Hello Community,
I have a few questions regarding the Check Point integration with Cisco ACI, especially in Multi-Pod deployments and when using Maestro.
I’ve reviewed the following document:
Private Cloud Security for Cisco ACI Infrastructure – Release 2.0
https://community.checkpoint.com/t5/Cloud-Network-Security/Private-Cloud-Security-for-Cisco-ACI-Infr...
The whitepaper describes two firewall deployment options for Multi-Pod stretched networks:
- Active-Active Firewall with different IP / MAC addresses using LPBR
- Active-Active Firewall with the same IP/MAC addresses using Cisco Anycast
The document mentions that Maestro deployment for both scenarios was not GA at the time. Since the document dates from 2022, could someone please confirm if this is now GA and officially supported by Check Point?
Additionally, both deployment examples describe a setup with one MHO per pod, with a sync interface between them.
From a Maestro perspective, it means as a single site / dual orchestrator configuration?
Finally, both designs rely on Active-Active firewall operation. Considering that Check Point introduced new capabilities with ElasticXL since 2022, which Active-Active model would be recommended for Multi-Pod stretched environments — ClusterXL, ElasticXL, or Maestro?
Any guidance or or help would be highly appreciated.
Regards