Skip to main content
GreatNetworks
New Member
January 26, 2014
Question

NAT port is exhausted

  • January 26, 2014
  • 12 replies
  • 35840 views
I keep getting ff. error in my event log every few seconds. The router seems to work fine otherwise. How do i trace the source of the problem and block it? Help is very much appreciated. Will this error have effect on performance in future, will the speed degrade? Number of devices is about there are no more than 10,000 sessions at a time, number of devices about 70. notice it gives same error even when connection drop to 5000-6000 and about 50 devices. the firmware is 4.0 mr2 patch 1 the model of router is 300A there was only 1 WAN interface being used the other 3 WAN interface was idle for the active interface there are 8 Policy rules with per ip shaping rules applied Any ideas, i checked for other similar case but have seen none Level critical Sub Type system ID 20007 Status failure Service kernel Message NAT port is exhausted.

    12 replies

    GreatNetworks
    New Member
    January 28, 2014
    I dont just a windows server on the internal interface doubling as DNS which was set as the secondary DNS for DHCP clients So you are saying that i have incorrectly configured clients on IPv6 they query opendns it returns AAA record then it blackholes then retransmit? So when i switched back to the ISP DNS it is IPV4 so everything goes back to normal? Ill check the DNS entries next time, just didnt know where to look initially but would be nice if i have a way to output the get system session list entirely into excel for analysis :)
    emnoc
    New Member
    January 28, 2014
    So you are saying that i have incorrectly configured clients on IPv6 they query opendns it returns AAA record then it blackholes then retransmit? So when i switched back to the ISP DNS it is IPV4 so everything goes back to normal?
    No, that' s not what implying, but you check for ipv6 protocols and rule it out of hthe equation. In might case we had a lot of traffic blacked hole due to a ipv6 rt-adv and the clients trying to connect via ipv6 , when the fortigate where not attached to a ipv6 backbone. ( do a search on disable ipv6 firefox to get a better understanding on web clients & ipv6 ) In our web traffic being blocked due to ipv6 it was mainly with firefox and any sites that where dualstacked & if the client had a ipv6+ipv4 enabled nic(s). Back to the dns-server question; we dropped a ton DNS request from our lan by installing a cache-only web server, and installing that into our DHCP_clients. If I had to guess, we seen anywhere from 12-20% of the on going sessions drop for DNS , due to the caching of the same nslookup . Did you rule out any TS that are applied to any policies? I still think that might be a issue and the age of your code. I' m guessing you do have access to upgrade the firewall?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!