NAT and the Correction Layer on a Security Gateway
Check Point Maestro R80.20SP Administration Guide | 65
NAT and the Correction Layer on a Security
Gateway
For optimal system performance, one Security Appliance handles all traffic for a session. With NAT,
packets sent from the client to the server can be distributed to a different Security Appliance than packets
from the same session sent from the server to the client. The system correction layer must then forward
the packet to the correct Security Appliance.
Configuring the Distribution Mode correctly keeps correction situations to a minimum and optimizes
system performance.
To achieve optimal distribution between Security Appliances in a Security Group in Gateway mode:
NAT Rules
Instructions
Not using NAT rules
Set the General Distribution Mode.
Using NAT rule
Set the hidden networks to the User Mode
Set the destination networks to the Network Mode