In fortigate 600d, All NAT session drops instantly, so to fix it i have to remove nat policies and add them again, it happens once every 3 or 4 month, i have voip,http,https traffic, In log there is only one "Session CLASH"
fortios 5.6.4
any suggestion
Seems like the internal NAT table becomes full. Wondering how many sessions you have active at one time.
Some suggestions:
a)
upgrade to v5.6.8; read (all) the Release Notes, esp. "Bugs fixed"
b)
instead of deleting policies disable them. The point is to kill all active NAT sessions to clear the internal NAT table. From GUI, disabling a policy will kill all sessions through it. From CLI, you could kill all (or a filtered subset of all) sessions with one command.
c)
if possible, use more WAN addresses for NATting.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.