> Source: [sk147853](https://support.checkpoint.com/results/sk/sk147853)

# sk147853 - Quantum Maestro Frequently Asked Questions (FAQ)

| Property | Value |
|----------|-------|
| Solution ID | sk147853 |
| Date Created | 2019-02-25 |
| Last Modified | 2026-04-27 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS), R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Solution

Show the Entire Article

**Note** : Click **[here](https://support.checkpoint.com/product/520#aq=(%40source%3D%3D(%22Downloads%22)%20AND%20%40product_versions_pairs%3D%3D(%22Quantum%20Maestro%7CR81.20%22%2C%22Quantum%20Maestro%7CR82%22%2C%22Quantum%20Maestro%7CHardware%22%2C%22Quantum%20Maestro%7CR80.20SP%20(EoS)%22%2C%22Quantum%20Maestro%7CR80.30SP%20(EoS)%22%2C%22Quantum%20Maestro%7CR81%20(EOS)%22%2C%22Quantum%20Maestro%7CR81.10%22%2C%22Quantum%20Maestro%7CAll%22))%20OR%20(%40source_name%3D%3D(%22SecureKnowledge%22)%20AND%20%40landing_page_type%20%3D%20(%22howto%22%2C%22config%22)%20AND%20%40status%20%3D%20(%22Approved%22%2C%22Approved%20by%20TAC%22)%20AND%20(%40products%20%3D%3D%20(%22Quantum%20Maestro%22)))%20OR%20(%40source%3D%3D(%22Documentation%22)%20AND%20(%40product_versions_pairs%3D%3D(%22Quantum%20Maestro%7CR81.20%22%2C%22Quantum%20Maestro%7CR82%22%2C%22Quantum%20Maestro%7CHardware%22%2C%22Quantum%20Maestro%7CR80.20SP%20(EoS)%22%2C%22Quantum%20Maestro%7CR80.30SP%20(EoS)%22%2C%22Quantum%20Maestro%7CR81%20(EOS)%22%2C%22Quantum%20Maestro%7CR81.10%22%2C%22Quantum%20Maestro%7CAll%22))))** for Quantum Maestro documentation.

Quantum Maestro Basics
======================

* What is a Maestro Hyperscale Orchestrator (MHO)?  
  > An MHO is a scalable Network Security System that connects multiple Check Point Security Appliances into a unified system.
* What is a Single Management Object (SMO)?  
  > An SMO is a single Security Gateway object in SmartConsole that represents a Security Group configured on Quantum Maestro Orchestrator.
* What is a Security Gateway Module (SGM) and how many are supported?  
  > A Security Group is a group of SGMs represented by an SMO.
  >
  > SGMs in a security group share the same:
  > * Security policy
  > * Configuration
  > * Software versions and Hotfixes
  > * Routing information
  >
  > Traffic is shared between members of a Security Group according to their distribution mode settings.
  >
  > Currently, a maximum of 8 Security Groups are supported.  
  >
  > A single-site Security Group supports a maximum of 14 appliances.
  >
  > A dual-site Security Group supports a maximum of 28 (14 per site) appliances.  
  >
  > **Note** : In R81 and higher versions, the maximum number of Security Gateway Members (SGMs) for each site is 14 for single-site **and**dual-site deployments.

Quantum Maestro Hardware
========================

* Does Check Point use a branded solution or its own product?  
  > The Orchestrator, which executes the orchestration and distribution functions, runs Check Point code.
* Does Maestro need specific interface cards for Check Point appliances on downlinks?  
  > Yes. Maestro requires interface cards of 10G and up.
  >
  > For all other supported cards, refer to [sk92755: Compatibility of transceivers for Check Point appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92755).
* In a dual Orchestrator deployment, can the SGM be connected to one Orchestrator only?  
  > No. One downlink to each orchestrator is required for the SGM to be Active. If the two Orchestrators are up and one downlink is down, the SGM will be placed in a Down state.
* Does Maestro support MDPS and CoreXL Dynamic Split running together?  
  > No. It is not supported to run MDPS and CoreXL Dynamic Split together on the same Security Group.
* Is it possible to share uplink interfaces between Security Groups?  
  > A bonded interface can be shared between multiple Security Groups. However, an LACP bond shared between multiple Security Groups decreases the segregation between these Security Groups.  
  >
  > For example, if Security Group 3 and Security Group 4 share eth1-05 and eth2-05 as subordinates of an LACP bond, and for some reason Security Group 3 stops sending LACP packets to the external switch, then traffic in VLAN interface eth1-05.40 could be affected. Using shared bonds in other bond modes (for example: XOR) does not decrease the segregation
* Is it possible to share appliances between Security Groups? Can an appliance be part of two Security Groups at the same time?  
  > An appliance can be moved between Security Groups, but it cannot participate in more than one Security Group at the same time.
* How many Management ports are supported?  
  > MHO-140 supports up to four Management ports for each Orchestrator.
  >
  > MHO-170 supports two Management ports for each Orchestrator.
  >
  > MHO-175 supports one Management port for each Orchestrator.
  >
  > Management ports can be shared between Security Groups.
* Which Check Point appliances are supported?  
  > Refer to [sk162373: Maestro Supported Appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162373).  
  >
  > In general, all 2012 and 2016 Check Point Gateway appliances with 10G or 40G connectivity can be supported after certification. To do this, submit an [RFE](https://www.checkpoint.com/rfe/rfe.htm).[](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162373)
* Are there any differences between regular appliances and appliances with MHO SKUs?  
  > Appliances with MHO SKUs might be different from normal appliance SKUs (memory, NICs, etc). Please refer to the [Product Catalog](https://usercenter.checkpoint.com/usercenter/portal/media-type/html/role/usercenterUser/page/default.psml/js_pane/PricingToolsId%2CProductsCatalogId?https://store.checkpoint.com/PricingTool/cart.htm) for more details.
* Is Open Server support planned?  
  > No.
* Is it possible to move customers' environments running Check Point clusters under MHO?  
  > Yes, this is a possible scenario. Check Point recommends that you contact [Professional Services](https://www.checkpoint.com/support-services/design-deploy-operate-optimize/) for the migration process.
* How many Orchestrators are supported in a cluster?  
  > In single-site installation, two Orchestrators can can work together. In dual-site installation, either single or dual Orchestrators per site works, but there must be the same number on both sites. (2x1 or 2x2). Support for more than two sites is planned for a future release.
* MHO supports 1m and 3m DAC cables. Are there any plans to add support for 5m and 10m cables?  
  > 5m and 10m cables can be certified based on business cases.
* Does the breakout DAC require transceivers on either end?  
  > No transceivers are required.
* Are there breakout cables for uplinks?  
  > Yes. CPAC-TR-40SPLIT-QSFP-3M or CPAC-TR-40SPLIT-QSFP-6M can be used with CPAC-TR-40SR-QSFP-300m transceiver.
* Is it supported to use 3rd party DAC cables?  
  > Check Point does not support 3rd party DAC cables.
* Which transceivers can be used on uplink ports?  
  > For a full list of transceivers, refer to [sk92755](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92755).
* Does Check Point plan to phase out Scalable Platforms (44000/64000) appliances?  
  > Maestro serves as an extension of Scalable Platform capabilities to other Check Point Appliances and not as a replacement to the 44000/64000 line. Chassis-based solutions have specific use cases and will continue to evolve according to the roadmap.
* How long are the included DAC cables?  
  > We provide 2 cables: one is 1m long, the other is 3m long.
* Are there any additional transceivers needed for connecting the Orchestrator to LAN/DMZ/Internet/etc?  
  > Yes. For a list of supported transceivers, refer to [sk92755](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92755).
* Is it supported to use fiber transceivers/cables for downlinks?  
  > Yes:
  > * Up to 300m length Short Range with suitable 10Gbps/40Gbps transceivers, and up to 100m with 100Gbps transceivers (see [sk92755](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92755))
  > * Up to 10km length Long Range with suitable 10Gbps/40Gbps/100Gbps transceivers (see [sk92755](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92755))
  > These limitations are related to transceivers' physical capabilities. Connection through patch panel is supported.
* Is MHO-175 compatible with MHO170?  
  > No.

Quantum Maestro Software
========================

* How does synchronization work? Is there an overhead with potentially 52 appliances in a MHO installation?  
  > MHO uses a special synchronization solution called HyperSync which provides high scale synchronization support without sacrificing Security Gateway performance.
* Does Check Point support virtual MHOs running in Private or Public Clouds?  
  > Not at the moment.
* Is it possible to monitor individual SGM load information?  
  > Yes, the same tools can be used as on our Scalable Platforms.
* Will the MHO web frontend be built into SmartConsole?  
  > There are plans to make management of the Security Groups, SGMs and MHO ports even simpler. It's too early to discuss SmartConsole integration, although Check Point is interested in customers' requirements and use cases.
* Is MHO available in SmartConsole?  
  > The individual Security Groups under MHO are available as SMOs in SmartConsole as Hardware Type Maestro. This makes the underlying architecture easier to manage in SmartConsole.
* Which versions of Check Point's Security Management Server/Multi Domain Management can be used to manage Maestro?  
  > R80.10 and R80.20 systems can manage Maestro if Jumbo Hotfix is added. Systems running R80.30 and above can manage it even by default.
* Does Check Point support 3rd party orchestration tools with MHO?  
  > MHO will have full Check Point API support when the Gaia Gateway API is available.
* Is it supported to upgrade Security Groups separately? Can they run different software releases?  
  > Security Groups work independently from one another and therefore they can run on different software versions.
* Is there any downtime introduced while upgrading SGMs in a Security Group with JHFs?  
  > SGMs can be upgraded individually or in groups without introducing downtime.
* Is any downtime introduced while upgrading the Orchestrators?  
  > If the Orchestrators are in cluster, no downtime is introduced.
* How does SIC work with MHO?  
  > Each Security Group has its own SMO. SIC is built up with the SMO and shared between SGMs in the same Security Group.
* How does the Security Management count the Gateway licenses in MHO?  
  > 1 Security Group equals 1 Gateway license.
* How is the MHO system licensed?  
  > There is no specific license needed on the MHO.
* How is a Security Group or Multiple Security Groups (MSG) licensed?  
  > There is no specific license needed for Security Groups.
* How are the SGMs licensed?  
  > The SGMs use the same licensing methodology as any other Check Point appliances. All features must be licensed per Gateway and the same type of licenses must be applied to all SGMs in a Security Group.  
  >
  > Licenses must be created with local licensing method, and the Gateway portion must be the sync IP of the appliance matching the SKU (for example: appliance one sync IP is: 192.0.2.1
* Is the LTE feature set supported?  
  > The CGNAT feature is supported with R80.20SP and R81SP. Other features of the LTE feature set will be added in the next releases.
* Which release enables vSwitch support?  
  > vSwitch support is enabled by [Jumbo Hotfix Accumulator Take 178](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk155832).
* Which release enables dual-site support?  
  > Dual-site support is enabled by [Jumbo Hotfix Accumulator Take 163](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk155832).
* Which clustering modes are supported in dual-site?  
  > Currently, the supported clustering modes in dual-site are SGW active-standby mode, VSX active-standby mode, and VSLS. These modes are per Security Group and can be different for each one. Example: Security Group 1 can be active on site A while the standby is on site B; Security Group 2 can be active on site B and standby on site A.  
  >
  > Starting in version R82, the active-active clustering mode is a **limited availability** feature.
* Is it supported to configure a MAGG (or simply Maestro management) interface as a default Gateway for a connected network?  
  > No. The management interface is not part of the normal traffic distribution architecture. Therefore, it cannot act as a default Gateway, nor does it support NAT or VPN (Site to Site or Remote Access) connections.

Quantum Maestro Redundancy and Scaling
======================================

* Is interface bonding between MHO and downlink appliances available?  
  > There's an automatic bonding inside, so if you are connecting more than one cable, it will be linked into the bond automatically. No additional configuration is required, but make sure to refer to the documentation for information on how to share downlinks between Orchestrators.
* Is interface bonding between MHO and uplink network systems available?  
  > Yes, this is the recommended configuration.
* Is there a redundant sync between two MHOs?  
  > Supported with R80.20SP Jumbo Hotfix Accumulator Take 210 or higher (see MBS-7993 in [sk155832](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk155832)).
* What throughput is needed between MHOs for sync?  
  > MHO-170 and MHO-175 require 40GB or 100GB DAC cables or transceivers. MHO-140 requires a 10GB DAC cable or transceivers.
* Does Check Point support single MHO appliance installations?  
  > Yes, but it's recommended to have two MHOs to provide redundancy and avoid a single point of failure.
* Is redundancy between different appliance models in a Security Group supported?  
  > Redundancy between different appliance models in a Security Group is supported starting in R81.10.  
  > Refer to [sk162373](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162373) for certified combinations of Security Appliance models in the same Security Group.
* Does the MHO support Dynamic Scaling?  
  > Dynamic Scaling (Auto-Scaling) is supported starting with R81.20. With Auto- Scaling, the system adds/removes SGMs from a Security Group or moves SGMs between Security Groups dynamically when the load requires it and if the scaling rules permit it.
* Does Maestro support CoreXL Dynamic Balancing?  
  > Yes, CoreXL Dynamic Balancing is supported starting in R81.20.
* Does Maestro support Hyperflow?  
  > Yes, Hyperflow is supported starting in R81.20.
* Is there any throughput degradation when adding multiple SGMs to a Security Group?  
  > Check Point reduced throughput degradation to 1% per added SGMs. For example, the overall throughput degradation is 10% for 10 SGMs in a Security Group. Check Point aims to reduce this even further in the future.
* Is there a redundant sync between MHOs?  
  > * Supported with R80.20SP Jumbo Hotfix Accumulator Take 210 or higher (see MBS-7993 in [sk155832](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk155832)).
* Is Multi-Queue setup needed on SGMs?  
  > Multi-Queue is set up automatically. There is no need to modify the configuration.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
