Create a Post
Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
icon Network Security

Understanding MDS for begginers

Understanding Check Point MDS Management Beginner-Friendly Guide

NOTE: I attach a PDF with all this informations to be easier.

Introduction

When you start your journey with Check Point Software Technologies Firewalls, one of the first things you’ll notice is that there are many different types of management.
 And yes… this can feel confusing at first — totally normal.

Types of Check Point Management

In the Check Point world, these are the most common management types you’ll hear about:

  • SMS – Security Management Server
  • Smart-1 Appliance
  • Smart-1 Cloud
  • Spark Management
  • MDS – Multi-Domain Server

Today, we’ll focus on MDS, a powerful option that is often less talked about, but extremely important in large environments.

What is MDS (Multi-Domain Server)?

Think of MDS as a “management server that can host multiple independent management servers inside it.”

Instead of having:
 - one SMS managing one environment

You get:
 - one MDS manag

...
TO READ THE FULL POST it's simple and free
6 Comments
the_rock
MVP Diamond
MVP Diamond

AMAZING!

Bob_Zimmerman
MVP Gold
MVP Gold

It's a bit misleading about how separate the CMAs and CLMs actually are. There's no virtualization involved except the virtualization inherent in preemptive multitasking.

The CMAs are not meaningfully separate from each other or from the MDS. There's no point monitoring all of your CMAs via SNMP, for example. They can't run different versions of the software. You can't reboot just one CMA. They're separate processes and separate database tables, but that's less distinct than even VSs are in VSX.

genisis__
MVP Silver
MVP Silver

I though you could stop a DMS (CMA)  mds_stop_customer <DMS>  (something like this, been a while since I did it).

the_rock
MVP Diamond
MVP Diamond

Im sure you can, I tested it recently on R82 lab.

Vincent_Bacher
MVP Silver
MVP Silver

Addendum: this is as well explained in the attached pdf above

When it comes to monitoring: given that, based on experience, the relevant processes of a CMA in multi-domain management can fail independently of the others, leading to a single CMA becoming unavailable or going down, it definitely makes sense to have some way of being aware when such a failure happens. So, I do consider it important.