- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Has anyone faced issues with outbound DNS on R80.20SP with 2 MHO-140 + 2 members? We have multiple private interfaces and performing hide NAT for traffic leaving our external interface - pretty standard. We have noticed very slow and unresponsive DNS queries and lookups.
The default distribution mode is "manual-general" and after reading sk108842, when performing Hide NAT, the external interface should be configured as "network" instead of "user"
After making the change to "auto-topology" and setting the external interface to "network," DNS queries are back to normal. Still experiencing odd DNS issues from certain private segments when pointing to an internal F5 VIP (using external forwarders), but wondering if anybody else has faced similar issues.
Before:
eth1-x :policy-internal
eth2-x: policy-external
After:
eth1-x :manual-internal
eth2-x: manual-external
Thanks
Turns out L4 is enabled by default and recommended by TAC to disable unless doing heavy NAT or SGMs are not balanced. DNS issues resolved.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
8 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY