- CheckMates
- :
- Products
- :
- Quantum
- :
- Maestro Masters
- :
- Maestro basic setup documentation
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Maestro basic setup documentation
Hey guys,
I've been playing around with some Maestro units and a number of gateways. I have been running into a number of problems that caused me to document all the actions that I needed to do for a specific type of installation, the document is about 3 different scenario's:
- Single site dual Maestro
- Dual site single Maestro
- Dual Site dual Maestro
Please check out the document and let me know what you think about it, also if you see things that you don't understand or know that should be different, please let me know.
Updated the document to v1.0, 16 dec 2019.
Updated the document to v1.2, 26 Feb. 2020. Added bonding.
Updated the document to v1.3, 03 Mar. 2020. updated some parts and added commands.
Updated the document to v1.5, 17 Mar. 2020. updated some parts and added commands after training.
Updated the document to v1.6, 25 May 2020. Update regarding HA licenses
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
More important would be to try and get a serial console (out of band) connection so yuou can see what is going on when you loose your management connection.
You would be making it more complicated than needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For single site dual Maestro setup, you only need 1 Sync, for dual site single Maestro you need a Remote Sync, for dual site dual Maestro you need a local Sync and a Remote Sync.
If this is not clear from my doc I will need to update that part.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Maarten,
I would also suggest to use a right terminology in your documentation and discussions. It will avoid any confusions.
There's no such device called "Maestro". Maestro is the complex of products.
What you meant is the MHO = Maestro Hyperscale Orchestrator, or Orchestrator.
Thank you,
Anatoly
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am reworking the doc as I am reinstalling a dual site single MHO site again and in the process looking at the document to remove the errors. I will update the doc with this info.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Updated the document yesterday after using it to setup a dual site single MHO setup.
@shay_solomon I will be double checking for the differences compared to the official documentation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Tnx for a great document!:)
I got two Orchestrators, this is what I assume is called a MHO ? So one Orchestrator=1 MHO ? And x numbers of orchestrators together with some appliances/gateways make up a Maestro solution ? - Its like Check Point wants to make it hard.. they are big fans of giving stuff name and then never ever use those names in any of the technical components.. they seem to mix up their concepts with tech solutions.
Anyways -
I have two orchestrators, and I have connected them with sync on the correct port (I got 140's). Then I have attached 4 appliances - two cabels from each appliance to each MHO. I power this up and there is absolutley nothing showing in my Gaia portal.. the only interfaces I see are my two mgmt interfaces. No gateways and no nothing... is there something globally I need to configure to get started ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MHO = Maestro Hyperscale Orchestrator
SGM = Security Gateway Module
Maestro is a solution consisting of any combination of MHO (currently max 4) and SGM (currently max total 104)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also, I am confused as to if there are any clish command that need to be run. To state what kin of setup I am running..two site.singe site. redundancy.etc etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Some minor updates just for your info.
When you use 1Gb UTP SFP's in a MHO140, just for the management of the Security groups for instance, they will not work with R80.20SP JHF 178, they do work with 191 and higher.
HA Licenses: When you move a existing cluster into a Maestro configuration you might get problems when you're creating the gateway while pushing a policy. This happens with R80.30 when you are using a SmartConsole build lower than 42. For R80.20 I don't know, was not able to test it. R80.40 GA works just fine.
I also uploaded version 1.1 of the document that mentions these limitations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great, tnx - that s a nice document to have indeed.
I am still struggeling with not seeing any gateways or interfaces, I have had the guys re-checking this several times and they say it should be fine.
There is no basic setup I am missing ? Do I need to put a lic on the orchestrators? - as far as I can see only the appliances should need lic's.
When i go into the gaia portal of either of the orchestrators I just get this:
Failed to load Security Groups:
Failed to get remote Orchestrator interfaces.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it is only one (or one per site), then you should set orchestrator amount accordingly:
clish> set maestro configuration orchestrator-amount 1
If you have two (or two per site), are you seeing the second orchestrator on CLI (expert mode) using lldpctl.
lldpctl also should show the connected gateways!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From the bottom of page 1:
Before you continue execute this command from the MHO clish:
'set maestro configuration orchestrator-amount 1'
Otherwise it just will not work the default value is 2.
The orchestrator itself does not require a license but the gateways do, based on the IP 192.0.2.x
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currentley my orchestrator-amount is set to 2 (the default)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 orchestrators, 4 appliances (140 and 6500's)
Only 1 of the appliances are turned on.
I have this set up as a single site, but the solution is installed in two different rooms. So I have a mix of fiber and dacs - all cabeling should be ok... But I am unsure now..
Running lldctl on both orchestrators.:
orch1: showing a 6500 appliance - nothing else.
orch2: shows nothing
So, I assume this is an issue related to the sync cable between the orchestrators.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
naming-sample: orch<site>-<id>
orch1-1 port 48 to orch1-2 port 48
orch2-1 port 48 to orch2-2 port 48
orch1-1 port 47 to orch2-1 port 47 (has to be configured for site_sync after JHF>= 163)
orch1-2 port 47 to orch2-2 port 47 (has to be configured for site_sync after JHF>= 163)
6500 appliance eth1-01 to orch1-1
6500 appliance eth1-02 to orch1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
set maestro configuration orchestrator-amount 1
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
please post output of # lldpctl of both orchestrators on primary site
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In any case, can you provide descriptions which cable to which appliance is connected to which port.
So is Appliance-1 in room A conntected to same orchestrator port in both rooms and are only eth1-01 and eth1-02 used for this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The other one just shows one appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Only use port 47 and follow the setup guide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would consider this a single site setup - but as a stretched. The hardware is just a few meters apart, so the only real differnece as far as I can see it is that I do not use DAC all the way,.
Talking to checkpoint, when ordering sfp's and dac's - they said this setup should be fine.
I am a bit usure about port 48 vs. port 47. As of now I am using the 48 port.
For the cabeling of the appliances, I have made sure the same ports are used for all appliances and all the cross connects. So all use same ports on both orchs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now in expert type: orchd restart
When finished open the WebUI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had the guys do a triple check of cabeling, and now it looks better.
Using lldpctl I get neighbors from both appliances and maestro.
The two maestros are connected on p48, that port is in sync state. But I still dont get any infercaes or anything else in Gaia. But I have requested a reboot - lets see 🙂
Update-> yeah, now all is good ! 🙂 Thanx for the help guys!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Guys,
Regarding the ports 47 and 48. Port 48 is the default sync-port between the orchestrators on the same site. 47 is the recommended site-sync port between the sites. However, you have to define the port 47 as the site-sync in orchestrator with the command:
set maestro port 1/47/1 type site_sync
