Configuring VLAN Interfaces on Uplink Ports

Introduction

Starting in the R81.10 release for Quantum Maestro Orchestrators, Check Point integrated a major enhancement for the configuration of VLAN interfaces on the Uplink portsClosed Interfaces on the Quantum Maestro Orchestrator used to connect to external and internal networks. Gaia operating system shows these interfaces in Gaia Portal and in Gaia Clish. SmartConsole shows these interfaces in the corresponding SMO Security Gateway object. of a Quantum Maestro OrchestratorClosed A scalable Network Security System that connects multiple Check Point Security Appliances into a unified system. Synonyms: Orchestrator, Quantum Maestro Orchestrator, Maestro Hyperscale Orchestrator. Acronym: MHO.:

Viewing VLAN Interfaces on Uplink Ports in Gaia Portal

Step

Instructions

1

On the Orchestrator page, in the Topology section, expand Security Groups.

2

Expand your Security Group.

3

Expand Interfaces.

4

Put the mouse cursor on an interface.

VLAN information appears in the tooltip.

Note - If this is a Dual Site deployment, and the Security Group contains Security Appliances that are located only at one of the sites (for example, Site 2), then the tooltip that shows VLAN interfaces appears only in Gaia Portal of the Orchestrator (for example, on Site 2) that is located at the same site as Security Appliances.

Viewing VLAN Interfaces on Uplink Ports in Gaia Clish

Syntax

show maestro security-group id <Security Group ID>

Parameters

Parameter

Description

id <Security Group ID>

Specifies the ID of the Security Group.

To see the existing IDs, press the Tab key.

Configuring More Than 4000 VLAN Interfaces on Orchestrators

If it is necessary to configure more than ~4000 VLAN interfaces on the Orchestrator, we recommend that you configure the physical interface on the Orchestrator as a VLAN trunk interface that allows all untagged and all tagged packet to be forwarded to the Security Group. This makes it possible for an internal automatic optimization to occur.

For a VLAN trunk interface to forward all tagged and all untagged packets, these conditions must be met:

  • VLAN Trunk mode must be enabled (see the instructions before how to enable the VLAN Trunk mode).

  • The distribution mode of all the VLAN interfaces on a specific physical interface must be the same (because this VLAN optimization occurs for each Orchestrator port).

To enable the VLAN Trunk mode:

Warnings:

  • Do this procedure during a maintenance window.

    No traffic flows through Security Groups while the 'orchd' process restarts.

  • All Orchestrators on your sites must run the same software version.

Step

Instructions

1

Connect to the command line on one of the Orchestrators.

2

Log in to Gaia Clish.

3

Enable the VLAN Trunk mode:

set maestro configuration uplink-trunk-mode state enabled

4

Examine the status of the VLAN Trunk mode:

show maestro configuration uplink-trunk-mode state

5

Restart the Maestro daemon:

  1. Connect to the command line on each Orchestrator on your sites.

  2. Log in to the Expert mode.

  3. Restart the 'orchd' process:

    orchd restart