< Home

nat full-cone global alarm ip-pool port-number threshold trap enable

Function

The nat full-cone global alarm ip-pool port-number threshold trap enable command enables the log and alarm function for the port usage of an address pool.

The undo nat full-cone global alarm ip-pool port-number threshold trap enable command disables the log and alarm function for the port usage of an address pool.

Format

nat full-cone global alarm ip-pool port-number threshold trap enable

undo nat full-cone global alarm ip-pool port-number threshold trap enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

In 3-tuple NAT scenarios, configure the function of sending port usage alarms to monitor address pool port usage. When the port usage in the 3-tuple address pool reaches a threshold, the FW sends an alarm and a log.

For example, the default smallest port allocatable for each address in the address pool is 2048, and the largest port is 65535. Then the number of allocatable ports for each address is 63488 (65535-2048+1). If the address pool has 10 IP addresses, there will be a total number of 63488 x 10 ports. When the number of used ports reaches 634880 x threshold-value, the FW will send a log and an alarm.

threshold-value can be set by the nat full-cone global alarm public-ip port-number threshold command.

By default, the port usage alarm sending function for the address pool is disabled.

Only the USG6510E/6510E-POE/6530E does not support this command.

Example

# Enable the port usage alarm sending function for the address pool.

<sysname> system-view
[sysname] nat full-cone global alarm ip-pool port-number threshold trap enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >