Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Graham1
Contributor

NAT performance (Hide NAT vs Static NAT)

I will try to keep this as brief as possible while also giving the pertinent information.

We have a HA cluster with ISP device IPs.  We proxy ARP additional customer IPs (which we have had for 20 years) to this cluster.
We static NAT specific networks to these IPs as per historical business rules.  IE keep the IPs you can get.

When I have network nodes that use the Hide NAT method it is considerably quicker than any static NAT method, which I can assume is related to the Proxy ARP.  I am using the same 3 devices and changing their NAT method each time to eliminate some variables.  The access rule order is not changing during my testing.

My cluster is a pair of 6700s using 10GbE interface for ingress and egress.  I found an article about peak 

[Expert@fw-ext-01:0]# fw tab -t fwx_cache -s
HOST NAME ID #VALS #PEAK #SLINKS
localhost fwx_cache 8116 64374 68428 0


Can anyone point my to documentation that can explain away this difference to Management?

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Please elaborate how HIDE NAT is "considerably quicker" than STATIC NAT.
Some packet captures might also provide clues as to what's actually going on here.
Also what version/JHF is this relevant to?

0 Kudos
the_rock
Legend
Legend

Personally, I never heard one type of nat be faster than the other, thats news to me.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events