Hi CheckMates Community,
I am currently evaluating two architectural options for a Check Point R82 VSNext deployment on a Quantum Maestro Security Group and would appreciate feedback from anyone running similar topologies in production.
Environment & Requirements:
- Architecture: 3 Virtual Gateways (VGW A, VGW B, VGW C) on R82 VSNext (Maestro SG – connected to LAN infra via singe bond interface).
- Downstream: Citrix NetScaler using Traffic Domains over a shared LACP bond trunk (managed by an external team).
- Upstream: 4 distinct external environments connected over the shared trunked bond (Cisco N9K with 4 VRFs).
- Blades & features - we use only FW blade (with NAT) currently, no dynamic routing. In near future we plan to add Identity Awareness using Identity Collector integrated with Active Directory.
- Key Constraints:
- No upstream inter-VRF routing interconnect exists, meaning cross-environment transit must be bridged/routed through the firewall chassis.
- Every flow strictly traverses only 1 VGW (no multi-VGW chaining).
Option 1: 4 Internal Virtual Switches (VSwitches)
- Provision 1 internal VSwitch per environment in Gaia OS and attach each VGW via internal virtual warp (wrp) interfaces.
Option 2: 12 Dedicated Point-to-Point VLANs
- Provision 12 point-to-point subnets.
Looking for Feedback / Community Experience:
- For those running high-throughput VSNext environments on Maestro, is the performance on wrp interfaces sufficient, or is physical VLAN sub-interfaces performance superior?
- Are there any hidden operational gotchas with wrp links, internal VSwitches, or Identity Awareness tables across network namespaces in R82 VSNext?