<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maestro Dual Site Dual Orchestrator Deployment - Site2 SGMs LOST in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/126942#M572</link>
    <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;We have a Maestro Dual Site / Dual Orchestrator (2 MHOs - 2 MHOs) new deployment with R80.20SP (MHO) and R80.30SP (SGM) software versions. Only 1 SG is configured and installed as VSX/VSLS.&lt;BR /&gt;Site1 looks fine, Chassis 1 ACTIVE and SGMs are both ACTIVE as well, but Site2 Chassis 2 DOWN and SGMs are both LOST &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;The only one SG consists of the Site1 SGMs currently, but Site2 SGMs are not in the group and not even FTW ran on them. Cabling and port types and amounts and IDs and ssm_sync and site_sync and magg are okay in my opinion.&lt;/P&gt;&lt;P&gt;As a reference sk168092 &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168092&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168092&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;BR /&gt;Scenario #2 is the relevant deployment.&lt;/P&gt;&lt;P&gt;At the bottom of the website:&lt;BR /&gt;Testing Dual-Site infrastructure&lt;BR /&gt;Connectivity between Orchestrators at different sites:&lt;/P&gt;&lt;P&gt;From MHO1_1 ping MHO 2_1: ping 203.0.113.15&lt;BR /&gt;From MHO1_2 ping MHO 2_2: ping 203.0.113.16&lt;BR /&gt;If there is no ping, check VLANs 3951 and 3952 accordingly&lt;/P&gt;&lt;P&gt;Connectivity between Orchestrators at the same site:&lt;BR /&gt;From MHO1_1 ping MHO1_2: ping 192.0.2.2&lt;BR /&gt;From MHO2_1 ping MHO2_2: ping 192.0.2.16&lt;BR /&gt;If there is no ping, check the Sync cable between Orchestrators within the same site.&lt;/P&gt;&lt;P&gt;Connectivity between SGMs (appliances)&lt;BR /&gt;From SGM1_1 ping SGM2_1 on sync network: ping 192.0.2.15&lt;BR /&gt;If there is no ping, check VLANs 3600 and 3601.&lt;/P&gt;&lt;P&gt;All ICMP test are okay!&lt;/P&gt;&lt;P&gt;I detached all the Site2 SGMs from the SG and attached again, all appliances were restarted, but the issue is the same and I'm stucked at this point.&lt;BR /&gt;There is an open SR regarding this with more info shared, but no progress yet.&lt;/P&gt;&lt;P&gt;site_sync connected switch port config:&lt;BR /&gt;interface Ethernetx/xx&lt;BR /&gt;description site_sync&lt;BR /&gt;switchport&lt;BR /&gt;switchport mode dot1q-tunnel&lt;BR /&gt;switchport access vlan xx&lt;BR /&gt;spanning-tree bpdufilter enable&lt;BR /&gt;mtu 9216&lt;BR /&gt;storm-control broadcast level 2.00&lt;BR /&gt;storm-control action trap&lt;BR /&gt;no shutdown&lt;/P&gt;&lt;P&gt;Maestros, do you have any idea, good advice or what to check? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Fri, 13 Aug 2021 13:57:01 GMT</pubDate>
    <dc:creator>Garbo</dc:creator>
    <dc:date>2021-08-13T13:57:01Z</dc:date>
    <item>
      <title>Maestro Dual Site Dual Orchestrator Deployment - Site2 SGMs LOST</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/126942#M572</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;We have a Maestro Dual Site / Dual Orchestrator (2 MHOs - 2 MHOs) new deployment with R80.20SP (MHO) and R80.30SP (SGM) software versions. Only 1 SG is configured and installed as VSX/VSLS.&lt;BR /&gt;Site1 looks fine, Chassis 1 ACTIVE and SGMs are both ACTIVE as well, but Site2 Chassis 2 DOWN and SGMs are both LOST &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;The only one SG consists of the Site1 SGMs currently, but Site2 SGMs are not in the group and not even FTW ran on them. Cabling and port types and amounts and IDs and ssm_sync and site_sync and magg are okay in my opinion.&lt;/P&gt;&lt;P&gt;As a reference sk168092 &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168092&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168092&amp;amp;partition=Basic&amp;amp;product=Quantum&lt;/A&gt;&lt;BR /&gt;Scenario #2 is the relevant deployment.&lt;/P&gt;&lt;P&gt;At the bottom of the website:&lt;BR /&gt;Testing Dual-Site infrastructure&lt;BR /&gt;Connectivity between Orchestrators at different sites:&lt;/P&gt;&lt;P&gt;From MHO1_1 ping MHO 2_1: ping 203.0.113.15&lt;BR /&gt;From MHO1_2 ping MHO 2_2: ping 203.0.113.16&lt;BR /&gt;If there is no ping, check VLANs 3951 and 3952 accordingly&lt;/P&gt;&lt;P&gt;Connectivity between Orchestrators at the same site:&lt;BR /&gt;From MHO1_1 ping MHO1_2: ping 192.0.2.2&lt;BR /&gt;From MHO2_1 ping MHO2_2: ping 192.0.2.16&lt;BR /&gt;If there is no ping, check the Sync cable between Orchestrators within the same site.&lt;/P&gt;&lt;P&gt;Connectivity between SGMs (appliances)&lt;BR /&gt;From SGM1_1 ping SGM2_1 on sync network: ping 192.0.2.15&lt;BR /&gt;If there is no ping, check VLANs 3600 and 3601.&lt;/P&gt;&lt;P&gt;All ICMP test are okay!&lt;/P&gt;&lt;P&gt;I detached all the Site2 SGMs from the SG and attached again, all appliances were restarted, but the issue is the same and I'm stucked at this point.&lt;BR /&gt;There is an open SR regarding this with more info shared, but no progress yet.&lt;/P&gt;&lt;P&gt;site_sync connected switch port config:&lt;BR /&gt;interface Ethernetx/xx&lt;BR /&gt;description site_sync&lt;BR /&gt;switchport&lt;BR /&gt;switchport mode dot1q-tunnel&lt;BR /&gt;switchport access vlan xx&lt;BR /&gt;spanning-tree bpdufilter enable&lt;BR /&gt;mtu 9216&lt;BR /&gt;storm-control broadcast level 2.00&lt;BR /&gt;storm-control action trap&lt;BR /&gt;no shutdown&lt;/P&gt;&lt;P&gt;Maestros, do you have any idea, good advice or what to check? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 13:57:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/126942#M572</guid>
      <dc:creator>Garbo</dc:creator>
      <dc:date>2021-08-13T13:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Dual Site Dual Orchestrator Deployment - Site2 SGMs LOST</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/139615#M762</link>
      <description>&lt;P&gt;Hello Garbo, than you for share switch's configuration. Can you share also the Inter-site link configuration?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;MHO 1 &amp;lt;---&amp;gt; SW1 &amp;lt;-------Inter-site link-------&amp;gt;SW2&amp;lt;---&amp;gt;MHO2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My ICMP test isn´t OK&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 18:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/139615#M762</guid>
      <dc:creator>Fernando_Lopez</dc:creator>
      <dc:date>2022-01-26T18:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Dual Site Dual Orchestrator Deployment - Site2 SGMs LOST</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/139637#M763</link>
      <description>&lt;P&gt;Typically QinQ support is required on this link, which version are the MHO/SGMs in your deployment?&lt;/P&gt;
&lt;P&gt;R81.10 provides some flexibility here that you may wish to discuss with TAC otherwise.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 23:07:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Dual-Site-Dual-Orchestrator-Deployment-Site2-SGMs-LOST/m-p/139637#M763</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-26T23:07:20Z</dc:date>
    </item>
  </channel>
</rss>

