
Check Point started 2019 with a bang, making several announcements right off the bat. It's not possible to cover everything in one article, so let's begin with the most important aspects — . Maestro is a new scalable platform that allows you to increase the "capacity" of the security gateway to "astronomical" numbers in a nearly linear fashion. This is naturally achieved by load balancing among individual gateways working in a cluster as a single entity. Someone might say — "It existed! The blade platforms 44000/64000 are already here". However, Maestro is a completely different matter. In this article, I will briefly explain what it is, how it works, and how this technology will help save on perimeter network protection.
Then — Now
The easiest way to understand how the new scalable platform differs from the old reliable 44000/64000 is to look at the picture below:

The difference is obvious.
Old platform Check Point 44000/64000
As seen in the image above, the first option is a fixed platform (chassis) into which a limited number of special "module blades" can be inserted (Check Point SGM). All of this connects to Security Switch Module (SSM), which manages traffic balancing between gateways. The image below provides a more detailed view of the components of this platform:

This is a great platform if you know exactly what performance you need now and how much it can grow. However, due to the fixed form factor (12 or 6 blades), you are limited in further scaling. Moreover, you are forced to use only SGM blades, without the opportunity to connect regular uplinks that have a much wider model range. With the advent of Maestro Hyperscale Network Security , the situation changes dramatically.
The new Check Point Maestro Hyperscale Network Security platform
Check Point Maestro was first introduced on January 22 at the CPX conference in Bangkok. The main features can be seen in the image below:

As you may notice, the main advantage of Check Point Maestro is the ability to use standard gateways (appliance) for load balancing. This means we are no longer limited to SGM blades. We can distribute the load across any devices starting from the 5600 model (SMB models and Chassis 44000/64000 are not supported). The image above shows the main performance metrics that can be achieved using the new platform. We can combine them into a single computing resource. up to 31! gateways. Now your “firewall” could look like this:

Maestro Hyperscale Orchestrator
I'm sure many of you have already wondered: “What is this Orchestrator?” Well, meet it. Maestro Hyperscale Orchestrator — this device is responsible for load balancing. It runs the operating system Gaia R80.20 SP. Currently, there are two models of Orchestrators — MHO-140 and MHO-170. The specifications are shown in the image below:

At first glance, it may seem like a regular switch. However, it is actually a “switch + load balancer + resource management system” all in one box.
These Orchestrators connect to gateways. If the load balancers are in a fault-tolerant configuration, each gateway connects to each orchestrator. “Optical” (sfp+ / qsfp+ / qsfp28+) or DAC cable (Direct Attach Copper) can be used for the connection. Additionally, there must naturally be a synchronization link between the orchestrators:

The image below shows how the ports of these orchestrators are distributed:

Security Groups
For the load to be distributed among gateways, these gateways must be in the same Security Group. Security Group is a logical group of devices that functions as an active/active cluster. This group operates independently of other Security Groups. From the management server's perspective, the Security Group appears as a single device with one IP address.
If necessary, we can move one or more gateways to a separate Security Group and use this group for other purposes, functioning as a separate firewall from a management standpoint. An example of use is shown in the image below:

An important limitationIn one Security Group, only identical gateways (models) can be used. That is, if you want to linearly increase the power of your security gateway (which is a cluster of several devices), you must add exactly the same gateways. This limitation should disappear in upcoming software releases.
The video below shows the process of creating a Security Group. The procedure is intuitive.

Again, if we compare the components of Maestro with the chassis platform, we get approximately the following picture of "before and after":

What are the benefits of the new platform?
There are actually many advantages, both from a technical and economic standpoint. I will briefly outline the main ones:
- We are practically unlimited in scaling. Up to 31 gateways within one Security Group.
- We can add gateways as needed. The minimum setup upon purchase is one orchestrator + two gateways. There's no need to plan for "growth" models.
- From the previous point follows another advantage. We no longer need to replace gateways that can no longer handle the load. Previously, this issue was resolved through a trade-in procedure — returning old hardware and receiving new equipment at a discount. In this scheme, financial "losses" are inevitable. The new scaling procedure eliminates this factor. There’s nothing to return; you can simply continue increasing performance with additional hardware.
- The ability to combine existing resources for load distribution. For example, you can "migrate" all your clusters to the Maestro platform and create several Security Groups depending on the load.
Maestro Hyperscale Network Security Bundles
Currently, there are several options for acquiring so-called bundles with the Maestro platform. The solution is based on the 23800, 6800, and 6500 gateways:

You can choose from two standard types of configurations:
- One orchestrator and two gateways;
- One orchestrator and three gateways.
You can see estimated prices. Naturally, you can also plan for an additional orchestrator and as many gateways as needed. Additional information on specifications can be requested. .
Devices 6500 and 6800 These are the latest models, which were also presented at the beginning of this year. But we will discuss them in more detail in the next article.
When can they be purchased?
There is no clear answer to this. Currently, there is no notification regarding the import of these solutions into our country. As soon as information on the timelines becomes available, we will promptly announce it in our social media channels (, , ). In addition, a webinar focused on the Check Point Maestro solution is planned for the near future, where all technical aspects will be discussed. You will also have the opportunity to ask any questions you may have. Stay tuned for updates!
Conclusion
Undoubtedly, the new platform is an excellent addition to Check Point's hardware solutions. Essentially, this product opens a new segment for which not every cybersecurity vendor has a similar solution. Moreover, currently, there are virtually no alternatives to Check Point Maestro when it comes to providing such unprecedented "security power." However, Maestro Hyperscale Network Security will be of interest not only to data center owners but also to regular companies. Those who own or plan to acquire devices starting from model 5600 can already begin to consider Maestro. In some cases, using Maestro Hyperscale Network Security may prove to be a highly beneficial solution, both economically and technically.
P.S. This article was prepared with the assistance of Anatoly Masover — Expert on scalable platforms, Check Point Software Technologies.
Source: habr.com
