- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- GNAT curiosity
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GNAT curiosity
I was looking at the new GNAT feature and considering it as something good to have but then I realized that it is not recommended if the number of core workers is less than 6.
I am just curious about what is the reason.
In my environment I am running 3 core workers for example.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It may be that when you don’t have enough cores to work with, there isn’t enough of a benefit of GNAT.
It’s a good question, though.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well in my case with 3 workers I guess that I could *3 the pool size which is quite good.
Perhaps there may be a negative performance impact more noticeable with less workers ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The pooling of source ports for Hide NAT between the various worker cores will be statically assigned if there are less than 6 worker cores. In this case it is more likely for a certain worker core to run out of source ports if it happens to draw a large number of connections from the Dynamic Dispatcher that are Hide NATted behind the same outside IP address.
When there are 6 or more worker cores present, Hide NAT source port pooling is fully dynamic between all the worker cores. This effect was mentioned in the second edition of my book (because it required a manual kernel tweak to enable dynamic allocation), but removed from the third edition once dynamic allocation became automatically enabled with 6+ worker cores defined. See here: sk103656: Dynamic NAT port allocation feature
CET (Europe) Timezone Course Scheduled for July 1-2
