[j-nsp] NAT

Stefan Fouant sfouant at shortestpathfirst.net
Sat Mar 27 19:42:31 EDT 2010


> -----Original Message-----
> From: juniper-nsp-bounces at puck.nether.net [mailto:juniper-nsp-
> bounces at puck.nether.net] On Behalf Of Ibariouen Khalid
> Sent: Friday, March 26, 2010 5:37 PM
> To: juniper-nsp at puck.nether.net
> Subject: [j-nsp] NAT
> 
> Hi all
> Can someone tell me what does "no nat vector means" exactelly :
> 
> 
> GFW01(M)-> get counter statistics interface ethernet1/3
> Hardware counters for interface ethernet1/3:
> in bytes       201903417 | out bytes     2103176764 | early frame
> 0
> in packets    2949387186 | out packets   2468188341 | late frame
> 0
> in no buffer           0 | out no buffer          0 | re-xmt limit
> 0
> in overrun            63 | out underrun           0 | drop vlan
> 0
> address spoof          0 | in icmp        164486382 | no nat vector
> 1977
> 
> 
> in some document No nat vector Indicates the number of packets dropped
> because the Network Address Translation (NAT) connection was
> unavailable for the gate.
> 
> 
> But it's not clear for me ?
> 4 Public ip addresses are enought for 61973 sessions .

If I recall correctly, that means that there aren't enough addresses in the
NAT pool available for connections at the time a given connection is made.
You might have 4 public addresses but do you have PAT enabled?  Can you
describe your setup in more detail?

Stefan Fouant, CISSP, JNCIE-M/T
www.shortestpathfirst.net
GPG Key ID: 0xB5E3803D



More information about the juniper-nsp mailing list