Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

NAT Port is Exhausted

Getting the Alert " NAT Port is Exhausted" in our log. It' s listed as critical and nothing on our Firewall is showing any hiccups. 1240B with v4.0,build0272,100331 (MR2)
12 REPLIES 12
g3rman
New Contributor

Look at the event log, particularly for a very large increase in sessions and a spike in the CPU. Once you kill the process or after the upgrade these should decrease significantly.
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
A Real World Fortinet Guide Configuration Examples & Frequently Asked Questions http://firewallguru.blogspot.com
Not applicable

I have just received this log too, but the system seems to work ok. It' s the first time I received it, so I don´t know if I have to worry about it. This device is a FG-50B v.4.0 MR2 patch 4 (b313). Regards, Edited: since this morning, I have received it several times, so I opened a support ticket.
emnoc
Esteemed Contributor III

You might need to do one of the following; adjust the NATs timeout split the SRCs into multiple ranges and apply SNAT pools to these ranges Your ephemeral port ranges are probably exhausted.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors