Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Degree
Participant

Maestro Single site Dual Maestro Status command

I'm trying to monitor the status of MHO for the failover scenario. I'm looking for a command like cphaprob stat to view the status however I didn't see any of it. It would be great if anyone has use a script for maestro monitoring.

 

Regards,

 

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

sk174202 provides commands such as the below that may help:

  • orch_stat
  • asg_if
CCSM R77/R80/ELITE
0 Kudos
Timothy_Hall
Legend Legend
Legend

The best you will be able to do is run orch_stat and look at the "MHO Sync LAGs Status" section of the output, but that only reflects whether the two MHOs can see each other over the sync interface for purposes of keeping their configs sync'ed with each other when a config change is made on peer MHO.  That's it.

There is no equivalent of cphaprob state available for the MHOs because they are not really clustering with each other like ClusterXL gateways do.  The "failover" of the traffic is not directly coordinated by the Orchestrators themselves, but by the bonding protocols such as LACP in use by the MHOs and surrounding network components. 

If one of the MHOs completely fails or an uplink/downlink interface is de-provisioned from a Security Group, link integrity (green light) is immediately dropped on that interface and the uplink device sees that interface of the bond has failed.  All traffic is sent to the surviving interface of the bond which leads to the MHO that is still working.  The same process happens with the downlink interfaces to the security gateways when an MHO or interface fails.  When an MHO boots up, link integrity is not restored on the uplinks/downlinks until the MHO has fully initialized, all Security Groups have been provisioned, and are ready to handle traffic.

The MHOs are not even directly coordinating who will take which traffic, tracking connection state, performing IP routing, or even trying to keep the overall load balanced between them.  Once again the bonding protocol's distribution algorithm (hopefully 802.3ad with Layer 3+4) on the MHOs and devices connected via uplink/downlinks are handling that.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos