Hello Community,
we’re preparing for a Check Point Maestro + ACI implementation and would appreciate any input or best practices.
Our environment and Architecture:
Platform: Check Point Maestro (2x 9700 SGMs + MHO-140)
Software: R81.20
Bonding mode: 802.3ad (LACP)
Each bond connects to ACI fabric (2x Leafs) – currently working with 25G SR links
One VS per ACI context (stage/prod)
L3 IPs assigned directly to bond interfaces
Are there best practices for one-arm PBR design with Maestro + ACI?
What’s the recommended interface setup for L3 one-arm traffic into VSX (e.g., VLAN tagging, IP on bond, subinterfaces)?
Any special considerations with LACP bonding on Maestro?
Any insights or shared experiences would be super helpful – we already resolved one port-down issue by hardcoding 25G speed on CP side (vs 10G default), so we’d love to avoid surprises during full implementation.
Thank you!
Katarina