Getting Started
|
Important - This section describes a general workflow. For the specific workflow, see:
|
Workflow:
-
Mount Quantum Maestro Orchestrators
A scalable Network Security System that connects multiple Check Point Security Appliances into a unified system. Synonyms: Orchestrator, Quantum Maestro Orchestrator, Maestro Hyperscale Orchestrator. Acronym: MHO. in their racks.
See:
-
-
Install the applicable Expansion Line Cards (if required) in the appliances.
See the Installing and Removing Line Cards.
Notes:
-
Maestro configuration supports only ports 10 Gbps or faster.
-
Maestro does not support Downlink connections from a 10 Gbps Expansion Line Card and a 25 / 40 / 100 Gbps Expansion Line Card at the same time on the same Security Appliance.
Warning - You must remove all unused Expansion Line Cards (not including 1Gbps) from Security Appliances.
-
-
Mount appliances in their racks.
See the Getting Started Guide for your appliances in sk96246.
-
Power on the appliances.
-
-
Connect the required network cables to Uplink ports
Interfaces on the Quantum Maestro Orchestrator used to connect to external and internal networks. Gaia operating system shows these interfaces in Gaia Portal and in Gaia Clish. SmartConsole shows these interfaces in the corresponding SMO Security Gateway object. on the Quantum Maestro Orchestrators
See "Maestro Orchestrator".:
-
Connect the required network cables from the Downlink ports
Interfaces on the Quantum Maestro Orchestrator used to connect to Check Point Security Appliances. You use DAC cables, Fiber cables (with transceivers), or Breakout cables to connect between the Downlink ports and Security Appliances. The Check Point Management traffic (policy, logs, synchronization, and so on) co-exists with the data (user) traffic on the Downlink ports. Bandwidth is guaranteed for the Check Point Management traffic (portion of the downlink bandwidth). These ports form the system backplane (management, data plane, synchronization). on the Quantum Maestro Orchestrators to Security Appliances:
-
Connect to each Quantum Maestro Orchestrator.
Note - It is important in which order you configure the Orchestrators in a Dual Site environment.
The first Orchestrator you configure becomes the "first" Orchestrator on this Site.
It synchronizes the configuration to the "second" Orchestrator on this Site.
Connecting over SSH
-
Connect the included Ethernet cable from your computer to the MGMT port on the Orchestrator.
See MGMT Ports.
You use this MGMT port only to manage the Orchestrator.
-
On your computer, configure a static IP address (see the documentation for your operating system):
-
IP address - between 192.168.1.2 and 192.168.1.254
-
Subnet mask - 255.255.255.0
-
Default Gateway - empty
-
DNS Servers - empty
-
-
Open an SSH client and connect to this IP address - 192.168.1.1
-
Log in to Gaia Clish on the Orchestrator with these default credentials:
-
Username -
admin
-
Password -
admin
Best Practice - Change the default password.
If the SSH connection is interrupted after the password change, log in again with the new password.
See the Gaia Administration Guide for your version.
-
-
Activate the Orchestrator - enter "
y
" when it asks you.This Orchestrator activation enables the Downlink ports and the Uplink ports.
For more information, see sk171784 - Activation of a Quantum Maestro Orchestrator.
-
Connect the MGMT port of the Orchestrator to your network.
Connecting through the Console port
-
Connect to the Console port. See Console Port.
-
Power on the Orchestrator.
-
In your Terminal application, log in to Gaia Clish with these default credentials:
-
Username -
admin
-
Password -
admin
Best Practice - Change the default password.
See the Gaia Administration Guide for your version.
-
-
Activate the Orchestrator - enter "
y
" when it asks you.This Orchestrator activation enables the Downlink ports and the Uplink ports.
For more information, see sk171784 - Activation of a Quantum Maestro Orchestrator.
-
-
Configure the required IPv4 settings on the MGMT port:
-
Configure the required IPv4 address and Mask Length:
set interface Mgmt1 ipv4-address <IPv4 Address> mask-length <Length>
Example:
set interface Mgmt1 ipv4-address 192.168.10.22 mask-length 24
-
Change the state of the MGMT port to "on":
set interface Mgmt1 state on
-
Configure the required Default Gateway:
set static-route default nexthop gateway address <IPv4 Address> on
Example:
set static-route default nexthop gateway address 192.168.10.1 on
-
Save the configuration:
save config
-
-
Connect the MGMT port of each Quantum Maestro Orchestrator to your network.
-
Connect to each Quantum Maestro Orchestrator through the MGMT port in one of these ways:
-
With a web browser to Gaia Portal on the Orchestrator:
See the Quantum Maestro Quick Start Guide in the shipping carton.
https://<IPv4 Address you configured on the MGMT port>
Example:
https://192.168.10.22
-
With an SSH client to Gaia Clish on the Orchestrator:
<IPv4 Address you configured on the MGMT port>
Example:
192.168.10.22
Use these credentials:
-
Username -
admin
-
Password - the password you configured (the default password is
admin
)
Notes:
-
On Quantum Maestro Orchestrators R80.20SP - R81.20, there is no Gaia First Time Configuration Wizard.
-
You do not need to install a license on Quantum Maestro Orchestrators.
-
-
In Quantum Maestro Orchestrators R82 and higher, run the Gaia First Time Configuration Wizard.
Procedure
-
In the Deployment Options window:
-
In the section Setup, select Continue with <Version> configuration.
Click Next.
-
In the section Environment, select the applicable option:
-
Create a new Maestro environment
Select this option if this is a new Maestro environment without Security Groups.
-
Join an existing Maestro environment
Select this option if you need to add this Maestro Orchestrator to an existing Maestro environment with configured Security Groups.
Click Next.
-
-
-
In the Authentication Details window:
-
Enter the desired administrator password for the Expert mode.
-
Enter the desired administrator password for the Maintenance mode.
Click Next.
-
-
In the Management Connection window:
If needed, configure the IP settings for the Orchestrator Management Port.
Click Next.
-
In the Device Information window:
Configure the required settings:
-
Hostname
-
Domain Name
-
DNS Servers
-
Proxy Server
Click Next.
-
-
In the Date and Time Settings window:
Configure the required settings.
Click Next.
-
In the Orchestrator Configuration window:
-
In the Number of Sites field, select the applicable value.
-
In the Number of Orchestrators on each Site field, select the applicable value.
-
In the Site ID field, select the applicable value.
-
In the Orchestrator ID on Site field, select the applicable value.
-
Click Next.
-
Optional: In the Internal Sync field, select the applicable interface other than the default.
-
Optional: In the External Sync field, select the applicable interface other than the default.
-
Optional: Select Change VLAN configuration, if it is necessary to change the default VLAN IDs used for Orchestrator synchronization. Configure the required VLAN IDs. See sk168092.
-
Click Next.
-
-
In the First Time Configuration Wizard Summary window:
-
Read the information on this page.
-
Click Finish.
-
-
-
On the Orchestrator (in Gaia Portal or Gaia Clish), configure the required Security Groups and configuring their Gaia settings.
Follow the Maestro Administration Guide for your version > Chapter Configuring Security Groups.