I will try to keep this as brief as possible while also giving the pertinent information.
We have a HA cluster with ISP device IPs. We proxy ARP additional customer IPs (which we have had for 20 years) to this cluster.
We static NAT specific networks to these IPs as per historical business rules. IE keep the IPs you can get.
When I have network nodes that use the Hide NAT method it is considerably quicker than any static NAT method, which I can assume is related to the Proxy ARP. I am using the same 3 devices and changing their NAT method each time to eliminate some variables. The access rule order is not changing during my testing.
My cluster is a pair of 6700s using 10GbE interface for ingress and egress. I found an article about peak
[Expert@fw-ext-01:0]# fw tab -t fwx_cache -s
HOST NAME ID #VALS #PEAK #SLINKS
localhost fwx_cache 8116 64374 68428 0
Can anyone point my to documentation that can explain away this difference to Management?