If you configured Dynamic IP NAT, use the
show counter
global filter aspect session severity drop | match nat
command to see if any sessions failed due to NAT IP allocation. If all
of the addresses in the Dynamic IP NAT pool are allocated when a new
connection is supposed to be translated, the packet will be
dropped.