<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Connection timeouts when using FusionAuth with GCP Cloud NAT]]></title><description><![CDATA[<p dir="auto">When running FusionAuth in containers on Google Cloud Platform with Cloud NAT configured for static IP assignment, we're experiencing intermittent connection timeouts and failures when making outbound connections from our application to FusionAuth.</p>
<p dir="auto">The issue appears to be related to network connectivity, but FusionAuth itself seems to be running correctly. The timeouts occur sporadically under load.</p>
<p dir="auto">Our setup:</p>
<ul>
<li>FusionAuth running in containers on GCP</li>
<li>Cloud NAT configured to assign static IP addresses to containers</li>
<li>Intermittent connection failures to FusionAuth APIs</li>
</ul>
<p dir="auto">Has anyone encountered similar networking issues when using FusionAuth with GCP Cloud NAT?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3153/connection-timeouts-when-using-fusionauth-with-gcp-cloud-nat</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 00:55:22 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3153.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 06:24:33 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Connection timeouts when using FusionAuth with GCP Cloud NAT on Mon, 28 Sep 2026 06:24:44 GMT]]></title><description><![CDATA[<p dir="auto">This issue is not actually related to FusionAuth itself, but rather to <strong>GCP Cloud NAT port allocation limits</strong>.</p>
<p dir="auto">By default, Cloud NAT only allocates <strong>64 TCP ports per VM</strong> for outbound connections. When your application makes many concurrent connections to FusionAuth (or any external service), you can quickly exhaust these ports, leading to connection timeouts.</p>
<h2>Solution</h2>
<p dir="auto">Enable dynamic port allocation and increase the port range with this gcloud command:</p>
<pre><code class="language-bash">gcloud compute routers nats update cloud-nat \
  --router=&lt;ROUTER&gt; \
  --region=&lt;REGION&gt; \
  --project=&lt;PROJECT&gt; \
  --enable-dynamic-port-allocation \
  --min-ports-per-vm=1024 \
  --max-ports-per-vm=32768
</code></pre>
<p dir="auto">Replace <code>&lt;ROUTER&gt;</code>, <code>&lt;REGION&gt;</code>, and <code>&lt;PROJECT&gt;</code> with your actual GCP resource names.</p>
<p dir="auto">This increases the available ports from 64 to between 1024-32768 per VM, which should resolve the connection timeout issues.</p>
<h2>Additional Considerations</h2>
<p dir="auto">While this is primarily a GCP infrastructure issue, if you continue to experience connection problems after adjusting your NAT configuration, consider reviewing:</p>
<ul>
<li><strong>Network latency between FusionAuth and your database</strong> - High latency or unstable network connectivity can cause database connection pool exhaustion, which may manifest as API timeouts</li>
<li><strong>Connection pooling settings</strong> - Ensure your application is properly reusing HTTP connections to FusionAuth rather than creating new connections for each request</li>
<li><strong>Load patterns</strong> - Monitor whether timeouts occur during specific load patterns that might indicate resource constraints</li>
</ul>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/operate/secure/networking" rel="nofollow ugc">FusionAuth Networking Configuration</a> - Configure how FusionAuth determines client IP addresses and network settings</li>
<li><a href="https://fusionauth.io/docs/operate/troubleshooting/#troubleshooting-api-calls" rel="nofollow ugc">Troubleshooting Connection Issues</a> - General guidance on troubleshooting API calls and connectivity</li>
<li><a href="https://fusionauth.io/blog/fusionauth-google-kubernetes-engine-deployment" rel="nofollow ugc">Deploying FusionAuth on Google Kubernetes Engine</a> - Best practices for running FusionAuth on GCP</li>
<li><a href="https://fusionauth.io/partners/google-cloud" rel="nofollow ugc">Google Cloud Platform with FusionAuth</a> - Overview of deploying FusionAuth in GCP environments</li>
</ul>
<h2>External Resources</h2>
<ul>
<li><a href="https://cloud.google.com/nat/docs/ports-and-addresses" rel="nofollow ugc">GCP Cloud NAT port allocation documentation</a></li>
<li>Consider monitoring your NAT port usage to right-size these settings for your workload</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8645</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8645</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 06:24:44 GMT</pubDate></item></channel></rss>