> Source: [sk174104](https://support.checkpoint.com/results/sk/sk174104)

# sk174104 - Traffic does not pass through the Security Gateway when NAT is configured to use an IP Range and the size of the NAT kernel table is limited

| Property | Value |
|----------|-------|
| Solution ID | sk174104 |
| Date Created | 2021-06-20 |
| Last Modified | 2021-06-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Traffic does not pass through the Security Gateway / Cluster.

* Kernel debug "`fw ctl zdebug drop`" on the Security Gateway / Cluster Members shows that the traffic is dropped:


  `fw_xlate_new_conn_from_template: fwx_apply_hide failed. packet will be dropped.;`

* Output of the "`fw tab -t connections | grep -i limit`" command on the Security Gateway / Cluster Members shows that the size of the Connections kernel table ("connections", ID 8158) is limited to a value other than the default.

* Output of the "`fw tab -t fwx_alloc | grep -i limit`" command on the Security Gateway / Cluster Members shows that the size of the NAT kernel table ("fwx_alloc", ID 8157) is limited to a value other than the default.

* Output of the "`fw tab -t fwx_alloc -s`" command on the Security Gateway / Cluster Members shows that the value of "#PEAK" (maximal number of NAT connections) exceeds the limit configured for the NAT kernel table.

* NAT is configured to use an IP Range.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
