Working with the Distribution Mode
Check Point Maestro R80.20SP Administration Guide | 57
Notes:
n
The default mode is
General
with Layer 4 distribution enabled.
n
The
User Mode
and
Network Mode
can work together. These combinations are supported:
l
User Mode and User Mode
l
User Mode and Network Mode
l
Network Mode and Network Mode
In many scenarios, the User Mode and Network Mode combination could be optimized to pass traffic
on same Security Appliance from both sides.
Automatic Distribution Configuration (Auto-Topology)
By default, Security Groups work in
General Mode
. The best Distribution Mode is selected based on the
Security Group topology as defined in SmartConsole.
The Distribution Mode is automatically based on these interface types:
n
Physical interfaces, except for management and synchronization interfaces
n
VLAN
n
Bond
n
VLAN over Bond
Manual Distribution Configuration (Manual-General)
In some deployments, you must manually configure a Distribution Mode on the Security Group to the
General
. In other cases, it may be necessary to force the Security Group to work in
General Mode
.
When the Distribution Mode is manually configured (
Manual-General Mode
), the Distribution Mode of the
Security Group is
General
. In this configuration, the topology of the interfaces is irrelevant.
Best Practice
- Do
not
change manually the Distribution Mode of a Virtual System.
This can cause performance degradation.