Good afternoon, colleagues!
I am currently studying the CCME guide and have come across a point that I would like to discuss with you.
The guide states that Maestro does not use GNAT in version 81.10 due to technical limitations. Instead, it uses Dynamic Allocation technology, which also has its own set of limitations.
The most important question I have for these two lines is:
Example 1 - Maestro Security Gateway with 6 INSPECT/Instance Cores(default 2/6 CoreXL split of 8 total cores):
Each instance has 8,333 source ports available for each Hide NATaddress/destination IP address pair.
Example 2 - Maestro Security Gateway with 48 cores and a default 4/44split:
Each INSPECT/Instance core only has 1,136 source ports available foreach Hide NAT address/destination IP address pair.
There is a greater risk of port exhaustion.
My main question is about the risk of port depletion for NAT connections when connections to certain destinations do not necessarily need to go through the same core instance. I might be misunderstanding something here.
It's also not clear to me what the main advantage of Dynamic Allocation is over NET, since GNAT also doesn't expand the pool of available ports.
Thanks for your future answers.