The SNAT IP expansion described in https://my.f5.com/manage/s/article/K33355231 is not applicable in this case, as there is no SNAT in the VS configuration. The recommended actions written on the article above are applicable mostly to typical configurations with a (standard) VS using SNAT (either Automap or SNAT pool). But, in case of AFM, it is not applicable.
The other option to solve the issue is to reduce or lower the value idle-timeout value that is too 'long'. Saving flow connections during 1 complete day seems to cause issues for its intended destination.
However, the second option may pose problems as there are possibly long lived connections. Is there any other way to solve the issue?
Hi @lttarvina - hopefully someone from the community can reply, but in case they don't, I'll see about finding someone from F5 to answer your questions.
Hello, and thanks for your feedback.
No one has answered my question yet.
Take a look at the AFM operations guide, "Port Exhaustion" section. It recommends to setup NAT/PAT.