Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DR_74
Collaborator

Management Network for remote site (dark fiber)

Hello,

 

We need to deploy new 39xx firewalls cluster XL on remote sites (linked to the Central site with Dark Fiber)

What would be the Best Practice to manage the remote gateways?

Is it better to manage the GAIA appliances over a Management Network behind the gateway or to manage over the interface "outside interface"?

Can this management network be used for other purpose or dedicated for the gateway management? Can we monitor each gateway separately (SNMP, ssh, webui)? (Assymetric routing if need to manage Secondary firewall?)

 

image.png

 

Thank you

0 Kudos
2 Replies
CheckPointerXL
Advisor
Advisor

my suggestion is to always use the first interface hitted by the flow, in front of Mgmt server, so outside in your case

0 Kudos
Martijn
MVP
MVP

Hi,

By default there is no dedicated management interface unless you configure MDPS (Management Data Plane Seperation).
So the interface you are managing the appliance on, can be used for production traffic also.

And the advice already given is a good one. Use the interface closest the Management server to manage your gateways. This can also be used for SSH, HTTPS and SNMP.

Martijn




0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events