08-20-2009 07:40 PM - edited 03-11-2019 09:08 AM
Hi,
Is there any limits on amount of translation that pix/asa can handle concurrently. Any commands to see this & for correcting it.
Thanks.
08-21-2009 12:21 AM
65535 is the limit for translation slots, this of course refers to PAT and not static NAT.
The limit is set by the amount of TCP/UDP ports numbers available in the TCP/IP stack.
HTH>
08-21-2009 06:06 AM
Correct.
If you're reaching the theoretical limit of translations, you should be investing in more IP's for further translations.
Ports 1024+ is available of the 65535 for each IP you use.
However please note:
Depending on your ASA/PIX your unit may have lower limits on max translations based on its processor and memory capabilities.
08-21-2009 08:03 AM
Also, just a heads up if youre using ASA5505, you have a host license, which can be 10, 50 or unlimited users going through the asa at the same time.
10-23-2009 09:43 AM
Can you please tell me how me how many muximum ip address can be natted with single public ip address.
10-23-2009 10:43 AM
1:1 NAT = 1
1:Many PAT = 65535
HTH>
10-26-2009 04:30 AM
Thnx Andrew,
Did you meen to say, i can nat 65535 IP addresses to one IP address?
10-26-2009 04:55 AM
Not really!! with a 1:many - you will be using Port Address Tranlsation. You could have 1000 internal IP addresses and NAT them to 1 external IP address - and the ASA will have a PAT translation table with specific translation ports.
You could only have 1 internal IP and you could make 10,000 seperate outbound connections to the internet and the same priciple applies.
For every seperate outbound connection, the ASA creates 1 x PAT table entry. So that would be 65535-1 = 65534 left.
HTH>
11-05-2009 01:32 AM
Thnx adrew,
If you have any document on this then please share with me.
11-05-2009 01:45 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide