- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters Series 2026
WATCH NOWWhile reviewing Maestro procedures, I found legacy commands that still appear in training materials and operational runbooks. When migrating from R81.20 to R82 or R82.10, review both the command syntax and the device and shell where each command must run.
Deprecated does not necessarily mean removed. The R82 Release Notes classify the commands below as deprecated and replaced. This does not establish that every executable has been physically removed from every build. New procedures and automation should use the documented interface for the target release.
1. Security Group Monitoring and Diagnostics
| Legacy command | R82/R82.10 alternative | Purpose |
|---|---|---|
| asg perf | insights | Performance dashboard |
| asg conns | cluster-cli show info connection / insights | Connection information |
| asg search, asg6 search | cluster-cli show info connection | Search using connection parameters |
| asg cores_stat | cluster-cli show info cpu | CPU utilization and core roles |
| asg if, asg_if, asg6 if | cluster-cli show info interfaces | Interface status and metrics |
| asg resource, asg6 resource | insights / specific cluster-cli queries | Resources and operational metrics |
| asg diag, asg_diag, asg6 diag | HCP / insights | Health checks |
| asg_bond | HCP Bond Health test | Bond verification |
| asg_collect_vsx_logs | cpinfo, following its help and the applicable procedure | Diagnostic collection |
The deprecation mapping appears in the Release Notes. The cluster-cli examples above use the complete syntax documented in the R82/R82.10 command references, including the info level, which is omitted from some abbreviated Release Notes examples.
Read-only examples on the Security Group — Expert mode:
cluster-cli show info overview cluster-cli show info cpu cluster-cli show info interfaces cluster-cli show info pnotes cluster-cli show info policy
For continuous CPU monitoring:
cluster-cli show info -l cpu
To search for a TCP connection by source address, destination address, and destination port:
cluster-cli show info connection \ --sip 192.0.2.10 \ --dip 198.51.100.20 \ --dport 443 \ --proto 6
The command reference also documents --sport for the source port. Filters must match the connection being investigated; copying arguments from the legacy asg search command is not sufficient.
2. insights Replaces the Interactive Use of asg perf, but Not Its Automation Interface
For interactive monitoring:
insights
The dashboard includes CPU, memory, throughput, connection rate, concurrent connections, packet rate, drops, and interfaces, alongside HCP integration. The tool is documented for both Maestro Security Groups and Maestro Orchestrators; the execution target remains relevant.
Migrating a procedure from asg perf -v to insights does not automatically preserve:
Legacy IPv4/IPv6 options.
Column structure.
Refresh intervals.
Output formats expected by a parser.
For automation, prefer a targeted query and, where applicable, structured output:
cluster-cli show -f json info cpu
JSON output is documented for cluster-cli. Nevertheless, validate the schema returned by the installed build before adapting the consuming script or application.
3. HCP Takes Over Checks Previously Associated with asg_diag
In Expert mode:
hcp --help
HCP is a self-updatable suite. Select the available tests applicable to the target; do not assume that every asg_diag verify parameter maps directly to a single HCP invocation.
The R82.10 documentation includes HCP support on both MHOs and Security Groups. This does not imply identical tests or execution scope on both platforms.
4. Administration and Configuration: Moving to cluster
The changes also affect administrative command families:
| Legacy syntax | Migration direction |
|---|---|
| asg cluster_site_admin / asg_chassis_admin | cluster_site_admin or site administration through set cluster |
| show/set chassis high-availability … | show/set cluster configuration high-availability … |
| show/set/delete chassis … unique_ip | The cluster configuration unique-ip family |
| show/set/delete smo … | Check the specific equivalent within the cluster family |
| toggle_same_vmac | toggle_same_vmac_os |
These changes require reviewing the subcommands. Replacing only the word chassis or smo in a script does not guarantee a correct migration.
Example HA query in Gaia gClish on the Security Group:
show cluster configuration high-availability mode
Do not confuse HA quality-grade factors, used to assess site health, with traffic-distribution weights assigned to SGMs. These settings serve different purposes.
5. A Specific R82 → R82.10 Change: Member Weights
This is an important exception to broad migration guidance: not every smo-to-cluster change was completed in R82.
The R82.10 Release Notes document the following:
| R82 | R82.10 |
|---|---|
| set smo security-group sgm-weight member-id <IDs> weight <value> | set cluster configuration member-weight member-id <IDs> weight <value> |
| set smo security-group sgm-weight apply | set cluster configuration member-weight apply |
| show smo security-group sgm-weight all | show cluster configuration member-weight all |
| show smo security-group sgm-weight current | show cluster configuration member-weight distribution |
Accepted values include default or a weight from 0 to 512.
Configuration takes place in Gaia gClish on the Security Group. Applying new weights can redistribute connections between members, so this is an operational change, not a diagnostic query.
6. What Should Not Appear in a Generic “Removed Commands” List
orch_stat remains documented for the MHO, including:
orch_stat -a orch_stat -p orch_stat -L orch_stat -A
These display all categories, port information, LLDP information, and authentication status, respectively. By contrast, cluster-cli runs on the Security Group in Expert mode. Using the correct tool on the wrong device undermines the troubleshooting process.
It is also incorrect to claim that all asg commands have disappeared. For example, asg stat -v is still referenced in the R82.10 HA documentation.
For drop_monitor and asg_affinity_enhance, the R82 table provides no direct replacement. This does not justify assuming equivalence with insights. Meanwhile, asg_session_control is identified as unsupported in documentation histories for earlier releases; it should not be presented as a removal exclusive to the R81.20 → R82 transition.
Very good update
Thank's bro
you nailed it!
Thank's
Super good update. A couple of comments:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY