Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

Multiple Outside NAT Causing VFR Overlap

%IP_VFR-3-OVERLAP_FRAGMENTS
%IP_VFR-4-FRAG_TABLE_OVERFLOW

We see the above errors on Dialer1 which is associated with an ADSL line which we are using with Policy Based Routing (PBR) to offload traffic from our outbound web proxy.  There is an outside NAT on Dialer1 and GigabitEthernet0/1 which is our main public network interface.

It seems to me that the VFR is not properly distinguishing IP packets containing fragments coming from the same IP address but arriving on different different interfaces and using a different NAT address.

What can I do?

 

 

 

Everyone's tags (1)
42
Views
0
Helpful
0
Replies
CreatePlease to create content