black listing of web traffic

Andrey Gordon andrey.gordon at
Tue Feb 9 22:29:59 UTC 2010

By changing my outbound IP address to a different one (i suspect effectively
resetting sessions) the problem was solved. So, after that I set it back to
the original source NAT. And the sites open up just fine still. It really
behaves like a NAT table exhaustion, but the firewall only reports 13000
sessions in progress for all the NAT addresses on that firewall. I'm
thinking memory leak or something. We only put that device in place this
winter break and this is the second time this is happening. Last time was
about 2-3 weeks ago.

Seems to be fixed for now and the f/w dude is opening a ticket with the f/w

Andrey Gordon [andrey.gordon at]

More information about the NANOG mailing list