- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Over the past few months, I’ve received many questions about Maestro, ElasticXL and VSNext, so I’ve put together the following overview to briefly highlight the differences.
This should help you decide which of the two solutions best fits your needs.
The following table provides a few ideas on when each solution might be the better fit.
|
|
Maestro Working with Quantum Maestro |
ElasticXL Working with ElasticXL Cluster |
| Architecture / Purpose | Hyperscale security orchestration using Security Groups managed by dedicated Maestro Orchestrators (MHO). Designed for large-scale horizontal scalability | New clustering technology (introduced in R82) with a Single Management Object (SMO); simplified configuration, no orchestrator hardware required. |
| Maximum Gateways in one Security Group | Single-Site: up to 14 appliances per Security Group. Dual-Site: up to 28 (14 per site). |
Single-Site: up to 3 cluster members. Dual-Site: up to 6 (3 per site). |
| Management Model | Security Group appears as one Security Gateway object (SMO) in SmartConsole. | The entire ElasticXL cluster is represented as one Security Gateway object (SMO) in management. |
| Scalability / Expansion | Scale-out by adding more Security Gateway Modules (SGMs) to the Security Group; requires the MHO fabric. | Cluster members can be added or removed on the fly; configuration and software are automatically cloned. |
| Site Topologies | Supports Single-Site and Dual-Site deployments. | Supports Single-Site and Dual-Site deployments. |
| Operation / Administration | Requires dedicated Maestro Orchestrator hardware; centralized management IP per Security Group (SMO). | Managed directly through Gaia Portal/CLI as one unit; automatic synchronization and setup. |
| Typical Use Cases | Large data centers, service providers, or hyperscale environments requiring high throughput and multi-gateway redundancy. | Simplified clustering and load sharing for small to mid-sized environments. |
| MHO | You need two MHOs (140 or 175, old 170) for a single-site deployment and four MHOs for a dual-site setup. | No MHO required. |
| Security Groups | Maestro supports more than one SG per site. Maestro can have up to 8 Security Groups off one set of MHOs. | EXL doesn't yet "will be added in JHF very soon" |
| Appliance mix and match mode | Maestro supports mix and match sk162373 - Maestro Mix and Match |
EXL doesn't yet |
| Virtual System sk79700 - VSNext / VSX supported features |
Maestro supports legacy VSX and VSNext | EXL only VSNext |
Maybe you can also share your own experiences and insights here.
Single site topologies are supported with ElasticXL as well.
Unless you create a second site, you're in Load Sharing by default. 🙂
Oh, I must have been daydreaming while writing.
Of course, EXL also allows single-site setups. I’ll update that in the article above.
The scalability statement for EXL applies to Maestro SGs as well.
Worth stating under scalability for Maestro that we can have up to 8 security groups off one set of MHOs.
For MHO, you can have one MHO per site if you want to (but obviously dual MHO per site recommended for HA).
Maestro supports mix and match, EXL doesn't (yet).
Maestro supports more than one SGM per site for VSNext, EXL doesn't (yet, will be added in JHF very soon).
Maestro supports legacy VSX and VSNext, EXL only VSNext.
@emmap I’ve added your information to the original article.
EXL will never support multiple security groups.
To expand on this, when I said more than one SGM per site, I mean within the Security Group. At the moment there's a limitation with VSNext over EXL that means it's not supported to have it running on a cluster with more than one SGM defined per site. It will let you do it, but it's listed on the limitations pages as not supported. It'll be fixed soon.
More than one security group is a concept that doesn't apply to EXL at all, as each EXL cluster is effectively the same as a security group as defined on a Maestro setup. As there are no MHOs involved, only the SGMs, the whole 'multiple security group' concept is irrelevant.
Adding @ShaiF to review
Hi @emmap, @PhoneBoy,
Just like with Maestro R80.20 SP in the initial phase, there are now many small limitations in ElasticXL that aren’t immediately obvious in the readme or admin guide. My request would be to create an SK that provides a detailed comparison between Maestro and ElasticXL, covering all features and differences. This would help us as SEs to plan and advise customers more effectively.
So far, I’ve only seen the following documentation for ElasticXL:
sk173183 - Scalable Platforms (Maestro and Chassis) comparison between versions
R82 Scalable Platforms Administration Guide- Working with ElasticXL Cluster
sk79700 - VSNext / VSX supported features
What's New in R82 - Quantum Maestro, Scalable Chassis, and ElasticXL
R82 Release Notes - Quantum Maestro, Scalable Chassis, and ElasticXL
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 18 | |
| 7 | |
| 7 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY