What is a SNAT port of a Azure FW?

Ananya Sarkar 311 Reputation points
2021-01-05T14:32:39.93+00:00

Hi,

Just need to clear a doubt. What is the SNAT port of an azure FW, for which the SNAT port utilization metrics of the FW gets generated? Is it a single port or any port from 0-65,535?
Is there way to engage only one SNAT port for outbound traffic load from VM behind a FW?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
600 questions
0 comments No comments
{count} votes

Accepted answer
  1. SUNOJ KUMAR YELURU 14,016 Reputation points MVP
    2021-01-05T14:48:12.413+00:00

    Hi @Ananya Sarkar

    Default port allocation
    Each public IP assigned as a frontend IP of your load balancer is given 64,000 SNAT ports for its backend pool members. Ports can't be shared with backend pool members. A range of SNAT ports can only be used by a single backend instance to ensure return packets are routed correctly.

    It's recommended you use an explicit outbound rule to configure SNAT port allocation. This rule will maximize the number of SNAT ports each backend instance has available for outbound connections.

    Should you use the automatic allocation of outbound SNAT through a load-balancing rule, the allocation table will define your port allocation.

    Refer - SNAT port preallocations for tiers of backend pool sizes

    ----------

    Please don’t forget to "Accept the answer" and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.


0 additional answers

Sort by: Most helpful