- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Q&A and slides are below.
It is not included in R81 and R81.10. We will add it to R81.20. The best place to check for Maestro feature parity with main train is sk173183.
It's already there for R81.10 as part of the admin guide and we will include the specific steps for MVC upgrade.
This is on the road map for the future, not sure on the exact release but it is planned.
It will operate similar to regular ClusterXL and will depend on traffic load. That means there can be a drop of connections that weren't synced (due to short connection for example) or protocols that do not survive fail-overs. Ping loss should be very low to none (usually none - depends on ping rate of course).
Since R81 JHF 34, and in R81.10 GA, you have these extra features as described in sk174228.
Support for GNAT will be added in R81.20, which will improve things substantially.
Maestro Fastforward (available in R81.20) will significantly improve throughput and latency for trusted connections:
R81.20 will include this support.
Yes, will be a firewall only log. The first packet of a connection will be passed to the gateway for logging purposes.
Hyperflow is a different feature geared toward handling Elephant Flows. It will be integrated with Maestro when it is ready. Fastforward is not focused on Deep Packet Inspection and is intended for trusted connections. Both features will co-exist.
Not currently, but it is on the roadmap.
In general, stateless. The only exception is the initial SYN packet being passed thru to the gateway.
You can use REST APIs with the management server and create rules/install policy.
The only packet you would see on the Security Gateway would be the initial SYN packet. The correct place to monitor these connections would be on the MHO, and we are currently evaluating what tools will be available for monitoring there.
No need, the gateway will take care of this.
Once on R81.10, the upgrade process is smoother, and with R81.20 it will be much better with MVC upgrade. Upgrades from SmartConsole are on the roadmap to align with main train.
Skyline support is coming shortly.
QinQ is not required as of R81.10.
Expected as part of R81.30.
It's in the roadmap, yes.
We have better (per appliance) SNMP monitoring coming, which is currently available in a private fix for R81.10 T45. There are also enhancements for R81.20 and later planned (around SNMP). Also enhancements for monitoring through the Skyline project
Check Point Professional Services can assist with this task.
graceful-restart feature is an industry standard and Maestro supports it for both OSPF and BGP. That way you don't lose routes. graceful-restart must be supported by the peer and timers need to be in sync. The routes will stay while peering is built up after failover.
They can coexist. Fast forwarding provides ultra-low latency for trusted connections and UDP packets. LightSpeed (MLS) is to have low latency and high throughput with stateful inspection.
We are working to address it with Lightspeed technology, which will also be supported with Maestro.
Get CCSA and CCSE first, then certify for CCME.
Currently planned for Q3 2022.
For troubleshooting traffic we support tcpdump, fw monitor and cppcap. You can also use asg search to find out the blade the traffic is hitting and run your monitoring there. The same debugs are supported in Maestro as in other appliances.
The 44000 and 64000 chassis went End of Sale in January 2022 per the Support Life Cycle Policy. Maestro is recommended for new deployments were Scalable Platform chassis were used previously.
R81.30 is the expected release that will support this.
Yes, this is planned for R81.30.
Already assigned resource won't be taken away. Free resources (scale-up nodes) can be used.
No, but there is a planned solution for Scalable Platform without MHO for lower scale deployments.
If you have lots of corrections, you likely have problems with your distribution. So, you "correct", because the traffic is being sent to the "wrong" (different) devices for example in either direction. So, it's probably worth looking into that area, to find out your heaviest flows, and then use the tools like "dxl calc" to confirm if you are handling traffic on different units (and therefore a change to distribution (mode, or the setting for the interface) is needed.
R81.20 should provide this ability. R81.10 can also be an option (not by default) - if needed support can be approached
Mix and match is supported with appliance models with similar specs. Not every appliance combination is supported. If you have a specific need, please approach your local Check Point office.
Thank you for posting this. Does the Fastforward feature get configured in the CLI or in SmartConsole. I did see they said it was configured in the access policy, but it would be great to tag access rules in SmartConsole.
Q&A and slides are below.
It is not included in R81 and R81.10. We will add it to R81.20. The best place to check for Maestro feature parity with main train is sk173183.
It's already there for R81.10 as part of the admin guide and we will include the specific steps for MVC upgrade.
This is on the road map for the future, not sure on the exact release but it is planned.
It will operate similar to regular ClusterXL and will depend on traffic load. That means there can be a drop of connections that weren't synced (due to short connection for example) or protocols that do not survive fail-overs. Ping loss should be very low to none (usually none - depends on ping rate of cours
...Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY