If you configured Dynamic IP NAT, use the
show counter global filter aspect session severity drop | match nat
command
to see if any sessions failed due to NAT IP allocation. If all of
the addresses in the Dynamic IP NAT pool are allocated when a new
connection is supposed to be translated, the packet will be dropped.