Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
andrej_kascak3
Participant

R82 VSNext Design Review: Cross-Environment Transit (VSwitch vs Dedicated VLANs) on Maestro

Hi CheckMates Community,

I am currently evaluating two architectural options for a Check Point R82 VSNext deployment on a Quantum Maestro Security Group and would appreciate feedback from anyone running similar topologies in production.

Environment & Requirements:

  • Architecture: 3 Virtual Gateways (VGW A, VGW B, VGW C) on R82 VSNext (Maestro SG – connected to LAN infra via singe bond interface).
  • Downstream: Citrix NetScaler using Traffic Domains over a shared LACP bond trunk (managed by an external team).
  • Upstream: 4 distinct external environments connected over the shared trunked bond (Cisco N9K with 4 VRFs).
  • Blades & features - we use only FW blade (with NAT) currently, no dynamic routing. In near future we plan to add Identity Awareness using Identity Collector integrated with Active Directory.
  • Key Constraints:
    1. No upstream inter-VRF routing interconnect exists, meaning cross-environment transit must be bridged/routed through the firewall chassis.
    2. Every flow strictly traverses only 1 VGW (no multi-VGW chaining).

Option 1: 4 Internal Virtual Switches (VSwitches)

  • Provision 1 internal VSwitch per environment in Gaia OS and attach each VGW via internal virtual warp (wrp) interfaces.

Option 2: 12 Dedicated Point-to-Point VLANs

  • Provision 12 point-to-point subnets.

Looking for Feedback / Community Experience:

  1. For those running high-throughput VSNext environments on Maestro, is the performance on wrp interfaces sufficient, or is physical VLAN sub-interfaces performance superior?
  2. Are there any hidden operational gotchas with wrp links, internal VSwitches, or Identity Awareness tables across network namespaces in R82 VSNext?
0 Kudos
0 Replies