Hi
We have an ARIN assigned /24 public range. The physical topology of external internet link is the typical ISP <> External Router <> Layer2 Switches <> Checkpoint ClusterXL.
Is it best to use /24 for addressing the external Checkpoint ClusterXL interfaces/VIP or use a smaller /28 or /29 for addressing the external Checkpoint ClusterXL interfaces and then route the /24 range on the External Router to the Checkpoint ClusterXL VIP interface?
I know both will work but wanted to get some feedback on best practices and security considerations. Note - we also have DDoS protection/scubbing on the /24 range. As a result is it safer to use the first option?