Networks, Hardware and Trading Infrastructure · Technology
23Futures Connectivity
In January 2018 an order on Eurex entered the exchange through one of sixteen high-frequency gateways, and the path on which competing orders raced was 22 microseconds long “with multiple µs variance”. Each gateway had its own queue and its own jitter, so a firm that opened sessions on many gateways and sent a copy down each could beat a faster firm with one. The exchange’s own account is blunt: “Latency jitter on parallel inbound paths had incentivised multiplicity to reduce latency.” Its answer was to change the gateways, and by September 2018 the competitive path was under two microseconds with nanosecond variance. The history of those changes is a history of what “fair” means at the microsecond.
Book 1 introduced futures commission merchants and clearing members, Book 10 the order-entry session, Book 11 the kill switch and the pre-trade check, Book 13 the drop copy and the binary market data. This chapter is about how a firm connects to a futures exchange: the sessions and the gateways behind them, the fairness designs the exchanges adopted, the clearing firm’s controls on the path, and the market data channels. The race between gateway designs is a labelled simulation built on the exchanges’ published numbers.
23.1 Order-entry sessions and market-segment gateways
Definition 23.1 (Market segment gateway)
A market segment gateway is an exchange’s order-entry gateway dedicated to one market segment, a group of products matched on one engine instance, so that every order for those products enters through the same gateway and in one sequence, rather than through any of several general gateways that route to all segments.
CME Group offers both models. A Convenience Gateway accepts orders for every market segment and routes them; a Market Segment Gateway connects to one segment, and the firm connects to each segment it trades, with one session identity shared across all of them and separate primary and backup addresses for each (Box 23.2). Deutsche Börse’s T7 has the same split: partition-specific gateways, for high-frequency sessions only, reach one partition; low-frequency gateways reach all partitions through them, 43 microseconds slower at the median; FIX gateways go through the low-frequency ones.
A session is therefore a set of choices: which gateway type, which segments or partitions, what throttle, and how many. On T7 a high-frequency session is throttled to 150 transactions a second (“Full”) or 250 (“Ultra”), a participant may order up to 80 sessions, and the price list charges more for the seventh Full session than for the sixth (Box 23.1).
As of September 2026 — High-frequency session types and fees on Eurex, from the June 2023 price list
ETI High Frequency Full session, at most 150 transactions a second: EUR 260 a month for each of a trading member’s first six sessions, EUR 520 from the seventh. Ultra session, at most 250 transactions a second: EUR 780 a month. Up to 80 sessions may be ordered (Deutsche Börse, 2021).
A session planner turns a transaction rate into the cheapest mix: firm_gwmodel.plan_sessions carries 3 000 transactions a second on one partition with five Full sessions and nine Ultra ones, EUR 8 320 a month, cheaper than twenty Full sessions (EUR 8 840) because the Full price doubles from the seventh.
23.2 Gateway fairness and its history
Definition 23.2 (Gateway fairness)
Gateway fairness is the property of an exchange’s order-entry path that competing messages reach the matching engine in the order in which they reached the exchange’s network, with a variance small against the differences the exchange means to reward, so that no participant gains by sending the same order through several paths.
As of September 2026 — Gateway designs and their fairness, from the exchanges’ documentation
- Eurex T7: January 2018, 16 high-frequency gateways, competitive path of 22 µs “with multiple µs variance”; September 2018, partition-specific gateways as a single point of entry, “sub 2 µs with ns level variance”. Since 2021: FIFO “guaranteed from network card to matching engine in”; colocation connections equal in length within ±2.5 ns.
- CME Globex: “The MSGW ensures messages are processed in the order in which they arrive at the gateway”; 17 market segments. Safeguards: a message split across packets, or received out of order, costs its session at least of extra processing, during which another session’s complete message may overtake it.
The model reproduces the incentive. Ten firms react to the same event at the same instant. Under the parallel design, each copy of an order crosses the network to a gateway (, jitter of ), waits behind that gateway’s queue (two messages already there on average, and the race’s own copies that arrived first, each), and the firm’s first copy to finish counts. Under the segment design every copy enters one gateway whose order is fixed at the network card, over connections equal to ±2.5 ns. All parameters are assumptions in the range the exchanges describe.
def race(design, sessions, rng):
"""sessions: copies per competitor. Returns the winner, the arrival of its first copy (us) and the completion of a
bystander message reaching a random gateway just after the race's copies (us)."""
owner = np.repeat(np.arange(len(sessions)), sessions)
if design.kind == "segment":
arrive = design.net_us + rng.uniform(-design.cable_ns, design.cable_ns, len(sessions)) / 1000
queue = rng.poisson(design.background) + int(np.sum(sessions))
return (int(np.argmin(arrive)), float(arrive.min() + design.service_us),
float(design.net_us + (queue + 1) * design.service_us))
gw = np.concatenate([rng.choice(design.gateways, size=s, replace=False) for s in sessions])
at_gw = design.net_us + design.net_sd_us * rng.standard_normal(len(gw))
queue = rng.poisson(design.background, design.gateways).astype(float)
done = np.empty(len(gw))
for i in np.argsort(at_gw):
queue[gw[i]] += 1
done[i] = at_gw[i] + queue[gw[i]] * design.service_us
best = np.full(len(sessions), np.inf)
np.minimum.at(best, owner, done)
by = design.net_us + (queue[rng.integers(design.gateways)] + 1) * design.service_us
return int(np.argmin(best)), float(best.min()), float(by)
Proposition 23.3 (Copies under the two designs)
Under a design where every copy of a firm’s order reaches one first-in first-out queue at the same instant, extra copies cannot change which firm is first. Under parallel queues with independent delays, the firm’s arrival is the minimum of its copies’ delays, which falls with every copy, so its chance of winning rises while the others keep one session.
Proof. In one queue, the copies of an order arrive together and the first is served no earlier than a single copy would be; the rest only queue behind it. With independent paths, the minimum of delays is at most the minimum of , and strictly smaller with positive probability when the delays are continuous. ∎
fig_futures.py, nw_futures.curves().Alone, a firm that sprays copies over twelve gateways wins 59.7% of the races instead of 10.0%. When everyone does it, the win rate returns to one in ten, and what remains is the load: a bystander message reaching a random gateway just after the race takes when every firm sends one copy and when every firm sends twelve, the “higher, less predictable latencies” of the exchange’s account. Under the segment design the firm wins 9.8% of races with one session or twelve: the order is decided by nanoseconds of cable, and copies only load the gateway.
The history reads as a sequence of such repairs. Parallel gateways with independent queues rewarded multiplicity; FIFO within a gateway and deterministic networks reduced the variance; a single entry point per partition removed the parallel paths; equal cables moved the tie-break to nanoseconds. Each repair closes one strategy and exposes the next margin. CME’s safeguards, which its documentation calls a market integrity control, target messages split across packets: sending the start of a message before its end is ready is a way to arrive first, and a session that does it now waits at least three microseconds.
23.3 Drop copy and clearing-firm risk layers
Definition 23.4 (Clearing-firm credit control)
A clearing-firm credit control is a limit that a clearing member sets, at the exchange or in its own system, on the exposure of an executing firm it guarantees, with actions the exchange takes when the limit is breached, such as blocking new orders or cancelling working ones.
A futures firm trades under a clearing member’s guarantee, and the clearing member controls it at the exchange. CME’s Globex Credit Controls let clearing-firm risk administrators set exposure limits and maximum order sizes per executing firm and choose what happens on a breach: an e-mail, blocked orders, cancelled orders; for mass quotes the check applies only after execution. Unlike the broker’s layer of chapter 22, this control sits inside the exchange, so it adds nothing to the firm’s path; its cost is the limit itself, which can stop a strategy in the middle of a busy day.
The drop copy is the firm’s independent record of every execution and cancellation, from the exchange. With several sessions it covers them all, and reconciliation must be per session: an order identifier is unique within its session, not across them. firm.gwmodel splits the drop copy by session and runs Book 13’s reconciler on each.
def reconcile_sessions(gateways, drop_copy):
"""Reconcile each session's gateway with its part of the firm's drop copy (firm_ordergw.reconcile)."""
breaks = []
for s, gw in gateways.items():
mine = [(k, cl, q) for (sess, k, cl, q) in drop_copy if sess == s]
breaks += [f"session {s}: {b}" for b in og.reconcile(gw, mine)]
unknown = sorted({sess for (sess, *_rest) in drop_copy} - set(gateways))
breaks += [f"session {s}: in the drop copy, not in the firm" for s in unknown]
return breaks
Multiplicity has a cost here too. Twelve copies of an immediate-or-cancel order produce up to twelve executions and cancellations to reconcile, and more than one copy may fill: a firm that sprays orders must size each copy as if all might execute, which is the worst-case accounting of Book 13’s gateway.
23.4 Market data: channels, recovery and bandwidth
CME disseminates market data by channel, a channel per product group (the E-mini S&P 500 futures on channel 310, their options on 311, interest rate futures on 312, NYMEX crude and refined futures on 382, among others), each on two UDP feeds, A and B, which the exchange strongly recommends processing both. A gap in the packet sequence numbers means that every book on the channel may be wrong; recovery is from snapshot loops, a TCP replay of missed packets or an instrument loop. The configuration file, not the channel guide, is authoritative for the addresses, and both change.
Two feeds protect only if their losses are independent. With a loss probability of per packet on each, independent losses lose a packet on both once in ; with a correlation of 0.5 between the two feeds’ losses (a shared switch, a shared buffer), once in 200 000 (firm_gwmodel.both_lost). The two feeds must reach the firm by separate paths, into separate switch ports, or the second one mostly duplicates the first’s failures.
23.5 The session budget
A firm can compute what an extra session is worth. At 20 000 races a month and EUR 0.50 for each race won (assumptions), the second session is worth EUR 840 a month under the parallel design and the twelfth EUR 180.5; against Eurex’s fees, the last session that pays for itself is the sixth, where the price per session doubles.
def marginal(curve):
p = [c[0] for c in curve]
return [(k, (p[i] - p[i - 1]) * RACES * VALUE_EUR) for i, k in enumerate(K) if i > 0]
def fee(k):
"""The monthly fee of the k-th Full session under the dated schedule."""
return FULL.fee_first if k <= FULL.first_n else FULL.fee_after
def last_paying(curve):
last = 1
for k, v in marginal(curve):
if v >= fee(k):
last = k
else:
break
return last
fig_futures.py, nw_futures.marginal().The fee schedule is part of the fairness design: a price that doubles from the seventh session makes the marginal copy cost more than it wins exactly where the curve flattens. Under a segment gateway the calculation is simpler: the second session wins nothing, and sessions are bought for throughput, segments and redundancy only.
Method 23.5 (Planning futures order entry)
- List the market segments or partitions the strategies trade; read the exchange’s gateway model and its fairness design.
- Size sessions for throughput and failover: transactions a second per segment against the throttles, with backup addresses tested in the exchange’s failover windows.
- If the design is fair, do not buy copies; if it is not, value each extra session against its fee and against the load it adds, and expect the exchange to change the design.
- Put the clearing member’s limits and the drop copy in the plan; reconcile per session.
- Take both market data feeds by separate paths, and certify recovery before trading.
23.6 Tutorial: racing through gateways
Goal. Simulate a race under parallel and segment gateways, and price the sessions a firm would buy. End state: Figures 23.1 and 23.2.
- Designs.
firm_gwmodel.Designwith the stated parameters;race(Listing 23.1) runs one event. - Win rates.
win_rateover 20 000 events for each number of sessions, the firm alone or everyone. - Budget.
nw_futures.marginalandlast_paying(Listing 23.3) against the dated fee schedule;plan_sessionsfor throughput.
What to change next. Let each firm’s reaction time vary, so that the fastest firm wins most races under a fair design, and measure how much multiplicity a slower firm needs to catch up under the parallel one.
23.7 Build: the gateway and session model
Purpose. Gateways, sessions and their prices for a futures desk: the futures rows of chapter 29’s plan.
Interface. firm_gwmodel: Design, race, win_rate, SessionType, load_sessions, session_cost, plan_sessions, both_lost, reconcile_sessions.
Rules. Fees and limits are dated rows with sources; the race is a labelled simulation with stated parameters; Book 13’s firm.ordergw is wrapped, not changed.
Acceptance tests. code/firm/gwmodel/tests/: fairness of the segment design, the gain from copies under the parallel one and the load they add, a queue by hand, the fee schedule and the planner, and a two-session reconciliation.
Stretch. Reaction-time differences between firms; exchange throttles on copies; ICE’s gateways.
Sources and further reading
- Deutsche Börse, T7 infrastructure and latency, Open Day 2018; Insights into Trading System Dynamics, 2021.
- CME Group Client Systems Wiki: iLink Architecture, Market Segment Gateway Safeguards, CME Globex Credit Controls, MDP 3.0 Recovery Services and Channel Guide.
- Eurex Circular 029/23 and its price list attachment.
23.8 Exercises
Exercise 23.1 ★
What do a Convenience Gateway and a Market Segment Gateway each connect a CME session to?
Solution
Solution of Exercise 23.1.
A Convenience Gateway session reaches every market segment, the gateway routing each message; a Market Segment Gateway connection reaches one segment, a group of products on one engine, and the firm connects to each segment’s gateway with the same session identity.
Exercise 23.2 ★
What does ten Full sessions cost a month on Eurex’s June 2023 schedule, and what do they carry?
Solution
Solution of Exercise 23.2.
EUR a month, for transactions a second.
Exercise 23.3 ★
Why does the exchange recommend processing both the A and the B feeds?
Solution
Solution of Exercise 23.3.
A packet missed on one feed is usually present on the other, so processing both avoids most gaps; a gap on both means every book on the channel must be resynchronised, which costs time exactly when data is busiest.
Exercise 23.4 ★★
Using Proposition 23.3, explain why the segment design’s win rate stays at one in ten.
Solution
Solution of Exercise 23.4.
All copies of each firm’s order reach the one gateway’s card together, and its queue is first-in first-out: the first copy is served no earlier than a single one would be, so the winner is the firm whose order arrives first, decided by ±2.5 ns of cable, uniformly among ten equally fast firms.
Exercise 23.5 ★★
Why does CME penalise a message split across two packets, and whose message benefits?
Solution
Solution of Exercise 23.5.
Sending the start of a message before its end is ready lets a firm begin its transmission early, a way to arrive first that the design did not mean to reward. The session is delayed at least and a complete message from another session may reach the engine first.
Exercise 23.6 ★★
A firm sends each IOC through four sessions. What must its risk system assume, and why?
Solution
Solution of Exercise 23.6.
That all four may execute: its position limits must count four times the order’s size until the other copies are cancelled or expire, and its reconciliation must expect up to four executions.
Exercise 23.7 ★★★
Coding. With firm_gwmodel.plan_sessions, what is the cheapest mix for 3 000 transactions a second, and how much more would Full sessions alone cost?
Solution
Solution of Exercise 23.7.
Five Full and nine Ultra sessions, EUR 8 320 a month; twenty Full sessions cost EUR 8 840, 520 more, because fourteen of them are at the price from the seventh.
Exercise 23.8 ★★★
Find the flaw. “Our twelve sessions win us six races in ten; if the other firms copy us we will add more.”
Solution
Solution of Exercise 23.8.
If the others copy, the gain disappears (one in ten again) while everyone’s latency rises, and adding sessions only restarts the race at a higher cost; and the exchange, whose system carries the load, has every reason to change the design, as Eurex did.
23.9 Problem: Twelve Sessions for One Order
Problem 23.1
Weekend problem — the value of multiplicity under two gateway designs
A firm is one of ten that race for the same events on a futures exchange. It can send a copy of each order through up to twelve sessions. Use the chapter’s model and the dated fees.
Part I — The parallel design.
- What is the firm’s chance of winning with one session, and with twelve?
- What does the second session add, and the twelfth?
- What is the proposition behind the rising curve?
- Which assumptions of the model drive the size of the gain?
Part II — Everyone copies.
- What happens to the firm’s chance when all ten firms send twelve copies?
- What happens to a bystander’s latency?
- Why did the exchange care?
- What did it change, and in what order?
Part III — The segment design.
- What is the firm’s chance with one session and with twelve?
- What decides the order now?
- What margin is left to compete on?
- Why do the CME safeguards exist?
Part IV — The verdict.
- State the named result: the probability of winning with sessions under jittery gateways against a segment gateway, and the session fee above which the extra sessions do not pay.
- What does the twelfth session’s value say about Eurex’s fee from the seventh?
- Which of the chapter’s numbers are published and which assumed?
- What would the firm buy under each design?
- How would it check which design it faces?
- What does multiplicity cost in reconciliation and risk?
- Where does this go in chapter 29’s plan?
- In one sentence: what does “fair” mean at the microsecond?
Solution
Solution of Problem 23.1.
Part I.
- 10.0% and 59.7%.
- 8.4 points (EUR 840 a month at the chapter’s values), and 1.8 points (EUR 180.5).
- The minimum of independent delays falls with every copy (Proposition 23.3).
- The gateways’ independent queues and jitter relative to the differences between firms; with no jitter there would be nothing to gain.
Part II.
- It returns to one in ten (10.2% in the simulation).
- It rises from to .
- The copies loaded its gateways at the busiest moments and made latency higher and less predictable for every participant.
- Deterministic networking, FIFO in the gateways, then a single partition-specific entry point; equal-length connections; and prices that rise with the number of sessions.
Part III.
- 9.8% with either.
- The order in which messages reach the gateway’s card, and so the firm’s own speed to the exchange, to within ±2.5 ns of cable.
- The firm’s own reaction: market data handling, decision, and its path to the card.
- To remove the advantage of splitting a message across packets to start sending it before it is complete.
Part IV.
- Named result: with parallel, jittery gateways a firm’s chance of winning a ten-firm race rises from 10.0% with one session to 59.7% with twelve, while under a segment gateway it stays at 9.8%; at 20 000 races a month and EUR 0.50 a race, the eleven extra sessions are worth EUR 4 973 a month, EUR 452 a session on average, but each session beyond the sixth is worth less than the EUR 520 it costs, and the twelfth only EUR 180.5.
- That the fee from the seventh is set where the marginal copy is worth less than it costs: the schedule enforces what the design no longer needs.
- Published: gateway designs, path lengths, variances, cable equality, session limits and fees. Assumed: the model’s delays, queues, service times, the number of firms, races and their value.
- Parallel: sessions up to where their marginal value meets the fee, knowing the gain vanishes if others copy. Segment: sessions for throughput, segments and failover only.
- Measure: send timestamped probes through several sessions and gateways and compare the exchange’s receive and matching timestamps; if order at the engine differs from order at the network card, the design is not FIFO.
- Up to executions per order to reconcile per session, and positions that must assume all copies fill.
- In the futures rows: segments, sessions and their fees, failover, clearing limits, drop copies, and both feeds by separate paths.
- That the order of arrival at the exchange’s edge, not the luck of a path inside it, decides who is first.
23.10 Interview questions
Interview question 23.1 ★ developer
What is a market segment gateway, and why would an exchange offer one?
Solution
Solution of Interview question 23.1.
A gateway dedicated to one group of products on one engine, so that all orders for them enter through one path in one sequence. It removes routing inside the exchange and the variance of parallel paths, and so the reward for sending copies.
What the interviewer is looking for: Segments; one sequence; fairness; routing removed.
Interview question 23.2 ★★ developer, researcher
Why might sending the same order through several sessions win more races, and when does it stop working?
Solution
Solution of Interview question 23.2.
Parallel gateways with independent queues and jitter make the firm’s arrival the minimum of its copies’ delays. It stops working when the exchange orders messages at one entry point, when everyone copies, or when fees and throttles make copies cost more than they win.
What the interviewer is looking for: Order statistics; independent paths; equilibrium; exchange response.
Interview question 23.3 ★★ developer
How would you measure whether an exchange’s gateways are fair?
Solution
Solution of Interview question 23.3.
Send pairs of messages at known times through different sessions and gateways, and compare the exchange’s timestamps at its network edge with the order of matching; measure variance on each path; check that equal cables and equal ports give equal times.
What the interviewer is looking for: Controlled probes; exchange timestamps; order inversion; variance.
Interview question 23.4 ★★ developer
You lost packets on both the A and B feeds at the same moment. What do you suspect first?
Solution
Solution of Interview question 23.4.
A common cause: the same switch, buffer, NIC or host receiving both feeds, or a burst above what that shared element can carry; less likely, a loss at the exchange. Check whether the feeds share any element and move them apart.
What the interviewer is looking for: Correlated losses; shared elements; recovery.
Interview question 23.5 ★★ trader
Your clearing member’s credit control blocked your orders at midday. What do you do now, and what do you change for tomorrow?
Solution
Solution of Interview question 23.5.
Flatten or hedge what can still be traded within the allowed actions, talk to the clearing member’s risk desk about the limit and the breach, and reconcile positions from the drop copy; tomorrow, size strategies to the limit with headroom, and ask for limits per product where they fit the risk better.
What the interviewer is looking for: Immediate risk; communication; reconciliation; limits in the plan.
Interview question 23.6 ★★★ developer, researcher
Design order entry for a firm trading five market segments on one exchange: sessions, gateways, failover, risk and reconciliation.
Solution
Solution of Interview question 23.6.
One session identity per the exchange’s model, connected to each segment’s gateway, primary and backup, with throttles sized per segment; no copies under a FIFO design; failover tested in the exchange’s windows; clearing limits known and monitored; drop copies reconciled per session; both market data feeds on separate paths.
What the interviewer is looking for: Segments; throughput; failover; risk; reconciliation; feeds.