- Use a single source interface for each rule.
- Use a single destination interface for each rule.
- Source selection preference –
- MAC address
- IP address
- IP subnet
- Use a single service for each rule.
- Enable AV, IPS & SSL inspection for all rules.
- Enable logging for all sessions.
- Enable Web Filter, DNS, and Application Control profile for all NAT rules.
- Enable schedule for NAT rules.