Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Interface and Bonding: Maestro vs ElasticXL

One of the main differences between Maestro and ElasticXL is how the network is plumbed into the devices. In Maestro, all of the SGMs are sharing the physical interfaces via the MHOs. In ElasticXL, each SGM has its own interfaces, separately plumbed to switches. I'll focus on a single site setup each way here - in a dual site, the other site is a repeat of the single site. In all cases, each interface or bond or VLAN must be in the same layer 2 domain between devices.

Maestro Generic.png

In Maestro we have our two MHOs and two SGMs. The uplinks are bonded across both MHOs, typically using LACP. When the MHOs are cross-connected to a switching layer, the switches must be stacked (vPC or vendor equivalent), presenting a single LACP bond down to the Maestro stack for each bond. These interfaces are presented down to the SGMs as regular interfaces, and the SMO SGM handles the ARP and LACP management. It is in bonding the uplinks across both MHOs that we achieve redundancy at the MHO layer. If an uplink from one MHO only is used at the security group, this uplink will experience an outage when the MHO is being rebooted for patching or maintenance. This is also why the default HA weighting will cause a site failover in a dual site setup when an MHO reboots. With default settings, each site has its own MAC address for each regular uplink interface. The easiest way to architect each site of a security group is to think of it as a single gateway. 

ElasticXL Generic.png

In ElasticXL, each SGM is directly connected up to the switches. Each SGM maintains its own independant interfaces, ARP tables and LACP negotiation. The switches must present separate bonds down to each SGM. Each SGM has its own MAC address for each interfaces, allowing the MAC address rewriting mechanism to work for the SMO to pivot traffic to other SGMs on the active site. This has the advantage of not requiring switches to be stacked if it is not an available option. It is basically the same architecture we would use for a ClusterXL cluster, only there may now be up to 6 devices in the cluster with up to 3 of them being active at a time.

Hopefully this clears up any confusion about how to set up your network for these clustering types. If anything is unclear, please let me know so I can clarify here.

 

 

1 Reply
Lari_Luoma
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Thank you Emma for the write-up. This is very important topic.

Let me summarize here quickly:

Maestro: Bonding mandatory in production environments. Bonds created across orchestrators and configured as a single bond on the switch
ElasticXL: Bonding adds an additional layer of resiliency. Cable same interfaces on each appliance (SGM) and configure separate LAGs for each one on a switch.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

 
Upcoming Maestro Events