Description

This article explains the difference in the behavior of flow mode as compare to the packet mode in Junos. The command 'show security nat incoming-table' in flow mode does not generate any output or always shows '0' as the output.

Symptoms

The show security nat incoming-table command does not generate any output in the flow mode of Junos.

Solution


In the older Junos version, the NAT was invoked in the Policy itself and the NAT incoming-table Display Network Address Translation (NAT) table information.

This command was introduced in Junos release 8.5 and node options were added in Junos release 9.0. In the new Junos version, NAT has ben moved to a separate module and the the output of the show security nat incoming-table does not generate any output.

This command is not applicable for the flow mode in Junos and has been removed from Junos 11.2 onwards.


In Junos version 10.4 :

root> show security nat incoming-table
In use: 0, Maximum: 512, Entry allocation failed: 0

In Junos version 11.2 :

root> show security nat ?
Possible completions:
destination Show destination NAT information
interface-nat-ports Show interface nat ports information
source Show source NAT information
static Show static NAT information


In older Junos version :

root> show security nat incoming-table
In use: 1, Maximum: 1024, Entry allocation failed: 0
Destination Host References Timeout Source-pool
10.1.1.26:1028 1.1.1.10:5060 1 3600 p1