Dynamic IP and Port NAT Oversubscription (2024)

Dynamic IP and Port NAT Oversubscription

Updated on

Jul 1, 2024

Focus

Download PDF

Updated on

Jul 1, 2024

Focus

  1. Home
  2. PAN-OS
  3. NAT
  4. Dynamic IP and Port NAT Oversubscription

Download PDF

Table of Contents

Previous NAT Rule Capacities
Next Dataplane NAT Memory Statistics

Dynamic IP and Port (DIPP) NAT allows you to use eachtranslated IP address and port pair multiple times (8, 4, or 2 times)in concurrent sessions. This reusability of an IP address and port(known as oversubscription) provides scalability for customers whohave too few public IP addresses. The design is based on the assumptionthat hosts are connecting to different destinations, therefore sessions canbe uniquely identified and collisions are unlikely. The oversubscriptionrate in effect multiplies the original size of the address/portpool to 8, 4, or 2 times the size. For example, the default limitof 64K concurrent sessions allowed, when multiplied by an oversubscriptionrate of 8, results in 512K concurrent sessions allowed.

The oversubscription rates that are allowed vary based on themodel. The oversubscription rate is global; it applies to the firewall.This oversubscription rate is set by default and consumes memory,even if you have enough public IP addresses available to make oversubscriptionunnecessary. You can reduce the rate from the default setting toa lower setting or even 1 (which means no oversubscription). By configuringa reduced rate, you decrease the number of source device translations possible,but increase the DIP and DIPP NAT rule capacities. To change thedefault rate, see Modify the Oversubscription Rate for DIPP NAT.

If you select

Platform Default

, your explicitconfiguration of oversubscription is turned off and the defaultoversubscription rate for the model applies. The

PlatformDefault

setting allows for an upgrade or downgrade ofa software release.

The Product Selection tool showsthe default (maximum) DIPP pool oversubscription rate for each model.

The firewall supports a maximum of 256 translated IP addressesper NAT rule, and each model supports a maximum number of translatedIP addresses (for all NAT rules combined). If oversubscription causesthe maximum translated addresses per rule (256) to be exceeded,the firewall will automatically reduce the oversubscription ratioin an effort to have the commit succeed. However, if your NAT rulesresult in translations that exceed the maximum translated addressesfor the model, the commit will fail.

"); adBlockNotification.append($( "Thanks for visiting https://docs.paloaltonetworks.com. To improve your experience when accessing content across our site, please add the domain to the allow list on your ad blocker application." )); let adBlockNotificationClose = $("x"); adBlockNotification.prepend(adBlockNotificationClose) $('body').append(adBlockNotification); setTimeout(function (e) { adBlockNotification.addClass('open'); }, 10); adBlockNotificationClose.on('click', function (e) { adBlockNotification.removeClass('open'); }) } }, 5000)

Previous NAT Rule Capacities
Next Dataplane NAT Memory Statistics

Recommended For You

{{ if(( raw.pantechdoctype != "techdocsAuthoredContentPage" && raw.objecttype != "Knowledge" && raw.pancommonsourcename != "TD pan.dev Docs")) { }} {{ if (raw.panbooktype) { }} {{ if (raw.panbooktype.indexOf('PANW Yellow Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Green Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Blue Theme') != -1){ }}

{{ } else { }}

{{ } }} {{ } else { }}

{{ } }} {{ } else { }} {{ if (raw.pantechdoctype == "pdf"){ }}

{{ } else if (raw.objecttype == "Knowledge") { }}

{{ } else if (raw.pancommonsourcename == "TD pan.dev Docs") { }}

{{ } else if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ } else { }}

{{ } }} {{ } }}

{{ if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } else { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } }}

{{ if (raw.pancommonsourcename != "TD pan.dev Docs"){ }} {{ if (raw.pandevdocsosversion){ }} {{ } else { }} {{ if ((_.size(raw.panosversion)>0) && !(_.isNull(raw.panconversationid )) && (!(_.isEmpty(raw.panconversationid ))) && !(_.isNull(raw.otherversions ))) { }} (See other versions) {{ } }} {{ } }} {{ } }}

{{ } }}{{ if (raw.pantechdoctype == "bookDetailPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "bookLandingPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "productLanding"){ }}

{{ } }}{{ if (raw.pantechdoctype == "techdocsAuthoredContentPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

© 2024 Palo Alto Networks, Inc. All rights reserved.

Dynamic IP and Port NAT Oversubscription (2024)
Top Articles
Renters' Insurance
Manage a newsletter on LinkedIn | LinkedIn Help
Danielle Moodie-Mills Net Worth
Visitor Information | Medical Center
Craigslist Cars And Trucks For Sale By Owner Indianapolis
The Realcaca Girl Leaked
35105N Sap 5 50 W Nit
Monticello Culver's Flavor Of The Day
Fallout 4 Pipboy Upgrades
Capitulo 2B Answers Page 40
Connexus Outage Map
Healing Guide Dragonflight 10.2.7 Wow Warring Dueling Guide
All Buttons In Blox Fruits
Magic Mike's Last Dance Showtimes Near Marcus Cedar Creek Cinema
boohoo group plc Stock (BOO) - Quote London S.E.- MarketScreener
Brett Cooper Wikifeet
Vistatech Quadcopter Drone With Camera Reviews
Dark Chocolate Cherry Vegan Cinnamon Rolls
Lonesome Valley Barber
Selfservice Bright Lending
Sussur Bloom locations and uses in Baldur's Gate 3
Tripadvisor Napa Restaurants
Gas Buddy Prices Near Me Zip Code
Pawn Shop Moline Il
Labcorp.leavepro.com
Coindraw App
Ff14 Sage Stat Priority
2487872771
Franklin Villafuerte Osorio
Grays Anatomy Wiki
Craigslist Central Il
Verizon TV and Internet Packages
Palmadise Rv Lot
Directions To 401 East Chestnut Street Louisville Kentucky
Academic important dates - University of Victoria
Ticket To Paradise Showtimes Near Regal Citrus Park
M Life Insider
Сталь aisi 310s российский аналог
Pro-Ject’s T2 Super Phono Turntable Is a Super Performer, and It’s a Super Bargain Too
Sdn Fertitta 2024
Denise Monello Obituary
Toomics - Die unendliche Welt der Comics online
Walmart 24 Hrs Pharmacy
Alba Baptista Bikini, Ethnicity, Marriage, Wedding, Father, Shower, Nazi
Mega Millions Lottery - Winning Numbers & Results
Walmart Front Door Wreaths
Ciara Rose Scalia-Hirschman
How To Win The Race In Sneaky Sasquatch
Billings City Landfill Hours
sin city jili
Chitterlings (Chitlins)
Gelato 47 Allbud
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5856

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.