Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Danny
Champion Champion
Champion

Check Point Maestro - FAQ


Author: Danny Jung

Q: What's the official product site ?
A: Check Point Quantum Maestro | Orchestrator Datasheet | Support Center

Q: What's the recommended version for Security Groups ?
A: Check Point R81 for Scalable Platforms | Release Notes | Known Limitations | Comparison to R81 and other versions

Q: What's the recommended version for Orchestrators ?
A: Check Point R81.10 for Scalable Platforms | Release Notes | Known Limitations

Q: Where's the Getting Started Guides ?
A: Quantum Maestro - Getting Started Guide (PDF) | MHO Quick Start Guide

Q: Where's the Admin Guide ?
A: Quantum Maestro - Admin Guide R81 (PDF)
A: Quantum Scalable Chassis - Admin Guide R81 (PDF)

Q: Where can I get a Maestro Demo ?
A: Right here.

Q: What are the Maestro HyperScale Orchestrators (MHO) based on?
A: MHO-140 Appliance: Nvidia Mellanox SN2410 Ethernet Switch
A: MHO-175 Appliance: Nvidia Mellanox SN3700C Ethernet Switch

Also see Check Point's Declaration of Conformity.
Info: The MHO-170 Appliance is discontinued.

Q: Which transceivers are compatible / supported ?
A:
Compatibility of transceivers for Check Point appliances

Q: What's the port mapping ?
A:
Port mapping for MHO-140 Appliance

Q: How is the m / member command working ?
A:
It's just a SSH wrapper that aims to make it easier to SSH-connect to members of security groups, i.e. Check Point Security Gateways (SGMs). You can also directly use ssh if you know the IP addresses or simply look them up via: lldpneighbors

Q: What's the CIN network ?
A:
The Sync & Chassis Internal Network (CIN) got it's name from Check Point chassis-based 41000 / 61000 appliances. In Maestro it's used for connectivity between the orchestrators and the security gateway modules where they are connected via DAC cables.

Q: How can I check the status of the connected ports on the MHO ?
A:
Simply use this tool from our toolbox or run the command: sx_api_ports_dump.py

Q: Where can I find training for Maestro ?
A:
As a Check Point partner, ask your local Check Point SE for the Maestro Partner Training KIT (PTK) and training dates.
A: Check Point also offers a free Maestro Jumpstart Training (part 2) and this community hosted a Maestro TechTalk.
A: Check Point Education & Certification offers a paid Maestro training & certification.
A: Check Point Partners can view recorded Maestro sessions within the Partner Onboarding Academy.
A: Check Point Maestro Webinars can be found on Eventbrite and BrightTalk.
A: Check Point Professional Services started a documentary on HyperScale solutions: Part 1, Part 2.
A: More training resources can be found here.

Q: How can I verify transceivers in an Orchestrator (MHO) appliance or SGM?
A:
Simply use this tool from our toolbox.

Q: How do I license my Maestro systems?
A:
MHOs don't require a license.
A: SGMs require a local license. Generate it for the 192.0.*.* IP of your SGM. Verify it via cphaprob stat. Your SGM will try to download the license and contract from Check Point's UserCenter. If that doesn't work automatically (verify via g_all cplic print -x), use the g_cplic command to import the license and contract files manually into your SGM.

Verify that the license info in these files is correct:

  • $CPDIR/conf/cp.license
  • $CPDIR/conf/cp.license.smo

Q: How do I identify which SGM is SMO?
A:
Command: asg_blade_config get_smo_ip
A: Command: asg stat -i tasks

Q: How do I identify which SGMs within a SG are active?
A:
Command: gexec -t
A: Command: g_all
A: Command: asg monitor

Q: How many snapshots fit on my Orchestrator?
A:
Disk space is limited on Orchestrators. Mostly just two or three snapshots will fit on the disk.
Best Practice: Create snapshots before downloading new packages. Verify your snapshots within WebUI > Snapshot Management after package installation.

**WORK IN PROGRESS**

3 Replies
Lari_Luoma
Ambassador Ambassador
Ambassador

It's time to update this FAQ...

Here are a few 2024 updates:

Q: What is the Recommended Version for Security Groups and Orchestrators?
A: R81.20

Q: How can I check the status of connected ports in MHO?
A: orch_stat -p  (shows the ports)
A: orch_stat -L (shows the LLDP neighbors)

Q: How do you identify which SGMs within an SG are active?
A: asg monitor

Q: Is 25G supported?
A. Yes, in R81.20
A. Splitters will be supported soon

Q. Is dual-site active-active available?
A. Not yet, but it will be. Stay tuned.

B. What are some best practice performance optimizations in Maestro?
A. If you have hide NAT, use the default auto-topology distribution mode with L4 disabled.
A. If you don't have hide NAT, use general distribution mode with L4 disabled.
A. If you have Internet and east-west traffic in the same SG or the number source or destination IP-addresses is low, and you have performance issues, contact Check Point Support to find the best settings.

A: Where can I find more Maestro FAQs?
sk147853 

0 Kudos
Timothy_Hall
Legend Legend
Legend

Any chance that L4 distribution might be disabled by default going forward for new Maestro installations in later releases?  It doesn't seem to me that L4 distribution is desirable in most scenarios.  Obviously for upgrades the state of L4 should be left alone.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Lari_Luoma
Ambassador Ambassador
Ambassador

Hi Tim! 
This is a good question and in my opinion it would make sense to have it disabled by default. I don't know a specific version or a Jumbo where that would happen, but maybe @Anatoly can advice?

0 Kudos