NAT and the Correction Layer on a VSX Gateway
Check Point Maestro R80.20SP Administration Guide | 66
NAT and the Correction Layer on a VSX
Gateway
In a VSX Gateway, the guidelines in NAT and the correction layer on a Security Gateway apply to each
Virtual System individually. For best results, manage an entire session by the same Security Appliance by
a specified Virtual System. When a Virtual Switch (junction) connects several Virtual Systems, the same
session can be handled by one Virtual System on one Security Appliance, and by another Virtual System
on a different Security Appliance.
When a packet reaches a Virtual System from a junction, the system VSX Stateless Correction Layer
rechecks the distribution according to the WRP interface's Distribution Mode. It can decide to forward the
packet to a different Security Appliance.
In addition, on each Virtual System, the system's correction layer, which is stateful, can forward session
packets, similar to the Security Gateway.
All forwarding operations have a performance impact. Therefore, the Distribution Mode configuration
should minimize forwarding operations.
To achieve optimal distribution between Security Appliances in a Security Group in VSX mode:
NAT Rules
Instructions
Not using NAT rules on any Virtual System
Set the General Distribution Mode.
Using NAT rule on at least one Virtual
System
n
On the Virtual Systems that use NAT rules:
l
Set the hidden networks to the User Mode
l
Set the destination networks to the Network
Mode
n
On the remaining Virtual Systems that do not use
NAT rules:
l
Set internal networks to the User Mode
l
Set the external networks to the Network
Mode