- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Dear Checkmates,
i have a question regarding Management Interfaces.
Would you recommend to use dedicated Mgmt Interfaces for the Secure Internal Communication
( for logging, policy installation) and mgmt traffic ( https - Gaia Portal ,ssh ) or better keep it simple
and use the LAN (internal) interface for transit and management traffic ?
thanks in advance
Stephan
Dedicated Management Interface is a good thing I think but it is only usefull with MDPS enabled so you have your own routing domain.
Unfortunately this feature is very buggy and many limitations. You have issues with upgrades because you have to disable MDPS before this, sometimes services run not through MDPS like Identity Awareness.
Other big issue is that you can not use "get topology" from SmartConsole because it only fetches the mplane interfaces and not the relevant dataplane interfaces.
Either works, but I dont see lots of people using Mgmt interface for that, mostly LAN interface.
Thanks you for your assessment.
Stephan
Either works but just note that it is a single (common) routing domain unless you implement MDPS or VSX.
Hi Chris,
thanks for your reply.
Yes, i ran into many issues , because of the missing dedicated VRF for the mgmt interface.
And MDPS seems to have man issues and limitations.
So i am going to use the LAN interface for all traffic.
Thanks
Stephan
Dedicated Management Interface is a good thing I think but it is only usefull with MDPS enabled so you have your own routing domain.
Unfortunately this feature is very buggy and many limitations. You have issues with upgrades because you have to disable MDPS before this, sometimes services run not through MDPS like Identity Awareness.
Other big issue is that you can not use "get topology" from SmartConsole because it only fetches the mplane interfaces and not the relevant dataplane interfaces.
Hi Alexander,
thanks for your very informative reply!
Stephan
As the other have said Checkpoint does have a software-based solution which is not commonly used due to the limitations.
I totally believe the control/management-plane traffic should be separated out from data-plane traffic, and it would be useful if checkpoint actually consider this for the next generation of hardware so that the control/management-plane traffic is truley separated without the need for software configuration.
I've mentioned in a few posts now that I personally feel that the hardware Checkpoint utilises is behind the times and they need a solution which truly has the ability to run all blades including https inspect from the bottom up rather than the current range which in reality would be high end devices which is not best fit for regional office from a pricing point of view.
This is somewhat of a challenge for Checkpoint considering they are software-based company, yes lightspeed card has been released and this mostly likely works well in high-end devices, but this does not address low/medium end deployments which most companies have.
I totally agree .
I am using 6200 appliances in this case.
Even most low cost switches does have a real management interface.
In case you aren’t aware, every firewall license includes the ability to run one VS. This is so you can have a management VRF (VS0) and a traffic VRF. VSX requires a separate management server (can’t be run as a standalone deployment), but it sounds like you already have that.
If you think you might want to deploy VSX to separate management routing from through-traffic routing, ask around here for advice from people who have run it for a while. I highly recommend only ever telling VSX about bonds, and never giving it physical interfaces. Bonds can have one member.
The interface named Mgmt is not special in any way beyond having a funny name.
Go for such complex stuff as VSX for doing something so elegant , simple and useful -and implemented by every normal network company is nonsense
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
12 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
3 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY