Hi all,
Currently we are to deploying the Check Point Maestro with single site dual MHO. We know that Maestro is running on Active-Active mode, however the internal and external switch connected is actually a cascading switch which is not support creating any port channel or LACP like stacking switch. Meanwhile, in the design due to insufficient port, we must bond the interface from each security group to provide redundancy within MHO1 & MHO2, but we unable to configure Bond operating mode 802.3ad LACP (load sharing) with both link is Active-Active, it will have issue with cascading switch as it is not like stacking switch.
Please refer to the diagram of the topology, MHO1 & MHO2 connecting straight link to switch 1 & switch 2 separately without cross.
This is the first time we meet maestro with Cascade Switches, so we are not sure whether it is supported?
Is there any similar setup? and What is the best way to configure for this scenario?
Is there any concern Maestro with bonding group connecting to cascaded switch that need to be highlighted?
The Maestro is running Active-Active, but the all the bonding group link is configured with Active-Backup which all active link will at MHO1 while backup link at MHO2 like normal clusterXL deployment. Its quite confusing.
We have tried to configure the bonding group with operating mode 802.3ad but it is totally not workable at all when connected to cascaded switch, unable to ping. Therefore, when we try to change the operating mode to Active-Backup and XOR is able to ping within upstream and downstream.
Maestro Quantum Maestro
Best Regards,
Keon