NAT Pool configuration to counter PAT exhaustion on WAN interface
Greetings, we have a very busy guest/byod wireless network which has recently started to exceed 1000 clients on a regular basis, up until now it has worked without issue but have had reports that people are frequently unable to connect to the internet at peak times (Lunchtime etc)
Investigations revealed that the WAN router (Cisco 3825) has started exceededing the maximum number of NAT/PAT translations on the external facing interface >65,000 - At one point it was showing as having 72,000 translations.
As such i have decided to create a NAT pool to make use of additonal public address space that we have on our WAN breakout and to load balance PAT across several external IP addresses to counter the problem, however when i look at the NAT translations it still appears that i'm only overloading on the interface IP address and not load balancing ammougst all 5 external addresses in the NAT pool.
interface GigabitEthernet0/0 bandwidth 25000 ip address 213.**.**.33 255.255.255.224 ip nat outside ip virtual-reassembly in rate-limit input 25000000 4687500 9375000 conform-action transmit exceed-action drop rate-limit output 25000000 4687500 9375000 conform-action transmit exceed-action drop duplex full speed 100 media-type rj45
ip nat pool GUEST_WLAN 213.**.**.33 213.**.**.37 prefix-length 27 ! ip nat inside source list NAT pool GUEST_WLAN overload ! ip access-list extended NAT permit ip 192.168.16.0 0.0.7.255 any deny ip any any
sh ip nat translations | include 213.**.**.34 tcp 213.**.**.52:51466 192.168.21.198:51466 18.104.22.168:443 22.214.171.124:443 tcp 213.**.**.34:52574 192.168.21.198:52574 126.96.36.199:443 188.8.131.52:443 --- 213.**.**.34 192.168.21.198 --- ---
sh ip nat translations | include 213.**.**.35 --- 213.**.**.35 192.168.16.223 --- ---
sh ip nat translations | include 213.**.**.36 --- 213.**.**.36 192.168.16.195 --- ---
sh ip nat translations | include 213.**.**.37 --- 213.**.**.37 192.168.21.214 --- ---
Really appreciate if someone could validate if this configuration is correct please? Would i be correct in assuming it wont load balance and will only utilise the pool members when the first one is exhausted?
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...