Overload PBA resource quota limitation
Because of an NP7 hardware limitation, for CGN traffic accepted by a hyperscale firewall policy that includes an overload with port block allocation CGN IP Pool, only one block is allocated per client. The setting of the hyperscale firewall policy CGN Resource Quota (cgn-resource-quota)
is ignored.
Because of this limitation, under certain rare conditions (for example, only a single server side IP address and port are being used for a large number of sessions), port allocation may fail even if the block usage of the client is less than its quota.
Here are two possible ways to resolve this issue:
-
In cases such as this, if the client has traffic towards some other servers or ports, additional port allocation can become successful.
-
You can also work around this problem by increasing the IP Pool block size (
cgn-block-size
).