Azure Firewall: Identifying SourceIPs with High SNAT Port Utilization

SafiyullahSA 85 Reputation points
2024-04-19T10:09:20.6333333+00:00

I received an alert that the SNAT port utilization for my Azure Firewall is high. Is there a way to see which SourceIPs are consuming more SNAT port data? I tried using a Kusto query but was unsuccessful. Can anyone help me identify the SourceIPs with high SNAT port utilization for my Azure Firewall?

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
674 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 26,216 Reputation points Microsoft Employee
    2024-04-21T23:43:04.7766667+00:00

    @SafiyullahSA

    Thank you for reaching out.

    I understand you are getting SNAT port exhaustion alert for your Azure Firewall. And you wish to know which Source IP contributed the most in SNAT port exhaustion.

    I think Top flows log will be helpful in this scenario. The Top flows log (known in the industry as Fat Flows), shows the top connections that are contributing to the highest throughput through the firewall. This query returns the top flows across Azure Firewall instances and these are the columns available.

    Meanwhile as documented here If your firewall is running into SNAT port exhaustion, you should add at least five public IP address. This increases the number of SNAT ports available.

    Hope this helps! Please let me know if you have any questions. Thank you!


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.