CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-05
Junior Member
 
Join Date: 2007-03-12
Posts: 15
Rep Power: 0
elzilcho has an average reputation (10+)
Default Number of connections behind Hide NAT

Apologies in advance if this makes no sense, it's been a long week....

Can anyone confirm:

a) How many connections a Hide NAT can manage?
b) Whether the limit is per-Hide NAT or global?

There are a number of Hide NATs on the firewall, each hiding pretty large internal ranges- eg 10.1.x.x /12 behind 1.x.x.1, 10.2.x.x /12 behind 1.x.x.2 etc...

Basically, the firewall keeps running out of ports to allocate to devices, so users can't get to the net. I need to know if breaking the Hide NATs down would help.

Also, when it reaches this stage, I am having to reboot the firewalls- is there a command that will allow me to do this without rebooting? And (finally) is there a way of seeing how many connections are using a particular hide NAT?

Cheers!

Last edited by elzilcho; 2007-10-05 at 06:24. Reason: Forgot to add bit at the bottom...
Reply With Quote
  #2 (permalink)  
Old 2007-10-05
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Number of connections behind Hide NAT

I never really tested, but I'm guessing that as you have 65535 ports (ignoring 0), you can probably hide a similar number of connections behind each IP.

You need to bear in mind that most machines will open quite a few, especially web browsers tend to open loads.

In most cases the firewall will struggle with the number of connections before the NAT even becomes an issue, but if you already increased the connection table, maybe you might need to split the Hide NAT rule and have maybe 2 or something.

To check number of connections edit your gateway object and check under "Capacity Optimization".
Reply With Quote
  #3 (permalink)  
Old 2007-10-05
Junior Member
 
Join Date: 2007-03-12
Posts: 15
Rep Power: 0
elzilcho has an average reputation (10+)
Default Re: Number of connections behind Hide NAT

Thanks Mario.

So to clarify, each Hide NAT should (in theory) have 65535 available ports behind it?

And is there a way of determining how many connections are currently using a specific Hide NAT?

Last edited by elzilcho; 2007-10-05 at 08:36.
Reply With Quote
  #4 (permalink)  
Old 2007-10-05
Junior Member
 
Join Date: 2007-10-01
Posts: 6
Rep Power: 0
bglass has an average reputation (10+)
Default Re: Number of connections behind Hide NAT

I'm not sure of a way to view specific NAT entries, but the following command will show the number of NATs currently being used:

fw tab -t fwx_alloc -s

You can clear this table without rebooting with the following command:

fw tab -t fwx_alloc -x

Obviously, this will force a lot of sessions to reconnect, but at least you don't have to reboot.
Reply With Quote
  #5 (permalink)  
Old 2007-10-08
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Number of connections behind Hide NAT

Quote:
Originally Posted by elzilcho View Post
Thanks Mario.

So to clarify, each Hide NAT should (in theory) have 65535 available ports behind it?
With NGX its even more than that, as the mapping is done per destination.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:17.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0