- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hey guys,
I've been playing around with some Maestro units and a number of gateways. I have been running into a number of problems that caused me to document all the actions that I needed to do for a specific type of installation, the document is about 3 different scenario's:
Please check out the document and let me know what you think about it, also if you see things that you don't understand or know that should be different, please let me know.
Updated the document to v1.0, 16 dec 2019.
Updated the document to v1.2, 26 Feb. 2020. Added bonding.
Updated the document to v1.3, 03 Mar. 2020. updated some parts and added commands.
Updated the document to v1.5, 17 Mar. 2020. updated some parts and added commands after training.
Updated the document to v1.6, 25 May 2020. Update regarding HA licenses
Hi,
I have a few comments and corrections here:
1. Console connection are needed to ALL devices - nice to have, but not must. You can "jump" in between devices using CIN network 198.51.0.0 (or using m command)
2. You also need a 10Gb switch for connecting all Mgmt ports - I guess here we're talking about MHO-140. MHO-140 supports 1Gbps transceivers as well (copper and fiber), so it's not necessary to use 10Gbps switch. With MHO-170 you can use 40Gbps, 100Gbps or 4x10Gbps as well
3. I would not say that the best practice is to use single orchestrator, and then to join second one (actually to move to dual orchestrator environment). If you need dual orchestrator - do it from the beginning, including proper cabling
4. I would not mention take number of JHF. Today it is 178, tomorrow it will be something else. You can mention just GA version of JHF
5. Upgrade to JHF on MHO from WebUI would be much more easier. Not clear why should we do it from command line. However, JHF installation on Security Group is not supported via WebUI, hence we have to do it via gclish
6. Dual site - I'm not sure, the best practice is to glue two separate single-site setups. If you have security groups on both sites before you connect them, one of them will be overwritten.
Please feel free to contact me offline at anatoly@checkpoint.com and I will be happy help you with finalizing this documentation.
Hi Maarten,
I understand your arguments, but this is related to specific case.
Regarding 5 - you should download a package from the internet and upload it offline using "import" in web ui. it takes a seconds.
Regarding "PS in the multisite situation, when you want to jump to another member there is no possibility to jump to a gateway in another site, you can only address the Sec Grp and member." - not true.
You can do "m 1_2" - member 2 on 1st site or "m 2_5" - member 5 on 2nd site, for example
Thank you,
Anatoly
In order to use m 2_2 Security group must be dual-sited with JHF installed on it.
Can you see both sites using asg monitor?
Regarding show configuration - you can use "show maestro security-group" command
... and one more comment: in order to move in between sites, you have to do m 2_2 from the gclish of security group, not from the clish of the orchestrator
I agree, it looks ugly. However, I suggest to do things in following order:
1. Install JHF on all orchestrators
2. Create security group with GWs from 1st site only
3. Install JHF on GWs from 1st site only
4. Enable dual-site on security group "set smo configuration site-amount 2"
5. Enable image-cloning "set smo image auto-clone state on"
6. Reboot all GWs on the first site
7, Via MHO add GWs from the 2nd site to this security group.
Then you don't need to install JHF on the 2nd site's GWs, because it will clone it automatically
Try this, it works, trust me 😉
Maarten,
You set dual site ONLY when members of site one are in the security group, after you install JHF on it.
You cannot add members from the second site to the security group before you enable dual-site on it.
That is what I'm actually saying.
After you enable dual-site on the security group that include only members from the first site and reboot them, you will be able to add members from the second site and install JHF on it (using auto-clone or manually).
If you still encounter any issue with this procedure, please open support ticket and we will be happy to do it with you.
Thanks
Anatoly
It's strange that auto-clone did not work. But yes, it looks like you used a right command.
In any case, please open support ticket on it and we will investigate it deeper.
Thank you,
Anatoly
Please use 192.0.2.0
Hi,
How can I create the bonding interface management security group, i create 1 SG.
When i want to create vsx gateway from 1 SG, is needed install jumbo hotfix? M170-2380.R80.20SP
I can guess, Ricki meant MAGG bond. So, in order to create MAGG bond, you have to use dummy IP and then to change to real one. This procedure is described in documentation. Please beware, MAGG does not support LACP mode.
Anatoly
Hi Anatoly,
I have try to this magg,
But not solved stack in gclish command, cannot use gclish command in gateway appliance.
Error is : you can't start interactive session from another interactive session
Looks like you entered to expert mode from gclish and trying to run gclish again from expert. If this is a case, please use exit instead in order to get back to gclish. Another option - just open another ssh session
Hi maarten,
In the doc started guide said when connected 2 maestro sync is only needed one interface (port1 mgmt connect to management server) on maestro1. So I want to make two interface for connected to management server.
Dear Ricki and All,
In order to avoid any confusions, we strongly suggest to read and use official documentation.
The official documentation is published here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Any feedback on official documentation is welcome!
Anatoly
Hi,
With respect to Maestro doc complexity, I will appreciate if you can email me few points for which you believe we can simplify the doc.
shay_sol@checkpoint.com
10x
Shay
Shay Solomon | Director, Education Services & Gamification
+972-52-3769206 (IL)
+415-2513078 (US)
Tel Aviv, Israel | Irving, TX
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY