Outbound SNAT relies on these ephemeral ports. About 64,000 come with each public frontend IP and are shared among all backend pool members, so adding frontend IPs or a prefix is the only way to get more.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SNAT ports in context, with comparison tables and the common traps.
Terms in this definition
- SNAT
Translating the source address of a flow. Azure Firewall does this automatically to its public IP for outbound internet traffic, and NAT gateway supplies SNAT ports for outbound connections.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Backend pool
Targets of a load balancer, identified by IP address or NIC IP configuration. A pool can't span VNets, and a Standard load balancer won't accept a VM that has a Basic public IP.
- Get
Key Vault permission on secrets that allows a single secret to be read; App Service Key Vault references need nothing beyond it.
Related terms
- SNAT port exhaustion
Failures of outbound connections that occur once a source has no SNAT ports left for new flows to one destination. With NAT gateway, adding public IPs or a prefix resolves it.