<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 GNAT issue after Upgrade in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/97209#M19094</link>
    <description>&lt;P&gt;We did upgrade of our cluster from &lt;STRONG&gt;R80.30&lt;/STRONG&gt; to &lt;STRONG&gt;R80.40&lt;/STRONG&gt; and also used &lt;STRONG&gt;MVC&lt;/STRONG&gt; upgrade.&lt;/P&gt;&lt;P&gt;Now both nodes of our cluster are R80.40 and MVC is turned off (according to "&lt;STRONG&gt;show cluster members mvc&lt;/STRONG&gt;"). We have &lt;STRONG&gt;6 CoreXL&lt;/STRONG&gt; instances and the "&lt;STRONG&gt;fw ctl get int fwx_gnat_enabled&lt;/STRONG&gt;" command gives the output "&lt;STRONG&gt;fwx_gnat_enabled = 1&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;But our &lt;STRONG&gt;/var/log/messages&lt;/STRONG&gt; is full of messages like this:&lt;/P&gt;&lt;P&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12858, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12857, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12847, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:04 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12859, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Sep 2020 18:14:59 GMT</pubDate>
    <dc:creator>benko2</dc:creator>
    <dc:date>2020-09-21T18:14:59Z</dc:date>
    <item>
      <title>R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/96353#M18978</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Bit of a strange one after a staged upgrade of an r80.20 cluster to r80.40 Y77.&lt;/P&gt;&lt;P&gt;We have upgraded one of the nodes and enabled MVC but have hit what appears to be an fwx_alloc issue:&lt;/P&gt;&lt;P&gt;cloningd: Error in delayed connection() 111 - Connection refused&lt;BR /&gt;kernel: [fw4_0];fwxlate_allocate_port_from_sync: synced port already exists. Port 10702 (protocol 6) of hide_src ##########, dst ##########.&lt;BR /&gt;kernel: [fw4_0];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;BR /&gt;kernel: [fw4_1];fwxlate_allocate_port_from_sync: synced port already exists. Port 10602 (protocol 6) of hide_src ##########, dst ##########.&lt;BR /&gt;kernel: [fw4_1];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;BR /&gt;kernel: [fw4_4];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: ##########, port: 10637, dest: ##########, dport: 443 (443)&amp;gt;&lt;/P&gt;&lt;P&gt;kernel: [fw4_0];fwxlate_allocate_port_from_sync: synced port already exists. Port 10708 (protocol 6) of hide_src ##########, dst ##########.&lt;BR /&gt;kernel: [fw4_0];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;BR /&gt;kernel: [fw4_0];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: ##########, port: 10404, dest: ##########, dport: 443 (443)&amp;gt;&lt;BR /&gt;kernel: [fw4_3];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: ##########, port: 10555, dest: ##########, dport: 443 (443)&amp;gt;&lt;/P&gt;&lt;P&gt;GNAT is set to 1 as its a 6 FW worker appliance.&lt;/P&gt;&lt;P&gt;Have a Ticket open with TAC but suspect next step is create and modify &lt;EM&gt;fwkern.conf&lt;/EM&gt; to 0 as per sk165153.&lt;/P&gt;&lt;P&gt;Anyone come across this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;UPDATE:&lt;/P&gt;&lt;P&gt;As per sk165153 and sk26202 we set fwx_gnat_enabled to 0 and rebooted the appliances. Fixed the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 19:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/96353#M18978</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2020-09-21T19:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/96606#M19011</link>
      <description>&lt;P&gt;The way I read sk165153 is that it should only be enabled if there are more than 5 worker instances, which won't ever happen on a 6 core box since at least one would be SND.&lt;BR /&gt;Setting it to zero would be a surefire way to make sure it's disabled.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 23:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/96606#M19011</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-11T23:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/97209#M19094</link>
      <description>&lt;P&gt;We did upgrade of our cluster from &lt;STRONG&gt;R80.30&lt;/STRONG&gt; to &lt;STRONG&gt;R80.40&lt;/STRONG&gt; and also used &lt;STRONG&gt;MVC&lt;/STRONG&gt; upgrade.&lt;/P&gt;&lt;P&gt;Now both nodes of our cluster are R80.40 and MVC is turned off (according to "&lt;STRONG&gt;show cluster members mvc&lt;/STRONG&gt;"). We have &lt;STRONG&gt;6 CoreXL&lt;/STRONG&gt; instances and the "&lt;STRONG&gt;fw ctl get int fwx_gnat_enabled&lt;/STRONG&gt;" command gives the output "&lt;STRONG&gt;fwx_gnat_enabled = 1&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;But our &lt;STRONG&gt;/var/log/messages&lt;/STRONG&gt; is full of messages like this:&lt;/P&gt;&lt;P&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12858, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12857, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:03 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12847, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;BR /&gt;Sep 21 20:01:04 2020 fwnode1 kernel: [fw4_2];de_allocate_port: fwx_alloc_global_del failed (second try). &amp;lt;ipp: 6 hide_src: xxx.xxx.xxx.xxx, port: 12859, dest: yyy.yyy.yyy.yyy, dport: 11680 (11680)&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 18:14:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/97209#M19094</guid>
      <dc:creator>benko2</dc:creator>
      <dc:date>2020-09-21T18:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/97221#M19095</link>
      <description>&lt;P&gt;As per sk165153 and sk26202 we set fwx_gnat_enabled to 0 and rebooted the appliances. Fixed the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 21:07:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/97221#M19095</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2020-09-21T21:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124717#M23043</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33562"&gt;@StackCap43382&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for jumping on this old post, but it's the only result that Google churns out when I search for the error I'm seeing in our /var/log/messages files!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an example of the error:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jul 16 13:10:39 2021 CORP-FW1 kernel: [fw4_19];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;/P&gt;&lt;P&gt;Jul 16 17:09:53 2021 CORP-FW1 kernel: [fw4_8];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;/P&gt;&lt;P&gt;Jul 19 10:55:25 2021 CORP-FW1 kernel: [fw4_22];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering if TAC gave you any explanation as to what these messages mean and what their impact could be? Also, did you notice any issues when disabling GNAT? I am contemplating disabling GNAT to see if it "resolves" another issue&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Implications-of-disabling-GNAT/m-p/123625#M22876" target="_blank" rel="noopener"&gt;(here is the link to the post)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice you could give would be much appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 21:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124717#M23043</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2021-07-22T21:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124736#M23045</link>
      <description>&lt;P&gt;Agree, we need to know what these messages imply and what effect they might have. Simply disabling GNAT is not really a "solution", it's a workaround. If one wants to utilise CoreXL Split / Dynamic Balancing on an appliance running R80.40-R81.10 you need to have GNAT enabled.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I can't see any reason why GNAT should not be working when having less than five CoreXL workers/instances. Sure it might not be on by default if you have less than five. But that doesn't mean it should cause issues if you enable it and you might want to enable it for various reasons so it's good to know what these messages actually mean and how to deal with them.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 06:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124736#M23045</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2021-07-23T06:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 GNAT issue after Upgrade</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124739#M23046</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Closed the TAC case once we got it working again. Customer didn't have any apatite for another drawn out TAC engagement.&lt;/P&gt;&lt;P&gt;Been working fine for nearly a year.&lt;/P&gt;&lt;P&gt;non-G-NAT has been the NAT method since forever, It will work just like it did before.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jul 2021 07:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-40-GNAT-issue-after-Upgrade/m-p/124739#M23046</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2021-07-23T07:06:38Z</dc:date>
    </item>
  </channel>
</rss>

