- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hey guys,
I've been playing around with some Maestro units and a number of gateways. I have been running into a number of problems that caused me to document all the actions that I needed to do for a specific type of installation, the document is about 3 different scenario's:
Please check out the document and let me know what you think about it, also if you see things that you don't understand or know that should be different, please let me know.
Updated the document to v1.0, 16 dec 2019.
Updated the document to v1.2, 26 Feb. 2020. Added bonding.
Updated the document to v1.3, 03 Mar. 2020. updated some parts and added commands.
Updated the document to v1.5, 17 Mar. 2020. updated some parts and added commands after training.
Updated the document to v1.6, 25 May 2020. Update regarding HA licenses
Hi Maarten,
I would also suggest to use a right terminology in your documentation and discussions. It will avoid any confusions.
There's no such device called "Maestro". Maestro is the complex of products.
What you meant is the MHO = Maestro Hyperscale Orchestrator, or Orchestrator.
Thank you,
Anatoly
Updated the document yesterday after using it to setup a dual site single MHO setup.
@shay_solomon I will be double checking for the differences compared to the official documentation.
Hi,
Tnx for a great document!:)
I got two Orchestrators, this is what I assume is called a MHO ? So one Orchestrator=1 MHO ? And x numbers of orchestrators together with some appliances/gateways make up a Maestro solution ? - Its like Check Point wants to make it hard.. they are big fans of giving stuff name and then never ever use those names in any of the technical components.. they seem to mix up their concepts with tech solutions.
Anyways -
I have two orchestrators, and I have connected them with sync on the correct port (I got 140's). Then I have attached 4 appliances - two cabels from each appliance to each MHO. I power this up and there is absolutley nothing showing in my Gaia portal.. the only interfaces I see are my two mgmt interfaces. No gateways and no nothing... is there something globally I need to configure to get started ?
Some minor updates just for your info.
When you use 1Gb UTP SFP's in a MHO140, just for the management of the Security groups for instance, they will not work with R80.20SP JHF 178, they do work with 191 and higher.
HA Licenses: When you move a existing cluster into a Maestro configuration you might get problems when you're creating the gateway while pushing a policy. This happens with R80.30 when you are using a SmartConsole build lower than 42. For R80.20 I don't know, was not able to test it. R80.40 GA works just fine.
I also uploaded version 1.1 of the document that mentions these limitations.
Great, tnx - that s a nice document to have indeed.
I am still struggeling with not seeing any gateways or interfaces, I have had the guys re-checking this several times and they say it should be fine.
There is no basic setup I am missing ? Do I need to put a lic on the orchestrators? - as far as I can see only the appliances should need lic's.
When i go into the gaia portal of either of the orchestrators I just get this:
Failed to load Security Groups:
Failed to get remote Orchestrator interfaces.
2 orchestrators, 4 appliances (140 and 6500's)
Only 1 of the appliances are turned on.
I have this set up as a single site, but the solution is installed in two different rooms. So I have a mix of fiber and dacs - all cabeling should be ok... But I am unsure now..
Running lldctl on both orchestrators.:
orch1: showing a 6500 appliance - nothing else.
orch2: shows nothing
So, I assume this is an issue related to the sync cable between the orchestrators.
please post output of # lldpctl of both orchestrators on primary site
I would consider this a single site setup - but as a stretched. The hardware is just a few meters apart, so the only real differnece as far as I can see it is that I do not use DAC all the way,.
Talking to checkpoint, when ordering sfp's and dac's - they said this setup should be fine.
I am a bit usure about port 48 vs. port 47. As of now I am using the 48 port.
For the cabeling of the appliances, I have made sure the same ports are used for all appliances and all the cross connects. So all use same ports on both orchs.
I had the guys do a triple check of cabeling, and now it looks better.
Using lldpctl I get neighbors from both appliances and maestro.
The two maestros are connected on p48, that port is in sync state. But I still dont get any infercaes or anything else in Gaia. But I have requested a reboot - lets see 🙂
Update-> yeah, now all is good ! 🙂 Thanx for the help guys!!
Guys,
Regarding the ports 47 and 48. Port 48 is the default sync-port between the orchestrators on the same site. 47 is the recommended site-sync port between the sites. However, you have to define the port 47 as the site-sync in orchestrator with the command:
set maestro port 1/47/1 type site_sync
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY