Forum Discussion
Snat Port Exhausting
Port exhaustion occurs when a single (source) IP exceeds its ability to handle new connections. Each IP has roughly 65,000 ports so that's an opportunity for 65k active and concurrent connections. This is generally only ever an issue with devices that handle heavy loads and that perform source address translation (SNAT) to backend resources. Any given load bearing device will have a maximum active connection count (based on size and throughput characteristics), so there is a finite limit to the number of ports needed. So for one IP it's 65k. For 2 IPs it's 130k active concurrent connections, etc. But I guess my real question is what would you want this alerting function to do? At some threshold (getting close to port exhaustion), would you want it to add more SNAT addresses? Or simply let you know that it's about to happen?
I'm not saying it's not a good idea, but that it just isn't a "feature", and I'm unaware of any software or product that could do this, and would have better insight that the BIG-IP itself. I'd recommend opening a support case to request this feature, but in the meantime it can be done with a little custom coding.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com