PDF(5.6 KB) View with Adobe Reader on a variety of devices
ePub(67.1 KB) View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Mobi (Kindle)(67.0 KB) View on Kindle device or Kindle app on multiple devices
Updated:March 26, 2018
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Half entries are created in certain cases where there is a mapping of inside -> outside or when packet is initiated from inside -> outside.
When the router is configured for NAT overload (Port Addess Translation (PAT)) and non-pattable traffic hits the router, non-pattable bind entries get created for this traffic. It leads to this kind of entry in the NAT table:
--- 10.10.10.1 172.16.9.9 --- ---
This bind entry consumes an entire address from the pool. In this example, 10.10.10.1 is an address from an overloaded pool.
That means an inside local IP Address gets bound to the outside global IP which is similar to static NAT. Because of this, until the current entry gets timed out, new inside local IP Addresses cannot use this global IP Address. All the translation created for this bind is 1-to-1 translations instead of overload.
In order to solve this issue, you can use route-maps with dynamic NAT. With route-maps, NAT won't create half-entries or use interface overload instead of pool overload. Non-pattable bindings are not created in case of interface overload.