> Source: [sk163772](https://support.checkpoint.com/results/sk/sk163772)

# sk163772 - Traffic drop by "fw_first_packet_xlation Reason: NAT rulematch failed"

| Property | Value |
|----------|-------|
| Solution ID | sk163772 |
| Date Created | 2020-01-17 |
| Last Modified | 2020-01-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Traffic drop with "fw_first_packet_xlation Reason: NAT rulematch failed" in the output of 'fw ctl zdebug + drop' output.   
  SmartLog / SmartView Tracker is showing: 'NAT port is not enough' in the log.
* Changing the *fwx_low_port_quota* and *fwx_high_port_quota* parameters values based on the calculation in [sk69480](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk69480) does not make any difference
* Reboot of the Security Gateway does not fix the issue.

## Cause

This is related to a router which crashed and lost its cache. The rebuilt of the cache is causing the NAT ports to be lost.

Since much NAT is re-initialized from the router, it will exhaust the available NAT ports at Check Point Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
