<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro: The Cable Is Connected. Why Is the Interface Still DOWN? in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283408#M4474</link>
    <description>&lt;P&gt;Another important verification is the switch configuration. For example If you use bonding, it is necessary to configure a port-channel trunk. Keep in mind that the EtherChannel configuration for Maestro is not the same as for ClusterXL.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2026 14:20:23 GMT</pubDate>
    <dc:creator>israelfds95</dc:creator>
    <dc:date>2026-10-08T14:20:23Z</dc:date>
    <item>
      <title>Maestro: The Cable Is Connected. Why Is the Interface Still DOWN?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283405#M4473</link>
      <description>&lt;P&gt;&lt;SPAN&gt;During a Maestro deployment, an Uplink or Management port may remain down even with the cable connected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Before concluding that the transceiver is faulty, check &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;the interface’s Security Group assignment and provisioning status&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. In Maestro, the availability of these ports also depends on the environment’s configuration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Physical connectivity, provisioning, and forwarding&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The behavior described in the training material is that Uplink and Management ports must be provisioned in a Security Group to establish a link under normal conditions. A port removed from all Security Groups may also lose its link, even though it remains physically connected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Downlinks serve a different purpose: they provide connectivity to appliances and enable their discovery. Therefore, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;an UP Downlink does not prove that the Security Group is ready to process traffic&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When troubleshooting, separate these checks:&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH&gt;&lt;SPAN&gt;Check&lt;/SPAN&gt;&lt;/TH&gt;
&lt;TH&gt;&lt;SPAN&gt;Question to answer&lt;/SPAN&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN&gt;Administrative state&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Is the port enabled?&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN&gt;Operational state&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Is the physical link established?&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN&gt;Assignment and provisioning&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Does the interface belong to the correct Security Group, and has the configuration been applied?&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;SPAN&gt;Forwarding&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;SPAN&gt;Are the Security Group and its interfaces ready to carry traffic?&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Start with the MHO&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the Orchestrator, in Gaia Clish or Expert mode:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN&gt;orch_stat -p
orch_stat -t
orch_stat -L&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Use the port view to identify interface state and mapping, the topology view to correlate objects, and LLDP to verify discovered appliances and their connected ports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;LLDP confirms appliance discovery, but it does not prove that production traffic is flowing.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Next, in &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Gaia Clish on the MHO&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, inspect the specific port:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN&gt;show maestro port &amp;lt;Port-ID&amp;gt; type
show maestro port &amp;lt;Port-ID&amp;gt; admin-state
show maestro port &amp;lt;Port-ID&amp;gt; qsfp-mode
show maestro port &amp;lt;Port-ID&amp;gt; auto-negotiation
show maestro port &amp;lt;Port-ID&amp;gt; optic-info
show maestro port &amp;lt;Port-ID&amp;gt; optic-info-details&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;These queries help correlate the port type, administrative state, configured speed, and transceiver information. Available optical diagnostics depend on the installed module.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The port identifier uses this format:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN&gt;&amp;lt;Orchestrator-ID&amp;gt;/&amp;lt;Port-Label&amp;gt;/&amp;lt;Split-ID&amp;gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Select the actual port using TAB completion. For breakout connections, the subport is part of the identifier.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Check Link State Propagation too&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If LSP is configured, a port may go DOWN because another port in the same LSP group has failed. This mechanism allows connected switches to stop forwarding traffic toward a compromised path.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In Gaia Clish on the MHO:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN&gt;show maestro lsp configuration all
show maestro lsp status&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Correlate the group configuration and status before attributing the failure to the port you are investigating.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;What about &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt;admin-state up&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following syntax is available:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;&lt;SPAN&gt;set maestro port &amp;lt;Port-ID&amp;gt; admin-state up&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;However, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;administratively enabling a port does not prove that provisioning is complete or forwarding is functional&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;. This command changes the configuration and should be used with a defined purpose, after checking the port assignment and potential impact on the environment.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My troubleshooting sequence would be: identify the port, check its state and type, validate assignment and provisioning, check LSP, and correlate the physical parameters at both ends.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;The goal is to determine why the port is DOWN before trying to bring it UP.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 13:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283405#M4473</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-08T13:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro: The Cable Is Connected. Why Is the Interface Still DOWN?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283408#M4474</link>
      <description>&lt;P&gt;Another important verification is the switch configuration. For example If you use bonding, it is necessary to configure a port-channel trunk. Keep in mind that the EtherChannel configuration for Maestro is not the same as for ClusterXL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 14:20:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283408#M4474</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-10-08T14:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro: The Cable Is Connected. Why Is the Interface Still DOWN?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283410#M4475</link>
      <description>&lt;P&gt;True, Israel is very well-positioned.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2026 14:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-The-Cable-Is-Connected-Why-Is-the-Interface-Still-DOWN/m-p/283410#M4475</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-10-08T14:40:02Z</dc:date>
    </item>
  </channel>
</rss>

