Visitor Mode is a backup mechanism for our IPsec clients, allowing them to operate in network environments where UDP port 4500 is blocked. It is implemented by adding additional encapsulations to the traffic. The above functionality reduces the effectiveness of cryptographic procedures, applied on such traffic.
Check Point's recommendation is to avoid Visitor Mode connections in environments, where there is no explicit need for this mode.
If a significant number of clients in the Remote Access environment are connected via Visitor Mode, and the administrator is not aware of the conditions dictating this, Check Point recommends that the user open a ticket with Check Point Support to investigate the matter and move the clients to the default NAT-T mode.
спасибо, Скудновато но всё же. Не понимаю только почему его рекомендуют отключать, но при этом чекбокс с visitor mode включен и неактивный (не выключается)