<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic portmap translation creation failed for tcp src inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177158#M359499</link>
    <description>&lt;P&gt;&lt;STRONG&gt;We have an ASA 5540 with 8.2(5)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Last three days in early afternoon we start getting these errors in the log and webpages either won't load or pages only half load.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|184.73.105.115|443|||portmap translation creation failed for tcp src inside:10.10.176.114/58217 dst outside:184.73.105.115/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1517 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.70|80|||portmap translation creation failed for tcp src inside:10.110.22.50/3968 dst outside:74.125.227.70/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1516 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1515 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.139.125|5222|||portmap translation creation failed for tcp src inside:10.160.230.91/49926 dst outside:74.125.139.125/5222&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|199.7.59.72|80|||portmap translation creation failed for tcp src inside:10.100.22.214/49988 dst outside:199.7.59.72/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|68.67.151.213|80|||portmap translation creation failed for tcp src inside:10.50.183.3/1420 dst outside:68.67.151.213/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|98.139.50.175|80|||portmap translation creation failed for tcp src inside:10.195.38.27/2259 dst outside:98.139.50.175/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|216.252.124.30|80|||portmap translation creation failed for tcp src inside:10.195.38.27/2258 dst outside:216.252.124.30/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|98.137.51.1|443|||portmap translation creation failed for tcp src inside:10.160.230.92/49984 dst outside:98.137.51.1/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.69|80|||portmap translation creation failed for tcp src inside:10.110.22.50/3966 dst outside:74.125.227.69/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.11|443|||portmap translation creation failed for tcp src inside:10.100.52.7/55758 dst outside:74.125.227.11/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|63.111.11.175|5222|||portmap translation creation failed for tcp src inside:10.10.184.106/52130 dst outside:63.111.11.175/5222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here's some of the config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; speed 1000&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 72.xxx.xxx.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; speed 1000&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.1.2 255.255.240.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif DMZ1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif DMZ2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa825-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 42&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor notifications&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside 10.10.3.35&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ1 1500&lt;/P&gt;&lt;P&gt;mtu DMZ2 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool attsupport 172.xxx.xxx.10-172.xxx.xxx.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover polltime unit 15 holdtime 45&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645-106.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 72.xxx.xxx.254&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (outside) 1 172.xxx.xxx.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl-out in interface outside&lt;/P&gt;&lt;P&gt;access-group email_egress in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 72.xxx.xxx.1 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.1.1.1 1&lt;/P&gt;&lt;P&gt;route inside 207.144.48.0 255.255.255.0 10.1.1.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any ideas?&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:19:33 GMT</pubDate>
    <dc:creator>zhuffines</dc:creator>
    <dc:date>2019-03-12T01:19:33Z</dc:date>
    <item>
      <title>portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177158#M359499</link>
      <description>&lt;P&gt;&lt;STRONG&gt;We have an ASA 5540 with 8.2(5)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Last three days in early afternoon we start getting these errors in the log and webpages either won't load or pages only half load.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|184.73.105.115|443|||portmap translation creation failed for tcp src inside:10.10.176.114/58217 dst outside:184.73.105.115/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1517 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.70|80|||portmap translation creation failed for tcp src inside:10.110.22.50/3968 dst outside:74.125.227.70/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1516 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|54.243.129.71|80|||portmap translation creation failed for tcp src inside:10.35.54.37/1515 dst outside:54.243.129.71/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.139.125|5222|||portmap translation creation failed for tcp src inside:10.160.230.91/49926 dst outside:74.125.139.125/5222&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|199.7.59.72|80|||portmap translation creation failed for tcp src inside:10.100.22.214/49988 dst outside:199.7.59.72/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|68.67.151.213|80|||portmap translation creation failed for tcp src inside:10.50.183.3/1420 dst outside:68.67.151.213/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|98.139.50.175|80|||portmap translation creation failed for tcp src inside:10.195.38.27/2259 dst outside:98.139.50.175/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|216.252.124.30|80|||portmap translation creation failed for tcp src inside:10.195.38.27/2258 dst outside:216.252.124.30/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|98.137.51.1|443|||portmap translation creation failed for tcp src inside:10.160.230.92/49984 dst outside:98.137.51.1/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.69|80|||portmap translation creation failed for tcp src inside:10.110.22.50/3966 dst outside:74.125.227.69/80&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|74.125.227.11|443|||portmap translation creation failed for tcp src inside:10.100.52.7/55758 dst outside:74.125.227.11/443&lt;/P&gt;&lt;P&gt;3|Mar 22 2013|13:22:24|305006|63.111.11.175|5222|||portmap translation creation failed for tcp src inside:10.10.184.106/52130 dst outside:63.111.11.175/5222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here's some of the config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; speed 1000&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 72.xxx.xxx.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; speed 1000&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.1.2 255.255.240.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif DMZ1&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif DMZ2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa825-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 42&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor notifications&lt;/P&gt;&lt;P&gt;logging trap notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside 10.10.3.35&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ1 1500&lt;/P&gt;&lt;P&gt;mtu DMZ2 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool attsupport 172.xxx.xxx.10-172.xxx.xxx.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover polltime unit 15 holdtime 45&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645-106.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 72.xxx.xxx.254&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (outside) 1 172.xxx.xxx.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl-out in interface outside&lt;/P&gt;&lt;P&gt;access-group email_egress in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 72.xxx.xxx.1 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.1.1.1 1&lt;/P&gt;&lt;P&gt;route inside 207.144.48.0 255.255.255.0 10.1.1.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any ideas?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177158#M359499</guid>
      <dc:creator>zhuffines</dc:creator>
      <dc:date>2019-03-12T01:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177159#M359500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked the "show xlate count" to see how many translations are active at that moment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe also check the "show conn count" output at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "show perfmon" is also something that tells the current rate of connections and translations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have a very basic Dynamic PAT configuration other than that you have 2 public IP addresses configured so you should have plenty of resource for PAT translations but I cant think of any other limitation at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just seem that this might be one possible reason. It might also explain why the pages load partially. When you load a web page there are most probably several connections involved to load the whole page. Some connections might not succeed because the firewall has exhausted all available translations. But still one would imagine that this would require some really heavy Internet use on your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Too bad your software level doesnt have the command "show nat pool" available &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 18:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177159#M359500</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-25T18:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177160#M359501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Not expereincing any problems when I took these stats.&amp;nbsp; Could we be reaching the limit for sessions behind one NAT IP address?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEX5-Firewall# sho xlate count&lt;/P&gt;&lt;P&gt;42710 in use, 48835 most used&lt;/P&gt;&lt;P&gt;LEX5-Firewall# sho conn count&lt;/P&gt;&lt;P&gt;36936 in use, 41027 most used&lt;/P&gt;&lt;P&gt;LEX5-Firewall# sho perfmon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PERFMON STATS:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Average&lt;/P&gt;&lt;P&gt;Xlates&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 338/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 347/s&lt;/P&gt;&lt;P&gt;Connections&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 388/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 431/s&lt;/P&gt;&lt;P&gt;TCP Conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 323/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 338/s&lt;/P&gt;&lt;P&gt;UDP Conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 90/s&lt;/P&gt;&lt;P&gt;URL Access&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 181/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 184/s&lt;/P&gt;&lt;P&gt;URL Server Req&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;TCP Fixup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21936/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;TCP Intercept Established Conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;TCP Intercept Attempts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;TCP Embryonic Conns Timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3/s&lt;/P&gt;&lt;P&gt;HTTP Fixup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21936/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 618/s&lt;/P&gt;&lt;P&gt;FTP Fixup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;AAA Authen&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;AAA Author&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;AAA Account&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VALID CONNS RATE in TCP INTERCEPT:&amp;nbsp;&amp;nbsp;&amp;nbsp; Current&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Average&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N/A&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 96.00%&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 19:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177160#M359501</guid>
      <dc:creator>zhuffines</dc:creator>
      <dc:date>2013-03-25T19:09:04Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177161#M359502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does seem you have quite abit of connections active on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though that being said it still to my understanding shouldnt even be close to reaching the limit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the fact that you have 2 Public IP address configured with the "global" command using the same "ID" number of the NAT configuration. This should mean that you should have more than enough resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess if you have some spare public IP addresses you could try adding a third PAT IP address with the "global" configuration command and see if theres any change in the situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I fear that this is one of the things where a person outside of Cisco might have problems troubleshooting wihtout trying to lab and reproduce the situation. But to be honest I havent looked at the this kind of situations that much and the few times I have, it have run into the problem that the firewall has been running too old software to actually get some clear output. Thats why I mentioned the "show nat pool" command from newer software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example output from my little ASA5505 running a newer software&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# show nat pool | inc WAN&lt;/P&gt;&lt;P&gt;TCP PAT pool WAN, address x.x.x.x, range 1-511, allocated 3&lt;/P&gt;&lt;P&gt;TCP PAT pool WAN, address x.x.x.x4, range 512-1023, allocated 0&lt;/P&gt;&lt;P&gt;TCP PAT pool WAN, address x.x.x.x, range 1024-65535, allocated 46&lt;/P&gt;&lt;P&gt;UDP PAT pool WAN, address x.x.x.x, range 1-511, allocated 17&lt;/P&gt;&lt;P&gt;UDP PAT pool WAN, address x.x.x.x, range 512-1023, allocated 0&lt;/P&gt;&lt;P&gt;UDP PAT pool WAN, address x.x.x.x, range 1024-65535, allocated 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;WAN = My "outside" interface&lt;/LI&gt;&lt;LI&gt;x.x.x.x = My "WAN" interface IP address&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know if there is a similiar command on your software. I would check the available parameters on the "show xlate" and "show nat" commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the command reference for your software should list the command parameters if you want to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as I said I would probably see if I could add a third PAT IP address and see if it has any kind of effect on the problem. Or perhaps wait if someone from Cisco has run into this before and would have good commands to troubleshoot this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 19:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177161#M359502</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-25T19:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177162#M359503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;STRONG&gt;We have over 12,000 devices on our network.&amp;nbsp; Should we lower these timeout values?&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Connections are going down.&amp;nbsp; After school hours now, I don't have values for what they were during school hours.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LEX5-Firewall# sho xlate count&lt;/P&gt;&lt;P&gt;33200 in use, 48835 most used&lt;/P&gt;&lt;P&gt;LEX5-Firewall# sho conn count&lt;/P&gt;&lt;P&gt;31056 in use, 41027 most used&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;LEX5-Firewall# sho run | i timeout&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;arp timeout 14400&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout xlate 24:00:00&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout conn 12:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;telnet timeout 10&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;ssh timeout 5&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt;console timeout 0&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt; vpn-idle-timeout 45&lt;/P&gt;&lt;P style="color: #000000; font-family: arial; font-size: small;"&gt; vpn-session-timeout none&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 20:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177162#M359503</guid>
      <dc:creator>zhuffines</dc:creator>
      <dc:date>2013-03-25T20:14:25Z</dc:date>
    </item>
    <item>
      <title>portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177163#M359506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well just to compare the stats that we have at our customer range from 3 hours to 9 hours. (for xlate)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the normal situation I would imagine that the translation is torn down after the connection is removed but I guess it wouldnt really hurt to lower the xlate timeout to perhaps closer to the connection timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though as I said if you would want to test with least amount of impact to current operation you could try adding additional PAT IP addresses using the same &lt;ID&gt; in the "global" configuration and monitor of the problem continues.&lt;/ID&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then again the "show xlate count" should already tell the "most used" value for the firewall unless they firewall has rebooted (but I doubt it?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 20:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177163#M359506</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-25T20:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: portmap translation creation failed for tcp src inside</title>
      <link>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177164#M359507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We did reboot the firewall because that was the "fix".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So all the counts were reset.&amp;nbsp; That most used count above was within 15 minutes of rebooting this afternoon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll find out tomorrow if it happens again.&amp;nbsp; Thanks for the info!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 20:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/portmap-translation-creation-failed-for-tcp-src-inside/m-p/2177164#M359507</guid>
      <dc:creator>zhuffines</dc:creator>
      <dc:date>2013-03-25T20:47:20Z</dc:date>
    </item>
  </channel>
</rss>

