Hi, If my calculations were correct you might not have enough of public IP > space for this. Increasing the port-limit is not going to help here, as the > contention is on the number of ports a single public IP can open.
One more thing to add here, even though 2048 port limit looks too much but this include TCP + UDP + ICMP flows, It doesn't differentiate. Secondly you can't find out if it is handful of subscribers causing the port exhaustion on their limits and resulting packet drops or this is happening across the board. Probably put a host and try simulating it on your own. CGN is always tricky to tweak. I'm using A10 now and sometime face similar kind of issues.. -- Best Wishes, Aftab A. Siddiqui _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
