<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hide NAT: Simultaneous Connections to the same destination in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35831#M7580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Does it mean that I can have more 50K concurrent connections using a single Hide NAT IP if it is to a different destination?&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The same port can be used again, if the connection is to a different destination, or using a different NAT hide IP address, or is a different IP protocol (e.g. TCP and UDP).&lt;/P&gt;&lt;P&gt;A single hide behind a single hide IP will be enough, unless you have more than 50K simultaneous connections to the same destination.&lt;BR /&gt;In that case you will need to hide behind a range of hide addresses.&lt;/P&gt;&lt;P&gt;The outbound connections are split among the HIDE range using X mod N.&lt;/P&gt;&lt;P&gt;That means that the same source IP will always get the same hide IP.&lt;BR /&gt;So if we have a lot of connections from the same source to the same destination, we will be out of ports, and hiding behind a range will not solve the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I have used the command you showed me to check the number of concurrent connections. I&amp;nbsp;get 146232 connections using a single Hide NAT IP. How do I know if it is to the same destination?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;Right now, there isn't a good way to do this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;If you suspect this is an issue, we have a way to determine this with an internal script that parses the fwx_alloc table.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;You can send the output of &lt;STRONG&gt;fw tab -t fwx_alloc -u&lt;/STRONG&gt;&amp;nbsp;during your peak connection time and we can run it for you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;This can be captured from your standby node.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;Note that we&amp;nbsp;do plan to expose these HIDE NAT statistics in later releases.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Nov 2018 23:37:54 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-11-20T23:37:54Z</dc:date>
    <item>
      <title>Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35812#M7561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mates&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need a help with the regards to clarification of Hide NAT. According to&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk27396, Hide NAT has a limitation of 50.000 simultaneous connections to the same destination. And one of the recomendation provided in the same&amp;nbsp;sk27396 is to Hide behind a range of addresses instead of Hiding behind a single address. Therefore, I need clarification on the following questions that I have:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;1. When hiding behind a range of addresses, how is the range IP allocated? Does it use the first available IP in the range, and when it reaches the maximum number of allowed connections (50.000), it automatically starts using the next available IP in the range, or we as administrator can influence on how the IPs in the range for Hide NAT&amp;nbsp; are allocated?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;2. Is there any command to verify the number of simultaneous connection to the same destination on the Firewall?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;The reason for my questions is because I am hiding a network of many users (Ex: 10.10.0.0/18) behind a single IP address, and they all establish simultaneous connections to the DNS server which is on the Internet leaving my internal network with the single public IP address assigned for Hide NAT. The users of this network use it in order to perform multiple sales transactions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Your help will be really appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2018 21:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35812#M7561</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-15T21:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35813#M7562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In regards to your first question it appears to be some kind of static hash function that you can't modify, please see my response here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238" title="https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238"&gt;https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the second question, please look at my "favorite" command #2 in this post:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/6843-my-top-3-check-point-cli-commands#comment-6946" title="https://community.checkpoint.com/message/6843-my-top-3-check-point-cli-commands#comment-6946"&gt;https://community.checkpoint.com/message/6843-my-top-3-check-point-cli-commands#comment-6946&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 00:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35813#M7562</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-16T00:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35814#M7563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim, thank you very much for always giving a hand when needed. I have been reading about this all issue and I found out that the number of availbale ports is further devided to the number of CoreXL fw instances.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My other question is whether there is any command that can show how many ports are assigned to each coreXL fw instances.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we have to configure Manual NAT for a network as big as 10.10.0.0/18 with a total of 16,382 available hosts, what would recommend as a range to use in Manual NAT in order to try and overcome the 50k limitation.&lt;/P&gt;&lt;P&gt;If there is another solution other than Manual NAT to overcome the 50K limitation on a network with 16,382 devices going to the same DNS, I would appreciate the recommendation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: even though the network can grow up to 16,382 hosts, we only have up to 7000 active hosts actively issuing the DNS request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 00:41:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35814#M7563</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-16T00:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35815#M7564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&amp;gt; Hi Tim, thank you very much for always giving a hand when needed. I have been reading about this all issue and I found out that the number of availbale ports is further devided to the number of CoreXL fw instances.&amp;nbsp; My other question is whether there is any command that can show how many ports are assigned to each coreXL fw instances.&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hide NAT ports are dynamically shared and allocated among the CoreXL instances starting in R77.30.&amp;nbsp; The static allocation of Hide NAT ports was a big limitation in R77.20 and earlier and was covered in the first edition of my book.&amp;nbsp; See &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656"&gt;Dynamic NAT port allocation feature&lt;/A&gt;.&amp;nbsp; So there is really no need to track how many Hide NAT ports are in use by a CoreXL instance (Firewall Worker) since it can always allocate one from the pool assuming there is one available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the setup in the &lt;A href="https://community.checkpoint.com/thread/5232"&gt;R80.10 - Hide behind many question&lt;/A&gt; post is appropriate for your situation.&amp;nbsp; Since it sounds like there will be a crapload of DNS traffic going through the firewall, if it will be a cluster I'd strongly recommend disabling cluster synchronization on the Advanced properties for service domain-udp, as your cluster sync network is likely to get overloaded by all the rapid-fire recursive DNS lookups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 01:17:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35815#M7564</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-16T01:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35816#M7565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes we are using a cluster in load sharing unicast mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks once again&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 01:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35816#M7565</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-16T01:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35817#M7566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Again Tim, I have been looking for a command to show whether the Hide NAT connection is being dropped dute to port Exhaustion.&lt;/P&gt;&lt;P&gt;Any hints?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 10:54:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35817#M7566</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-16T10:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35818#M7567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is any kind of counter to examine, you just need to watch for this error message in your logs: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69480&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk69480: 'NAT Hide failure - there are currently no &lt;STRONG&gt;available&lt;/STRONG&gt; ports for hide operation' log appears repeatedly in SmartView Tracker&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 11:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35818#M7567</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-16T11:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35819#M7568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim&lt;/P&gt;&lt;P&gt;As I have mentioned, we have a clustering solution in load sharing unicast mode, we I run the suggest command on both cluster members, I get different number of concurrent connections&amp;nbsp; I get different counters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 1:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#fw tab -u -t connections | grep -ci &lt;SPAN&gt;294E11EE&lt;/SPAN&gt;&lt;BR /&gt;57475&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;# fw tab -u -t connections | grep -ci 294E11EE&lt;BR /&gt;53514&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Are these counters isolated from each member? in the sense that each member is showing how many connections it has towards the limit which is 50k separately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Does it represents the counter for the entire cluster (combining the connections from both cluster members)?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Why is it showing different counters (one is&amp;nbsp;&lt;SPAN&gt;53514, and the other is&amp;nbsp;53514&lt;/SPAN&gt; )?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks once again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 13:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35819#M7568</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-16T13:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35820#M7569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would have to diff the raw un-grepped output to figure out the differences between the two members, but they don't seem far enough off to me to indicate a problem is present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 21:02:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35820#M7569</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-16T21:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35821#M7570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim, thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the commands you provided helped me explain how the problem was not in the firewall. For a second I forgot to devide by 2 and I got scared lol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are about to implement the Manual NAT today in order to assign additional range for the public IPs, because our DNSs have rule to block a certain number of concurrent traffic from a specific IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am again following the instructions you provided about the Manual NAT (many-to-few), so far it worked so well in my Lab. Now I have to implement in the production environment.&lt;/P&gt;&lt;P&gt;Just as an additional question is, since I have a cluster in load sharing, I have to create ARP entry on both members right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, I just ordered your book from Amazon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thank you a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 21:10:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35821#M7570</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-16T21:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35822#M7571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," style="max-width: 840px;"&gt;sk30197: Configuring Proxy ARP for Manual NAT&lt;/A&gt; as the exact steps for adding proxy ARPs vary widely depending on OS, cluster mode, and version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2018 21:43:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35822#M7571</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-16T21:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35823#M7572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything worked as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 00:35:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35823#M7572</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-10-17T00:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35824#M7573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything seems to be working now, but the access to the corporate resources is very slow specially when accessing through a browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints on how this issue could be overcome? Or some suggestions to improve the response time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 03:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35824#M7573</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-11-06T03:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35825#M7574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please characterize the bad performance?&amp;nbsp; Does the web browser:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Spin for a long time then the entire page loads relatively quickly&lt;/LI&gt;&lt;LI&gt;Page starts loading immediately but elements load slowly one by one&lt;/LI&gt;&lt;LI&gt;Most of page loads quickly but last few elements hang&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 13:56:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35825#M7574</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-06T13:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35826#M7575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Spin for a long time then&amp;nbsp; page loads quickly but few elements load slowly one by one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 14:07:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35826#M7575</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-11-06T14:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35827#M7576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, is all the content being rendered for the loading webpage located on the one server using the Hide NAT?&amp;nbsp; In other words are there external references to other web servers for part of the loading content?&amp;nbsp; That might give you a clue about what is holding you up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use of Hide NAT should not cause this slow loading behavior on its own, since you are seeing a couple of different elements here I'd say taking a full tcpdump of the page load process and pulling it into Wireshark is probably the only definitive way to determine what is going on.&amp;nbsp; When looking at the capture, be on the lookout for long gaps of time between network activity while the page is still trying to load (Wireshark can be configured to sort packet times by the largest inter-packet delays instead of absolute timestamp which is great for situations like these).&amp;nbsp; This should start giving you hints about whether the long delays are mainly caused by the client waiting for the server or the server waiting for the client, which should give you an idea of where to start looking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 14:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35827#M7576</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-06T14:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35828#M7577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; @&lt;A _jive_internal="true" class="" data-userid="41625" data-username="d401179d-0d5b-369d-a0f2-387c3ef54533" href="https://community.checkpoint.com/people/d401179d-0d5b-369d-a0f2-387c3ef54533" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 200; text-decoration: none; font-size: 1.286rem;"&gt;Timothy Hall&lt;/A&gt;&lt;SPAN style="color: #e45785; background-color: #ffffff; font-weight: 500;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;IMG alt="Campeão" class="" height="16" src="https://community.checkpoint.com/resources/statics/rolebadges/roleBadge-4-1013-1507073279203.png?a=1507073279265" style="color: #e45785; background-color: #ffffff; border: 0px; font-weight: 500; font-size: 10.9998px; margin: 0px 2px -3px -1px;" title="Campeão" width="16" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am struggling to undertand what has been said in&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk27396 (&lt;EM&gt;see extract in picture bellow&lt;/EM&gt;).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74149_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;Does it mean that I can have more 50K concurrent connections using a single Hide NAT IP if it is to a different destination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I have used the command you showed me to check the number of concurrent connections. I&amp;nbsp;get 146232 coonections using a single Hide NAT IP. How do I know if it is to the same destination? if it is to different destination, do connections dont get dropped? because if I devide this number by 2, I get more than 50K limit. How can tell if any connection was dropped if I dont see any logs on smartView Tracker.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74155_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2018 16:04:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35828#M7577</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-11-12T16:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35829#M7578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately there are a lot of different ways to get to the "NAT Hide failure - there are currently no available ports for hide operation" message , so I've never really been able to conclusively determine if Check Point can support more than 50k hide NATs behind the same source IP address as long as the destinations are unique.&amp;nbsp; It is alluded to in several SKs that this is possible but I've gotten that error message enough times over the years to be wary.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will probably need a definitive answer from R&amp;amp;D, so I'm tagging &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌ here and hopefully he can find out for us if it is possible, and when it became possible (version-wise) because I'm pretty sure this has not been possible since the very beginning.&amp;nbsp; Probably changed around version R75 or so which is also when "many to fewer" Hide NATs became possible:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238" title="https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238"&gt;https://community.checkpoint.com/message/6516-r8010-hide-behind-many-question#comment-8238&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2018 19:58:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35829#M7578</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-12T19:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35830#M7579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Theoretically, yes.&lt;/P&gt;&lt;P&gt;In reality, there are some caveats to getting to 50,000 connections to the same destination IP.&lt;/P&gt;&lt;P&gt;Of course, there are only so many ports connections connections can be multiplexed through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is why things like Carrier-Grade NAT exist as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll see if I find the right resource to comment on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2018 20:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35830#M7579</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-12T20:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT: Simultaneous Connections to the same destination</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35831#M7580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Does it mean that I can have more 50K concurrent connections using a single Hide NAT IP if it is to a different destination?&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The same port can be used again, if the connection is to a different destination, or using a different NAT hide IP address, or is a different IP protocol (e.g. TCP and UDP).&lt;/P&gt;&lt;P&gt;A single hide behind a single hide IP will be enough, unless you have more than 50K simultaneous connections to the same destination.&lt;BR /&gt;In that case you will need to hide behind a range of hide addresses.&lt;/P&gt;&lt;P&gt;The outbound connections are split among the HIDE range using X mod N.&lt;/P&gt;&lt;P&gt;That means that the same source IP will always get the same hide IP.&lt;BR /&gt;So if we have a lot of connections from the same source to the same destination, we will be out of ports, and hiding behind a range will not solve the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I have used the command you showed me to check the number of concurrent connections. I&amp;nbsp;get 146232 connections using a single Hide NAT IP. How do I know if it is to the same destination?&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;Right now, there isn't a good way to do this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;If you suspect this is an issue, we have a way to determine this with an internal script that parses the fwx_alloc table.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;You can send the output of &lt;STRONG&gt;fw tab -t fwx_alloc -u&lt;/STRONG&gt;&amp;nbsp;during your peak connection time and we can run it for you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;This can be captured from your standby node.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;Note that we&amp;nbsp;do plan to expose these HIDE NAT statistics in later releases.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2018 23:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Hide-NAT-Simultaneous-Connections-to-the-same-destination/m-p/35831#M7580</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-20T23:37:54Z</dc:date>
    </item>
  </channel>
</rss>

