Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Network Address Translation (NAT)

  • Monitor subscriber port utilization (cSRX, MX240, MX480, MX960, SRX1500, SRX1600, SRX2300, SRX4200, SRX4300, SRX4600, SRX4700, SRX5400, SRX5600, SRX5800, and vSRX3.0)–You can monitor and manage port utilization when deploying Carrier Grade Network Address Translation (CGNAT).

    Configure threshold limits to receive notifications when port or port block usage exceeds the configured thresholds.

    • If a pool is configured as Port Block Allocation (PBA) and a subscriber uses more port blocks than the threshold, a notification is generated.

    • For Deterministic NAT (DETNAT) pools, if a subscriber uses more ports than the threshold in the allocated block, a notification is generated.

    The system log messages are:

    • RT_SRC_NAT_SUBS_POOL_ALARM_DAMPENINGRT_NAT: RT_SRC_NAT_SUBS_POOL_ALARM_RAISE: Subscriber ip: 10.0.0.1, Source NAT pool: pool-name, Pool type: PBA, threshold: 90%, current: 100%
    • RT_SRC_NAT_SUBS_POOL_ALARM_CLEARRT_NAT: RT_SRC_NAT_SUBS_POOL_ALARM_CLEAR: Subscriber ip: 10.0.0.1, Source NAT pool: pool-name, Pool type: PBA, threshold: 50%, current: 25%
    • RT_SRC_NAT_SUBS_POOL_ALARM_RAISERT_NAT: RT_SRC_NAT_SUBS_POOL_ALARM_DAMPENING: Subscriber IP: 10.1.1.2, NAT pool: pool-name, threshold alarm [raise, clear] suppressed for 2 times in last 10 seconds

    [See jnxJsSrcNatSubThresholdStatus, jnxJsNAT, Monitor Subscriber Port Utilization Using Carrier Grade NAT, subscriber-pool-utilization-alarm, and pool-utilization-alarm (Security Source NAT Pool).]

  • Distinct NAT ports for the same IP address on PCP and DS-Lite (MX240, MX480, and MX960)―Junos OS Release 24.4R1 supports distinct NAT port and pool mapping for Port Control Protocol (PCP) and Dual-Stack Lite (DS-Lite).

    The PCP and DS-Lite can use the same NAT IP address with different port and NAT pools if the traffic originates from the same subscriber.

    Ensure that PCP and DS-Lite are configured with:

    • Address pooling, or address pooling paired (APP)

    • Endpoint independent mapping (EIM)

    • Endpoint independent filtering (EIF)

    You must configure the allow-distinct-port-pools at [set services nat source] hierarchy to assign same NAT IP address with different ports from different NAT pools.

    [See allow-distinct-port-pools, Port Control Protocol and IPv6 Dual-Stack Lite.]