You can configure the BIG-IP® system to log information about carrier grade network address translation (CGNAT) processes and send the log messages to remote high-speed log servers.
When configuring remote high-speed logging (HSL) of CGNAT processes, it is helpful to understand the objects you need to create and why, as described here:
|Pool of remote log servers||Create a pool of remote log servers to which the BIG-IP system can send log messages.|
|Destination (unformatted)||Create a log destination of Remote High-Speed Log type that specifies a pool of remote log servers.|
|Destination (formatted)||If your remote log servers are the Splunk, IPFIX, or Remote Syslog type, create an additional log destination to format the logs in the required format and forward the logs to a remote high-speed log destination.|
|Publisher||Create a log publisher to send logs to a set of specified log destinations.|
|Logging Profile (optional)||Create a logging profile to configure logging options for various large scale NAT (LSN) events. The options apply to all HSL destinations.|
|LSN pool||Associate an LSN pool with a logging profile and log publisher in order to log messages about the traffic that uses the pool.|
This illustration shows the association of the configuration objects for remote high-speed logging of CGNAT processes.
Association of remote high-speed logging configuration objects
Create a log destination of the Remote High-Speed Log type to specify that log messages are sent to a pool of remote log servers.
Create a formatted logging destination to specify that log messages are sent to a pool of remote log servers, such as Remote Syslog, Splunk, or IPFIX servers.
|Start Outbound Session||Generates event log entries at the start of a translation event for an LSN client.|
|End Outbound Session||Generates event log entries at the end of a translation event for an LSN client.|
|Start Inbound Session||Generates event log entries at the start of an incoming connection event for a translated endpoint.|
|End Inbound Session||Generates event log entries at the end of an incoming connection event for a translated endpoint.|
|Quota Exceeded||Generates event log entries when an LSN client exceeds allocated resources.|
|Errors||Generates event log entries when LSN translation errors occur.|