- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: MDPS - sk138672
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MDPS - sk138672
Hey boys and girls,
Just wanted to post this to see if anyone had any experience with it so far and what feedback is. I recall this concept from Palo Alto few years back, but had not seen it on CP side as of yet.
https://support.checkpoint.com/results/sk/sk138672
If anyone has any feedback to share, please be free.
Best,
Andy
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have multiple customers using MDPS. It helps in case the system runs a high CPU, for example. What's the question?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Routing & Resource separation would be the usual reasons for turning to MDPS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Basic / simplified examples:
- Preventing traffic processing consuming all resources of the system resulting in poor management responsiveness
- Allow separate default routes for the isolated management network versus production
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have multiple customers using MDPS. It helps in case the system runs a high CPU, for example. What's the question?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for answering Val, appreciated. I did not have really specific question about it, more just to get feedback, though I guess one question I have would be what might be biggest advantage of using this method compared to not using it?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Routing & Resource separation would be the usual reasons for turning to MDPS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Chris,
Is there good example of that? I mean in a sense of how it would help with routing and resource separation?
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Basic / simplified examples:
- Preventing traffic processing consuming all resources of the system resulting in poor management responsiveness
- Allow separate default routes for the isolated management network versus production
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Awesome, thanks guys, that helps.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
One more question @Chris_Atkinson
I assume this cant be configured via web UI based on the sk...correct? Appears only via clish?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CLI only correct, similar to VSX.
Well perhaps that's too much of a generalisation but it's listed in the limitations in any case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks mate, always greateful for your help.
Have a nice weekend.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will this limitation be fixed in the future?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What limitation @Jarvis_Lin ?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
setting from command, not from Gaia GUI.
It’s no problem for engineers setting from command, but it’s a big challenge for customers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
O that, right. I really could not say, maybe best to submit RFE, I suppose.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Btw, I checked the sk again and dont see anything about it there either, so as I mentioned, I would submit RFE about it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Rock,
My English is not good, I checked the sk,
I was referring to the limitations of PMTR-81746, Security groups are not supported for Gaia Portal when MDPS is enabled.
It's hard for customers. If they need to set VLAN or routing.etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, now I got it, sorry. Yes, I can imagine that would be somewhat inconvenient, for sure. I would still submit RFE or maybe comment on the sk or if you can, also message your local SE to see if they can push that further within Check Point internally.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you click below, it would ask you to submit a feedback and you would get an email about it from skhelp@checkpoint.com
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I mispelled this, but you get an idea, see below, my feedback, exactly what you said essentially.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, you're such a kind person.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks man for the kind words. Im just trying to help fellow CP brothers and sisters, thats all 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Btw, I got an email again from sk team indicating the sk will be updated once the limitation is fixed. No time frame on it though.
Andy
