<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic IP Pool utilization - 10.2.9-h1 in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-pool-utilization-10-2-9-h1/m-p/597931#M3742</link>
    <description>&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt; Hi Team&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;We have an issue where we use Dynamic IP pool for outbound NAT but 'show running ippool' does not reflect the accurate NAT xlate pool usage.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;For example, we see 9k Available IPs but on checking the global counter we can see the NAT Utilization errors:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorUtkarshKumar_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UtkarshKumar_1-1726519436193.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62263iC8B1B26C205D91FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="UtkarshKumar_1-1726519436193.png" alt="UtkarshKumar_1-1726519436193.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show running nat-rule-ippool &amp;lt;rule&amp;gt; also shows the same number stating 9k available IPs.&lt;BR /&gt;&lt;BR /&gt;Why can't we see the actual number of utilized and Free IPs?&lt;BR /&gt;&lt;BR /&gt;Is there a more specific command or way to check this on the firewall?&lt;BR /&gt;&lt;BR /&gt;I see this but not sure if it also applies to Dynamic IP type NAT rule:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkPCAS" target="_blank" rel="noopener"&gt;Packet drop due to source NAT IP/port allocation failed - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2024 20:51:35 GMT</pubDate>
    <dc:creator>UtkarshKumar</dc:creator>
    <dc:date>2024-09-16T20:51:35Z</dc:date>
    <item>
      <title>Dynamic IP Pool utilization - 10.2.9-h1</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-pool-utilization-10-2-9-h1/m-p/597931#M3742</link>
      <description>&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt; Hi Team&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;We have an issue where we use Dynamic IP pool for outbound NAT but 'show running ippool' does not reflect the accurate NAT xlate pool usage.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;For example, we see 9k Available IPs but on checking the global counter we can see the NAT Utilization errors:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorUtkarshKumar_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UtkarshKumar_1-1726519436193.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62263iC8B1B26C205D91FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="UtkarshKumar_1-1726519436193.png" alt="UtkarshKumar_1-1726519436193.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show running nat-rule-ippool &amp;lt;rule&amp;gt; also shows the same number stating 9k available IPs.&lt;BR /&gt;&lt;BR /&gt;Why can't we see the actual number of utilized and Free IPs?&lt;BR /&gt;&lt;BR /&gt;Is there a more specific command or way to check this on the firewall?&lt;BR /&gt;&lt;BR /&gt;I see this but not sure if it also applies to Dynamic IP type NAT rule:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkPCAS" target="_blank" rel="noopener"&gt;Packet drop due to source NAT IP/port allocation failed - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;&lt;SPAN class="ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 20:51:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/dynamic-ip-pool-utilization-10-2-9-h1/m-p/597931#M3742</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2024-09-16T20:51:35Z</dc:date>
    </item>
  </channel>
</rss>

