- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- New! R80.30 feature: Management Data Plane Separat...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
New! R80.30 feature: Management Data Plane Separation (for gateways with 4+ cores)
I really like the all new R80.30 feature for separating management from data traffic via
- Routing Separation and
- Resource Separation
as described in sk138672.
Did anyone test this already?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I am using an Open Server with 8 cores and release R81.10 and it does not activate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @CarlosDias, please open SR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Aviad,
My question is that it makes sense to open a service request.
On sk138672 it refers only Quantum appliances. I am asking this question because on the Open Servers I can see that the commands exist, but maybe they do not work.
If the SK only refers Quantum appliances I am afraid that TAC closes the SR just saying that ...
But I don see any reason for this not be possible on Open Servers ...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @CarlosDias , MDPS is supported on GAiA platform, regardless if the hardware is physical or virtual.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I only need to separate routing.
1. Do I also need to activate resource separation?
2. Can the sync interface be the same as dplane?
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. No
2. The sync needs to be on mplane due to some ports that are opened on management plane
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thanks for you answer.
I have a further question. Although I have separated management plane, I found the the gateways use an interface on dataplane to contact Checkpoint Services in order to check Contract. I am Using R81.10. Is this supposed to be like this?
I would prefer it also used management interface.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The best practice is that dedicated management networks should be isolated (i.e. not connected to the Internet).
As the various Check Point services are hosted on the Internet, it doesn't make sense to use the management interface for this.
This is, therefore, expected behavior.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK Thanks a lot

- « Previous
- Next »