- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters Series 2026
WATCH NOWGood afternoon. We want to migrate network termination from our current hardware to Check Point Maestro; we have Security Groups (SGs), four Orchestrators, and a configured Bond interface.
What is the required configuration plan? Am I correct in assuming that simply adding the device to the topology in SmartConsole won't be enough, and that we need to configure settings on both the Orchestrator and the SGs?
Could you provide some details of your Maestro installation, like network diagram, vlan trunks and if you have more than one Security Group, on which of these security group you want to attach the new network.
You'll need to add the physical interfaces to the security group, configure them in gclish in the security group, then configure them in SmartConsole.
It sounds like you're new to Maestro, there some videos in the CheckFlix section under Learn up the top all about Maestro that will help you with the process.
But can I also assign a VLAN to the existing physical interfaces and configure the VLAN IP address within the bond? For example:
We already have interfaces like bond1.1,
bond1.2,
bond1.3,
etc.
If I want to add bond1.4, I would need to:
1. Add the VLAN tag to the current ports (not required starting from version 81.10).
2. Add the VLAN tag to the bond1 interface group and assign an address (this can be done via the web interface; as I understand it, if we have 4 appliances, the settings will propagate to all of them via the management IP).
3. Add it in SmartConsole without topology.
Hi,
Assuming the Security Group is in Gateway Mode you can add the required VLAN to the bonding group via gclish and configure the interface in the topology in SmartConsole. Install policy and you are good to go to use the interface.
And offcourse add the VLAN to the switch ports.
Make sure you are in gclish so all SGM's will be configured correctly. Do not forget to save the configuration.
Martijn
Yes if the interfaces and bond are already there, and it's not a VSX deployment, you can just add the sub interface in either gclish or WebUI and then add it in SmartConsole.
Important to note, the interface won't work until you install policy after adding it in SmartConsole.
Thanks, we applied the settings and everything is working:
We added a VLAN to the existing bond via gclish, assigned an IP address, and saved the configuration. Next, we added the address to Smart Console (without topology) and—in our case—configured interface redistribution into OSPF.
The interface is successfully pingable from other networks.
We didn't manually add a tag to the interfaces in the orchestrators; it was assigned automatically.
Maestro has some characteristics that can be confusing at first.
Assuming your Maestro environment is already deployed and in production, if you simply want to add a new VLAN/network, you only need to configure it on the Security Group (SG) (think of it as the firewall itself), either through the WebUI or gClish.
The basic steps are:
In other words, adding the network only in SmartConsole is not enough. The interface must first exist on the Security Group.
I also recommend these resources:
Maestro for Beginners – Core Concepts Explained
https://community.checkpoint.com/t5/Check-Point-for-Beginners/Maestro-for-Beginners-Core-Concepts-Ex...
Maestro Jump Start video series
https://www.youtube.com/watch?v=SE48WQtqCFY&list=PLMAKXIJBvfAhYnVrdkjZqT6pcnlUv7X4g
If you have access to the Check Point eLearning portal, I also highly recommend the course:
Check Point Maestro Hyperscale Firewall – Technical Specialist | eLearning
https://checkpointpartners.litmoseu.com/home/LearningPath/12261?r=false&ts=1784032352609
It provides an excellent overview of the Maestro architecture and configuration workflow.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 6 | |
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY