Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ramesh_M
New Contributor

PAT sessions in a single PAT IP

Hi Team, In my environment I am doing the source NAT with single IP(two /23 and one /24 segments). How many PAT sessions can accommodate with the same PAT IP. Is any performance issues happen? Please suggest.

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in
4 REPLIES 4
emnoc
Esteemed Contributor III

You need to be concern wth ephemeral port exhuasting. Outside of that I never seen a performance issues or limitations. I ' ve nat a full /22 behind one ip_addresss before. I tried not to go over 4 class C worth of address behind a single ip_address. Make adjustments based on your session counts, lifetime,etc,........

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Ramesh_M
New Contributor

Hi, Thanks for your reply. But I am expecting the counts like how many sessions can have with single PAT IP. FGT have any Session limits based on policy. Can we allow all segments in single policy / each segment in one policy and PAT the same single PAT IP.

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in

Ramesh M Technical Specialist - CCNA(Security), FCNSP, ACE, ASE, ITIL blogs.itzecuriry.in
rwpatterson
Valued Contributor III

I have over 500 nodes (in various levels of Internet use) behind a single IP on my 1000A without ever having an issue.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

But I am expecting the counts like how many sessions can have with single PAT IP.
you will be limited to 64K or less, no matter if it' s 254 512 or 4096 address mapped behind it.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors