- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hello Community,
we’re preparing for a Check Point Maestro + ACI implementation and would appreciate any input or best practices.
Platform: Check Point Maestro (2x 9700 SGMs + MHO-140)
Software: R81.20
Bonding mode: 802.3ad (LACP)
Each bond connects to ACI fabric (2x Leafs) – currently working with 25G SR links
One VS per ACI context (stage/prod)
L3 IPs assigned directly to bond interfaces
One-arm mode
Policy-Based Routing (PBR)
Interfaces connected to ACI (via LACP bundles)
Are there best practices for one-arm PBR design with Maestro + ACI?
What’s the recommended interface setup for L3 one-arm traffic into VSX (e.g., VLAN tagging, IP on bond, subinterfaces)?
Any special considerations with LACP bonding on Maestro?
Any insights or shared experiences would be super helpful – we already resolved one port-down issue by hardcoding 25G speed on CP side (vs 10G default), so we’d love to avoid surprises during full implementation.
Thank you!
Katarina
Hello @katarina_ 
With ACI service graphing and PBR is the recommended setup. You are correctly using VSX with a VS per tenant in one-arm mode. That's the best practice. Using trunked bonds is more scalable solution in my opinion. It needs fewer physical interfaces, and you can add more VLANs into a trunk when necessary. Then you would assign a VLAN from the trunk to each VS. With one-arm mode you should keep anti-spoofing disabled from the interface.
The only limitation with LACP is that the bond members need to be connected to the same logical switch. In ACI you most likely have vPC enabled on leaf switches anyway, so you should be covered. My recommendation is to hard code the speed for the uplinks at the MHO.
Hi @katarina_,
We've recently deployed Maestro & VSX with Cisco ACI using Symmetric PBR and have deployed it similar to how you've described. Here are a couple of things I've learned during the process:
If I think of any more, I'll add them here.
Thanks,
Aaron.
@Lari_Luoma, @Anatoly can you advise?
Hello @katarina_ 
With ACI service graphing and PBR is the recommended setup. You are correctly using VSX with a VS per tenant in one-arm mode. That's the best practice. Using trunked bonds is more scalable solution in my opinion. It needs fewer physical interfaces, and you can add more VLANs into a trunk when necessary. Then you would assign a VLAN from the trunk to each VS. With one-arm mode you should keep anti-spoofing disabled from the interface.
The only limitation with LACP is that the bond members need to be connected to the same logical switch. In ACI you most likely have vPC enabled on leaf switches anyway, so you should be covered. My recommendation is to hard code the speed for the uplinks at the MHO.
Hi @Lari_Luoma,
Thank you very much for your response, I have already hard-coded the speed, as I encountered this issue at the beginning.
Let me also add that you might want to engage with Check Point Professional Services. PS has a long experience with the best practices setups including the ACI environments.
Hi @katarina_,
We've recently deployed Maestro & VSX with Cisco ACI using Symmetric PBR and have deployed it similar to how you've described. Here are a couple of things I've learned during the process:
If I think of any more, I'll add them here.
Thanks,
Aaron.
To clarify, the dummy drop rule for VS0 should contain the objects pulled in from the Generic Data Centre object. This is so the objects get loaded on VS0 so that they can be used by the Virtual System(s).
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 15 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | 
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY