Loading...
Loading...
Deployment blocked due to error similar to below error. [ManualNatRule 27] This rule contains a port object with IP range (Original sources, Destinations and Translated sources, Destinations: 262144) exceeding the maximum limit of 131838.
Threat Defense NAT policy having NAT rule(s) using Network objects that exceeds IP range max limit of 131838
Split the network object with IP range exceeding the limit of 131838 into multiple network object and then create multiple NAT rules using them.
Fixed versions will have following message when trying to deploy such config: - Pre-deployment Error message (For 1xxx and 21xx series) : The NAT rule contain port objects and exceeds the maximum limit of 131838 IPs. Reduce the number of IPs and retry deployment. - Pre-deployment Warning Message (For all other devices): The NAT rule exceeds the threshold limit of 131838 IPs. Though the deployment may succeed, the device may encounter instability issues such as high CPU utilization, policy deployment failure, inability to run commands from CLISH, traceback and reload failure. We recommend that you reduce the number of IPs and deploy again.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.