cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3967
Views
10
Helpful
4
Replies

How to monitor IP NAT Pool for ASA (Firepower ASA Appliance)

jewfcb001
Level 4
Level 4

Hi All,

I would like to monitor IP NAT POOL If IP NAT Pool Full how can monitor this situation ? Is it trigger or send log for Nat Pool Full ?

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

there are couple ways :

 

1. if you have enabled syslog to syslog server, it will give an error when the pool exhausted.

example : %ASA-3-202010: [NAT | PAT] pool exhausted for pool-name, port range

2. you can run command (show nat pools)frequently  out of box script make a graph or alerts

3. or you can use SNMP polling if you have any NMS in Place and get alerts based on threshold.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

there are couple ways :

 

1. if you have enabled syslog to syslog server, it will give an error when the pool exhausted.

example : %ASA-3-202010: [NAT | PAT] pool exhausted for pool-name, port range

2. you can run command (show nat pools)frequently  out of box script make a graph or alerts

3. or you can use SNMP polling if you have any NMS in Place and get alerts based on threshold.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

jewfcb001
Level 4
Level 4

@balaji.bandi 

Thank you for your information . For Answer Number 3 what is the SNMP polling for IP Nat Pool Full ?

balaji.bandi
Hall of Fame
Hall of Fame

SNMP :

 

1.3.6.1.2.1.123.1.4.1.19. natAddrMapAddrUsed

 

But i you may have differ results snmp polling vs real time show nat pool - because it changes dynamically.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

jewfcb001
Level 4
Level 4

@balaji.bandi 

 

Thank you so much.

Review Cisco Networking for a $25 gift card