- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello All
We are planning to replace ASA with Check Point and are looking for an equivalent command in Check Point for the ASA management-only command.
We have already reviewed the information about this MDPS site,(sk138672)
but other threads (from 2022) mention that it has many bugs,
which makes us hesitant to use it. Have all these issues been resolved by lateset R81.20?
Do you have any information on this?
Thank you for all the advice.
One of my colleagues did this for a customer in R81.20 and they are happy with it. No issues so far.
Andy
What are the specific concerns you have with MDPS?
move to vsx, same goal, much more support and reliability
One of my colleagues did this for a customer in R81.20 and they are happy with it. No issues so far.
Andy
So I'm kind in the same situation but for me it's not working.
I separated mplane from dplane according to the (poorly documented) sk138672.
Right now the management plane is isolated which is good. BUT as this is done is software I have some strange issues:
Packets originating from the management interface traverse the management plane and lands on dplane to be processed by the firewall. dplane recognise the source IP and it's marking it as spoofed. if MDPS is to fully isolate the network. This breaks almost everything like DNS, AD for Gaia LDAP AD binding, TACACS. SMS still works because due to an "error" is in the same network 🙂 but otherwise it will fail.
THe inbound traffic originating from inside the network (from one of many internal interfaces) arrives in DP where is processed but due to "mdps_tun" the traffic is sent over to mplane. Of course, as MDPS has a default route, traffic is sent over the default route, which lands on dplane and flow is broken due to symmetry issues.
So basically from the internal network I cannot access the management interface).
I know it's software but still. MDPS should be a real isolation.
I'm thinking on switching to a dedicated VSX just for managemnet but.. as everything is in place right now, removing mdps will be a mess.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY