- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Been trying to find this in the documentation but there is very little to find on this.
Single site is easy, but how to go about a dual site? I have 2 interfaces on site 1 and 2 interfaces on site 2, now I need to create a VSX environment, do I create a cluster (a security group per site) or a single gateway? If a single gateway do I add all 4 interfaces to the same bond? In LACP (VPC) Mode would that work?
There is nothing in the R80.20SP VSX admin guide, nor in the R80.20SP admin guide, in the Maestro R80.20SP Getting Started Guide there is some information on the usage of Bond interfaces for Uplinks but it is only very basic and it refers to the Maestro Gaia R80.20SP Administration Guide which also does not take the Dual site setup's into account.
Another issue regarding dual MHO is that you need to setup Management Bond, which is also missing in the Maestro R80.20SP Getting Started Guide, which should be part of the Configuring Gaia Settings of a Security Group.
Sevral manuals are just copies of the R80.20 manulas and have parts that are adjusted but i.e. the VSX manual still does not tell you how VSLS works in the Maestro setup in a dual site configuration.
Looking into it and will post back
Thanks for reporting Maarten
-Uri
Hi,
Dual site is defined per Security Group. If Security Group is defined to be dual-sited, it will include SGMs from both sites, but it will be still the same security groups.
Regarding bonds, these must to be identical on both sites.
As Security Group configuration performed as a single GW, and you configure Bond1 = eth1-05 and eth2-05, for example, these ports must to be connected to switches the same on both sites.
Thank you,
Anatoly
These are not 4 ports, these are just two. As security group works as a single GW, it does not differ between sites.
eth1-05 and eth2-05 represent same ports on both sites.
From the physical perspective, both switches will have different port channels, but located under the same vlan (s)
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
5 | |
4 | |
4 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY