What mechanism can ensure that the Security Gateway can communicate with the Management Server with ease in situations with overwhelmed network resources?
A.
There is a feature for ensuring stable connectivity to the management server and is done via Priority Queuing.
B.
The corresponding feature is new to R81.10 and is called “Management Data Plane Separation”
C.
The corresponding feature is called “Dynamic Split”
D.
The corresponding feature is called “Dynamic Dispatching”
Firewall Priority Queues in R80.x / R81.x
Note: starting from R80.40, the Firewall Priority Queues are enabled by default.
The Priority Queues (PrioQ) mechanism is intended to prioritize part of the traffic, when we need to drop packets because the Security Gateway is stressed (CPU is fully utilized).
Security Gateway R80.x / R81.x handle both aforementioned cases in the following ways:
Prioritizing control connections over data connections.
Each connection of the same priority will get an equal share of CPU resources.
https://support.checkpoint.com/results/sk/sk105762
Management Data Plane Separation (MDPS) allows a Security Gateway to have isolated Management and Data networks, ensuring stable connectivity to the management server even when network resources are overwhelmed.
According to Check Point Cybersecurity Bootcamp CCSE course that I took 1 month ago the same text that jerj5 posted:
With heavy network traffic, the Security Gateway might become overwhelmed and be unable to communicate with some systems, losing some functionality or management connectivity.
To prevent such situations, Management Data Plane Separation (MDPS) lets a Security Gateway to have isolated Management and Data networks.
Although MDPS was introduced in version R80.20, the CCSE guide mentions the following:
With heavy network traffic, the Security Gateway might become overwhelmed and be unable to communicate with some systems, losing some functionality or management connectivity.
To prevent such situations, Management Data Plane Separation (MDPS) lets a Security Gateway to have isolated Management and Data networks.
Priority queue pyritizes traffic to mgmt server on Control queue, second highest level. Level 0, highest is used for Routing whch guarantees the communication from GW to mgmt server will be in place
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
FMorales
2 weeks, 4 days agokeikei1228
1 month agoZiamsu
6 months agodavid_vera
8 months, 2 weeks agojerj5
8 months, 3 weeks agoKuKuKu83
10 months, 1 week agoRajeshkashi
10 months, 1 week ago