- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a case for @Timothy_Hall 🙂
We are running VSX R80.30.
There are 10 CoreXL instances, dynamic NAT (sk103656) and SXL NAT templates (sk71200) enabled by default in R80.30
Up until now we used gateway public IP (so single IP) to hide our traffic going to O365 and everything worked without any issues. Dynamic NAT feature handles "hide NAT, dest IP, proto" limitations perfectly.
Today we decided to change the NAT from single IP to IP range (sk140432). Never mind the reasons, but it still should work and technically make it better as we would have more IPs for hide NAT.
BUT! As the sun came up and people returned to work (despite corona virus), we started getting NAT hide failures in logs:
We had 20 IPs actually in the IP range. And SK156852 actually says to use port range instead of single IP 🙂 NOT!
The feeling I get with IP range enabled, "dynamic NAT" gets turned off / ignored and gateway returns to static port pools and they would be rather small with 10 FWK cores plus SXL NAT templates enabled.
Any other ideas?
When doing a many-to-fewer NAT, the same source IP address will always be assigned to the same address pool for source port allocations via a simple modulus function detailed in sk140432. Could the fact that your range of 20 addresses is not a power of 2 (2,4,8,16, etc.) somehow have led to suboptimal distribution of source addresses between the 20 pools? I can't remember ever setting up a many-to-fewer NAT to an address range that was not a power of two for some reason; I don't think it is mandatory but I can't remember why I always did it that way either. 🙂 Worth a try?
Thanks Tim! That's a very good point! I'll see how it works next time as I have ready made NAT stats too to have a quick look!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY