- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters Series 2026
WATCH NOWOne of the main differences between Maestro and ElasticXL is how the network is plumbed into the devices. In Maestro, all of the SGMs are sharing the physical interfaces via the MHOs. In ElasticXL, each SGM has its own interfaces, separately plumbed to switches. I'll focus on a single site setup each way here - in a dual site, the other site is a repeat of the single site. In all cases, each interface or bond or VLAN must be in the same layer 2 domain between devices.
In Maestro we have our two MHOs and two SGMs. The uplinks are bonded across both MHOs, typically using LACP. When the MHOs are cross-connected to a switching layer, the switches must be stacked (vPC or vendor equivalent), presenting a single LACP bond down to the Maestro stack for each bond. These interfaces are presented down to the SGMs as regular interfaces, and the SMO SGM handles the ARP and LACP management. It is in bonding the uplinks across both MHOs that we achieve redundancy at the MHO layer. If an uplink from one MHO only is used at the security group, this uplink will experience an outage when the MHO is being rebooted for patching or maintenance. This is also why the default HA weighting will cause a site failover in a dual site setup when an MHO reboots. With default settings, each site has its own MAC address for each regular uplink interface. The easiest way to architect each site of a security group is to think of it as a single gateway.
In ElasticXL, each SGM is directly connected up to the switches. Each SGM maintains its own independant interfaces, ARP tables and LACP negotiation. The switches must present separate bonds down to each SGM. Each SGM has its own MAC address for each interfaces, allowing the MAC address rewriting mechanism to work for the SMO to pivot traffic to other SGMs on the active site. This has the advantage of not requiring switches to be stacked if it is not an available option. It is basically the same architecture we would use for a ClusterXL cluster, only there may now be up to 6 devices in the cluster with up to 3 of them being active at a time.
Hopefully this clears up any confusion about how to set up your network for these clustering types. If anything is unclear, please let me know so I can clarify here.
Thank you Emma for the write-up. This is very important topic.
Let me summarize here quickly:
Maestro: Bonding mandatory in production environments. Bonds created across orchestrators and configured as a single bond on the switch
ElasticXL: Bonding adds an additional layer of resiliency. Cable same interfaces on each appliance (SGM) and configure separate LAGs for each one on a switch.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 6 | |
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY