cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
560
Views
6
Helpful
3
Replies

PIX Limit on PAT?

cminch
Level 1
Level 1

Hi,

Does anyone know if there is a limit on PAT?

One problem that we are having it seems that our PAT addresses are not being freed up fast enough. We have the xlate time down to about 30 minutes should we go lower?

Is there a rule of thumb on something like this?

Thanks for any info.

Regards,

Corey

3 Replies 3

nkhawaja
Cisco Employee
Cisco Employee

Logically PAT should have 65536 sessions. I cant say what the physical limit is.

Are the XLAT entries ever freed up? There was a bug earlier in 6.2.2 code in this regard. what code are you running?

Thanks

Nadeem

Nadeem,

It happened in our firewall as well. My firewall is 501 with 6.2(2). How can I do to free up the XLAT entries? Thanks!

manish
Level 1
Level 1

Hi,

Theoritically PAT can handle 64,000 entries. There is no thumb rule. Try reducing the connection timeout also. If you are using 6.2.2 upgrade to some other image, as there is a bug identified in this image.

Thanks,

Manish

Review Cisco Networking for a $25 gift card