Deployment considerations
This section provides an overview of the MVE deployment options and features.Check Point’s architecture is different from many other firewall vendors.Check Point uses a central Security Management Server (Policy Server) to manage and configure its Security Gateways, including MVEs. The Security Management Server defines security policies and distributes them to gateways, which then enforce those policies.
- Use vNIC 0 for initial communication with the device.
- Configure vNIC 0 as untagged to allow first-time administrative login.
- Check Point firewalls disable Internet Control Message Protocol (ICMP) by default. You cannot use ping or other ICMP-based tools to verify connectivity immediately after deployment.
- After the MVE is live, log in using SSH or HTTPS.
- Use Check Point Smart Console for advanced configuration and policy management. You must fully configure the Smart Console before you can create or publish firewall policies.
- Deploy a Management Gateway (Security Management Server) to define and distribute firewall policies. You can deploy the Management Gateway in any CSP environment.
Network and Security Vendors
MVE integrates with Check Point CloudGuard to deliver advanced threat prevention and secure, policy-based traffic routing between your network and cloud environments. For more information about supported on the MVE platform, see the Megaport Virtual Edge (MVE) product page.MVE locations
For a list of global locations where you can connect to an MVE, see Megaport Virtual Edge Locations.Sizing your MVE instance
The instance size determines the MVE capabilities, such as how many concurrent connections it can support. To size your MVE correctly, consult the vendor’s sizing documentation to ensure it aligns with the number and type of features you plan to enable. When choosing an MVE instance size, keep in mind these items:- Any increase on the network data stream load can degrade performance. For example, establishing secure tunnels with IPsec, adding traffic path steering, or using deep packet inspection (DPI) can affect the maximum throughput speed.
- Future plans to scale the network.
- In the , go to the Services page.
- Click Add Services, then select MVE.
- Select Check Point CloudGuard Network.
- Select the software version.
- Click Next.
- Select an MVE location. Select a location geographically close to your target branch and/or on-premises locations. You can use the Search field to find the Port name, Country, Metro City, or address of your destination Port. You can also filter by diversity zone.
-
A list of available instance sizes appear based on the selected location. Available sizes are highlighted in green and labeled Available. The sizes support varying numbers of concurrent connections, and individual partner product metrics vary slightly.
If the MVE size you want is not in the list, then there is not enough capacity at the selected location. You can either select another location with enough capacity or contact your Account Manager to discuss requirements.
- You can provision another MVE instance, add it to your overlay network, and split the workload between the two MVEs.
- You can provision a larger MVE instance, add it to your overlay network, migrate connections from the old MVE to the new larger MVE, and then retire the old MVE.