Can a firewall show more XLATE created than CONNECTIONS?
Is that theoretically possible to have more XLATEs than the total number of connections?. the reason I am asking, that assuming a Cisco 5510 has have maximum 130,000 total connections, however xlate limit on an ASA is considered as UNLIMITED.
I am designing a large network having multiple CIsco ASAs deployed as multi context mode to cater various networks inside the organization. I want to create proper resources per class. So far Xlate count vs. connection count is not very clear.. I tried putting a very large value for xlate and the firewall accepted it, and still showed the total percentage as 0%
Xlates default all CA unlimited
123 2 C 2147483647 4294967294 0.00%
All Contexts: 3 4294967294 0.00%
Whereas connection count is shown as
Conns default all CA unlimited
123 2 C 65000 130000 100.00%
All Contexts: 3 130000 100.00%
Any help is highly appreciated.