Forum Discussion
Remove subnet from NAT pools without any impact
- Sep 07, 2023
Hi zztop123 ,
Look ,
you should first see how this pool of NAT IPs used , see if it's used by huge amount of traffic , or by little or isn't used.
if this subnet not used , you can remove it , it will not cause any impact.
but if this subnet is used much in NATing you should remove it , as you maybe impacted by port exhausion so at this case you shouldn't remove it.
So the impact only is with port exhausion not anything else.
Hi Mohammed,
Its not SNAT pool , just a NAT pool. is the procedure the same for it ? Please find the screen shot
Hi zztop123 ,
ohh , this AFM NATing.
first you need to see if this subnet is used in transulations or not
> look at logging profile.
> use this command on bash ( #tmsh show sys connection > /var/tmp/AFM_NAT.txt )
This is the Article to view the connections : https://my.f5.com/manage/s/article/K53851362
you can use filters
I recommended to move these the connections to a text file , because it may impact your device performance if you viewed these connections in bigip cli.
then remove this subnet.
but I can't measure the impact if there is impact from removing this subnet , it depends on your number of subscribers.
Seeing if this subnet is used much or not may help you to detect if this will case a shortage in available ips or not.
If this a deterministic NAT you can calculate the estimated number of reserved ips for each subscriber , look at this article : https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/cgn-implementations-11-5-0/13.html
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com