Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Muazzam
Contributor
Contributor

Port re-use issue on R80.20

Hardware: 13800 or 23500
OS: GAIA R80.20 T103 or T161
Blades: Only FW


Overall utilization of the firewall is low, throughput around 100-200 Mbps, cores mostly in single digits.
Interface drops: Some drops but less than 0.001%

We have similar issues on multiple firewalls but not able to find any clear SK on our issue.
What we found is that firewall use the same NAT source port before a previous connection has completely expires and this cause a drop on the vendor side among other symptoms we have seen.

There are other factors that we are considering as the traffic goes from end-user to proxy to load balancer, multiple NAT's involved, finally traffic goes to out to the external vendor.

Just wondering if anyone has seen the port NAT source port re-use issue?
I heard that R80.40 works in a different way for allocating the NAT ports?

0 Kudos
2 Replies
the_rock
Legend
Legend

I have a feeling below might be your solution...but if not, you may wish to contact TAC possibly and confirm.

 

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
Muazzam
Contributor
Contributor

The SK looks related to this issue.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events