> Source: [sk32224](https://support.checkpoint.com/results/sk/sk32224)

# sk32224 - NAT Kernel Table "fwx_alloc"

| Property | Value |
|----------|-------|
| Solution ID | sk32224 |
| Date Created | 2006-12-18 |
| Last Modified | 2025-12-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

Starting in R80.40, Security Gateway / Cluster Members can allocate NAT ports using one global allocation table. The name of this method is GNAT (Global NAT). In versions R80.40 and higher, GNAT replaced dynamic port allocation and is enabled by default on Security Gateway / Cluster Members with 6 or more CoreXL Firewall instances. For more information, see [sk165153](https://support.checkpoint.com/results/sk/sk165153) and [sk172933](https://support.checkpoint.com/results/sk/sk172933).***fwx_alloc*** is a kernel table that maps real source ports with Security Gateway's allocated source ports that are used for NAT. This kernel table appears in these configurations:

* Versions R80.40 and higher - NAT configurations with static port allocation
* Versions R80.30 and lower - all NAT configurations (dynamic port allocation or static port allocation)

**Note:** In GNAT configurations in versions R80.40 and higher, the kernel table `fwx_alloc_global`replaced the kernel table `fwx_alloc`.

**Note**: NAT kernel tables are not cleared during Security Policy installation.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
