<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single site dual MHO-140 and 3 6700 in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126304#M563</link>
    <description>&lt;P&gt;I have just configured the same.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Routes for the MHOs are configured directly on them, probably just the default Route. Routes for the Security Group (SG) are configured on the first appliance within the SG and are then cloned to the other appliances when these are added to the SG in the last step.&lt;/LI&gt;
&lt;LI&gt;Interface bonds have to be configured within the SG using gClish. On the MHO you just drag the interfaces to the SG that it will work with.&lt;/LI&gt;
&lt;LI&gt;Yes, both MHOs have a Management IP.&lt;/LI&gt;
&lt;LI&gt;Doesn‘t matter. As long as you have a Sync cable between both MHOs and the Operator Status of the Sync port is up and is showing RX packets you are good.&lt;/LI&gt;
&lt;LI&gt;No, this is done on the SG. Just connect to the SG‘s management IP and configure it there.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 11 Aug 2021 06:02:05 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2021-08-11T06:02:05Z</dc:date>
    <item>
      <title>Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126302#M562</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I have a scenario where&amp;nbsp; I have 2 MHO140 and 3 6700s. I need to configure single site dual Orchs&lt;/P&gt;&lt;P&gt;Hence I have certain queries about the same. MHOs I have upgraded to R81.10 SP and 6700 with R81SP with latest HFA&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The routes will be configured on MHO? [Default and Network routes]&lt;/LI&gt;&lt;LI&gt;Since I need to terminate fibre on two MHO, I need to configure Bond on MHO, right?&lt;/LI&gt;&lt;LI&gt;Both MHO should have management IP?&lt;/LI&gt;&lt;LI&gt;Since there are two MHO; which one I need access from mgmt IP to configure SGM?&lt;/LI&gt;&lt;LI&gt;Do I always need to connect to primary MHO and perform the administrative tasks, like adding routes, defining bonds, etc..&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Blason R&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 03:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126302#M562</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-11T03:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126304#M563</link>
      <description>&lt;P&gt;I have just configured the same.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Routes for the MHOs are configured directly on them, probably just the default Route. Routes for the Security Group (SG) are configured on the first appliance within the SG and are then cloned to the other appliances when these are added to the SG in the last step.&lt;/LI&gt;
&lt;LI&gt;Interface bonds have to be configured within the SG using gClish. On the MHO you just drag the interfaces to the SG that it will work with.&lt;/LI&gt;
&lt;LI&gt;Yes, both MHOs have a Management IP.&lt;/LI&gt;
&lt;LI&gt;Doesn‘t matter. As long as you have a Sync cable between both MHOs and the Operator Status of the Sync port is up and is showing RX packets you are good.&lt;/LI&gt;
&lt;LI&gt;No, this is done on the SG. Just connect to the SG‘s management IP and configure it there.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 11 Aug 2021 06:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126304#M563</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-08-11T06:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126305#M564</link>
      <description>&lt;P&gt;Thanks for the info - So&lt;/P&gt;&lt;P&gt;My MHO1 is 10.10.10.10 and MHO2 is 10.10.10.20 with DG 10.10.10.1&lt;/P&gt;&lt;P&gt;While my external interface is 30.30.30.30/28&lt;/P&gt;&lt;P&gt;Internal LAN is 192.168.40.2/24&lt;/P&gt;&lt;P&gt;In this case to access the MHO Management IP; I just need to add route on MHO with default gateway pointed to 10.10.10.1&lt;/P&gt;&lt;P&gt;And since my external and internal interfaces are terminated on MHO [with bond]; my internet default gateway will be on SG using gclish?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 05:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126305#M564</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-11T05:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126306#M565</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The default gateway for your production traffic and internal is defined on the SGM, using gclish as you say.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 05:54:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/126306#M565</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2021-08-11T05:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127011#M573</link>
      <description>&lt;P&gt;So my Mgmt port from MHO to connect SMO can be on different subnet? Wondering if not then who would route the traffic to SGM? Like&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lets say my Management server IP is 192.168.14.10 and SGM is 172.16.10.10?&amp;nbsp; Will that work?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 03:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127011#M573</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-16T03:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127019#M574</link>
      <description>&lt;P&gt;Hi, I know from experience that it &lt;EM&gt;will&lt;/EM&gt; work - but you should really get the mgmt interface of the SMO directly connected to the same subnet as the Management and log server etc...&lt;/P&gt;
&lt;P&gt;There will/can be issues related to NAT, and also - if your management network in addition to contain management server, also has some esx hosts, a server or two...whatever else - that traffic will get issues.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my last setup, the customer had a subnet where the management server was on a subnet that containd lots of "other stuff" to - due to design and historical configs, I ended ut adding an additional interface on the management server, and had my SMO connect to that, just to get it directly connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 05:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127019#M574</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2021-08-16T05:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Single site dual MHO-140 and 3 6700</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127058#M575</link>
      <description>&lt;P&gt;Thanks man for the valuable input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 11:03:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Single-site-dual-MHO-140-and-3-6700/m-p/127058#M575</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-16T11:03:50Z</dc:date>
    </item>
  </channel>
</rss>

