Hi,
I have a few comments and corrections here:
1. Console connection are needed to ALL devices - nice to have, but not must. You can "jump" in between devices using CIN network 198.51.0.0 (or using m command)
2. You also need a 10Gb switch for connecting all Mgmt ports - I guess here we're talking about MHO-140. MHO-140 supports 1Gbps transceivers as well (copper and fiber), so it's not necessary to use 10Gbps switch. With MHO-170 you can use 40Gbps, 100Gbps or 4x10Gbps as well
3. I would not say that the best practice is to use single orchestrator, and then to join second one (actually to move to dual orchestrator environment). If you need dual orchestrator - do it from the beginning, including proper cabling
4. I would not mention take number of JHF. Today it is 178, tomorrow it will be something else. You can mention just GA version of JHF
5. Upgrade to JHF on MHO from WebUI would be much more easier. Not clear why should we do it from command line. However, JHF installation on Security Group is not supported via WebUI, hence we have to do it via gclish
6. Dual site - I'm not sure, the best practice is to glue two separate single-site setups. If you have security groups on both sites before you connect them, one of them will be overwritten.
Please feel free to contact me offline at anatoly@checkpoint.com and I will be happy help you with finalizing this documentation.