FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
leej
Staff
Staff
Article Id 359758
Description This article describes how often to log of 'NAT port is exhausted.' while NAT port is being constantly used.
Scope FortiGate.
Solution

When FortiGates already exhausted all NAT ports with new sessions coming, creating sessions can be denied by FortiGates that increment 'clash' and write logs.

 

Writing every single log of 'NAT port is exhausted.' could be an extreme burden for FortiGates. So FortiGates write 10 lines every 7 to 8 seconds.

 

In this example, a FortiGate has only one SNAT IP which can create 60,418 sessions.

  1. Only 60,418 sessions are created. New sessions are denied due to the exhaustion of the NAT port. The value of 'clash' is on the rise.

1.jpg

 

  1. Logs are written 10 lines every 7 to 8 seconds.

     

    2.jpg

     

     

  2. The log sample below shows only one line at a time for convenience.

 

 

3.jpg

Contributors