NAT Leak Issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

NAT Leak Issue

L3 Networker

Hi All,

Been troubleshooting an issue with viewing live streams from cameras from one specific location.  We've had the system in place for awhile and it was working fine until recently.  Any time we try to establish a connection over tcp 960, it was failing.  I noticed in packet capture that the firewall was not performing NAT for that traffic.  I ran command "debug dataplane nat sync-ippool rule <rule name>" and now its working fine (at least temporarily).

 

While troubleshooting, we re-routed this traffic to another location that was working fine.  However, now when I view the NAT table on that firewall, I see "NAT pool is leaking!!!".   It appears this location is now going to have an issue.

 

Running pan-os 10.1.11.  Seems we are running into a bug, but didn't see this listed in known issues.

 

Any advice would be appreciated

 

 

4 REPLIES 4

Cyber Elite
Cyber Elite

How many concurrent sessions you have?

 

show session all filter count yes

 

How is status of NAT IP pool cache?

 

show running ippool

show running global-ippool

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Thanks for the reply.

 

So a few things, for the firewall with the initial issue, I don't recall the exact sessions/nat pool stats but they were both low.  After we routed traffic for that destination to one of our other sites,  I cleared all sessions to that destination.  However, my TCP sessions were still not being established.  Only way to resolve was to clear/reclaim the stale NAT buffers.  One thing we previously tried was to create a pool of public IPs.  This helped but only for a week.   

 

On the firewall where the traffic was rerouted to, where it was showing NAT Pool is Leaking,  it was using around 2200 out of 126798

 

Based on the timing when this issue started, it appears to be related to the upgrade from 9.1 to 10.1

L0 Member

Any update?

not yet.  Seems like maybe it is fixed in 10.1.13, but I can't say for sure yet.   

  • 2033 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!