hi,Harry
A bad news.The dip problem is still alive.
I upgrade software to 5.4r10 this morning,but the problem reappeared after about 5 hours.
Must I upgrade again?
firewall info is as below:
(1)DIP config:
set interface ethernet3 dip interface-ip incoming
set interface ethernet3 ext ip 220.231.14.193 255.255.255.224 dip 4 220.231.14.194 220.231.14.195
set interface ethernet3 ext ip 220.231.14.193 255.255.255.224 dip 7 220.231.14.222 220.231.14.223
set interface ethernet3 ext ip 220.231.14.193 255.255.255.224 dip 11 220.231.14.219 220.231.14.220
set interface ethernet3 ext ip 220.231.14.193 255.255.255.224 dip 6 220.231.14.201 220.231.14.204
set interface ethernet3 ext ip 220.231.14.193 255.255.255.224 dip 5 220.231.14.196 220.231.14.197
set dip sticky
(2)debug flow basic
****** 25986.0: <Trust/ethernet1> packet received [200]******
ipid = 14342(3806), @c7d15110
packet passed sanity check.
ethernet1:172.16.30.24/4006->219.133.60.26/8000,17<Root>
no session found
flow_first_sanity_check: in <ethernet1>, out <N/A>
chose interface ethernet1 as incoming nat if.
flow_first_routing: in <ethernet1>, out <N/A>
search route to (ethernet1, 172.16.30.24->219.133.60.26) in vr trust-vr for vsd-0/flag-0/ifp-null
[ Dest] 46.route 219.133.60.26->220.231.5.1, to ethernet3
routed (x_dst_ip 219.133.60.26) from ethernet1 (ethernet1 in 0) to ethernet3
policy search from zone 2-> zone 1
policy_flow_search policy search nat_crt from zone 2-> zone 1
RPC Mapping Table search returned 0 matched service(s) for (vsys Root, ip 219.133.60.26, port 8000, proto 17)
No SW RPC rule match, search HW rule
Permitted by policy 44
dip alloc failed. dip_id = 0
packet dropped, dip alloc failed
(3)get pport
ns25> get pport
Pseudo port information:
All Ports Single Ports Paired Ports
Index Total allocated - available allocated - available
0 33000 8801 23175 0 1024
(4)when I login firewall,still a lot of error info such as below
## 2008-10-09 16:15:12 : ###Release twin port-xlate DIP [Root][ethernet3], failed free port(25147) in did(4)!
It is so trouble,pls help me to troubleshooting it!
thanks!
BR/Luo