F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question
An administrator configures a standard Virtual Server with a destination IP of 10.10.10.20:443, using a SNAT Pool instead of Auto Map. During peak hours, connections begin to fail because the SNAT pool only contains a single IP address and port exhaustion occurs. Which architectural adjustment best resolves this issue while maintaining security?
⚠ Common exam trap
Candidates often suggest replacing SNAT with direct routing or disabling it entirely during port exhaustion, compromising security policies instead of expanding the translation pool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add additional IP addresses to the existing SNAT pool to increase the total number of available ephemeral translation ports.
Expanding the SNAT pool by adding multiple IP addresses provides a larger translation address space and multiplies the available ephemeral port capacity per destination. This prevents port exhaustion during traffic spikes without sacrificing the controlled source IP mapping required by downstream security policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Switch the source address translation setting from SNAT Pool to Auto Map to leverage all available self IP addresses.
Why it's wrong here
Using Auto Map utilizes every floating and non-floating self IP address on the egress VLAN, which dramatically increases the pool of available source ports. However, this approach can expose unpredictable source IP addresses to backend servers, complicating firewall rules and security auditing.
- ✗
Increase the connection timeout profile value to allow closed connections to linger and free up sockets more gradually.
Why it's wrong here
Extending the idle timeout settings causes TCP connection states to remain active in memory longer. This exacerbates port exhaustion by preventing recycled ephemeral ports from becoming available for new client sessions during high-volume traffic bursts.
- ✓
Add additional IP addresses to the existing SNAT pool to increase the total number of available ephemeral translation ports.
Why this is correct
Adding more IP addresses directly scales the total translation capacity, as each IP provides approximately 64,000 source ports. This targeted mitigation preserves the defined egress IP range while successfully eliminating port exhaustion on the BIG-IP system.
- ✗
Configure a OneConnect profile on the virtual server to enable HTTP connection multiplexing across backend servers.
Why it's wrong here
OneConnect multiplexes client HTTP requests over fewer persistent server-side TCP connections, reducing backend server resource consumption. While this helps server-side port utilization, it does not directly resolve client-to-BIG-IP SNAT port exhaustion caused by high concurrent TCP sessions.
Visual reference
About these practice questions
One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official F5 exam blueprint
This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.