- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Mates,
I am looking for advice regarding topology and setup.
Currently the customer has one environment with FW where is FW connected only with one bond interface with many VLANs. Those VLANs are used by different customers for their networks like Internal, External etc.
They want to have the same setup with VSX where only one interface is and its Bond. Every VLAN is totally different subnet and is assigned directly to VS. This customer VLAN should be terminated on VS as Bond5.10 IP X.X.X.X.
I am not sure if this is possible to configure it like this as I have only a little experience with VSX design. To make it more complex, the HW is maestro.
I also find that Virtual Router is not supported. sk148074
| 01413513 | All | Virtual Routers are not supported. |
So there can be only Virtual switch but I dont know how to fit in this design. Or do we need it at all? Can it work without?
I am attaching the topology and my question is if this setup is possible and supported or advice how to configure it. Thx
You only need a switch context if you want multiple VSs to talk on the same VLAN on the same interface (either physical or bond). In your topology, I don't see the same VLAN being used in two places, so you don't need a switch context.
ok, I also think that Switch is not fitting in the design. Then there is no problem with only one physical interface(with multiple VLANs) for incoming and outgoing traffic as on the topology?
I would recommend using a separate physical interface for managing the VSX box.
If it's meant to be a cluster, you should also use a separate physical interface for sync. Sync should always be run through a switch, not over a simple cable connected directly between the units.
There's definitely no problem with using only one physical interface or only one bond for all VS traffic, though. Just keep in mind that tightly couples your firewall member failure domain with your switch/router failure domain.
Its maestro, there is separate Mgmt connections and its one member from SC console view, one security group.
I hear this first time, could you explain, please?
"Sync should always be run through a switch, not over a simple cable connected directly between the units."
For ClusterXL different topologies for the Sync network have pros and cons.
In the context of Maestro please refer:
sk168092: Maestro Dual Site configuration using a direct connection and via L2 switches
Further to Bob's comments some of these recommendations are enforced by your hardware choice being Maestro since the corresponding ports are on the orchestrators.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY