cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
678
Views
0
Helpful
2
Replies

HELP: NAT translation time out optimization?

paolobyte
Level 1
Level 1

Hi guys I need some of your opinions on how to optimize our nat translations time out

 

First of all here's the current config we have. 

 

ip nat translation timeout 10800
ip nat translation tcp-timeout 10800
ip nat translation udp-timeout 360
ip nat translation dns-timeout 40

 

public IPs allocated: 64

approximate number of translations during peak hours: 250,000

 

Issues we're encountering:

1) We are just on 250K translations entry, yet the pool allocation shows always 100%. I understand there's some non-pattable protocols, we will modify our ACL soon. 

2) Some users are having a hard time establishing a stable session with some AWS sites, Webhosting sites, Cpanel.

 

What I'm seeing in the translation table is that, there's always multiple translation entry to a single user with different inside global (public IPs) addresses which could break their existing tcp session with those services mentioned above as some of them are very strict in terms of source ips when you've logged in.

 

Users are actually getting error messages "Your IP address has changed. please log in again"

 

Any recommendations guys?

2 Replies 2

Hello,

 

what platform (e.g. ISR 4321) is this on, and which IOS version are you running ? Post your config, we might spot something...

We got it sorted by enabling PAP or paired-address-pooling feature :)

 

Review Cisco Networking for a $25 gift card