sk183481 - In ElasticXL, each Security Group Member allocates only 1785 ports for Hide NAT instead of approximately 16600 ports
In ElasticXL, each Security Group Member allocates only 1785 ports for Hide NAT instead of approximately 16600 ports
Product: ElasticXL
Version: R82, R82.10
OS: Gaia
Last Modified: 2025-11-05
Symptoms
- In ElasticXL, when moving to the context each Security Group Member with the
membercommand, the CPview tool >Advancedtab >NATtab >Pool-IPv4page > theHigh portsection > theCapacitycolumn shows 1785 ports for Hide NAT
Example:
Cause
Incorrect calculation of Hide NAT ports in ElasticXL (50000 / 28 = 1785 instead of 50000 / 3 = 16666).
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 44
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue ( requires manual configuration).
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the ElasticXL involved in the case.
Configuration Part 1 of 2 - Install the hotfix
Refer to the R82 Scalable Platforms Administration Guide > Chapter "Common Procedures for Scalable Platforms" > Section "Installing and Uninstalling a Hotfix on Security Group Members".
Configuration Part 2 of 2 - Enable the fix (Zero Downtime procedure)
Important Notes:
Follow these steps only on the Active ElasticXL Site. The Standby ElasticXL Site will synchronize the required configuration from the Active ElasticXL Site.
- Steps in Gaia Portal to see the state of each ElasticXL Site:
- Connect to Gaia Portal on the ElasticXL.
- In the left panel, click Cluster Management.
- In Gaia gClish to see the state of each ElasticXL Site:
- Connect to the command line on the ElasticXL.
- Log in.
- If the default shell is the Expert mode, then go to Gaia gClish:
gclish - Run:
show cluster info overview
- Steps in Gaia Portal to see the state of each ElasticXL Site:
If the Security Group Member 1_01 is currently not part of the Security Group, then during this procedure, run the required commands on the ElasticXL Cluster Member 1_02. In such a case, the Security Group may drop some traffic.
Enabling the fix:
Connect to the command line on ElasticXL.
Log in.
If the default shell is the Expert mode, then go to Gaia gClish:
gclish
- Make sure the ElasticXL Cluster Member 1_01 is in the state "ACTIVE".
show cluster info overview
- Change the state of the ElasticXL Cluster Members 1_2 and 1_3 to "DOWN".
set cluster members-admin-state ids 1_2 down
set cluster members-admin-state ids 1_3 down
- Go from Gaia gClish to the Expert mode:
- If the default shell is the Expert mode, then exit from Gaia gClish:
exit
- If the default shell is Gaia gClish, then go to the Expert mode:
expert
- Enable the fix:
exl_cli set cluster increase_nat_ports [--force]
The "--force" option applies the change to all Active Security Group Members, which may cause:
- A temporary packet loss
- A temporary reset of NAT connections
- A brief network disruption
- Go from the Expert mode to Gaia gClish:
- If the default shell is the Expert mode, then go to Gaia gClish:
gclish
- If the default shell is Gaia gClish, then exit the Expert mode:
exit
- Change the state of the ElasticXL Cluster Members 1_2 and 1_3 to "UP".
set cluster members-admin-state ids 1_2 up
set cluster members-admin-state ids 1_3 up
- Examine the number of allocated Hide NAT ports:
- Run:
cpview
2. At the top, click the "Advanced" tab > click the "NAT" tab > click the "Pool-IPv4" tab.
3. In the "High port" section, examine the "Capacity" column - it must show the value 16600 (approximately).
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.