Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dashrath
New Contributor

NAT port is exhausted.

Hello,

 

we are using Fortingate 240D unit and suddenly we found "NAT port is exhausted" event, what can i do for this?

 

Thanks

3 REPLIES 3
MikePruett
Valued Contributor

You have so much traffic traversing the border and being NAT'd that you are utilizing all ports. You either need to create an IP Pool that has more than one external IP tied to it (so it load balances across them) or reduce the traffic traversing the border.

 

For a 240D it is impressive that you have enough sessions flowing to do that though...

Mike Pruett Fortinet GURU | Fortinet Training Videos
emnoc
Esteemed Contributor III

Yes agreed more ippools. You can do something like split half of your address space behind 2 or more   SNAT pool address

 

Alos keep in mind, if your network is a SRC or infection and are flooding the internet, you can see nat_pool exhaustation, so make sure that's not the case.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dashrath
New Contributor

Dear Michael and emnoc,

Thanks for your comments, problem is resolved.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors