Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GreatNetworks
New Contributor

NAT port is exhausted

I keep getting ff. error in my event log every few seconds. The router seems to work fine otherwise. How do i trace the source of the problem and block it? Help is very much appreciated. Will this error have effect on performance in future, will the speed degrade? Number of devices is about there are no more than 10,000 sessions at a time, number of devices about 70. notice it gives same error even when connection drop to 5000-6000 and about 50 devices. the firmware is 4.0 mr2 patch 1 the model of router is 300A there was only 1 WAN interface being used the other 3 WAN interface was idle for the active interface there are 8 Policy rules with per ip shaping rules applied Any ideas, i checked for other similar case but have seen none Level critical Sub Type system ID 20007 Status failure Service kernel Message NAT port is exhausted.
I Live to Solve
I Live to Solve
12 REPLIES 12
emnoc
Esteemed Contributor III

Do you have a local DNS-server server maybe? As far as monitoring, I use a mix of cacti/nagios3 and sometime the opsview ( which is really nagios). Rare, but some times OpenNMS or Solarwinds. All has it pros and cons, but cacti is well documented for being opensource, easy to setup on debian/ubuntu and pretty much reliable. Only the fortigate mibs could be different so some cacti templates will have to be re-worked for querying. YMMV but the experience overall is good with cacti/nagios3. On OpenDNS, have you tried GooglePUBLIC DNS? Also do you have ipv6 enabled anywhere? The reason I' m mentioning this, I just ran into problems Google/Yahoo, these providers are IPv6 enabled, and DNS queries for any record , returns both the AAA and A resource-types. So some clients where querying and getting AAAA response and then their ipv6 was blackholed. So the client' s kept sending request and where in a big loop. Youtube was mainly effected btw. It was easy to spot by the number of DNS related sessions in the table.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
GreatNetworks
New Contributor

I dont just a windows server on the internal interface doubling as DNS which was set as the secondary DNS for DHCP clients So you are saying that i have incorrectly configured clients on IPv6 they query opendns it returns AAA record then it blackholes then retransmit? So when i switched back to the ISP DNS it is IPV4 so everything goes back to normal? Ill check the DNS entries next time, just didnt know where to look initially but would be nice if i have a way to output the get system session list entirely into excel for analysis :)
I Live to Solve
I Live to Solve
emnoc
Esteemed Contributor III

So you are saying that i have incorrectly configured clients on IPv6 they query opendns it returns AAA record then it blackholes then retransmit? So when i switched back to the ISP DNS it is IPV4 so everything goes back to normal?
No, that' s not what implying, but you check for ipv6 protocols and rule it out of hthe equation. In might case we had a lot of traffic blacked hole due to a ipv6 rt-adv and the clients trying to connect via ipv6 , when the fortigate where not attached to a ipv6 backbone. ( do a search on disable ipv6 firefox to get a better understanding on web clients & ipv6 ) In our web traffic being blocked due to ipv6 it was mainly with firefox and any sites that where dualstacked & if the client had a ipv6+ipv4 enabled nic(s). Back to the dns-server question; we dropped a ton DNS request from our lan by installing a cache-only web server, and installing that into our DHCP_clients. If I had to guess, we seen anywhere from 12-20% of the on going sessions drop for DNS , due to the caching of the same nslookup . Did you rule out any TS that are applied to any policies? I still think that might be a issue and the age of your code. I' m guessing you do have access to upgrade the firewall?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors