> Source: [sk159572](https://support.checkpoint.com/results/sk/sk159572)

# sk159572 - Port exhaustion issue in R80.20SP Maestro Security Group when using NAT and L4 Distribution

| Property | Value |
|----------|-------|
| Solution ID | sk159572 |
| Date Created | 2019-08-01 |
| Last Modified | 2024-12-10 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |
| Platform | 15000, 3000, 5000, 7000, 28000, 9000, 16000, 26000, 19000, 29000, 6000 |

## Symptoms

- * A port exhaustion issue occurs when you use NAT with Maestro.

* NAT-related traffic is dropped.

* There are "`allocate_port_impl: could not find a free port`" log messages in the `$FWDIR/log/fwk.elg` file.

* There are "`fw_xlate_new_conn_from_template: fwx_apply_hide failed. packet will be dropped`" log messages in the `$FWDIR/log/fwk.elg` file.

* The output of kernel drop debug contains "`fw_first_packet_xlation Reason: NAT rulematch failed`" messages.

## Cause

The default traffic distribution configuration in Maestro Security Groups is:

* In R80.20SP - **Manual-General**
* In R80.30SP, R81 and higher - **Auto-Topology (Per-Port)**

When using the "Manual-General" distribution mode, each Security Group Member cannot use the entire range of NAT ports.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
