<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Xlate limits in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/4037073#M1067101</link>
    <description>&lt;P&gt;the show resources commands are not showing this information. Maybe this has changed over the past 8 years. I see no way to tell how high a number we can set. We have pools of ip's NATing to Internet so we can go higher than 65k xlates and we do. This is on an ASA 5555. Some of the resources do show a percentage of possible limits to set but others, like xlates, do not. Even with a limit set in every class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa5555-fw# sh resource allocation&lt;BR /&gt;Resource Total % of Avail&lt;BR /&gt;Conns [rate] 31000 0.00%&lt;BR /&gt;Inspects [rate] 13500 0.00%&lt;BR /&gt;Syslogs [rate] 38000 0.00%&lt;BR /&gt;Conns 392500 39.21%&lt;BR /&gt;Hosts 32000 0.00%&lt;BR /&gt;IPSec unlimited&lt;BR /&gt;Mac-addresses 22000 33.56%&lt;BR /&gt;ASDM 25 12.50%&lt;BR /&gt;SSH Client 15(U) 15.00%&lt;BR /&gt;SSH Server 22 22.00%&lt;BR /&gt;Storage unlimited&lt;BR /&gt;Telnet 15 15.00%&lt;BR /&gt;&lt;STRONG&gt;Xlates 218000 0.00%&lt;/STRONG&gt;&lt;BR /&gt;Routes 4200 0.00%&lt;BR /&gt;Other VPN Sessions 0&lt;BR /&gt;Other VPN Burst 0&lt;BR /&gt;AnyConnect 0&lt;BR /&gt;AnyConnect Burst 0&lt;BR /&gt;IKEv1 in-negotiatio 960 19.20%&lt;BR /&gt;U = Unlimited: Some contexts have no limit and are not included in the total&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2020 19:13:43 GMT</pubDate>
    <dc:creator>jimgriffin</dc:creator>
    <dc:date>2020-02-27T19:13:43Z</dc:date>
    <item>
      <title>ASA Xlate limits</title>
      <link>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923688#M458359</link>
      <description>&lt;P&gt;I have an ASA 5520 in a school environment.&amp;nbsp; I currently only have 1 public IP NATing for about 3000 students.&amp;nbsp; I was wondering if there were any limits per public IP as far as translations go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923688#M458359</guid>
      <dc:creator>mdieken01</dc:creator>
      <dc:date>2019-03-11T22:39:55Z</dc:date>
    </item>
    <item>
      <title>ASA Xlate limits</title>
      <link>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923689#M458360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found anything about the XLATES, but the following gives you the basics about how many connections for all the ASA5500 series devices and what their basic capabilites are.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and do rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2012 22:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923689#M458360</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2012-03-08T22:56:37Z</dc:date>
    </item>
    <item>
      <title>ASA Xlate limits</title>
      <link>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923690#M458361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the "show resource usage summary"&amp;nbsp; or "show resource usage resource Xlates" command on the ASA to see information about ASAs own resource usage and limits.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you are using single public IP address for users with PAT translation I think it limits the connections &lt;/P&gt;&lt;P&gt;65535 as thats the maximum amount of ports you have at our disposal for PAT translations. Not sure if thats the exact amount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2012 13:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/1923690#M458361</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-09T13:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Xlate limits</title>
      <link>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/4037073#M1067101</link>
      <description>&lt;P&gt;the show resources commands are not showing this information. Maybe this has changed over the past 8 years. I see no way to tell how high a number we can set. We have pools of ip's NATing to Internet so we can go higher than 65k xlates and we do. This is on an ASA 5555. Some of the resources do show a percentage of possible limits to set but others, like xlates, do not. Even with a limit set in every class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa5555-fw# sh resource allocation&lt;BR /&gt;Resource Total % of Avail&lt;BR /&gt;Conns [rate] 31000 0.00%&lt;BR /&gt;Inspects [rate] 13500 0.00%&lt;BR /&gt;Syslogs [rate] 38000 0.00%&lt;BR /&gt;Conns 392500 39.21%&lt;BR /&gt;Hosts 32000 0.00%&lt;BR /&gt;IPSec unlimited&lt;BR /&gt;Mac-addresses 22000 33.56%&lt;BR /&gt;ASDM 25 12.50%&lt;BR /&gt;SSH Client 15(U) 15.00%&lt;BR /&gt;SSH Server 22 22.00%&lt;BR /&gt;Storage unlimited&lt;BR /&gt;Telnet 15 15.00%&lt;BR /&gt;&lt;STRONG&gt;Xlates 218000 0.00%&lt;/STRONG&gt;&lt;BR /&gt;Routes 4200 0.00%&lt;BR /&gt;Other VPN Sessions 0&lt;BR /&gt;Other VPN Burst 0&lt;BR /&gt;AnyConnect 0&lt;BR /&gt;AnyConnect Burst 0&lt;BR /&gt;IKEv1 in-negotiatio 960 19.20%&lt;BR /&gt;U = Unlimited: Some contexts have no limit and are not included in the total&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 19:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-xlate-limits/m-p/4037073#M1067101</guid>
      <dc:creator>jimgriffin</dc:creator>
      <dc:date>2020-02-27T19:13:43Z</dc:date>
    </item>
  </channel>
</rss>

