Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DominusRex23
Explorer
Jump to solution

NAT HIDE FAILURE

Hide NAT Failure – Need Advice

Client is getting Hide NAT failure errors in ElasticXL setup. CPview shows only 1,785 available ports for hide NAT, which is way too low. Normally, we expect around 50,000 ports per hide IP to avoid session drops.

Has anyone encountered this issue in ElasticXL?

 

 

image (4).pngimage (3).png

0 Kudos
1 Solution

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

This is a known issue, see: 

https://support.checkpoint.com/results/sk/sk183481

The patch is slated to be in the next JHF release (it's in the list of upcoming fixes in the JHF page) but TAC can supply it immediately if you raise a case and cite that SK.

View solution in original post

3 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

This is a known issue, see: 

https://support.checkpoint.com/results/sk/sk183481

The patch is slated to be in the next JHF release (it's in the list of upcoming fixes in the JHF page) but TAC can supply it immediately if you raise a case and cite that SK.

Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Emma has provided the correct solution.

In case your interested in further background sk159572 provides a bit of a history lesson / alternate workarounds regarding NAT config.

CCSM R77/R80/ELITE
0 Kudos
the_rock
MVP Gold
MVP Gold

Since it is a known issue, maybe check if below is set to 1, if not, just set it and see if any luck.

Andy

fw ctl get int fwx_gnat_enabled

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events