- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hello, I'm interested in is it possible to access to security group (SSH, WebUI) in Maestro environment over Uplink interface?
If answer is NO, what are you thinking about "Management Data Plane Separation" sk138672 because during a creation of security group, FTW (First Time Wizard) when you type default gateway for managament, that becomes a default route for that security group. We will need an another default route towards external interface.
I think that one solution is to use "Management Data Plane Separation" other is PBR (Policy Based Routing) to accomplish this.
Best regards,
Milan Babic
You don't have to use the management interface on the security group, but it has to exist on there. If you're not going to use it, give it an IP that doesn't overlap with anything else on your network. It's all one routing table so you would remove the default route added when you create the security group (or just don't put one on there at SG creation) and add the required default route and any other routes to operate it afterwards. You can manage the security group from an uplink, you can SIC to an uplink, all that is fine, you just won't end up connecting to SGM1 every time you log in. You should disable L4 distribution in this scenario.
MDPS is an option if you wish but it might be simpler to avoid it. PBR is not really an option because any traffic destined to or originating from the gateway itself will not use the PBR tables.
@emmap wrote:You don't have to use the management interface on the security group, but it has to exist on there. If you're not going to use it, give it an IP that doesn't overlap with anything else on your network. It's all one routing table so you would remove the default route added when you create the security group (or just don't put one on there at SG creation) and add the required default route and any other routes to operate it afterwards. You can manage the security group from an uplink, you can SIC to an uplink, all that is fine, you just won't end up connecting to SGM1 every time you log in. You should disable L4 distribution in this scenario.
MDPS is an option if you wish but it might be simpler to avoid it. PBR is not really an option because any traffic destined to or originating from the gateway itself will not use the PBR tables.
What does it mean, that you can't use PBR in Maestro?
I want to achieve this. Default route to external interface will be primary (priority 1), default route to management interface will be secondary (priority 2). Let's assume that management of SG1 is 10.10.10.1/24, gateway 10.10.10.254. I want to use PBR on the way when traffic arrives on 10.10.10.1 with source ip 192.168.10.0/24 send it on gateway 10.10.10.254.
I think that example is obvious.
Emma is talking about the locally generated traffic limitation PBR has, documented in sk167135.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
7 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY