homeskillet
IS-IT--Management
We are running NAT for about 150 users. We were having some problems with P2P apps, so we implemented a few new ACL's to block a few ports. However, as soon as we applied the new ACL's, we ran into a problem.
When the router was restarted (for good measure) everything went rather well. We were getting more bandwidth per person than ever before, and the targeted P2P apps would not work.
However, as soon as we get to about 4000 dynamic translations, no one can get through the router anymore...at least until we go in and enter "clear ip nat translation *". As soon as you hit enter, everyone can get through (for a while). SH PROC shows only about 5%.
So...any ideas how to get it to keep working? More memory (there's currently 8MB)? We currently have dynamic translations timing out in 30 seconds, and we tried setting a max number of translations, but that didn't work either.
When the router was restarted (for good measure) everything went rather well. We were getting more bandwidth per person than ever before, and the targeted P2P apps would not work.
However, as soon as we get to about 4000 dynamic translations, no one can get through the router anymore...at least until we go in and enter "clear ip nat translation *". As soon as you hit enter, everyone can get through (for a while). SH PROC shows only about 5%.
So...any ideas how to get it to keep working? More memory (there's currently 8MB)? We currently have dynamic translations timing out in 30 seconds, and we tried setting a max number of translations, but that didn't work either.