- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi. Just decided to share our typical Maestro project. Here you can see the topology. I hope it will help someone to create their own project or just for better understanding how Maestro works.
L1 scheme:
L2 shceme:
L3 scheme:
If you have any question feel free to ask.
Hi Evgeniy,
thank you for sharing your topology design and the outstanding diagrams!
In this topology is the Maestro being used to inspect east-west traffic (between local vlans) in addition to north-south traffic (to/from internet)? - or is it used only for north-south traffic inspection ?
If the Maestro is used to inspect east-west traffic, are the local vlans gateways on the core-switch or are they (moved) onto the Maestro (security appliances) ?
Cheers,
Sherif
I must have missed this when it was originally posted. Very interesting!
Is the sync between the Maestro boxes directly connected? I know with firewalls this is a very bad idea. Firewall sync should go through a switch to avoid problems when rebooting one of the members (when they're directly connected and you reboot member A, member B sees its interface go down, and has to go into contention to see if its peer failed or it failed; a failure in contention can cause B to refuse to take over). How do the Maestro boxes handle that?
Hi Evgeniy,
Nice diagram. Relatively easy to understand and interpret your diagram. Could you please share what tools you are using to draw this network diagram?
Regards,
Darren
Hi Evgeniy,
I have used this topology with VSX, and I have issues with connection between security group (SG) with VSX. I have config one VSX for management zone (include SG management and others management devices), and all devices have default gateway is IP of VSX. All devices on management zone could ping and connect but only IP of SG couldn't ping or connect to IP of VSX. I have show arp on SG and see mac address of VSX but on I don't see mac address of SG on VSX.
@Outis, this is a very old post. I suggest you to open a new discussion and ask community for help
Hi. Just decided to share our typical Maestro project. Here you can see the topology. I hope it will help someone to create their own project or just for better understanding how Maestro works.
L1 scheme:
L2 shceme:
L3 scheme:
If you have any question feel free to ask.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY