Working with PA support on NAT DIPP oversubscription , We might have stumbled across a solution. I come from a cisco ASA background and always have used nat pool or many to many NAT. Recently we hit a NAT DIPP problem and as a result I personally had to get PA support to explain to me what was going on. After a detailed explanation and each model has a hardware limitation. PA support advised I shrink (use a /25 or smaller ) or stop using NAT pool and just NAT our customer behind a single IP. At first I was very against this idea but after PA support explained for them this is a best practice and because they are confident in how they block botnet and other malware, I broke down and did it. After a hour I notice a HUGE increase in traffic and as a result we went out and started testing our self. We found that things improved overall Latency / packet loss / etc. Also the warnings about NAT on commit went away about downgrading to 1x oversubscription. I then had several XBOX and PS4 users redo network test and this resulted in OPEN or TYPE 2 NAT depending on the console. I will confirm on Monday when I take my own PS4 and XBOX to work to test in the office, but I think avoiding NAT pool oversubscription might have fixed this issue. along with the firewall rules I posted early on to open the traffic to XBOX LIVE and Playstation Network. Also we use secure works to watch our outgoing traffic and after 48hours and no notifications of botnet / malware from our RESNET. I was really worried going down to smaller subnet or single IP would have made us more vulnerable. I am guessing with us blocking incoming and the PA security features / protections this might be fine, but I am going to wait a full week before I make a final decision. End result for the NAT was I mapped /22 to /21 for each building WiFi to a single ip. We have a large subnet to use thanks to our ISP. As a result I used a different IP for each building to avoid major oversubscription. for LAN users I am still using 1 to 1 NAT /24 to /24 I will report more as we move along but I think this might be a solution. Welcome to feedback sense this has been a very deep discussions with PA support.
... View more