD&gt;
&lt;TD&gt;Resources and operational metrics&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg diag, asg_diag, asg6 diag&lt;/TD&gt;
&lt;TD&gt;HCP / insights&lt;/TD&gt;
&lt;TD&gt;Health checks&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg_bond&lt;/TD&gt;
&lt;TD&gt;HCP Bond Health test&lt;/TD&gt;
&lt;TD&gt;Bond verification&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg_collect_vsx_logs&lt;/TD&gt;
&lt;TD&gt;cpinfo, following its help and the applicable procedure&lt;/TD&gt;
&lt;TD&gt;Diagnostic collection&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;The deprecation mapping appears in the Release Notes. The cluster-cli examples above use the complete syntax documented in the R82/R82.10 command references, including the info level, which is omitted from some abbreviated Release Notes examples.&lt;/P&gt;
&lt;P&gt;Read-only examples on the Security Group — Expert mode:&lt;/P&gt;
&lt;PRE&gt;cluster-cli show info overview
cluster-cli show info cpu
cluster-cli show info interfaces
cluster-cli show info pnotes
cluster-cli show info policy&lt;/PRE&gt;
&lt;P&gt;For continuous CPU monitoring:&lt;/P&gt;
&lt;PRE&gt;cluster-cli show info -l cpu&lt;/PRE&gt;
&lt;P&gt;To search for a TCP connection by source address, destination address, and destination port:&lt;/P&gt;
&lt;PRE&gt;cluster-cli show info connection \
  --sip 192.0.2.10 \
  --dip 198.51.100.20 \
  --dport 443 \
  --proto 6&lt;/PRE&gt;
&lt;P&gt;The command reference also documents --sport for the source port. Filters must match the connection being investigated; copying arguments from the legacy asg search command is not sufficient.&lt;/P&gt;
&lt;P&gt;2. insights Replaces the Interactive Use of asg perf, but Not Its Automation Interface&lt;/P&gt;
&lt;P&gt;For interactive monitoring:&lt;/P&gt;
&lt;PRE&gt;insights&lt;/PRE&gt;
&lt;P&gt;The dashboard includes CPU, memory, throughput, connection rate, concurrent connections, packet rate, drops, and interfaces, alongside HCP integration. The tool is documented for both Maestro Security Groups and Maestro Orchestrators; the execution target remains relevant.&lt;/P&gt;
&lt;P&gt;Migrating a procedure from asg perf -v to insights does not automatically preserve:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Legacy IPv4/IPv6 options.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Column structure.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Refresh intervals.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Output formats expected by a parser.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For automation, prefer a targeted query and, where applicable, structured output:&lt;/P&gt;
&lt;PRE&gt;cluster-cli show -f json info cpu&lt;/PRE&gt;
&lt;P&gt;JSON output is documented for cluster-cli. Nevertheless, validate the schema returned by the installed build before adapting the consuming script or application.&lt;/P&gt;
&lt;P&gt;3. HCP Takes Over Checks Previously Associated with asg_diag&lt;/P&gt;
&lt;P&gt;In Expert mode:&lt;/P&gt;
&lt;PRE&gt;hcp --help&lt;/PRE&gt;
&lt;P&gt;HCP is a self-updatable suite. Select the available tests applicable to the target; do not assume that every asg_diag verify parameter maps directly to a single HCP invocation.&lt;/P&gt;
&lt;P&gt;The R82.10 documentation includes HCP support on both MHOs and Security Groups. This does not imply identical tests or execution scope on both platforms.&lt;/P&gt;
&lt;P&gt;4. Administration and Configuration: Moving to cluster&lt;/P&gt;
&lt;P&gt;The changes also affect administrative command families:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;Legacy syntax&lt;/TH&gt;
&lt;TH&gt;Migration direction&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;asg cluster_site_admin / asg_chassis_admin&lt;/TD&gt;
&lt;TD&gt;cluster_site_admin or site administration through set cluster&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;show/set chassis high-availability …&lt;/TD&gt;
&lt;TD&gt;show/set cluster configuration high-availability …&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;show/set/delete chassis … unique_ip&lt;/TD&gt;
&lt;TD&gt;The cluster configuration unique-ip family&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;show/set/delete smo …&lt;/TD&gt;
&lt;TD&gt;Check the specific equivalent within the cluster family&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;toggle_same_vmac&lt;/TD&gt;
&lt;TD&gt;toggle_same_vmac_os&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;These changes require reviewing the subcommands. Replacing only the word chassis or smo in a script does not guarantee a correct migration.&lt;/P&gt;
&lt;P&gt;Example HA query in Gaia gClish on the Security Group:&lt;/P&gt;
&lt;PRE&gt;show cluster configuration high-availability mode&lt;/PRE&gt;
&lt;P&gt;Do not confuse HA quality-grade factors, used to assess site health, with traffic-distribution weights assigned to SGMs. These settings serve different purposes.&lt;/P&gt;
&lt;P&gt;5. A Specific R82 → R82.10 Change: Member Weights&lt;/P&gt;
&lt;P&gt;This is an important exception to broad migration guidance: not every smo-to-cluster change was completed in R82.&lt;/P&gt;
&lt;P&gt;The R82.10 Release Notes document the following:&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;R82&lt;/TH&gt;
&lt;TH&gt;R82.10&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;set smo security-group sgm-weight member-id &amp;lt;IDs&amp;gt; weight &amp;lt;value&amp;gt;&lt;/TD&gt;
&lt;TD&gt;set cluster configuration member-weight member-id &amp;lt;IDs&amp;gt; weight &amp;lt;value&amp;gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;set smo security-group sgm-weight apply&lt;/TD&gt;
&lt;TD&gt;set cluster configuration member-weight apply&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;show smo security-group sgm-weight all&lt;/TD&gt;
&lt;TD&gt;show cluster configuration member-weight all&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;show smo security-group sgm-weight current&lt;/TD&gt;
&lt;TD&gt;show cluster configuration member-weight distribution&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;Accepted values include default or a weight from 0 to 512.&lt;/P&gt;
&lt;P&gt;Configuration takes place in Gaia gClish on the Security Group. Applying new weights can redistribute connections between members, so this is an operational change, not a diagnostic query.&lt;/P&gt;
&lt;P&gt;6. What Should Not Appear in a Generic “Removed Commands” List&lt;/P&gt;
&lt;P&gt;orch_stat remains documented for the MHO, including:&lt;/P&gt;
&lt;PRE&gt;orch_stat -a
orch_stat -p
orch_stat -L
orch_stat -A&lt;/PRE&gt;
&lt;P&gt;These display all categories, port information, LLDP information, and authentication status, respectively. By contrast, cluster-cli runs on the Security Group in Expert mode. Using the correct tool on the wrong device undermines the troubleshooting process.&lt;/P&gt;
&lt;P&gt;It is also incorrect to claim that all asg commands have disappeared. For example, asg stat -v is still referenced in the R82.10 HA documentation.&lt;/P&gt;
&lt;P&gt;For drop_monitor and asg_affinity_enhance, the R82 table provides no direct replacement. This does not justify assuming equivalence with insights. Meanwhile, asg_session_control is identified as unsupported in documentation histories for earlier releases; it should not be presented as a removal exclusive to the R81.20 → R82 transition.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 14:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283211#M4442</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-05T14:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283213#M4443</link>
      <description>&lt;P&gt;Very good update&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 15:38:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283213#M4443</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-10-05T15:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283225#M4444</link>
      <description>&lt;P&gt;you nailed it!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 20:13:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283225#M4444</guid>
      <dc:creator>PedroMacena24</dc:creator>
      <dc:date>2026-10-05T20:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283230#M4445</link>
      <description>&lt;P&gt;Super good update. A couple of comments:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;set cluster commands were introduced in R82. R81.x uses set smo. I don't have R82 Maestro right now to test with so my apologies if this is not entirely correct. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;You can shorten cluster-cli to cinfo&lt;/LI&gt;
&lt;LI&gt;Insights is your main monitoring tool with all information under one command. With cluster-cli/cinfo you can check individual topics.&lt;/LI&gt;
&lt;LI&gt;hcp can be run from insights. It replaced asg diag largely already in R81.20.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 05 Oct 2026 23:30:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283230#M4445</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-10-05T23:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283248#M4449</link>
      <description>&lt;P&gt;Thank's bro&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 11:47:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283248#M4449</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-06T11:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283260#M4453</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank's&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 16:47:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283260#M4453</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-06T16:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.20 → R82/R82.10: Deprecated Commands, Replacements, and Troubleshooting Implications</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283337#M4463</link>
      <description>&lt;P&gt;My lab Maestro is on version R81.10, but I’m going to perform the upgrade next week; I’ll re-verify this and post the results here. Thanks a lot for the contribution,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2026 12:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-20-R82-R82-10-Deprecated-Commands-Replacements-and/m-p/283337#M4463</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-07T12:40:57Z</dc:date>
    </item>
  </channel>
</rss>

