156-836 · Question #34
There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?
The correct answer is A. Between 2 and 4. In a Check Point Security Group (Maestro environment), NAT connections require synchronized state across more than one appliance for failover, but synchronizing across all members would be wasteful and inefficient - so the platform syncs a connection to a subset of between 2…
Question
There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?
Options
- ABetween 2 and 4
- BAll 10
- C2
- D3
How the community answered
(40 responses)- A78% (31)
- B5% (2)
- C13% (5)
- D5% (2)
Explanation
In a Check Point Security Group (Maestro environment), NAT connections require synchronized state across more than one appliance for failover, but synchronizing across all members would be wasteful and inefficient - so the platform syncs a connection to a subset of between 2 and 4 SGMs (Security Group Members), covering the handling member plus backup members.
Why the distractors are wrong:
- B (All 10): Full synchronization to every member is unnecessary overhead; only the members likely to take over a connection need its state.
- C (Exactly 2): Two is possible, but the correct answer is a range - the number can go higher based on topology and redundancy configuration, making "exactly 2" too narrow.
- D (Exactly 3): Same problem - fixing it at exactly 3 ignores that the platform can use 2 to 4 depending on configuration.
Memory tip: Think of it as "NAT needs a backup team, not the whole squad." A connection under NAT needs at least one backup SGM (giving you 2 minimum), but for resilience may involve a few more - capping at 4 to stay practical, never the full group of 10.
Topics
Community Discussion
No community discussion yet for this question.