Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
Lari_Luoma
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Let me add here what you should STOP using.

1. Install-on field on rules. 
Create a separate policy for each security gateway/cluster.

2. Manual NAT-rules
Use manual NAT only for complex NAT where you will have to translate source and destination or port.
In all other cases use automatic NAT. It keeps your environment a lot less complex.

3. Rules that have tens of objects
Consolidate rules when possible, use simple object groups (avoid nested groups though) and allow access based on identities instead of IP-addresses.

4. Large policies with no structure
Use unified policies with inline layers, use section headers and add a comment to each rule.

5. Ordered layers
Use unified policies rather than having a separate policy for every access control blade

(1)
Who rated this post