<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting error when committing more NAT rules &amp;quot;Total NAT DIPP rules 401 exceeds the capacity of 400&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-error-when-committing-more-nat-rules-quot-total-nat-dipp/m-p/245390#M69937</link>
    <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-rule-capacities" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-rule-capacities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;describes the &lt;STRONG&gt;NAT Rule capacities&lt;/STRONG&gt; as follows:&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;number of NAT rules&lt;/STRONG&gt; allowed is based on the firewall model. Individual rule limits are set for static, Dynamic IP (DIP), and Dynamic IP and Port (DIPP) NAT. The sum of the number of rules used for these NAT types cannot exceed the total NAT rule capacity. &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;For DIPP, the rule limit is based on the &lt;U&gt;oversubscription setting (8, 4, 2, or 1) of the firewall&lt;/U&gt; and the assumption of &lt;U&gt;one translated IP address per rule&lt;/U&gt;. &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last sentence is unclear? I believe the limit is based on the &lt;U&gt;&lt;STRONG&gt;number&lt;/STRONG&gt; &lt;/U&gt;of NAT rules in &lt;STRONG&gt;Policies-&amp;gt;NAT .&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Or does oversubscription also affect this NAT rule capacity somehow?&lt;/P&gt;&lt;P&gt;Or does it mean if my oversubscription is 2x, and I have 5 of these rules, then I have 10 NAT rules used out of 400??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a CLI that shows how many NAT rules (eg. out of the 400) are currently in use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ... Leslie&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2019 20:46:54 GMT</pubDate>
    <dc:creator>LeslieGomba</dc:creator>
    <dc:date>2019-01-09T20:46:54Z</dc:date>
    <item>
      <title>Getting error when committing more NAT rules "Total NAT DIPP rules 401 exceeds the capacity of 400"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-error-when-committing-more-nat-rules-quot-total-nat-dipp/m-p/245390#M69937</link>
      <description>&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-rule-capacities" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-rule-capacities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;describes the &lt;STRONG&gt;NAT Rule capacities&lt;/STRONG&gt; as follows:&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;number of NAT rules&lt;/STRONG&gt; allowed is based on the firewall model. Individual rule limits are set for static, Dynamic IP (DIP), and Dynamic IP and Port (DIPP) NAT. The sum of the number of rules used for these NAT types cannot exceed the total NAT rule capacity. &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;For DIPP, the rule limit is based on the &lt;U&gt;oversubscription setting (8, 4, 2, or 1) of the firewall&lt;/U&gt; and the assumption of &lt;U&gt;one translated IP address per rule&lt;/U&gt;. &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The last sentence is unclear? I believe the limit is based on the &lt;U&gt;&lt;STRONG&gt;number&lt;/STRONG&gt; &lt;/U&gt;of NAT rules in &lt;STRONG&gt;Policies-&amp;gt;NAT .&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Or does oversubscription also affect this NAT rule capacity somehow?&lt;/P&gt;&lt;P&gt;Or does it mean if my oversubscription is 2x, and I have 5 of these rules, then I have 10 NAT rules used out of 400??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a CLI that shows how many NAT rules (eg. out of the 400) are currently in use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards ... Leslie&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 20:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-error-when-committing-more-nat-rules-quot-total-nat-dipp/m-p/245390#M69937</guid>
      <dc:creator>LeslieGomba</dc:creator>
      <dc:date>2019-01-09T20:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Getting error when committing more NAT rules "Total NAT DIPP rules 401 exceeds the capacity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-error-when-committing-more-nat-rules-quot-total-nat-dipp/m-p/245405#M69940</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bi-directional NAT rules create 2 different NAT policies, even though one rule is in place. That may be tripping you up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can see all the rules in place (not including disabled rules) with the CLI command:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show running nat-policy&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to only see the rule numbers themselves, add a match criteria such as:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show running nat-policy | match index&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That will spit out only the index numbers of the rules.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 21:30:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-error-when-committing-more-nat-rules-quot-total-nat-dipp/m-p/245405#M69940</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-01-09T21:30:57Z</dc:date>
    </item>
  </channel>
</rss>

