No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


After NE40 configures nat and policy routes, the underlying users cannot connect Internet normally via the proxy server

Publication Date:  2012-07-27 Views:  2 Downloads:  0

Issue Description

NE40 connects with the users and configures nat and the policy route application. Only few PCs can connect Internet after the users connect with the proxy server. If they do not use the proxy server, all of them can connect Internet directly.

Alarm Information


Handling Process

1.via disp nat userCommand to check and detect all the single user concurrency number cannot exceed 100, otherwise the connection cannot be established.
re-configure nat service-class 2 connect 3000, change the connecting number of level 2 service-class to 3000 (change the connecting number of service-class 3 more than 3000), all the users of the downlink proxy server can go on line normally. (the changed range must be within the number of service-class 3 and service-class 1, otherwise the error information is prompted).
.the problem can also be solved via re-configuring the sercie-class after flow-action to level 3(by default 200 connections) or level 4 (by default 65535 concurrency connection)

Root Cause

The concurrency number is too small.
because as configure the policy, we do not specify the service-class after flow-action, so service-class is set to level 2 by default, while we can see, via "disp nat service-class", service-class 2 only allows to establish 100 concurrent number by default, so the downlink single private network user can establish 100 concurrent number only. Because the taken users are too many after using the proxy server, so as the connecting number exceeds 100, the TCP connection cannot be established any longer, so the following users cannot go on line.