Description | This article describes how often to log of 'NAT port is exhausted.' while NAT port is being constantly used. |
Scope | FortiGate. |
Solution |
When FortiGates already exhausted all NAT ports with new sessions coming, creating sessions can be denied by FortiGates that increment 'clash' and write logs.
Writing every single log of 'NAT port is exhausted.' could be an extreme burden for FortiGates. So FortiGates write 10 lines every 7 to 8 seconds.
In this example, a FortiGate has only one SNAT IP which can create 60,418 sessions.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.