Dual Site with two Switches
|
Warning - When you connect the external synchronization ports of Orchestrators See "Maestro Orchestrator". on different Maestro Sites through switches (and not directly to each other), make sure your Layer 2 network between Orchestrators is secured. |
This example is for MHO-140.
Description
-
On each site, two Quantum Maestro Orchestrators A scalable Network Security System that connects multiple Check Point Security Appliances into a unified system. Synonyms: Orchestrator, Quantum Maestro Orchestrator, Maestro Hyperscale Orchestrator. Acronym: MHO. are connected for redundancy:
-
On each site, Port 48 on Quantum Maestro Orchestrators is for the internal synchronization.
-
On each site, Port 47 on Quantum Maestro Orchestrators is for the external synchronization between sites.
This Port 47 on Quantum Maestro Orchestrators connects to the Layer 2 Switch on the site.
(Starting in R81.10, Port 56 is the external synchronization port.)
-
On each site, each Security Appliance has an Expansion Line Card.
Downlink ports Interfaces on the Quantum Maestro Orchestrator used to connect to Check Point Security Appliances. You use DAC cables, Fiber cables (with transceivers), or Breakout cables to connect between the Downlink ports and Security Appliances. The Check Point Management traffic (policy, logs, synchronization, and so on) co-exists with the data (user) traffic on the Downlink ports. Bandwidth is guaranteed for the Check Point Management traffic (portion of the downlink bandwidth). These ports form the system backplane (management, data plane, synchronization). on different Quantum Maestro Orchestrators connect to odd and to even ports on the Expansion Line Card.
-
-
Port 47 on the first Orchestrator on the first site (Orchestrator ID 1_1) connects to the Layer 2 Switch (to Port 1) on the first site.
-
Port 47 on the second Orchestrator on the first site (Orchestrator ID 1_2) connects to the same Layer 2 Switch (to Port 2) on the first site.
-
Port 47 on the first Orchestrator on the second site (Orchestrator ID 2_1) connects to the Layer 2 Switch (to Port 1) on the second site.
-
Port 47 on the second Orchestrator on the second site (Orchestrator ID 2_2) connects to the same Layer 2 Switch (to Port 2) on the second site.
-
The Layer 2 Switch (Port 32) on the first site connects directly to the Layer 2 Switch (to Port 32) on the second site.
Diagram for MHO-140 with R80.20SP
Explanations
Item |
Description |
||
---|---|---|---|
1 |
A port on the Layer 2 switch on the first site (3) that connects to a corresponding port (2) on the Layer 2 switch on the second site (5). |
||
2 |
A port on the Layer 2 switch on the second site (5) that connects to a corresponding port (1) on the Layer 2 switch on the first site (3). |
||
3 |
The Layer 2 switch on the first site. |
||
4 |
Port on the Layer 2 switch on the first site that connects to the dedicated external synchronization port (10) on the first Quantum Maestro Orchestrator (11) on the first site. |
||
5 |
The Layer 2 switch on the second site. |
||
6 |
Port on the Layer 2 switch on the second site that connects to the dedicated external synchronization port (13) on the first Quantum Maestro Orchestrator (14) on the second site. |
||
7 |
Port on the Layer 2 switch on the first site that connects to the dedicated external synchronization port (18) on the second Quantum Maestro Orchestrator (19) on the first site. |
||
8 |
Port on the Layer 2 switch on the second site that connects to the dedicated external synchronization port (21) on the second Quantum Maestro Orchestrator (22) on the second site. |
||
9 |
DAC cables Direct Attach Copper cable. A form of the high-speed shielded twinax copper cable with pluggable transceivers on both ends. Used to connect to network devices (switches, routers, or servers)., Fiber cables (with transceivers), or Breakout cables An optical fiber cable that contains several jacketed simplex optical fibers that are packaged together inside an outer jacket. Synonyms: Fanout cable, Fan-Out cable, Splitter cable. that connect Downlink ports on the first Quantum Maestro Orchestrator (11) on the first site to the Security Appliance (25, 27 and 30) on the first site. These cables connect to the odd port of an Expansion Line Card on Security Appliances. |
||
10 |
The dedicated external synchronization port (Port 47) on the first Quantum Maestro Orchestrator (11) on the first site. This port connects with a DAC cable or Fiber cable (with transceivers) to the Layer 2 switch (3 to port 4) on the first site. |
||
11 |
The first Quantum Maestro Orchestrator on the first site. |
||
12 |
DAC cables, Fiber cables (with transceivers), or Breakout cables that connect Downlink ports on the first Quantum Maestro Orchestrator (14) on the second site to the Security Appliance (26, 29 and 31) on the second site. These cables connect to the odd port of an Expansion Line Card on Security Appliances. |
||
13 |
The dedicated external synchronization port (Port 47) on the first Quantum Maestro Orchestrator (14) on the second site. This port connects with a DAC cable or Fiber cable (with transceivers) to the Layer 2 switch (5 to port 6) on the first site. |
||
14 |
The first Quantum Maestro Orchestrator on the second site. |
||
15 |
The dedicated internal synchronization port (Port 48) on the first Quantum Maestro Orchestrator (11) on the first site. This port connects with a DAC cable to the dedicated internal synchronization port (23) on the second Quantum Maestro Orchestrator (19) on the first site.
|
||
16 |
The dedicated internal synchronization port (Port 48) on the first Quantum Maestro Orchestrator (14) on the second site. This port connects with a DAC cable to the dedicated internal synchronization port (24) on the second Quantum Maestro Orchestrator (22) on the second site.
|
||
17 |
DAC cables, Fiber cables (with transceivers), or Breakout cables that connect Downlink ports on the second Quantum Maestro Orchestrator (19) on the first site to the Security Appliance (25, 27 and 30) on the first site. These cables connect to the even port of an Expansion Line Card on Security Appliances. |
||
18 |
The dedicated external synchronization port (Port 47) on the second Quantum Maestro Orchestrator (19) on the first site. This port connects with a DAC cable or Fiber cable (with transceivers) to the Layer 2 switch (3 to port 7) on the first site. |
||
19 |
The second Quantum Maestro Orchestrator on the first site. |
||
20 |
DAC cables, Fiber cables (with transceivers), or Breakout cables that connect Downlink ports on the second Quantum Maestro Orchestrator (22) on the second site to the Security Appliance (26, 29 and 31) on the second site. These cables connect to the even port of an Expansion Line Card on Security Appliances. |
||
21 |
The dedicated external synchronization port (Port 47) on the second Quantum Maestro Orchestrator (14) on the second site. This port connects with a DAC cable or Fiber cable (with transceivers) to the Layer 2 switch (5 to port 8) on the second site. |
||
22 |
The second Quantum Maestro Orchestrator on the second site. |
||
23 |
The dedicated internal synchronization port (Port 48) on the second Quantum Maestro Orchestrator (19) on the first site. This port connects with a DAC cable to the dedicated internal synchronization port (15) on the first Quantum Maestro Orchestrator (11) on the first site.
|
||
24 |
The dedicated internal synchronization port (Port 48) on the second Quantum Maestro Orchestrator (22) on the second site. This port connects with a DAC cable to the dedicated internal synchronization port (16) on the first Quantum Maestro Orchestrator (14) on the first site.
|
||
25 |
Security Appliance 1 on the first site - member of the Security Group (28). |
||
26 |
Security Appliance 1 on the second site - member of the Security Group (28). |
||
27 |
Security Appliance 2 on the first site - member of the Security Group (28). |
||
28 |
Security Group that contains Security Appliances from both sites (25, 26, 27, 29, 30 and 31). |
||
29 |
Security Appliance 2 on the second site - member of the Security Group (28). |
||
30 |
Security Appliance 3 on the first site - member of the Security Group (28). |
||
31 |
Security Appliance 3 on the second site - member of the Security Group (28). |
Configuration of the synchronization ports:
-
Layer 2 switches must support VLAN Q-in-Q Tunneling (encapsulation of 802.1Q VLAN inside 802.1Q VLAN).
You must configure VLAN Trunks and Q-in-Q exactly as described below:
Site
Switch Port
Port Configuration 1
and
2
SW 1
and
SW 2
1
VLAN Trunk that accepts these VLAN IDs:
-
3600* (used for a site internal synchronization)
-
3951 (used for external synchronization)
1
and
2
SW 1
and
SW 2
2
VLAN Trunk that accepts these VLAN IDs:
-
3601* (used for a site internal synchronization)
-
3952 (used for external synchronization)
1
and
2
SW 1
and
SW 2
32
VLAN Trunk that accepts these VLAN IDs:
-
3600* (used for a site internal synchronization)
-
3601* (used for a site internal synchronization)
-
3951 (used for external synchronization)
-
3952 (used for external synchronization)
Important:
-
VLAN ID 3951 and VLAN ID 3952:
-
Starting from the version R81.10, it is possible to change the default VLAN IDs with this command:
set maestro configuration orchestrators base-vlan <VLAN ID 1> <VLAN ID 2> ... <VLAN ID N>
-
In the version R80.20SP, it is not possible to change these VLAN IDs.
-
-
*The default Site Sync VLAN IDs are:
-
3600 on Orchestrator ID 1_1 and Orchestrator ID 2_1
-
3601 on Orchestrator ID 1_2 and Orchestrator ID 2_2
If these default Site Sync VLAN IDs conflict with the existing VLAN IDs in your environment, then it is possible to change the Base Site Sync VLAN IDs on Quantum Maestro Orchestrators.
-
-
-
Latency between the Layer 2 switches on different sites must be lower than 100ms.
-
Packet lost between the Layer 2 switches on different sites must be lower than 5%.
This procedure explains how to configure a new Security Group that contains Security Appliances from two sites in a new Dual Site configuration.
|
Important - Make sure to read the existing Known Limitations for Dual Site in sk148074. |
|
Warning - This procedure interrupts the traffic. Schedule a maintenance window. |
Step | Instructions | ||||||||
---|---|---|---|---|---|---|---|---|---|
1 |
On each site, install the Quantum Maestro Orchestrators in their racks. Follow the applicable instructions: |
||||||||
2 |
On each site, connect the cables between:
Follow: |
||||||||
3 |
On each site, connect fiber cables (with transceivers) or DAC cables between the dedicated external synchronization ports on the Quantum Maestro Orchestrator and the ports on the Layer 2 switch.
It is possible to use any port for external synchronization, except these ports:
|
||||||||
4 |
Use an SSH Client or a Serial Console to connect to the command line on each Quantum Maestro Orchestrator on each site. |
||||||||
5 |
On each site, configure the dedicated ports for the external synchronization on the Quantum Maestro Orchestrators.
|
||||||||
6 |
On each site, configure the total number of Sites on each Quantum Maestro Orchestrator. Procedure
Run this command in Gaia Clish:
For information about this Gaia Clish command, see the Maestro Administration Guide for your version > Chapter Configuring Security Groups > Section Configuration Procedure > Section Configuring Security Groups in Gaia Clish > Section Configuring the Number of Maestro Sites. |
||||||||
7 |
Configure the Site ID on each Quantum Maestro Orchestrator. Configuring the Site ID on the first site
Configuring the Site ID on the second site
|
||||||||
8 |
Optional: Configure a new Base Site Sync VLAN ID on each Quantum Maestro Orchestrator. This step applies if the default Site Sync VLAN IDs 3600 and 3601 conflict with the existing VLAN IDs in your environment. For information about the Base Site Sync VLAN ID, see the Maestro Administration Guide for your version > Chapter Configuring Security Groups > Section Configuration Procedure > Section Configuring Security Groups in Gaia Clish > Section Configuring the Base Site Sync VLAN ID in Dual Site Deployment. Explanation
The default Site Sync VLAN IDs are:
If you configure a new Base Site Sync VLAN ID, then Quantum Maestro Orchestrators assign the new Site Sync VLAN IDs in this way:
Example: If you configure the Base Site Sync VLAN ID 4800 on all Quantum Maestro Orchestrators, then
Procedure
|
||||||||
9 |
Follow these configuration steps:
See the Maestro Administration Guide for your version > Chapter Configuring Security Groups. |
||||||||
|
|
||||||||
|
|
||||||||
|
|