- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-20-2024 08:37 AM
Hi All,
Been troubleshooting an issue with viewing live streams from cameras from one specific location. We've had the system in place for awhile and it was working fine until recently. Any time we try to establish a connection over tcp 960, it was failing. I noticed in packet capture that the firewall was not performing NAT for that traffic. I ran command "debug dataplane nat sync-ippool rule <rule name>" and now its working fine (at least temporarily).
While troubleshooting, we re-routed this traffic to another location that was working fine. However, now when I view the NAT table on that firewall, I see "NAT pool is leaking!!!". It appears this location is now going to have an issue.
Running pan-os 10.1.11. Seems we are running into a bug, but didn't see this listed in known issues.
Any advice would be appreciated
01-21-2024 05:51 AM - edited 01-21-2024 05:57 AM
How many concurrent sessions you have?
show session all filter count yes
How is status of NAT IP pool cache?
show running ippool
show running global-ippool
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CliQCAS
01-21-2024 09:48 AM - edited 01-21-2024 09:48 AM
Thanks for the reply.
So a few things, for the firewall with the initial issue, I don't recall the exact sessions/nat pool stats but they were both low. After we routed traffic for that destination to one of our other sites, I cleared all sessions to that destination. However, my TCP sessions were still not being established. Only way to resolve was to clear/reclaim the stale NAT buffers. One thing we previously tried was to create a pool of public IPs. This helped but only for a week.
On the firewall where the traffic was rerouted to, where it was showing NAT Pool is Leaking, it was using around 2200 out of 126798
Based on the timing when this issue started, it appears to be related to the upgrade from 9.1 to 10.1
03-22-2024 07:21 AM
not yet. Seems like maybe it is fixed in 10.1.13, but I can't say for sure yet.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!